Target URI Resolver
Description
Uses the original forward location (extracted from the URI parameter 'Location') to resolve the target URI for identity propagation.
If the original forward location matches any of the allowed URI patterns, the forward location is passed to the chain of URI transformers, where it gets transformed to the target URI to be used for identity propagation. If none of the allowed URI pattern matches the forward location, the default value is instead passed to the transformation chain. If any of the URI transformers vetoes the transformation, the default value is provided as target URI.
This is typically used to allow or block certain deep links into target applications and to add information to the URI like a language parameter.
Properties
Default Value (
defaultValue) Description
The default URI to be used as input for transformation if the original forward location is not allowed. This URI is also used if an URI transformer produces a veto.
Attributes
String
Mandatory
Example
/
Example
https://domain.com/public
Allowed URIs (
allowedURIs) Description
A list of regular expressions defining the allowed forward locations.
If the authentication flow was started using such a location, its value is matched against the specified list of allowed location parameter patterns. If at least one matches, the location parameter is accepted. If not, it is not accepted and the "Default Value" is used instead.
If the authentication flow was started using such a location, its value is matched against the specified list of allowed location parameter patterns. If at least one matches, the location parameter is accepted. If not, it is not accepted and the "Default Value" is used instead.
- If left empty, any provided location is ignored and the default value is always used.
- To only allow context relative locations (starting with a slash), the pattern "/(?!/).*" should be used. The pattern "/.*" is not sufficient as it allows URLs starting with "//" which can be used to specify an absolute URL including a domain. See also CVE-2013-2764.
- Note that forward locations provided by Airlock Gateway (WAF) always contain the full URL including protocol and hostname. It is therefore usually necessary to add a pattern for the application specific URLs, e.g. "https?://example\.com/my-path/.*".
- Note that URLs with any 'User Information' part in front of the host name (for example "https://user@domain.com/") are never accepted.
- Security warning: The provided forward location may contain arbitrary user input! It is therefore highly recommended that the configured patterns be as restrictive as possible. Overly lax patterns like '.*' expose Airlock IAM and the target application to severe attacks, e.g.: open redirect, server-side request forgery and injection attacks (SQL, XSS, etc ...). Such patterns are therefore not allowed.
- Security warning: Unescaped dots in URLs match any single character in RegExes. If unescaped dots are used by mistake, this can be exploited for attacks! E.g.: If pattern "https://subdomain.example.com/.*" is configured, attackers can register "subdomain-example.com" which will be allowed by this pattern.
Attributes
RegEx-List
Optional
URI Transformers (
uriTransformers) Description
The chain of URI transformers that transform the forward location to the provided target URI.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)
type: TargetURIResolver
id: TargetURIResolver-xxxxxx
displayName:
comment:
properties:
allowedURIs:
defaultValue:
uriTransformers: