← Back to plugin index

Session-less REST Endpoints

Description

Configures protected session-less endpoints of the Loginapp REST API. These endpoints require authentication credentials attached to each request, but don't require previous authentication with a flow.

These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/.

For most of the session-less protected REST APIs, there is a corresponding flow-based API in the protected self-service REST APIs. Whenever possible, prefer the flow-based variant over the session-less configured here.

Type name
SessionlessRestEndpoints
Class
com.airlock.iam.login.rest.application.configuration.LoginappRestConfig
May be used by
Properties
User Self-Service Settings (userSelfServiceSettings)
Description

Configures session-less user self-service REST endpoints.

These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/.

Attributes
Plugin-Link
Optional
Assignable plugins
User Token Settings (userTokenSettings)
Description

Configures session-less token REST endpoints related to user tokens.

These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/tokens/.

Attributes
Plugin-Link
Optional
Assignable plugins
Request Authentication (requestAuthentication)
Description
Determines how a credential is extracted and used to authenticate single requests.

This property is only effective for the protected Loginapp REST API outside of the "self-service" sub-path.

Attributes
Plugin-Link
Optional
Assignable plugins
Request Authorization (accessController)
Description
Controls how authenticated users can access and modify resources. When no access controller is configured, all authenticated incoming requests are per default authorized.

This property is only effective for the protected Loginapp REST API outside of the "self-service" sub-path.

Attributes
Plugin-Link
Optional
Assignable plugins
Username Transformation (usernameTransformers)
Description
Transforms user name aliases into real user names for these REST endpoints. This allows for e.g. the email to be used instead of the username.

Transformation is done for:

  • Resource URLs: the user id in the REST resource URL (e.g. in self-registration) is transformed before further processing is done.
  • Authentication: for protected calls, the username of the provided credential (request credential policy) is transformed before passing it to the configured authenticator.

Attributes
Plugin-List
Optional
Assignable plugins
Link Response Rewriting (linkResponseRewritingEnabled)
Description
Enables rewriting of links in REST responses. If rewriting is disabled or cannot be done correctly due to missing information, the internal URI is written to the response.

If a 'Base URI' is configured, links are rewritten according to the configured value. Otherwise, links are rewritten according to the external view provided by the WAF (if configured an a WAF environment cookie is present).

Attributes
Boolean
Optional
Default value
true
Base URI (baseUri)
Description
Allows to change the base URI for all links in REST responses.

This property is useful in test environments where you want links contained in REST responses to be relative to the configured base URI. Note that configuring this property will take precedence over link rewriting based on the WAF environment cookie.

In order to produce correct links, the property must be configured up to and including the /rest subpath. IAM will automatically append public to the configured value for calls to the public API and protected for calls to the protected API of the Loginapp (or oauth2 for OAuth 2.0/OpenId Connect endpoints).

Example:

  • Property value: http://myhost:8090/test/rest
  • The response from the REST call to /<loginapp-uri>/rest/public/users/register will contain a link to http://myhost:8090/test/rest/protected/my/self

Attributes
String
Optional
Validation RegEx: .*(?
Example
https://myhost:8090/test/rest
YAML Template (with default values)

type: SessionlessRestEndpoints
id: SessionlessRestEndpoints-xxxxxx
displayName: 
comment: 
properties:
  accessController:
  baseUri:
  linkResponseRewritingEnabled: true
  requestAuthentication:
  userSelfServiceSettings:
  userTokenSettings:
  usernameTransformers: