Public Self-Service Flow
Description
Configuration for a public self-service flow.
May be used by
Properties
Flow ID (
flowId) Description
Unique ID for this flow, which is used for selecting or referencing a flow.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Steps (
steps) Description
Steps of the flow.
Attributes
Plugin-List
Mandatory
Assignable plugins
Abort Step Acknowledge Message Step Airlock 2FA Activation Letter Order Step Airlock 2FA Delete Devices Step Airlock 2FA Public Self-Service Approval Step Cronto Approval Stealth Step Cronto Device Reset Step Cronto Letter Order Step Cronto Public Self-Service Approval Step Delete All Device Tokens Step Device Token Identity Verification Step Email Identity Verification Step Email Notification Step FIDO Public Self-Service Approval Step Failure Step Flow Continuation Step Flow Continuation Token Consumption Step Matrix Public Self-Service Approval Step No Operation Step OAuth 2.0 Session Reset Step Password Letter Order Step Password Reset Step Public Self-Service OATH OTP Approval Step Realm Assignment Step Red Flag Raising Step Remember-Me Reset Step SMS Identity Verification Step SSI Verification Step Scriptable Step Secret Questions Identity Verification Step Selection Step for Public Self-Service Send Email Link Step Tag Removal Step Unlock User Step (Public Self-Service) User Identification By Data Step (Public Self-Service) User Identification Step (Public Self-Service) User Lock Step Vasco OTP Public Self-Service Approval Step mTAN Public Self-Service Approval Step
Restrictions (
restrictions) Description
Restrictions to define which users are allowed to perform this public self-service. These restrictions are checked for each step of the flow. Typically, it is also possible to configure whether feedback to the user is enabled or not (user enumeration protection).
Attributes
Plugin-Link
Mandatory
Assignable plugins
Processors (
processors) Description
Processors are notified at various stages of the flow and offer hooks for custom logic.
Attributes
Plugin-Link
Optional
Assignable plugins
Custom Flow Processors Default Authentication Processors Default Authorization Processors Default One-Shot Authentication Processors Default Persistency-less Authentication Processors Default Persistency-less Protected Self-Service Processors Default Protected Self-Service Processors Default Public Self-Service Processors Default Technical Client Registration Processors Default Transaction Approval Processors Default User Self-Registration Processors
Username Transformers (
usernameTransformers) Description
Username transformers may transform the provided username into the single unique user ID required for the flow.
The transformation of a username takes place in the first step before the user is loaded. Note that username transformers have no effect on the propagated username value. Transformers can be chained, i.e. a first transformer could normalize the original name, where the next transformer looks up the normalized name in a database for potential transformation matches.
In contrary to the above description of chaining, a transformer can also signal that it already found the final user ID and the chain must stop after it.
For further details please refer to the documentation of the username transformer plugins.
The transformation of a username takes place in the first step before the user is loaded. Note that username transformers have no effect on the propagated username value. Transformers can be chained, i.e. a first transformer could normalize the original name, where the next transformer looks up the normalized name in a database for potential transformation matches.
In contrary to the above description of chaining, a transformer can also signal that it already found the final user ID and the chain must stop after it.
For further details please refer to the documentation of the username transformer plugins.
Attributes
Plugin-List
Optional
Assignable plugins
Initialize Next Auth Flow (
initializeNextAuthFlow) Description
If enabled, the next authentication flow after completing this public self-service flow will be initialized with the user identity and tags from the public self-service flow. By combining this feature with authentication flows where steps can be skipped based on tags from public self-service, a non-interactive authentication after completed public self-service can be achieved.
Information is propagated only if a user has been identified in the public flow.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: PublicSelfServiceFlow
id: PublicSelfServiceFlow-xxxxxx
displayName:
comment:
properties:
flowId:
initializeNextAuthFlow: false
processors:
restrictions:
steps:
usernameTransformers: