← Back to plugin index

Default Self-Unlock Restrictions

Description

Default restrictions for self-unlock flows. Currently, they are (in this order):

  • Nonexistent User Restriction
  • Invalid User Restriction
  • Locked User Restriction (only users with one of the configured "Allowed Lock Reasons" are allowed to perform self-unlock. Users that are not locked may still perform a self-unlock flow.)
  • Too Many Unlocks Restriction

By default, these restrictions do not report violations and therefore prevent user enumeration. To include custom restrictions or to configure restrictions for other types of self-service flows, the "Custom Public Self-Service Restrictions" plugin can be used.

Type name
DefaultSelfUnlockRestrictions
Class
com.airlock.iam.publicselfservice.application.configuration.restrictions.DefaultSelfUnlockRestrictionsConfig
May be used by
Properties
Nonexistent User Feedback (nonexistentUserFeedback)
Description

If enabled, nonexistent users attempting to start a self-unlock flow receive an error response with error code "USER_NOT_FOUND". Otherwise, the flow would also continue for nonexistent users but fail in the verification step (to protect against user enumeration).

Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.

Attributes
Boolean
Optional
Default value
false
Invalid User Feedback (invalidUserFeedback)
Description

If enabled, invalid users attempting to start a self-unlock flow receive an error response with error code "USER_INVALID". Otherwise, the flow would also continue for invalid users, but fail in the verification step (to protect against user enumeration).

Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.

Attributes
Boolean
Optional
Default value
false
Locked User Feedback (lockedUserFeedback)
Description

If enabled, locked users attempting to start a self-unlock flow receive an error response with error code "USER_LOCKED". Otherwise, the flow would also continue for locked users but fail in the verification step (to protect against user enumeration).

Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.

Attributes
Boolean
Optional
Default value
false
Too Many Unlock Feedback (tooManyUnlockFeedback)
Description

If enabled and the 'Public Self-Service Flow Settings' configuration has a 'Max Number of Unlocks' limit configured, locked users with more unlock attempts attempting to start a self-unlock flow receive an error response with error code "TOO_MANY_UNLOCKS". Otherwise, the flow would also continue for locked users but fail in the verification step (to protect against user enumeration).

Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.

Attributes
Boolean
Optional
Default value
false
Allowed Lock Reasons (allowedLockReasons)
Description

List of lock reasons that still allow the user to perform the self-unlock. Locked users with any lock reason not listed here will be rejected.

Note that a user is not automatically unlocked after a successful public self-service. A "Unlock User Step (Public Self-Service)" step has to be configured to perform this task.

Attributes
String-List
Optional
Default value
[LockReason.TooManyAuthAtts.PASSWORD]
YAML Template (with default values)

type: DefaultSelfUnlockRestrictions
id: DefaultSelfUnlockRestrictions-xxxxxx
displayName: 
comment: 
properties:
  allowedLockReasons: [LockReason.TooManyAuthAtts.PASSWORD]
  invalidUserFeedback: false
  lockedUserFeedback: false
  nonexistentUserFeedback: false
  tooManyUnlockFeedback: false