← Back to plugin index

Locked User Restriction

Description
Does not allow locked users to perform public self-services, unless the lock reason is one of the white-listed reasons (see property "Allowed Lock Reasons").
Type name
LockedUserRestriction
Class
com.airlock.iam.publicselfservice.application.configuration.restrictions.LockedUserRestrictionConfig
May be used by
Properties
Allowed Lock Reasons (allowedLockReasons)
Description

List of lock reasons that still allow the user to perform public self-services. Locked users with any lock reason not listed here will not be allowed to perform public self-services.

Note that a user is not automatically unlocked after a successful public self-service. A "Unlock User Step (Public Self-Service)" step has to be configured to perform this task.

Attributes
String-List
Optional
Enable Feedback (enableFeedback)
Description

If enabled, the User Identification Step always returns a specific error code in case this restriction is violated.

If no restrictions are configured to provide feedback, a flow can also be started for users violating one or more restrictions and the flow will advance to the user identity verification step in stealth mode. In this mode, the initial behavior of the step is the same as for unrestricted users (e.g. an mTAN OTP is required), but all responses are rejected as if they were incorrect. This behavior prevents restricted users from ever proceeding further in the flow and thus offers protection against user enumeration. Please refer to the documentation for more details.

Irrespective of this settings, once the identity verification step is passed, restriction are always checked before and after each method call and violations are always reported.

Security notice: Enabling this feature might allow a client to determine whether certain users exist in the system.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: LockedUserRestriction
id: LockedUserRestriction-xxxxxx
displayName: 
comment: 
properties:
  allowedLockReasons:
  enableFeedback: false