← Back to plugin index

Nonexistent User Restriction

Description
Ensures that for users that don't exist, public self-service continues in Stealth Mode (simulating the next step), or that they are immediately rejected (if the "Enable Feedback" property is enabled).
Type name
NonexistentUserRestriction
Class
com.airlock.iam.publicselfservice.application.configuration.restrictions.NonexistentUserRestrictionConfig
May be used by
Properties
Enable Feedback (enableFeedback)
Description

If enabled, the User Identification Step always returns a specific error code in case this restriction is violated.

If no restrictions are configured to provide feedback, a flow can also be started for users violating one or more restrictions and the flow will advance to the user identity verification step in stealth mode. In this mode, the initial behavior of the step is the same as for unrestricted users (e.g. an mTAN OTP is required), but all responses are rejected as if they were incorrect. This behavior prevents restricted users from ever proceeding further in the flow and thus offers protection against user enumeration. Please refer to the documentation for more details.

Irrespective of this settings, once the identity verification step is passed, restriction are always checked before and after each method call and violations are always reported.

Security notice: Enabling this feature might allow a client to determine whether certain users exist in the system.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: NonexistentUserRestriction
id: NonexistentUserRestriction-xxxxxx
displayName: 
comment: 
properties:
  enableFeedback: false