← Back to plugin index

Protected Self-Service Flows

Description

Settings for flow-based self-services via protected REST.

Note that self-service flows require an authenticated flow session which can only be obtained by successfully completing an authentication flow. Request credentials and API access control are not applicable here.

Type name
ProtectedSelfServiceFlows
Class
com.airlock.iam.selfservice.application.configuration.ProtectedSelfServiceFlowsConfig
May be used by
Properties
Max Failed Factor Attempts (maxFailedFactorAttempts)
Description
Maximal number of allowed attempts on a particular factor (like mTAN or Cronto). Factors are typically used to approve operations in self-service flows through a second channel. Whenever this limit is exceeded, the user is locked and the session is terminated. This is a global limit and it is enforced independently of how many retries a particular step allows.
Attributes
Integer
Optional
Default value
5
Legacy Response Behavior (legacyResponseBehavior)
Description
If enabled, unauthenticated requests to self-service flow endpoints will be answered with a 403 HTTP status code instead of 401. Additionally, an unauthenticated abort of a self-service flow will be answered with a 204 instead of 401. Enable this option if your clients rely on the undesired behavior of IAM 7.2.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: ProtectedSelfServiceFlows
id: ProtectedSelfServiceFlows-xxxxxx
displayName: 
comment: 
properties:
  flows:
  legacyResponseBehavior: false
  maxFailedFactorAttempts: 5