Protected Self-Service Flows
Description
Settings for flow-based self-services via protected REST.
Note that self-service flows require an authenticated flow session which can only be obtained by successfully completing an authentication flow. Request credentials and API access control are not applicable here.
May be used by
Properties
Flows (
flows) Description
The list of available self-service flows.
Attributes
Plugin-List
Mandatory
Assignable plugins
Custom Protected Self-Service Flow Default Account Link Linking Flow Default Account Link Removal Flow Default Cronto Device Removal Flow Default Cronto Device Renaming Flow Default Disable Cronto Device Flow Default Disable Cronto Push Flow Default Disable FIDO Credential Flow Default Enable Cronto Device Flow Default Enable Cronto Push Flow Default Enable FIDO Credential Flow Default FIDO Credential Display Name Change Flow Default FIDO Credential Removal Flow Default OAuth 2.0 Consent Deny Flow Default OAuth 2.0 Consent Grant Flow Default OAuth 2.0 Consents Delete Flow Default OAuth 2.0 Session Deletion Flow Default Remember-Me Device Deletion Flow Default mTAN Deletion Flow Default mTAN Token Edit Flow Default mTAN Token Registration Flow Legacy mTAN Registration Flow
Max Failed Factor Attempts (
maxFailedFactorAttempts) Description
Maximal number of allowed attempts on a particular factor (like mTAN or Cronto). Factors are typically used to approve operations in self-service flows through a second channel. Whenever this limit is exceeded, the user is locked and the session is terminated. This is a global limit and it is enforced independently of how many retries a particular step allows.
Attributes
Integer
Optional
Default value
5
Legacy Response Behavior (
legacyResponseBehavior) Description
If enabled, unauthenticated requests to self-service flow endpoints will be answered with a 403 HTTP status code instead of 401. Additionally, an unauthenticated abort of a self-service flow will be answered with a 204 instead of 401. Enable this option if your clients rely on the undesired behavior of IAM 7.2.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: ProtectedSelfServiceFlows
id: ProtectedSelfServiceFlows-xxxxxx
displayName:
comment:
properties:
flows:
legacyResponseBehavior: false
maxFailedFactorAttempts: 5