Custom Protected Self-Service Flow
Description
Configuration for a custom protected self-service flow.
May be used by
Properties
Flow ID (
flowId) Description
Unique ID for this flow, which is used for selecting or referencing a flow.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Steps (
steps) Description
Steps of the flow.
Attributes
Plugin-List
Mandatory
Assignable plugins
Abort Step Account Link Linking Initiation Step Account Link Removal Initiation Step Acknowledge Message Step Airlock 2FA Activation Step Airlock 2FA Activation Trusted Session Binding Step Airlock 2FA Delete Devices Step Airlock 2FA Device Deletion Initiation Step Airlock 2FA Device Edit Initiation Step Airlock 2FA Device Edit Step Airlock 2FA Recovery Trusted Session Binding Step Airlock 2FA Self-Service Approval Step Apply Changes Step Cronto Activation Step Cronto Device Reset Step Cronto Device Selection Step Cronto Letter Order Step Cronto Self-Service Approval Step CrontoSign Swiss Push Activation Step Delete All Device Tokens Step Delete Cronto Device Initiation Step Delete FIDO Credential Initiation Step Delete OAuth 2.0 Session Initiation Step Delete Remember-Me Device Initiation Step Delete mTAN Number Initiation Step Device Token Registration Step Disable Cronto Device Initiation Step Disable Cronto Push Initiation Step Disable FIDO Credential Initiation Step Email Change Verification Step Email Notification Step Enable Cronto Device Initiation Step Enable Cronto Push Initiation Step Enable FIDO Credential Initiation Step FIDO Credential Display Name Change Step FIDO Credential Selection Step FIDO Registration Step FIDO Self-Service Approval Step Failure Step Matrix Self-Service Approval Step No Operation Step OATH OTP Activation Step OAuth 2.0 Consent Deny Initiation Step OAuth 2.0 Consent Grant Initiation Step OAuth 2.0 Consents Delete Initiation Step OAuth 2.0 Session Reset Step Password Change Self-Service Step Password Letter Order Step Remember-Me Reset Step Rename Cronto Device Step SSI Issuance Step SSI Verification Step Scriptable Step Select mTAN Token Step Selection Step for Self-Service Set Context Data Step Start User Representation Step Stop User Representation Step Tag Removal Step User Data Edit Step User Lock Step Vasco OTP Device Activation Vasco OTP Self-Service Approval Step mTAN Self-Service Approval Step mTAN Token Edit Step mTAN Token Registration Step mTAN Verification Step
Access Condition (
accessCondition) Description
Precondition that must be fulfilled for a user to access this flow.
Note the difference to the "Authorization Condition":- Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
- Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
Account Linking Required Red Flag Condition Active Authentication Method Airlock 2FA Device Deletion Possible Airlock 2FA was used for login (Transaction Approval only) Always False Always True Boolean Condition Cronto Activation Possible Cronto Activation Required Cronto Device Removal Possible Cronto Letter Order Condition Cronto was used for login (Transaction Approval only) CrontoSign Swiss Push Activation Possible Email OTP was used for login (Transaction Approval only) FIDO Credential Removal Possible FIDO was used for login (Transaction Approval only) First Usage of Device Has Cronto Account Has Cronto Device Has Device Token Has Email Address Has FIDO Credential Has Matching Role Has Matrix Card Has OATH OTP Token Has Password Has Suitable Airlock 2FA Device Has Tag Has Vasco OTP Token Has mTAN Activation Letter Has mTAN Token IdP-Initiated SSO Flow On SP Logical AND Logical NOT Logical OR Matching Username Never Migrate Possible New Device Condition Next Authentication Method-based Migration Condition OAuth 2.0 Authorization Code Grant In Progress OIDC prompt=none Condition Password Letter Order Interval Condition Public Self-Service Allowed Condition Red Flag Raised Request Has SSO Ticket Step Activated String Regex Condition User Attribute Is Unique User Identified User Represented Condition Vasco Activation Possible mTAN Number Changed mTAN Number Deletion Possible mTAN Number Registration Possible mTAN was used for login (Transaction Approval only)
Authorization Condition (
authorizationCondition) Description
Precondition that must be fulfilled for the user to be authorized to access this flow without further authentication. Note the difference to the "Access Condition":
- Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
- Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
Account Linking Required Red Flag Condition Active Authentication Method Airlock 2FA Device Deletion Possible Airlock 2FA was used for login (Transaction Approval only) Always False Always True Boolean Condition Cronto Activation Possible Cronto Activation Required Cronto Device Removal Possible Cronto Letter Order Condition Cronto was used for login (Transaction Approval only) CrontoSign Swiss Push Activation Possible Email OTP was used for login (Transaction Approval only) FIDO Credential Removal Possible FIDO was used for login (Transaction Approval only) First Usage of Device Has Cronto Account Has Cronto Device Has Device Token Has Email Address Has FIDO Credential Has Matching Role Has Matrix Card Has OATH OTP Token Has Password Has Suitable Airlock 2FA Device Has Tag Has Vasco OTP Token Has mTAN Activation Letter Has mTAN Token IdP-Initiated SSO Flow On SP Logical AND Logical NOT Logical OR Matching Username Never Migrate Possible New Device Condition Next Authentication Method-based Migration Condition OAuth 2.0 Authorization Code Grant In Progress OIDC prompt=none Condition Password Letter Order Interval Condition Public Self-Service Allowed Condition Red Flag Raised Request Has SSO Ticket Step Activated String Regex Condition User Attribute Is Unique User Identified User Represented Condition Vasco Activation Possible mTAN Number Changed mTAN Number Deletion Possible mTAN Number Registration Possible mTAN was used for login (Transaction Approval only)
Processors (
processors) Description
Processors are notified at various stages of the flow and offer hooks for custom logic.
Attributes
Plugin-Link
Optional
Assignable plugins
Custom Flow Processors Default Authentication Processors Default Authorization Processors Default One-Shot Authentication Processors Default Persistency-less Authentication Processors Default Persistency-less Protected Self-Service Processors Default Protected Self-Service Processors Default Public Self-Service Processors Default Technical Client Registration Processors Default Transaction Approval Processors Default User Self-Registration Processors
Persistency-less (
persistencyless) Description
If enabled, this flow does not consider persistency, i.e. users don't have to exist locally in order to use a self-service. This is typically used with SSO tickets or external authentication using OAuth or SAML.
Persistency-less flows are very limited in their capabilities, in particular:
- The user state (locked, invalid etc.) cannot be verified.
- Flow steps editing user data will complete without failure but changed data is lost.
Note that configuration validation support is limited. It is essential to test such a flow extensively to ensure it behaves correctly in all situations.
It is recommended to use the "Default Persistency-less Protected Self-Service Processors" when using a persistency-less flow.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: CustomProtectedSelfServiceFlow
id: CustomProtectedSelfServiceFlow-xxxxxx
displayName:
comment:
properties:
accessCondition:
authorizationCondition:
flowId:
persistencyless: false
processors:
steps: