← Back to plugin index

Custom Protected Self-Service Flow

Description
Configuration for a custom protected self-service flow.
Type name
CustomProtectedSelfServiceFlow
Class
com.airlock.iam.selfservice.application.configuration.flow.CustomProtectedSelfServiceFlowConfig
May be used by
Properties
Flow ID (flowId)
Description
Unique ID for this flow, which is used for selecting or referencing a flow.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Steps (steps)
Description
Steps of the flow.
Attributes
Plugin-List
Mandatory
Assignable plugins
Abort Step Account Link Linking Initiation Step Account Link Removal Initiation Step Acknowledge Message Step Airlock 2FA Activation Step Airlock 2FA Activation Trusted Session Binding Step Airlock 2FA Delete Devices Step Airlock 2FA Device Deletion Initiation Step Airlock 2FA Device Edit Initiation Step Airlock 2FA Device Edit Step Airlock 2FA Recovery Trusted Session Binding Step Airlock 2FA Self-Service Approval Step Apply Changes Step Cronto Activation Step Cronto Device Reset Step Cronto Device Selection Step Cronto Letter Order Step Cronto Self-Service Approval Step CrontoSign Swiss Push Activation Step Delete All Device Tokens Step Delete Cronto Device Initiation Step Delete FIDO Credential Initiation Step Delete OAuth 2.0 Session Initiation Step Delete Remember-Me Device Initiation Step Delete mTAN Number Initiation Step Device Token Registration Step Disable Cronto Device Initiation Step Disable Cronto Push Initiation Step Disable FIDO Credential Initiation Step Email Change Verification Step Email Notification Step Enable Cronto Device Initiation Step Enable Cronto Push Initiation Step Enable FIDO Credential Initiation Step FIDO Credential Display Name Change Step FIDO Credential Selection Step FIDO Registration Step FIDO Self-Service Approval Step Failure Step Matrix Self-Service Approval Step No Operation Step OATH OTP Activation Step OAuth 2.0 Consent Deny Initiation Step OAuth 2.0 Consent Grant Initiation Step OAuth 2.0 Consents Delete Initiation Step OAuth 2.0 Session Reset Step Password Change Self-Service Step Password Letter Order Step Remember-Me Reset Step Rename Cronto Device Step SSI Issuance Step SSI Verification Step Scriptable Step Select mTAN Token Step Selection Step for Self-Service Set Context Data Step Start User Representation Step Stop User Representation Step Tag Removal Step User Data Edit Step User Lock Step Vasco OTP Device Activation Vasco OTP Self-Service Approval Step mTAN Self-Service Approval Step mTAN Token Edit Step mTAN Token Registration Step mTAN Verification Step
Access Condition (accessCondition)
Description

Precondition that must be fulfilled for a user to access this flow.

Note the difference to the "Authorization Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
Authorization Condition (authorizationCondition)
Description
Precondition that must be fulfilled for the user to be authorized to access this flow without further authentication. Note the difference to the "Access Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
Persistency-less (persistencyless)
Description

If enabled, this flow does not consider persistency, i.e. users don't have to exist locally in order to use a self-service. This is typically used with SSO tickets or external authentication using OAuth or SAML.

Persistency-less flows are very limited in their capabilities, in particular:

  • The user state (locked, invalid etc.) cannot be verified.
  • Flow steps editing user data will complete without failure but changed data is lost.

Note that configuration validation support is limited. It is essential to test such a flow extensively to ensure it behaves correctly in all situations.

It is recommended to use the "Default Persistency-less Protected Self-Service Processors" when using a persistency-less flow.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: CustomProtectedSelfServiceFlow
id: CustomProtectedSelfServiceFlow-xxxxxx
displayName: 
comment: 
properties:
  accessCondition:
  authorizationCondition:
  flowId:
  persistencyless: false
  processors:
  steps: