← Back to plugin index

Default FIDO Credential Removal Flow

Description

Simple configuration for a FIDO credential removal self-service flow.

The following steps are automatically generated:

  • A Delete FIDO Credential Initiation Step.
  • An Apply Changes Step

If more advanced features are needed, a Custom Protected Self-Service Flow can be configured.

Type name
DefaultFidoCredentialDeletionFlow
Class
com.airlock.iam.selfservice.application.configuration.flow.DefaultFidoCredentialDeletionFlowConfig
May be used by
License-Tags
FIDO
Properties
Flow ID (flowId)
Description
Unique ID for this flow, which is used for selecting or referencing a flow.
Attributes
Plugin-Link
Mandatory
Assignable plugins
FIDO Settings (fidoSettings)
Description
Settings for FIDO.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Allow Deleting Last Credential (allowDeletingLastCredential)
Description
If enabled, the last credential can be deleted. This can leave the user without a means to login again.
Attributes
Boolean
Optional
Default value
false
Authorization Condition (authorizationCondition)
Description
Precondition that must be fulfilled for the user to be authorized to access this flow without further authentication. The "Access Condition" is always the FIDO Credential Removal Possible. Note the difference to the "Access Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: DefaultFidoCredentialDeletionFlow
id: DefaultFidoCredentialDeletionFlow-xxxxxx
displayName: 
comment: 
properties:
  allowDeletingLastCredential: false
  authorizationCondition:
  fidoSettings:
  flowId: