← Back to plugin index

Legacy mTAN Registration Flow

Description

Simple configuration for an mTAN registration self-service flow.

The following steps are automatically generated:

  • A User Data Edit Step (step ID "register-mtan") with an mTAN number item and optionally an mTAN label item.
  • An mTAN Verification Step
  • An Apply Changes Step

If more advanced features are needed, a Custom Protected Self-Service Flow can be configured.

Type name
DefaultMtanRegistrationFlow
Class
com.airlock.iam.selfservice.application.configuration.flow.DefaultMtanRegistrationFlowConfig
May be used by
Properties
Flow ID (flowId)
Description
Unique ID for this flow, which is used for selecting or referencing a flow.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Access Condition (accessCondition)
Description

Precondition that must be fulfilled for a user to access this flow.

Note the difference to the "Authorization Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
Authorization Condition (authorizationCondition)
Description
Precondition that must be fulfilled for the user to be authorized to access this flow without further authentication. Note the difference to the "Access Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
mTAN Settings (mtanSettings)
Description
Defines the settings for mTAN.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Number Key (numberKey)
Description
The key under which the client is expected to provide the number. The number will be a required field with a maximum length of 30 characters.
Attributes
String
Optional
Default value
mtanNumber
Label Key (labelKey)
Description
The key under which the client can provide the label. It will be an optional field with a maximum length of 30 characters. If left empty, only the number can be registered.
Attributes
String
Optional
Suggested values
mtanLabel
Message Provider (messageProvider)
Description
Creates the message for the verification SMS.
Attributes
Plugin-Link
Mandatory
Assignable plugins
mTAN Number Field Input Purpose (mtanNumberInputPurpose)
Description

The input purpose allows labeling data items using standardized values (see https://www.w3.org/TR/WCAG22/#input-purposes).

It is rendered using the HTML attribute "autocomplete". Browsers can use this to automatically fill input fields with data that was previously entered in other fields with the same purpose.

Note that the input purpose provided here will be used in the default Loginapp UI components and is available to custom single-page applications via the REST endpoints */info/retrieve.

If the Loginapp UI is used with configuration-based 'Customized Step UIs', the input purpose has to be defined on the UI elements ('Input UI Element', 'Drop-Down UI Element', 'Date UI Element').

Attributes
String
Optional
Suggested values
tel, tel-national, tel-local
mTAN Label Field Input Purpose (mtanLabelInputPurpose)
Description

The input purpose allows labeling data items using standardized values (see https://www.w3.org/TR/WCAG22/#input-purposes).

It is rendered using the HTML attribute "autocomplete". Browsers can use this to automatically fill input fields with data that was previously entered in other fields with the same purpose.

Note that the input purpose provided here will be used in the default Loginapp UI components and is available to custom single-page applications via the REST endpoints */info/retrieve.

If the Loginapp UI is used with configuration-based 'Customized Step UIs', the input purpose has to be defined on the UI elements ('Input UI Element', 'Drop-Down UI Element', 'Date UI Element').

Attributes
String
Optional
YAML Template (with default values)

type: DefaultMtanRegistrationFlow
id: DefaultMtanRegistrationFlow-xxxxxx
displayName: 
comment: 
properties:
  accessCondition:
  authorizationCondition:
  flowId:
  labelKey:
  messageProvider:
  mtanLabelInputPurpose:
  mtanNumberInputPurpose:
  mtanSettings:
  numberKey: mtanNumber