Default mTAN Token Registration Flow
Simple configuration for an mTAN token registration self-service flow.
The following steps are automatically generated:
- A mTAN Token Registration Step (step ID "register-mtan") to register the mTAN number and optionally also a label.
- An mTAN Verification Step to verify the new number by sending and verifying an OTP
- An Apply Changes Step
The access condition for the flow is always an mTAN Number Registration Possible.
If more advanced features are needed, a Custom Protected Self-Service Flow can be configured.
flowId) authorizationCondition) - Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
- Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
mtanSettings) labelRegistration) messageProvider) mtanNumberInputPurpose) The input purpose allows labeling data items using standardized values (see https://www.w3.org/TR/WCAG22/#input-purposes).
It is rendered using the HTML attribute "autocomplete". Browsers can use this to automatically fill input fields with data that was previously entered in other fields with the same purpose.
Note that the input purpose provided here will be used in the default Loginapp UI components and is available to custom single-page applications via the REST endpoints */info/retrieve.
If the Loginapp UI is used with configuration-based 'Customized Step UIs', the input purpose has to be defined on the UI elements ('Input UI Element', 'Drop-Down UI Element', 'Date UI Element').
mtanLabelInputPurpose) The input purpose allows labeling data items using standardized values (see https://www.w3.org/TR/WCAG22/#input-purposes).
It is rendered using the HTML attribute "autocomplete". Browsers can use this to automatically fill input fields with data that was previously entered in other fields with the same purpose.
Note that the input purpose provided here will be used in the default Loginapp UI components and is available to custom single-page applications via the REST endpoints */info/retrieve.
If the Loginapp UI is used with configuration-based 'Customized Step UIs', the input purpose has to be defined on the UI elements ('Input UI Element', 'Drop-Down UI Element', 'Date UI Element').
type: DefaultMtanTokenRegistrationFlow
id: DefaultMtanTokenRegistrationFlow-xxxxxx
displayName:
comment:
properties:
authorizationCondition:
flowId:
labelRegistration: true
messageProvider:
mtanLabelInputPurpose:
mtanNumberInputPurpose:
mtanSettings: