← Back to plugin index

Remember-Me Device List

Description
Configures the Remember-Me device list REST self-service. Additional self-service functionality can be configured in "Protected Self-Service Flows".
Type name
RememberMeDeviceListSelfServiceRest
Class
com.airlock.iam.selfservice.application.configuration.rememberme.RememberMeDeviceListSelfServiceRestConfig
May be used by
Properties
Remember-Me Settings (rememberMeConfig)
Description
Common configuration for the Remember-Me feature.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Include Geolocation (includeGeolocation)
Description
If enabled, the geolocation data of Remember-Me devices is included. For privacy reasons, it may be desirable to disable this feature.
Attributes
Boolean
Optional
Default value
false
Include IP Address (includeIpAddress)
Description
If enabled, the IP address of Remember-Me devices is included. For privacy reasons, it may be desirable to disable this feature.
Attributes
Boolean
Optional
Default value
false
User-Agent Mapping (userAgentMappings)
Description
If configured, the listed devices contain the result of this mapping in addition to the original user-agent header. The mappings are processed in order and the first matching mapping is used. If none matches, no display value is provided. This may be useful in cases where a non-standard user-agent header is present and a specific display value is desired.

The Loginapp UI will use this value if available. Otherwise, the UI tries to display the user-agent header in a compact representation.

Attributes
Plugin-List
Optional
Assignable plugins
Access Condition (accessCondition)
Description

Precondition that must be fulfilled for a user to access the Remember-Me device list.

Note the difference to the "Authorization Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
Authorization Condition (authorizationCondition)
Description

Precondition that must be fulfilled for the user to be authorized to access the Remember-Me device list without further authentication.

Note the difference to the "Access Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: RememberMeDeviceListSelfServiceRest
id: RememberMeDeviceListSelfServiceRest-xxxxxx
displayName: 
comment: 
properties:
  accessCondition:
  authorizationCondition:
  includeGeolocation: false
  includeIpAddress: false
  rememberMeConfig:
  userAgentMappings: