← Back to plugin index

Selection Step for Self-Service

Description
Selection between different subflows depending on configurable options.
Type name
SelectionStepConfigForSelfServiceFlows
Class
com.airlock.iam.selfservice.application.configuration.step.SelectionStepConfigForSelfServiceFlows
May be used by
Properties
Available Options (availableOptions)
Description
All available options for this selection. For each option, a condition can be configured that determines if it is available in a specific situation and for a particular user. If no option is available and a "Fallback Flow" is configured, it is executed, otherwise the step fails. If exactly one option is available, it could be selected automatically (see "Auto Select One Option" flag). If more than one option is available, the user is asked to interactively select one.
Attributes
Plugin-List
Mandatory
Assignable plugins
Auto Select Only Option (autoSelectOnlyOption)
Description
If only one option is available, it is selected automatically. Disable this setting to always present a choice to the user, even if there is only one option.
Attributes
Boolean
Optional
Default value
true
Fallback Flow (fallbackFlow)
Description
Fallback flow that is executed if none of the other options are available. If no fallback flow is configured and no option is fulfilled, the selection fails. To do nothing as a fallback, a flow with a "No Operation Step" can be configured.
Attributes
Plugin-List
Optional
Assignable plugins
Abort Step Account Link Linking Initiation Step Account Link Removal Initiation Step Acknowledge Message Step Airlock 2FA Activation Letter Order Step Airlock 2FA Activation Step Airlock 2FA Activation Step (with additional Activation) Airlock 2FA Activation Trusted Session Binding Step Airlock 2FA Authentication Step Airlock 2FA Delete Devices Step Airlock 2FA Device Deletion Initiation Step Airlock 2FA Device Edit Initiation Step Airlock 2FA Device Edit Step Airlock 2FA Mobile Only Authentication Step Airlock 2FA Public Self-Service Approval Step Airlock 2FA Recovery Trusted Session Binding Step Airlock 2FA Self-Service Approval Step Airlock 2FA Transaction Approval Step Airlock 2FA Usernameless Authentication Step Apply Changes Step Certificate Credential Extraction Step Complete Migration Step Cronto Activation Step Cronto Approval Stealth Step Cronto Authentication Step Cronto Device Reset Step Cronto Device Selection Step Cronto Letter Order Step Cronto Public Self-Service Approval Step Cronto Self-Service Approval Step Cronto Transaction Approval Step CrontoSign Swiss Push Activation Step Delete All Device Tokens Step Delete Cronto Device Initiation Step Delete FIDO Credential Initiation Step Delete OAuth 2.0 Session Initiation Step Delete Remember-Me Device Initiation Step Delete mTAN Number Initiation Step Device Token Authentication Step Device Token Identity Verification Step Device Token Registration Step Disable Cronto Device Initiation Step Disable Cronto Push Initiation Step Disable FIDO Credential Initiation Step Email Change Verification Step Email Identity Verification Step Email Notification Step Email OTP Authentication Step Email OTP Transaction Approval Step Email Verification Step Enable Cronto Device Initiation Step Enable Cronto Push Initiation Step Enable FIDO Credential Initiation Step FIDO Authentication Step FIDO Credential Display Name Change Step FIDO Credential Selection Step FIDO Passwordless Authentication Step FIDO Public Self-Service Approval Step FIDO Registration Step FIDO Self-Service Approval Step FIDO Transaction Approval Step Failure Step Flow Continuation Step Flow Continuation Token Consumption Step HTTP Basic Authentication Step Kerberos Authentication Step Legacy Email OTP Authentication Step Login From New Device Step Mandatory Password Change Step Matrix Checking Step Matrix Public Self-Service Approval Step Matrix Self-Service Approval Step Migration Selection Step Missing Account Link Step Never Migrate Step No Operation Step OATH OTP Activation Step OATH OTP Authentication Step OAuth 2.0 Client Persisting Step OAuth 2.0 Client Registration Step OAuth 2.0 Consent Deny Initiation Step OAuth 2.0 Consent Grant Initiation Step OAuth 2.0 Consent Step OAuth 2.0 Consents Delete Initiation Step OAuth 2.0 SSO Step OAuth 2.0 Session Reset Step OTP Check via RADIUS Step Password Change Self-Service Step Password Letter Order Step Password Reset Step Password-only Authentication Step Phone Number Verification Step Public Self-Service OATH OTP Approval Step Realm Assignment Step Red Flag Raising Step Remember-Me Reset Step Remember-Me Token Generating Step Remember-Me User Identifying Step Rename Cronto Device Step Representation SSO Ticket Identifying Step Risk Assessment Step Role-based Tag Acquisition Step SAML 2.0 SP User Identifying Step SMS Identity Verification Step SSI Authentication Step SSI Issuance Step SSI Passwordless Authentication Step SSI Self-Registration Issuance Step SSI Verification Step SSO Ticket Authentication Step Scriptable Step Secret Questions Identity Verification Step Secret Questions Provisioning Step Select mTAN Token Step Selection Step Selection Step for Public Self-Service Selection Step for Self-Service Selection Step for User Self-Registration Send Email Link Step Set Authentication Method Migration Step Set Authentication Method Step Set Context Data Step Set Password Step Start User Representation Step Stop User Representation Step Tag Removal Step Terms Of Services Step Transaction Approval Parameter Step Unlock User Step (Public Self-Service) User Data Edit Step User Data Registration Step User Identification By Data Step User Identification By Data Step (Public Self-Service) User Identification Step User Identification Step (Public Self-Service) User Identification with FIDO Authentication Step User Lock Step User Persisting Step User Role Assignment Step User Unlock Step (Self-Registration) Username Generation Step Username Password Authentication Step Username Password with FIDO Authentication Step Vasco OTP Authentication Step Vasco OTP Device Activation Vasco OTP Public Self-Service Approval Step Vasco OTP Self-Service Approval Step Voluntary Password Change Step mTAN Authentication Step mTAN Public Self-Service Approval Step mTAN Self-Service Approval Step mTAN Token Edit Step mTAN Token Registration Step mTAN Transaction Approval Step mTAN Verification Step
Last Selection Repository (lastSelectionRepository)
Description
A repository which persists, per user, the last interactive selection made in this step. If this repository is configured, a step ID is mandatory as the selection is identified by the step ID among other things. This also means that the last selection is lost if the step ID is altered. If a last selection is found in the repository, the corresponding option is marked in the REST response and preselected in the UI.
Attributes
Plugin-Link
Optional
Assignable plugins
Interactive Goto Targets (interactiveGotoTargets)
Description
Manually selectable Goto targets. These are steps to which the user can chose to jump when this is the current flow step.
Attributes
Plugin-List
Optional
Assignable plugins
Dynamic Step Activations (dynamicStepActivations)
Description
Steps that can be dynamically activated while in this step.
Attributes
Plugin-List
Optional
Assignable plugins
Skip Condition (skipCondition)
Description

If this condition is configured and fulfilled, the step is skipped and the flow execution continues with the subsequent step.

Attributes
Plugin-Link
Optional
Assignable plugins
Pre Condition (preCondition)
Description
This step is executed only if the configured pre condition is fulfilled. If the condition is not fulfilled, the step and flow execution fail immediately. The step is not initialized and no step method can be called. If no condition is configured, the behavior is that of a fulfilled pre condition.
Attributes
Plugin-Link
Optional
Assignable plugins
Requires Activation (requiresActivation)
Description
If enabled, this step is only executed if it has been dynamically activated from a previous step. If it has not been activated, the step is skipped (equivalent to when the skip condition is fulfilled).
Attributes
Boolean
Optional
Default value
false
Step ID (stepId)
Description
ID of this step. This is only needed if this step is the target of a goto action or if this step requires activation.
Attributes
Plugin-Link
Optional
Assignable plugins
On Failure Gotos (onFailureGotos)
Description

If the step fails (no retry) and a goto target for the error code is defined here, the flow does not fail and instead a "goto" to the specified target step is executed. Note that even when the "goto" is executed, any error codes that are considered a failed factor attempt will still increment the "failed attempts" counter, and may lead to the user being locked. Therefore, this may still result in a failed flow.

A typical application of this feature is switching to an alternative authentication factor step, if an external service (e.g. Futurae server, SMS gateway) is not available (error code EXTERNAL_SERVICE_UNAVAILABLE with "Strict Counting" disabled, which will not increment the "failed attempts" counter). Other error codes can be found in the IAM REST documentation, in both the general "Error Codes" section and in the documentation of specific endpoints.

Attributes
Plugin-Map
Optional
Assignable plugins
Custom Response Attributes (customResponseAttributes)
Description

A list of custom attributes that are returned in the REST response in addition to the standard attributes the step already returns. The custom attributes defined here are only returned if the step result does not lead to an error response.

Custom attributes are added to the response when a step is initialized and when actions are executed on the step. They will therefore be available in the response leading to this step, and in any responses from endpoints specific to this step. For non-interactive steps, custom attributes are accumulated and added to the response leading to the next interactive step.

Custom attributes are not returned for 'retrieve' endpoints.

Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: SelectionStepConfigForSelfServiceFlows
id: SelectionStepConfigForSelfServiceFlows-xxxxxx
displayName: 
comment: 
properties:
  autoSelectOnlyOption: true
  availableOptions:
  customFailureResponseAttributes:
  customResponseAttributes:
  dynamicStepActivations:
  fallbackFlow:
  interactiveGotoTargets:
  lastSelectionRepository:
  onFailureGotos:
  preCondition:
  requiresActivation: false
  skipCondition:
  stepId: