← Back to plugin index

Account Linking Lists Self Services

Description
Configures the account link and provider list REST APIs. Additional self-service functionality can be configured in "Protected Self-Service Flows". Requires an Account Link Persister in OAuth 2.0/OIDC Client settings.
Type name
AccountLinkingListsSelfServiceRest
Class
com.airlock.iam.selfservice.application.configuration.token.AccountLinkingListsSelfServiceRestConfig
May be used by
License-Tags
OAuthAccountLinking
Properties
Access Condition (accessCondition)
Description

Precondition that must be fulfilled for a user to access the account link and provider list.

Note the difference to the "Authorization Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
Authorization Condition (authorizationCondition)
Description
Precondition that must be fulfilled for the user to be authorized to access the account link and provider list without further authentication. Note the difference to the "Access Condition":
  • Access Condition: This condition determines whether a user is allowed to access a service at all. If this condition is not fulfilled, there is nothing that can be done (at least not immediately). Typical examples include having a certain authentication token, or a certain static role. This condition is always checked before the Authorization Condition and if it fails, the REST response has status 403 with error code PRECONDITION_NOT_FULFILLED.
  • Authorization Condition: This condition determines whether the user is currently authorized to access a service. It is expected that completing another authentication flow (step-up) would enable the user to then fulfill the condition. The typical authorization condition checks whether the user has obtained a certain tag (or combination of tags). If the condition fails, the REST response has status 403 with error code NOT_AUTHORIZED.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: AccountLinkingListsSelfServiceRest
id: AccountLinkingListsSelfServiceRest-xxxxxx
displayName: 
comment: 
properties:
  accessCondition:
  authorizationCondition: