User Self-Service Settings
Settings for session-less user self-services. In contrast to the "Protected Self-Services" these self-services don't require an authenticated session. Instead, each request must contain authentication information, as defined by the "API Access Control" settings.
These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/.
passwordSettings) Configures the session-less password change REST endpoint /<loginapp-uri>/rest/protected/my/password/change/ by using the "Password Service" and the "Password Policy" plugins from the referenced "Password Settings" plugin.
Deprecated: The session-less password self-service endpoints are deprecated and will be removed in a future IAM version. Use protected self-service flows instead.
enablePasswordPolicyCheck) Enables the public REST endpoint to check passwords against the policy configured in the configured "Password Settings" plugin.
Password policy checks are not applicable when using end-to-end encrypted passwords.
REST endpoint: /<loginapp-uri>/rest/public/password/policy/check/
userInformationSelfService) /<loginapp-uri>/rest/protected/my/self/. mtanSelfService) Configures the protected session-less REST endpoints used to manage mobile phone numbers for mTAN authentication.
REST endpoints: /<loginapp-uri>/rest/protected/my/tokens/mtan/*
Deprecated: The session-less mTAN self-service endpoints are deprecated and will be removed in a future IAM version. Use protected self-service flows instead.
crontoSelfService) Configures the protected session-less REST endpoints used to manage Cronto tokens.
REST endpoints: /<loginapp-uri>/rest/protected/my/tokens/cronto/*
Deprecated: The session-less Cronto self-service endpoints are deprecated and will be removed in a future IAM version. Use protected self-service flows instead.
type: UserSelfService
id: UserSelfService-xxxxxx
displayName:
comment:
properties:
crontoSelfService:
enablePasswordPolicyCheck: false
mtanSelfService:
passwordSettings:
userInformationSelfService: