← Back to plugin index

Credential Report Task

Description
This task plug-in iterates over user or credential records and - if certain conditions are met - executes a report renderer on the user (or credential). It is thought to produce for example letters for newly issued tokens or other credentials.

The task uses a user iterator plug-in to go through the set of users or credential records and looks at a specific flag telling this plug-in that a report should be rendered for the user (or credential). If the flag is set, the "delivery security gap" is checked: This is the minimum amount of time there must be between two reports being generated for one and the same user. If this check is ok, the configured report renderer is called and the flag reset.

Note:: There are special tasks for generating password letters (PasswordBatchTask) and matrix cards/TAN lists (TanBatchTask).
Type name
CredentialReportTask
Class
com.airlock.iam.servicecontainer.app.application.configuration.task.CredentialReportTask
May be used by
Properties
Report Type Short Desc (reportTypeShortDesc)
Description
Defines a short textual description of the type of the report being rendered.
The text is used in the user trail log written when a report is rendered. Please specify a text like in the examples below, so it suits the structure of the log statement it is used in.
If this property is not specified, a general statement will be logged.
Attributes
String
Optional
Example
password letter
Example
keyfile accompanying report
Example
mobile number registration letter
Credential Persister (credentialPersister)
Description
The credential persister plug-in is used to read and store credential data structures.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Credential Iterator (credentialIterator)
Description
The credential iterator plug-in used to iterate over a set or credential structures. For efficiency reasons it makes sense to limit the set of credential structures returned by this plug-in as much as possible. It is usually a good idea to already include the "order-credential" flag already in the additional where clause of the iterator plug-in. Like this, this plug-in only gets the "interesting" records.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Report Renderer (reportRenderer)
Description
Tells the this task which generic renderer to use to render reports. Like this, this plug-in only gets the "interesting" records.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Delivery Security Gap (deliverySecurityGap)
Description
Specifies the minimum number of days there must be between two reports being generated for the same user. This delivery gap tries to prevent that a user gets - as an example - a password letter and a token within a short amount of time resulting in a security risk because both letters are handled at the same time (e.g. by the postal service).
This feature only works correct, if the underlying credential persister knows about the other credentials delivery timestamps. Make sure these are properly configured for the credential persister.
Not setting this property turns this feature off.
Attributes
Integer
Optional
Default value
0
Language Attribute Name (languageAttributeName)
Description
Tells the report task which attribute in the context data container contains the language to be used for rendering the password. If this property is configured and if the context data container of the user has a value for this attribute, it is used when calling the report renderer plug-in.
Attributes
String
Mandatory
Suggested values
language
Working Directory (workingDirectory)
Description
A writable directory used to store partial reports.
If this property is defined, the credential reports are not directly generated into the output directory (see other property) but they are generated into this working directory and are moved to the output directory once they are done.
This helps to solve problems with processes automatically reading the rendered reports and reading partial reports during the generation process. Make sure that the working directory and the output directory reside in the same file system (if not the moving of the generated file will not be atomic).
The directory is either absolute or relative to the JVMs current directory.
Attributes
File/Path
Optional
Output Directory (outputDirectory)
Description
Directory in the file system to put the rendered reports in. The directory is either absolute or relative to the JVMs current directory.

This property is not required if the renderer plugin (see separate property) does not write on the outputstream (e.g. sends it somewhere else). It is required otherwise.

Note: If this property is not defined and the used renderer plugin writes on the output stream, then the result (e.g. a PDF file) is lost.

Attributes
File/Path
Optional
File Name Prefix (fileNamePrefix)
Description
Filename prefix for rendered report files. It is important to set this to a unique value for the kind of reports generated by this task. When this task deletes old reports, it looks at this prefix (and the user id) in order to find out what files to delete. Thus, if this prefix is the same as for other reports and the reside in the same directory, other reports may be deleted.
Do not use the prefix "pwd-" or the empty prefix if password- or tokenlist reports are stored in the same directory. The latter is used as default for token lists (matrix card) and the former for password letters.
Attributes
String
Mandatory
Example
token-letter
Example
smartcardLetter
File Name Suffix (fileNameSuffix)
Description
Filename suffix for rendered report files. The indicated suffix is appended to the generated reports. This may be required if the files are processed (e.g. printed) by another process (manual or automatic).
Attributes
String
Mandatory
Suggested values
.pdf, .txt
Delete Old Reports (deleteOldReports)
Description
Deletes old rendered reports of a user from the file system when a new one is rendered. Setting this to TRUE results in at most one rendered report of this type per user.
Caution: This feature will delete all reports starting with the prefix configured by property "file-name-prefix" and the user's name. Thus you must make sure, that different report types use different filename prefixes.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: CredentialReportTask
id: CredentialReportTask-xxxxxx
displayName: 
comment: 
properties:
  credentialIterator:
  credentialPersister:
  deleteOldReports: false
  deliverySecurityGap: 0
  fileNamePrefix:
  fileNameSuffix:
  languageAttributeName:
  outputDirectory:
  reportRenderer:
  reportTypeShortDesc:
  workingDirectory: