← Back to plugin index

Airlock 2FA Activation Letter Task

Description

Settings to batch process Airlock 2FA activation letter orders. Each order will generate at most one activation letter. No activation letter will be generated for a permanently disabled Airlock 2FA account. Each order will be deleted after being processed.

An Airlock 2FA letter contains a QR code to be scanned and is typically necessary for the registration of the first Airlock 2FA device.

Note that once the letter is generated, Airlock IAM is no longer involved in the activation of a user's device. This implies in particular, that a user who has been locked out after the generation of an activation letter could still use it to successfully register an Airlock 2FA device. Login will of course remain impossible as long the the user is locked out.

Type name
Airlock2FAActivationLetterOrderTask
Class
com.airlock.iam.servicecontainer.app.application.configuration.task.airlock2fa.Airlock2FAActivationLetterOrderTaskConfig
May be used by
License-Tags
Airlock2FA
Properties
Airlock 2FA Settings (airlock2faSettings)
Description
Settings of Airlock 2FA.
Attributes
Plugin-Link
Mandatory
Assignable plugins
User Store (userStore)
Description
The user store to retrieve all user data.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Renderer (renderer)
Description
Defines how activation letters (e.g. PDFs) are rendered.

The following placeholders can be used in the templates

  • ${User Context Data Name} - context data of the user.
  • ${activationQRCode} - QR code image for the activation. Image size in document can be adjusted: ${activationQRCode,imageSize,width in points,height in points}
  • ${expires} - expiring date of the activation. Can be used with extended format (e.g. ${expires,date,short})
  • ${activationCodeShort} - Short 16-digit activation code as an additional option for the activation.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Working Directory (workingDirectory)
Description
A writable directory used to store a partially rendered activation letter.
If this property is defined, activation letters are not directly generated into the output directory (see other property) but they are generated into this working directory and are then moved into the output directory once they are done.
This helps to solve problems with processes that automatically read the rendered activation letters and therefore might not see the fully rendered result. Make sure that the working directory and the output directory reside in the same file system (otherwise the moving of the generated file will not be atomic).
The directory is either absolute or relative to the JVMs current directory.
Attributes
File/Path
Optional
Output Directory (outputDirectory)
Description
The directory where the printable letters will be stored.
Attributes
File/Path
Mandatory
Language Context Data Name (languageContextDataName)
Description
The user's context data attribute containing its language. The language is used to choose the template in the renderer. If left empty, the default template will be used.
Attributes
String
Optional
Suggested values
language
Enrollment Validity [s] (enrollmentValidityInSeconds)
Description
The duration (in seconds) an enrollment code should be valid.

Note: This value is only used for the validity of the QR code in the enrollment letter and does not affect enrollment self-services.

Attributes
Integer
Optional
Default value
604800
YAML Template (with default values)

type: Airlock2FAActivationLetterOrderTask
id: Airlock2FAActivationLetterOrderTask-xxxxxx
displayName: 
comment: 
properties:
  airlock2faSettings:
  enrollmentValidityInSeconds: 604800
  languageContextDataName:
  outputDirectory:
  renderer:
  userStore:
  workingDirectory: