← Back to plugin index

Transaction Approval

Description
Configures the Transaction Approval web application.
Type name
TransactionApprovalApp
Class
com.airlock.iam.transactionapproval.application.configuration.TransactionApprovalApp
License-Tags
TransactionApproval
Properties
Flows (flows)
Description
The transaction approval flows.
Attributes
Plugin-List
Mandatory
Assignable plugins
User Store (userStore)
Description
The user store containing the users that approve transactions.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Max Failed Factor Attempts (maxFailedTransactionApprovals)
Description
Maximal number of allowed transaction approval attempts. Failed transaction approval attempts are counted as failed logins for the given credential, i.e., the same counter is used. The user is locked if the number of failed attempts for some credential exceeds this limit.
Attributes
Integer
Optional
Default value
5
Gateway Settings (gatewaySettings)
Description
Settings regarding an Airlock Gateway or Airlock Microgateway reverse proxy placed in front of Airlock IAM.

If no settings are configured, extra information from the reverse proxy will not be available and it may be harder to correlate log messages that are written to different log files.

Attributes
Plugin-Link
Optional
Assignable plugins
Request Authentication (requestAuthentication)
Description
Determines how a credential is extracted and used to authenticate single requests.
Attributes
Plugin-Link
Mandatory
Assignable plugins
CSRF Protection (csrfProtection)
Description

If enabled, REST endpoints are protected against CSRF attacks.

With this protection, the REST API only accepts requests that contain the custom header X-Same-Domain with an arbitrary non-empty value. In cross-origin resource sharing (CORS), such requests are not considered simple requests and thus must always be preceded by a preflight request, which prevents cross-site request forgery (CSRF) attacks.

Security warning: Disabling this feature may allow CSRF attacks. Only do so if the REST client is unable to comply with the aforementioned restrictions.

Attributes
Boolean
Optional
Default value
true
Fixed Response Duration (fixedResponseDuration)
Description
Defines how long it takes (in milliseconds) until IAM answers an 'unsuccessful' request in the transaction approval API. Faster answers are delayed until the configured duration is reached. This helps to avoid timing attacks. Successful or slower responses are not affected by this property. Protection against timing attacks is only provided if IAM is able to process 'unsuccessful' requests within the configured duration.

The endpoint that checks a password against the configured policy is excluded from response delays.

Attributes
Integer
Optional
Default value
2000
CORS Settings (corsSettings)
Description
The settings to allow cross-domain REST calls.
Attributes
Plugin-Link
Optional
Assignable plugins
State Repository (stateRepository)
Description
Defines where IAM stores all state. As long as only one instance of IAM is running (no horizontal scaling), the in-memory repository can be used.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Language Settings (languageSettings)
Description
Configures language settings.
Attributes
Plugin-Link
Optional
Assignable plugins
Session Idle Timeout (sessionIdleTimeout)
Description
Session idle timeout for the Transaction Approval App. When IAM is deployed behind an Airlock Gateway (WAF), timeout and lifetime values should always be longer than those maintained by the Gateway.
Attributes
String
Optional
Default value
30m
Example
30m
Example
2h 15m
Session Lifetime (sessionLifetime)
Description
Session lifetime for the Transaction Approval App. Unlike an idle timeout, the lifetime cannot be extended by activity and is always terminated once the lifetime has been reached. When IAM is deployed behind an Airlock Gateway (WAF), timeout and lifetime values should always be longer than those maintained by the Gateway.
Attributes
String
Optional
Default value
8h
Example
4h 30m
Example
8h
Context Extractor (contextExtractor)
Description
Specifies how a context is to be extracted from a request.
Attributes
Plugin-Link
Optional
Assignable plugins
Custom Extensions (customExtensions)
Description
Custom extensions for the REST API.
Attributes
Plugin-List
Optional
Assignable plugins
Readiness Health Check Endpoint (readinessHealthCheckEndpoint)
Description
Readiness health check endpoint for the Transaction Approval module.
Attributes
Plugin-Link
Optional
Assignable plugins
Log User Trail To Database (logUserTrailToDatabase)
Description

Configures the database settings to use when persisting user trail log entries.

If this value is defined, then all user trail log messages generated by the Transaction Approval App module will additionally be forwarded to the database configured within the referenced repository plugin.

All forwarded log entries are stored inside the table "USER_TRAIL_LOG". Note that setting this value does not disable writing log messages to the Transaction Approval App log file.

Attributes
Plugin-Link
Optional
Assignable plugins
Correlation ID Settings (correlationIdSettings)
Description

Defines settings for correlation ID transfer and logging inside the Transaction Approval module.

If undefined, no correlation ID will be logged for this module.

Attributes
Plugin-Link
Optional
Assignable plugins
Device Usage Repository Config (deviceUsageRepositoryConfig)
Description
Configures the database settings to use when persisting device usage data. This repository is used by the Device Usage Processor. If not configured, the device usages are not stored and thus no conditions and events based on previous/first device usage can be used.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: TransactionApprovalApp
id: TransactionApprovalApp-xxxxxx
displayName: 
comment: 
properties:
  contextExtractor:
  correlationIdSettings:
  corsSettings:
  csrfProtection: true
  customExtensions:
  deviceUsageRepositoryConfig:
  fixedResponseDuration: 2000
  flows:
  gatewaySettings:
  languageSettings:
  logUserTrailToDatabase:
  maxFailedTransactionApprovals: 5
  readinessHealthCheckEndpoint:
  requestAuthentication:
  sessionIdleTimeout: 30m
  sessionLifetime: 8h
  stateRepository:
  userStore: