Transaction Approval Flow
Description
Configuration for a transaction approval flow.
May be used by
Properties
Flow ID (
flowId) Description
Unique ID for this flow, which is used for selecting or referencing a flow.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Steps (
steps) Description
Steps of the flow.
Attributes
Plugin-List
Mandatory
Assignable plugins
Abort Step Acknowledge Message Step Airlock 2FA Delete Devices Step Airlock 2FA Transaction Approval Step Cronto Transaction Approval Step Email Notification Step Email OTP Transaction Approval Step FIDO Transaction Approval Step Failure Step Matrix Checking Step No Operation Step OTP Check via RADIUS Step Red Flag Raising Step Scriptable Step Selection Step Tag Removal Step Transaction Approval Parameter Step User Identification Step mTAN Transaction Approval Step
Processors (
processors) Description
Processors get notified about the various stages of the flow and offer hooks to plug in custom logic. These processors realize the entire authentication logic such as incrementing failed login counters or checking of user validity.
Attributes
Plugin-Link
Optional
Assignable plugins
Custom Flow Processors Default Authentication Processors Default Authorization Processors Default One-Shot Authentication Processors Default Persistency-less Authentication Processors Default Persistency-less Protected Self-Service Processors Default Protected Self-Service Processors Default Public Self-Service Processors Default Technical Client Registration Processors Default Transaction Approval Processors Default User Self-Registration Processors
Username Transformers (
usernameTransformers) Description
Username transformers may transform the provided username into the single unique user ID required for the flow.
The transformation of a username takes place in the first step before the user is loaded. Note that username transformers have no effect on the propagated username value. Transformers can be chained, i.e. a first transformer could normalize the original name, where the next transformer looks up the normalized name in a database for potential transformation matches.
In contrary to the above description of chaining, a transformer can also signal that it already found the final user ID and the chain must stop after it.
For further details please refer to the documentation of the username transformer plugins.
The transformation of a username takes place in the first step before the user is loaded. Note that username transformers have no effect on the propagated username value. Transformers can be chained, i.e. a first transformer could normalize the original name, where the next transformer looks up the normalized name in a database for potential transformation matches.
In contrary to the above description of chaining, a transformer can also signal that it already found the final user ID and the chain must stop after it.
For further details please refer to the documentation of the username transformer plugins.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)
type: TransactionApprovalFlow
id: TransactionApprovalFlow-xxxxxx
displayName:
comment:
properties:
flowId:
processors:
steps:
usernameTransformers: