← Back to plugin index

User Self-Registration Flow

Description
Configuration for a user self-registration flow.
Type name
UserSelfRegFlow
Class
com.airlock.iam.userselfreg.application.configuration.flow.UserSelfRegFlowConfig
May be used by
License-Tags
SelfRegistration
Properties
Flow ID (flowId)
Description
Unique ID for this flow, which is used for selecting or referencing a flow.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Additional Unique Items (additionalUniqueItemDefinitions)
Description
List of additional user data items whose global uniqueness is enforced by the system. Note that all login names (username and alias names) are automatically considered for the uniqueness verification.
Attributes
Plugin-List
Optional
Assignable plugins
Initial Lock Reason (initialLockReason)
Description

The lock reason used for initially locking the self-registered user.

At the start of the flow the user is initially locked and a User Unlock Step is needed to unlock it.

Attributes
String
Optional
Default value
LockReason.AwaitingAdminApproval
Suggested values
LockReason.PendingChannelVerification, LockReason.AwaitingAdminApproval
Password Repository (passwordRepository)
Description

The password repository used to persist passwords. Required if there is a data registration step with a "Password User Item" configured.

The "Default Password Repository" cannot be used here.

Attributes
Plugin-Link
Optional
Assignable plugins
Initialize Next Auth Flow (initializeNextAuthFlow)
Description

If enabled, the next authentication flow after completing this self-registration flow will be initialized with the user identity and tags from the self-registration. By combining this feature with authentication flows where steps can be skipped based on tags from self-registration, a non-interactive authentication after completed self-registration can be achieved.

Attributes
Boolean
Optional
Default value
false
Enable Stealth Mode (enableStealthMode)
Description

Determines whether the registration should run in Stealth Mode, which can protect against enumeration attacks on the first channel verification target. All other user items (including login names) are not protected against enumeration attacks.

Enabling this flag has the following effects:

  • The target item definition from the first channel verification step is protected from enumeration attacks.
  • At any stage (except when persisting the user), conflicts with existing users are not reported for that item. Hence the channel verification step has to precede persisting steps.
  • Any other unique user item (i.e. login names and items explicitly listed as 'unique' in Additional Unique Items), must not be valid according to the validation property configured for the first channel verification target. (E.g.: if channel verification is performed on the email address, no other unique item is allowed to be a valid email address).

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: UserSelfRegFlow
id: UserSelfRegFlow-xxxxxx
displayName: 
comment: 
properties:
  additionalUniqueItemDefinitions:
  enableStealthMode: false
  flowId:
  initialLockReason: LockReason.AwaitingAdminApproval
  initializeNextAuthFlow: false
  passwordRepository:
  processors:
  steps: