The Digipass S3 API Server handles all communication between the App SDK and the Authentication Server. It functions as a gatekeeper on incoming requests and the amount of information that the Authentication Server returns to the App SDK. configuration objects of type Main enable you to control this behavior.
Fields
The Main configuration object contains the fields below:
Field | Description |
|---|---|
mfas_response_filter | Optional. If your app specifically requests additional information, then you also need to modify the API Server's response filter to allow that information to reach the App SDK. Examples of additional information include the user's device as well as the authenticator and authentication method that they used. The value of this field is a response filter configuration structure. See Response Filter Configuration. The default value directs the API Server to send the unique identifier for a registered authenticator and information about the user's device to the App SDK. |
origin_allowlist | Optional. The API Server rejects requests from URLs that are different from its URL. If your web client apps have a different origin than the API Server, add those URLs to this field. The default value for this field is an empty list. |
Example Main configuration object
{
"mfas_response_filter":{
"additionalInfo":{
"device":true,
"authenticatorsResult":[
{
"handle":true,
"attachmentHints": true
}
]
}
},
"origin_allowlist":[
"https://massive-dynamic1.com",
"https://massive-dynamic2.com"
]
}Response filter configuration
You can control what data the API Server sends or removes from additionalInfo by using a response filter configuration object inside the Main object. The Authentication Server uses additionalInfo to return optional data such as the user's device, the authenticators used, the calling app, FIDO policy used for the operation, and so on. For details about additionalInfo, see the REST API Reference to the Digipass S3 Data Types. By default, the API Server filters out all this information from the Auth Server's response before sending it to the App SDK.
The example below directs the API Server to send the following to the App SDK:
The FIDO Policy name that was used to verify the authenticator
Depending on the FIDO operation, the list of registered authenticators that succeeded or failed to complete authentication or the authenticator that was successfully registered.
The device model
The device's unique identifier
The device type (android, ios, or browser)
{
"policyName":true,
"authenticatorsResult": true,
"device":
{
"model":true,
"id":true,
"type":true
}
}Below is the default response filter which sends all device information. In addition, for any registered authenticators in the result, it includes its handle (unique ID), a hint about how the authenticator communicates with the client, and its name. The attachmentHints are required to handle FIDO2.
{
"additionalInfo":{
"device":true,
"authenticatorsResult":[
{
"handle":true,
"attachmentHints":true,
"authenticatorName":true
}
]
}
}The additionalInfo response filter configuration uses a JSON format structure
{
"Field1": true,
"FieldThatIsAnArray":
[
{
"Field2": true,
"Field3": false
}
],
"FieldThatIsAnObject":
{
"Field4": true,
"Field5": false
}
}Each field in this structure corresponds to an attribute of additionalInfo. The attribute could be scalar, an array (like authenticatorsResult in the previous example), or an object (like device). As you see with authenticatorsResult, you can individually configure specific attributes of an array or an object. For additionalInfo's attributes, see the REST API Reference to the Digipass S3 Data Types.
By default, all unassigned attributes are assumed to be excluded. Assign a boolean value to control whether the API Server sends the attribute's value to the App SDK.
true: The attribute is sent
false: The attribute isn't sent
If you don't want all values for a particular attribute to be allowed through the filter, you can set up the filter to only send a specific value to the App SDK. In addition to setting the attribute to true, use the following notation:
the attribute name ("__key__": "<attribute_name>")
value ("__value__":"<attribute_value>")
For example, the following snippet directs the API Server to only send the FIDO policy name if it matches acmeAuthPolicy.
"policyName": true,
"__key__": "policyName",
"__value__": "acmeAuthPolicy",This example doesn't send the policy name, only sends the AAID if the value matches "4e4e#400e", sends the registered authenticator's version, status, handle, a hint about how the authenticator communicates with the client, sends the device info and ID but not the type, and doesn't send transaction information or the protocol.
{
"policyName":false,
"authenticatorsResult":[
{
"aaid":true,
"__key__":"aaid",
"__value__":"4e4e#400e",
"authenticatorVersion":true,
"status":true,
"handle":true,
"attachmentHints": true
}
],
"device":{
"info":true,
"id":true,
"type":false
},
"transaction":false,
"protocol":false
}