Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Utility app configuration

Prev Next

The Nok Nok Server and Web App SDK both ship with two utility apps developed at Nok Nok Labs, nnlsignin and nnlfedapp. Use nnlsignin together with a Nok Nok Federation Adapter to bring FIDO authentication into a Federation Server. Use nnlfedapp to support Federated Credential Management accessible through an OIDC flow.

To deploy these apps when you install the Server, set the DEPLOY_OPTIONAL_WEB_APP_LIST property in the nnl-install.properties file as described in Install the Nok Nok Servers on Linux. You can also deploy them with the Web App SDK.

These two utility apps use the Web App SDK to perform various operations. You can configure how the Web App SDK behaves for these utility apps by creating the nnlapp_config object of type Main. Upload nnlapp_config to the API Server using the Admin Console. Navigate to Configuration > API Server > Main > Nok Nok App Config and click the Upload button.

If your Nok Nok Server is deployed on premises and the default values do not work for you, modify the default values by editing nnlfedapp/static/config/config.js or nnlsignin/config/config.js. Then set only tenant-specific fields inside nnlapp_config.fedAppConfig and nnlapp_config.signinConfig.

The nnlapp_config configuration object is tenant-specific and it contains:

Field

Description

appSdkConfig

Optional: Specifies options for the AppSdkConfig object. For more details about those options, see the AppSdkConfig object in the ClientAPI docs for Nok Nok Web App SDK.

authOpts

Optional. Specifies authentication options in nnlsignin. For more information see the authOpts parameter of the AdaptiveUI.getAuthenticationView() function in the Client API docs for Nok Nok Web SDK.

fedAppConfig

Optional. A configuration object that specifies options for nnlfedapp. See table below for specific fields inside this object. These configurations override the defaults set in nnlfedapp/static/config/config.js.

fidoRegOpts

Optional. Specifies options when nnlfedapp registers FIDO authenticators. For more details see the Extras parameter of the AppSdk.getFidoRegistrationView() function in the Client API docs for Nok Nok Web App SDK.

manageRegOpts

Optional. Specifies options when nnlfedapp manages registrations. For more details see the Extras parameter of the AppSdk.getManageRegistrationsView() function in the Client API docs for Nok Nok Web SDK.

regOpts

Optional. Specifies options when nnlfedapp registers non-FIDO authentication methods. For more details see the regOpts parameter of the AdaptiveUI.getRegistrationView() function in the Client API docs for Nok Nok Web App SDK.

signinConfig

Optional. A configuration object that specifies options for nnlsignin. See table below for specific fields inside this object. These configurations override the defaults set in nnlsignin/config/config.js file.

suggestRegOpts

Optional. Specifies Suggest Registration options in nnlsignin. For more information see the suggestRegOpts parameter of the AdaptiveUI.getAuthenticationView() function in the Client API docs for Nok Nok Web SDK.

The fedAppConfig object nested inside nnlapp_config can have the following fields:

Field

Description

nnlappsdk_url

The URL where the Nok Nok Web App SDK is located. Default value is "${host}/nnlappsdk-${appsdk_version}"

reg_endpoint

The registration endpoint for the API Server. Default value is "${host}/nnlgateway/nnl/${tenant_id}/reg"

auth_endpoint

The authentication endpoint for the API Server. Default value is "${host}/nnlgateway/nnl/${tenant_id}/auth"

storage_endpoint

The endpoint of the cookie-based storage. The default value is "${host}/nnlgateway/storage"

ui_config_url

The URL of the root configuration directory for the JSON UI Configuration files used by nnlfedapp. Default value is null. See App UI Customization for details on how to create your UI Configuration files, and see the section Storing Your UI Configuration Files Using a Remote Server for information about how to structure the directories that contain your UI configuration.

  • nnlfedapp substitutes actual values for ${host}, ${tenant_id} and ${appsdk_version}.

  • To configure OIDC parameters for nnlfedapp, see Credential Management Page page.

The signinConfig object nested inside nnlapp_config can have the following fields:

Field

Description

auth_endpoint

The authentication endpoint for the API Server. Default value is "${host}/nnlgateway/nnl/${tenant_id}/auth"

auth_start_mode

The mode that authentication should start in. For available values see the AutoStart enum in the Web App SDK API Docs. The default value is "SIGN_IN".

cookie_domain

The domain of the authentication cookie that nnlsignin uses to pass the JWT of authenticated user to the Nok Nok Federation Adapter.

cookie_name

The name of the authentication cookie that nnlsignin uses to pass the JWT of an authenticated user to the Nok Nok Federation Adapter.

federation_resume_uri

Default value is null. The nnlsignin app can pass the JWT of an authenticated user to the Nok Nok Federation Adapter in 2 different ways:

1. Drop the JWT into the cookie and redirect to the Federation Server. In this case the nnlsignin app and the Federation Server are assumed to be on the same origin or share the same parent origin. In this case, signinConfig.federation_resume_uri parameter is not used and should be left with its default value.
2. Pass the JWT through the form-post request. The nnlsignin app and the Federation Server can be on completely different origins (cross-origin form-post) or share the same or parent origin. The signinConfig.federation_resume_uri specifies a base or full URL on the Federation Server to do a form-post after successful authentication at Nok Nok. The URL can be full or relative, e.g.:

signinConfig.federation_resume_uri = "${host}/path/to/fedserver";

or

signinConfig.federation_resume_uri = "/path/to/fedserver";

In some cases the signinConfig.federation_resume_uri is a base URI because a full form-post URL may contain the resume path which is not known yet. The Nok Nok Federation Adapter may provide the resume path to nnlsignin during the redirect. The nnlsignin app then concatenates the resume path with the base URI before making the form-post:

form_post_url = signinConfig.federation_resume_uri + resume_path.

nnlappsdk_url

The URL where the Nok Nok Web App SDK is located. Default value is "${host}/nnlappsdk-${appsdk_version}"

reg_endpoint

The registration endpoint for the API Server. Default value is "${host}/nnlgateway/nnl/${tenant_id}/reg"

storage_endpoint

The endpoint of the cookie based storage. The default value is "${host}/nnlgateway/storage"

ui_config_url

The URL of the root configuration directory for the JSON UI Configuration files used by nnlsignin. Default value is null. See App UI Customization for details on how to create your UI Configuration files, and see the section Storing Your UI Configuration Files Using a Remote Server for information about how to structure the directories that contain your UI configuration.

web_oob_url

The URL of the page that processes the scanned QR code for Appless OOB operations. Default value is "${host}/nnlsignin/oobrecv.html". This field is mandatory if you use OOB authentication.

nnlsignin substitutes actual values for ${host}, ${tenant_id} and ${appsdk_version}.

Example nnlapp_config Configuration Object

{
    "appSdkConfig": {
        "otp": {
            "maxFalseAttempts": 1,
            "lockoutPeriod": 5
        },
        "darkMode": "on"
    },
    "fedAppConfig": {
        "ui_config_url": "https://example.com/fedapp_ui_config"
    },
    "fidoRegOpts": {
        "askSecurityKeyCredentialName": false
    },
    "manageRegOpts": {
        "options": {
            "needDetails": 3
        }
    },
    "signinConfig": {
        "federation_resume_uri": "http://ping.noknokeval.com:9031/as/authorization.oauth2",
        "ui_config_url": "https://example.com/signin_ui_config"
    },
    "authOpts": {
        "signInWithMobile": "CONDITIONALLY"
    },
    "suggestRegOpts": {
        "askSecurityKeyCredentialName": true,
        "autoReg": true,
        "suggestRegEnabled": true
    }
}