Cloud Identity-Aware Proxy v1 API - Class AttributePropagationSettings (2.3.0)

public sealed class AttributePropagationSettings : IMessage<AttributePropagationSettings>, IEquatable<AttributePropagationSettings>, IDeepCloneable<AttributePropagationSettings>, IBufferMessage, IMessage

Reference documentation and code samples for the Cloud Identity-Aware Proxy v1 API class AttributePropagationSettings.

Configuration for propagating attributes to applications protected by IAP.

Inheritance

object > AttributePropagationSettings

Namespace

GoogleGoogle.CloudGoogle.Cloud.IapV1

Assembly

Google.Cloud.Iap.V1.dll

Constructors

AttributePropagationSettings()

public AttributePropagationSettings()

AttributePropagationSettings(AttributePropagationSettings)

public AttributePropagationSettings(AttributePropagationSettings other)
Parameter
NameDescription
otherAttributePropagationSettings

Properties

Enable

public bool Enable { get; set; }

Whether the provided attribute propagation settings should be evaluated on user requests. If set to true, attributes returned from the expression will be propagated in the set output credentials.

Property Value
TypeDescription
bool

Expression

public string Expression { get; set; }

Raw string CEL expression. Must return a list of attributes. Maximum of 45 attributes can be selected. Expressions can select different attribute types from attributes: attributes.saml_attributes, attributes.iap_attributes. Limited functions are supported:

  • filter: <list>.filter(<iter_var>, <predicate>) -> returns a subset of <list> where <predicate> is true for every item.
  • in: <var> in <list> -> returns true if <list> contains <var>
  • selectByName: <list>.selectByName(<string>) -> returns the attribute in <list> with the given <string> name, otherwise returns empty.
  • emitAs: <attribute>.emitAs(<string>) -> sets the <attribute> name field to the given <string> for propagation in selected output credentials.
  • strict: <attribute>.strict() -> ignore the x-goog-iap-attr- prefix for the provided <attribute> when propagating via the HEADER output credential, i.e. request headers.
  • append: <target_list>.append(<attribute>) OR <target_list>.append(<list>) -> append the provided <attribute> or <list> onto the end of <target_list>.

Example expression: attributes.saml_attributes.filter(x, x.name in [&apos;test&apos;]).append(attributes.iap_attributes.selectByName(&apos;exact&apos;).emitAs(&apos;custom&apos;).strict())

Property Value
TypeDescription
string

HasEnable

public bool HasEnable { get; }

Gets whether the "enable" field is set

Property Value
TypeDescription
bool

HasExpression

public bool HasExpression { get; }

Gets whether the "expression" field is set

Property Value
TypeDescription
bool

OutputCredentials

public RepeatedField<AttributePropagationSettings.Types.OutputCredentials> OutputCredentials { get; }

Which output credentials attributes selected by the CEL expression should be propagated in. All attributes will be fully duplicated in each selected output credential.

Property Value
TypeDescription
RepeatedFieldAttributePropagationSettingsTypesOutputCredentials