Class DefaultAuthServerProperties.AuthServerProperties

java.lang.Object
com.broadleafcommerce.auth.tenant.domain.DefaultAuthServerProperties.AuthServerProperties
Enclosing class:
DefaultAuthServerProperties

public static class DefaultAuthServerProperties.AuthServerProperties extends Object
  • Constructor Details

    • AuthServerProperties

      public AuthServerProperties()
  • Method Details

    • getAuthorizationServerId

      public String getAuthorizationServerId()
      Optional. The default authorization server ID to use when creating an authorized client. Settings this will cause all new applications to share a single authorization server, which allows logins to be shared across multiple applications. If blank, a new Authorization server will be created for each application.

      Note that an ID can be set here even if an authorization server with this ID does not yet exist. If an authorization server does not exist, one will be created with this ID.

    • getUserRoleIds

      public Set<String> getUserRoleIds()
      Optional. The default user role IDs to assign on new authorization servers for this tenant.
    • getPermissionIds

      public Set<String> getPermissionIds()
      Optional. The default permission IDs to assign on new authorization servers for this tenant.
    • getRequireLoginTimeoutSeconds

      public int getRequireLoginTimeoutSeconds()
      Default of 86400 (24 hours). The maximum amount of time, in seconds, a user's session will persist before requiring re-login.
    • getInactivityTimeoutSeconds

      public int getInactivityTimeoutSeconds()
      Default is 21600 (6 hours). The period of time, in seconds, that the user's session will timeout if no action is taken.
    • isCrossOrigin

      public boolean isCrossOrigin()
      Whether or not the user's session with this authorization server is active for cross-origin requests. If set to true, the session cookie will include a SameSite policy of "None", thereby allowing the session cookie for cross-origin requests. Defaults to false.
    • isSsoEnabled

      public boolean isSsoEnabled()
      Default is true. Is SSO enabled for this authorization server?
    • isEmbeddedLoginEnabled

      public boolean isEmbeddedLoginEnabled()
      Default is false. Is embedded login enabled for this authorization server?
    • getDomainDefaultRedirectUris

      public Set<String> getDomainDefaultRedirectUris()
      Optional. The default redirect URIs for authorization clients. Supports the special variable {domain} that uses the application's identifier value when it's of the ResolutionIdentifierType.DOMAIN identifier type.

      For example, for a new application with the domain "my-ecommerce-site.com", a default redirect URI of https://{domain} would result in a redirect URI of https://my-ecommerce-site.com.

    • getDomainDefaultPostAuthSuccessRedirectUris

      public Set<String> getDomainDefaultPostAuthSuccessRedirectUris()
      A whitelist of default post-authentication redirect URIs. Supports the special variable {domain} that uses the application's identifier value when it's of the identifier type of DOMAIN.
    • getDomainPrefixDefaultRedirectUris

      public Set<String> getDomainPrefixDefaultRedirectUris()
      Optional. The default redirect URIs for authorization clients. Supports the special variable {domain} that uses the application's identifier value when it's of the ResolutionIdentifierType.DOMAIN_PREFIX identifier type.

      For example, for a new application with a domain prefix of "my-ecommerce-site", a default redirect URI of https://{domain}.shopping.com would result in a redirect URI of https://my-ecommerce-site.shopping.com.

    • getDomainPrefixDefaultPostAuthSuccessRedirectUris

      public Set<String> getDomainPrefixDefaultPostAuthSuccessRedirectUris()
      A whitelist of default post-authentication redirect URIs. Supports the special variable {domain} that uses the application's identifier value when it's of the identifier type of DOMAIN_PREFIX.
    • getParameterDefaultRedirectUris

      public Set<String> getParameterDefaultRedirectUris()
      Optional. The default redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.PARAMETER identifier type.

      For example, for a new application with the param "my-ecommerce-site", a default redirect URI of https://my-domain.com/?application={identifier} would result in a redirect URI of https://my-domain.com/?application=my-ecommerce-site.

    • getParameterDefaultPostAuthSuccessRedirectUris

      public Set<String> getParameterDefaultPostAuthSuccessRedirectUris()
      A whitelist of default post-authentication redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.PARAMETER identifier type.
    • getContextPathDefaultRedirectUris

      public Set<String> getContextPathDefaultRedirectUris()
      Optional. The default redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.CONTEXT_PATH identifier type.

      For example, for a new application with the param "my-ecommerce-site", a default redirect URI of https://my-domain.com/{identifier} would result in a redirect URI of https://my-domain.com/my-ecommerce-site.

    • getContextPathDefaultPostAuthSuccessRedirectUris

      public Set<String> getContextPathDefaultPostAuthSuccessRedirectUris()
      A whitelist of default post-authentication redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.CONTEXT_PATH identifier type.
    • getTokenTimeoutSeconds

      public int getTokenTimeoutSeconds()
      Default of 300 seconds. The period of time, in seconds, that an access token issued will be valid for.
    • getDomainDefaultClientRedirectUri

      public String getDomainDefaultClientRedirectUri()
      Optional. The default client redirect URI. Supports the special variable {domain} that uses the application's identifier value when it's of the identifier type of DOMAIN.

      For example, for a new application with the domain "my-ecommerce-site.com", a default redirect URI of https://{domain} would result in a redirect URI of https://my-ecommerce-site.com.

    • getDomainPrefixDefaultClientRedirectUri

      public String getDomainPrefixDefaultClientRedirectUri()
      Optional. The default client redirect URI. Supports the special variable {domain} that uses the application's identifier value when it's of the identifier type of DOMAIN_PREFIX.

      For example, for a new application with a domain prefix of "my-ecommerce-site", a default redirect URI of https://{domain}.shopping.com would result in a redirect URI of https://my-ecommerce-site.shopping.com.

    • getParameterDefaultClientRedirectUri

      public String getParameterDefaultClientRedirectUri()
      Optional. The default redirect URI for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.PARAMETER identifier type.

      For example, for a new application with the param "my-ecommerce-site", a default redirect URI of https://my-domain.com/?application={identifier} would result in a redirect URI of https://my-domain.com/?application=my-ecommerce-site.

    • getContextPathDefaultClientRedirectUri

      public String getContextPathDefaultClientRedirectUri()
      Optional. The default redirect URI for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.CONTEXT_PATH identifier type.

      For example, for a new application with the param "my-ecommerce-site", a default redirect URI of https://my-domain.com/{identifier} would result in a redirect URI of https://my-domain.com/my-ecommerce-site.

    • getResetPasswordBaseUri

      public String getResetPasswordBaseUri()
      Optional. The reset password form's base URI. If blank, the default client redirect uri will be used instead.

      This is only needed in cross-origin auth scenarios where the client is on a different domain from the auth server and SSO is in use instead of embedded login, e.g., client is on https://www.my-store.com and auth (where the form is) is https://www.my-auth-server.com.

    • getDisabled

      public Boolean getDisabled()
      If set to true, no Authorization servers or Clients will be automatically created for this tenant. Note that the most specific configuration always wins. So if the 'default' value is disabled, and properties are defined for a specific tenant ID, the tenant ID properties will be used.
    • getGrantTypes

      public Set<String> getGrantTypes()
      Optional. The grant types to be used for the authorized client. If none are set, 'authorization_code' will be used.
    • getAuthenticationMethods

      public Set<String> getAuthenticationMethods()
      Optional. The authentication methods to be used for the authorized client. If none are set, 'none' will be used.
    • setAuthorizationServerId

      public void setAuthorizationServerId(String authorizationServerId)
      Optional. The default authorization server ID to use when creating an authorized client. Settings this will cause all new applications to share a single authorization server, which allows logins to be shared across multiple applications. If blank, a new Authorization server will be created for each application.

      Note that an ID can be set here even if an authorization server with this ID does not yet exist. If an authorization server does not exist, one will be created with this ID.

    • setUserRoleIds

      public void setUserRoleIds(Set<String> userRoleIds)
      Optional. The default user role IDs to assign on new authorization servers for this tenant.
    • setPermissionIds

      public void setPermissionIds(Set<String> permissionIds)
      Optional. The default permission IDs to assign on new authorization servers for this tenant.
    • setRequireLoginTimeoutSeconds

      public void setRequireLoginTimeoutSeconds(int requireLoginTimeoutSeconds)
      Default of 86400 (24 hours). The maximum amount of time, in seconds, a user's session will persist before requiring re-login.
    • setInactivityTimeoutSeconds

      public void setInactivityTimeoutSeconds(int inactivityTimeoutSeconds)
      Default is 21600 (6 hours). The period of time, in seconds, that the user's session will timeout if no action is taken.
    • setCrossOrigin

      public void setCrossOrigin(boolean crossOrigin)
      Whether or not the user's session with this authorization server is active for cross-origin requests. If set to true, the session cookie will include a SameSite policy of "None", thereby allowing the session cookie for cross-origin requests. Defaults to false.
    • setSsoEnabled

      public void setSsoEnabled(boolean ssoEnabled)
      Default is true. Is SSO enabled for this authorization server?
    • setEmbeddedLoginEnabled

      public void setEmbeddedLoginEnabled(boolean embeddedLoginEnabled)
      Default is false. Is embedded login enabled for this authorization server?
    • setDomainDefaultRedirectUris

      public void setDomainDefaultRedirectUris(Set<String> domainDefaultRedirectUris)
      Optional. The default redirect URIs for authorization clients. Supports the special variable {domain} that uses the application's identifier value when it's of the ResolutionIdentifierType.DOMAIN identifier type.

      For example, for a new application with the domain "my-ecommerce-site.com", a default redirect URI of https://{domain} would result in a redirect URI of https://my-ecommerce-site.com.

    • setDomainDefaultPostAuthSuccessRedirectUris

      public void setDomainDefaultPostAuthSuccessRedirectUris(Set<String> domainDefaultPostAuthSuccessRedirectUris)
      A whitelist of default post-authentication redirect URIs. Supports the special variable {domain} that uses the application's identifier value when it's of the identifier type of DOMAIN.
    • setDomainPrefixDefaultRedirectUris

      public void setDomainPrefixDefaultRedirectUris(Set<String> domainPrefixDefaultRedirectUris)
      Optional. The default redirect URIs for authorization clients. Supports the special variable {domain} that uses the application's identifier value when it's of the ResolutionIdentifierType.DOMAIN_PREFIX identifier type.

      For example, for a new application with a domain prefix of "my-ecommerce-site", a default redirect URI of https://{domain}.shopping.com would result in a redirect URI of https://my-ecommerce-site.shopping.com.

    • setDomainPrefixDefaultPostAuthSuccessRedirectUris

      public void setDomainPrefixDefaultPostAuthSuccessRedirectUris(Set<String> domainPrefixDefaultPostAuthSuccessRedirectUris)
      A whitelist of default post-authentication redirect URIs. Supports the special variable {domain} that uses the application's identifier value when it's of the identifier type of DOMAIN_PREFIX.
    • setParameterDefaultRedirectUris

      public void setParameterDefaultRedirectUris(Set<String> parameterDefaultRedirectUris)
      Optional. The default redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.PARAMETER identifier type.

      For example, for a new application with the param "my-ecommerce-site", a default redirect URI of https://my-domain.com/?application={identifier} would result in a redirect URI of https://my-domain.com/?application=my-ecommerce-site.

    • setParameterDefaultPostAuthSuccessRedirectUris

      public void setParameterDefaultPostAuthSuccessRedirectUris(Set<String> parameterDefaultPostAuthSuccessRedirectUris)
      A whitelist of default post-authentication redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.PARAMETER identifier type.
    • setContextPathDefaultRedirectUris

      public void setContextPathDefaultRedirectUris(Set<String> contextPathDefaultRedirectUris)
      Optional. The default redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.CONTEXT_PATH identifier type.

      For example, for a new application with the param "my-ecommerce-site", a default redirect URI of https://my-domain.com/{identifier} would result in a redirect URI of https://my-domain.com/my-ecommerce-site.

    • setContextPathDefaultPostAuthSuccessRedirectUris

      public void setContextPathDefaultPostAuthSuccessRedirectUris(Set<String> contextPathDefaultPostAuthSuccessRedirectUris)
      A whitelist of default post-authentication redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.CONTEXT_PATH identifier type.
    • setTokenTimeoutSeconds

      public void setTokenTimeoutSeconds(int tokenTimeoutSeconds)
      Default of 300 seconds. The period of time, in seconds, that an access token issued will be valid for.
    • setDomainDefaultClientRedirectUri

      public void setDomainDefaultClientRedirectUri(String domainDefaultClientRedirectUri)
      Optional. The default client redirect URI. Supports the special variable {domain} that uses the application's identifier value when it's of the identifier type of DOMAIN.

      For example, for a new application with the domain "my-ecommerce-site.com", a default redirect URI of https://{domain} would result in a redirect URI of https://my-ecommerce-site.com.

    • setDomainPrefixDefaultClientRedirectUri

      public void setDomainPrefixDefaultClientRedirectUri(String domainPrefixDefaultClientRedirectUri)
      Optional. The default client redirect URI. Supports the special variable {domain} that uses the application's identifier value when it's of the identifier type of DOMAIN_PREFIX.

      For example, for a new application with a domain prefix of "my-ecommerce-site", a default redirect URI of https://{domain}.shopping.com would result in a redirect URI of https://my-ecommerce-site.shopping.com.

    • setParameterDefaultClientRedirectUri

      public void setParameterDefaultClientRedirectUri(String parameterDefaultClientRedirectUri)
      Optional. The default redirect URI for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.PARAMETER identifier type.

      For example, for a new application with the param "my-ecommerce-site", a default redirect URI of https://my-domain.com/?application={identifier} would result in a redirect URI of https://my-domain.com/?application=my-ecommerce-site.

    • setContextPathDefaultClientRedirectUri

      public void setContextPathDefaultClientRedirectUri(String contextPathDefaultClientRedirectUri)
      Optional. The default redirect URI for authorization clients. Supports the special variable {identifier} that uses the application's identifier value when it's of the ResolutionIdentifierType.CONTEXT_PATH identifier type.

      For example, for a new application with the param "my-ecommerce-site", a default redirect URI of https://my-domain.com/{identifier} would result in a redirect URI of https://my-domain.com/my-ecommerce-site.

    • setResetPasswordBaseUri

      public void setResetPasswordBaseUri(String resetPasswordBaseUri)
      Optional. The reset password form's base URI. If blank, the default client redirect uri will be used instead.

      This is only needed in cross-origin auth scenarios where the client is on a different domain from the auth server and SSO is in use instead of embedded login, e.g., client is on https://www.my-store.com and auth (where the form is) is https://www.my-auth-server.com.

    • setDisabled

      public void setDisabled(Boolean disabled)
      If set to true, no Authorization servers or Clients will be automatically created for this tenant. Note that the most specific configuration always wins. So if the 'default' value is disabled, and properties are defined for a specific tenant ID, the tenant ID properties will be used.
    • setGrantTypes

      public void setGrantTypes(Set<String> grantTypes)
      Optional. The grant types to be used for the authorized client. If none are set, 'authorization_code' will be used.
    • setAuthenticationMethods

      public void setAuthenticationMethods(Set<String> authenticationMethods)
      Optional. The authentication methods to be used for the authorized client. If none are set, 'none' will be used.
    • equals

      public boolean equals(Object o)
      Overrides:
      equals in class Object
    • canEqual

      protected boolean canEqual(Object other)
    • hashCode

      public int hashCode()
      Overrides:
      hashCode in class Object
    • toString

      public String toString()
      Overrides:
      toString in class Object