Class DefaultAuthServerProperties.AuthServerProperties
- Enclosing class:
- DefaultAuthServerProperties
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionprotected booleanbooleanOptional.Optional.Optional.A whitelist of default post-authentication redirect URIs for authorization clients.Optional.If set to true, no Authorization servers or Clients will be automatically created for this tenant.Optional.A whitelist of default post-authentication redirect URIs.Optional.Optional.A whitelist of default post-authentication redirect URIs.Optional.Optional.intDefault is 21600 (6 hours).Optional.A whitelist of default post-authentication redirect URIs for authorization clients.Optional.Optional.intDefault of 86400 (24 hours).Optional.intDefault of 300 seconds.Optional.inthashCode()booleanWhether or not the user's session with this authorization server is active for cross-origin requests.booleanDefault is false.booleanDefault is true.voidsetAuthenticationMethods(Set<String> authenticationMethods) Optional.voidsetAuthorizationServerId(String authorizationServerId) Optional.voidsetContextPathDefaultClientRedirectUri(String contextPathDefaultClientRedirectUri) Optional.voidsetContextPathDefaultPostAuthSuccessRedirectUris(Set<String> contextPathDefaultPostAuthSuccessRedirectUris) A whitelist of default post-authentication redirect URIs for authorization clients.voidsetContextPathDefaultRedirectUris(Set<String> contextPathDefaultRedirectUris) Optional.voidsetCrossOrigin(boolean crossOrigin) Whether or not the user's session with this authorization server is active for cross-origin requests.voidsetDisabled(Boolean disabled) If set to true, no Authorization servers or Clients will be automatically created for this tenant.voidsetDomainDefaultClientRedirectUri(String domainDefaultClientRedirectUri) Optional.voidsetDomainDefaultPostAuthSuccessRedirectUris(Set<String> domainDefaultPostAuthSuccessRedirectUris) A whitelist of default post-authentication redirect URIs.voidsetDomainDefaultRedirectUris(Set<String> domainDefaultRedirectUris) Optional.voidsetDomainPrefixDefaultClientRedirectUri(String domainPrefixDefaultClientRedirectUri) Optional.voidsetDomainPrefixDefaultPostAuthSuccessRedirectUris(Set<String> domainPrefixDefaultPostAuthSuccessRedirectUris) A whitelist of default post-authentication redirect URIs.voidsetDomainPrefixDefaultRedirectUris(Set<String> domainPrefixDefaultRedirectUris) Optional.voidsetEmbeddedLoginEnabled(boolean embeddedLoginEnabled) Default is false.voidsetGrantTypes(Set<String> grantTypes) Optional.voidsetInactivityTimeoutSeconds(int inactivityTimeoutSeconds) Default is 21600 (6 hours).voidsetParameterDefaultClientRedirectUri(String parameterDefaultClientRedirectUri) Optional.voidsetParameterDefaultPostAuthSuccessRedirectUris(Set<String> parameterDefaultPostAuthSuccessRedirectUris) A whitelist of default post-authentication redirect URIs for authorization clients.voidsetParameterDefaultRedirectUris(Set<String> parameterDefaultRedirectUris) Optional.voidsetPermissionIds(Set<String> permissionIds) Optional.voidsetRequireLoginTimeoutSeconds(int requireLoginTimeoutSeconds) Default of 86400 (24 hours).voidsetResetPasswordBaseUri(String resetPasswordBaseUri) Optional.voidsetSsoEnabled(boolean ssoEnabled) Default is true.voidsetTokenTimeoutSeconds(int tokenTimeoutSeconds) Default of 300 seconds.voidsetUserRoleIds(Set<String> userRoleIds) Optional.toString()
-
Constructor Details
-
AuthServerProperties
public AuthServerProperties()
-
-
Method Details
-
getAuthorizationServerId
Optional. The default authorization server ID to use when creating an authorized client. Settings this will cause all new applications to share a single authorization server, which allows logins to be shared across multiple applications. If blank, a new Authorization server will be created for each application.Note that an ID can be set here even if an authorization server with this ID does not yet exist. If an authorization server does not exist, one will be created with this ID.
-
getUserRoleIds
Optional. The default user role IDs to assign on new authorization servers for this tenant. -
getPermissionIds
Optional. The default permission IDs to assign on new authorization servers for this tenant. -
getRequireLoginTimeoutSeconds
public int getRequireLoginTimeoutSeconds()Default of 86400 (24 hours). The maximum amount of time, in seconds, a user's session will persist before requiring re-login. -
getInactivityTimeoutSeconds
public int getInactivityTimeoutSeconds()Default is 21600 (6 hours). The period of time, in seconds, that the user's session will timeout if no action is taken. -
isCrossOrigin
public boolean isCrossOrigin()Whether or not the user's session with this authorization server is active for cross-origin requests. If set to true, the session cookie will include a SameSite policy of "None", thereby allowing the session cookie for cross-origin requests. Defaults to false. -
isSsoEnabled
public boolean isSsoEnabled()Default is true. Is SSO enabled for this authorization server? -
isEmbeddedLoginEnabled
public boolean isEmbeddedLoginEnabled()Default is false. Is embedded login enabled for this authorization server? -
getDomainDefaultRedirectUris
Optional. The default redirect URIs for authorization clients. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.DOMAINidentifier type.For example, for a new application with the domain "my-ecommerce-site.com", a default redirect URI of
https://{domain}would result in a redirect URI ofhttps://my-ecommerce-site.com. -
getDomainDefaultPostAuthSuccessRedirectUris
A whitelist of default post-authentication redirect URIs. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theidentifier typeof DOMAIN. -
getDomainPrefixDefaultRedirectUris
Optional. The default redirect URIs for authorization clients. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.DOMAIN_PREFIXidentifier type.For example, for a new application with a domain prefix of "my-ecommerce-site", a default redirect URI of
https://{domain}.shopping.comwould result in a redirect URI ofhttps://my-ecommerce-site.shopping.com. -
getDomainPrefixDefaultPostAuthSuccessRedirectUris
A whitelist of default post-authentication redirect URIs. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theidentifier typeof DOMAIN_PREFIX. -
getParameterDefaultRedirectUris
Optional. The default redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.PARAMETERidentifier type.For example, for a new application with the param "my-ecommerce-site", a default redirect URI of
https://my-domain.com/?application={identifier}would result in a redirect URI ofhttps://my-domain.com/?application=my-ecommerce-site. -
getParameterDefaultPostAuthSuccessRedirectUris
A whitelist of default post-authentication redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.PARAMETERidentifier type. -
getContextPathDefaultRedirectUris
Optional. The default redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.CONTEXT_PATHidentifier type.For example, for a new application with the param "my-ecommerce-site", a default redirect URI of
https://my-domain.com/{identifier}would result in a redirect URI ofhttps://my-domain.com/my-ecommerce-site. -
getContextPathDefaultPostAuthSuccessRedirectUris
A whitelist of default post-authentication redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.CONTEXT_PATHidentifier type. -
getTokenTimeoutSeconds
public int getTokenTimeoutSeconds()Default of 300 seconds. The period of time, in seconds, that an access token issued will be valid for. -
getDomainDefaultClientRedirectUri
Optional. The default client redirect URI. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theidentifier typeof DOMAIN.For example, for a new application with the domain "my-ecommerce-site.com", a default redirect URI of
https://{domain}would result in a redirect URI ofhttps://my-ecommerce-site.com. -
getDomainPrefixDefaultClientRedirectUri
Optional. The default client redirect URI. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theidentifier typeof DOMAIN_PREFIX.For example, for a new application with a domain prefix of "my-ecommerce-site", a default redirect URI of
https://{domain}.shopping.comwould result in a redirect URI ofhttps://my-ecommerce-site.shopping.com. -
getParameterDefaultClientRedirectUri
Optional. The default redirect URI for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.PARAMETERidentifier type.For example, for a new application with the param "my-ecommerce-site", a default redirect URI of
https://my-domain.com/?application={identifier}would result in a redirect URI ofhttps://my-domain.com/?application=my-ecommerce-site. -
getContextPathDefaultClientRedirectUri
Optional. The default redirect URI for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.CONTEXT_PATHidentifier type.For example, for a new application with the param "my-ecommerce-site", a default redirect URI of
https://my-domain.com/{identifier}would result in a redirect URI ofhttps://my-domain.com/my-ecommerce-site. -
getResetPasswordBaseUri
Optional. The reset password form's base URI. If blank, the default client redirect uri will be used instead.This is only needed in cross-origin auth scenarios where the client is on a different domain from the auth server and SSO is in use instead of embedded login, e.g., client is on
https://www.my-store.comand auth (where the form is) ishttps://www.my-auth-server.com. -
getDisabled
If set to true, no Authorization servers or Clients will be automatically created for this tenant. Note that the most specific configuration always wins. So if the 'default' value is disabled, and properties are defined for a specific tenant ID, the tenant ID properties will be used. -
getGrantTypes
Optional. The grant types to be used for the authorized client. If none are set, 'authorization_code' will be used. -
getAuthenticationMethods
Optional. The authentication methods to be used for the authorized client. If none are set, 'none' will be used. -
setAuthorizationServerId
Optional. The default authorization server ID to use when creating an authorized client. Settings this will cause all new applications to share a single authorization server, which allows logins to be shared across multiple applications. If blank, a new Authorization server will be created for each application.Note that an ID can be set here even if an authorization server with this ID does not yet exist. If an authorization server does not exist, one will be created with this ID.
-
setUserRoleIds
Optional. The default user role IDs to assign on new authorization servers for this tenant. -
setPermissionIds
Optional. The default permission IDs to assign on new authorization servers for this tenant. -
setRequireLoginTimeoutSeconds
public void setRequireLoginTimeoutSeconds(int requireLoginTimeoutSeconds) Default of 86400 (24 hours). The maximum amount of time, in seconds, a user's session will persist before requiring re-login. -
setInactivityTimeoutSeconds
public void setInactivityTimeoutSeconds(int inactivityTimeoutSeconds) Default is 21600 (6 hours). The period of time, in seconds, that the user's session will timeout if no action is taken. -
setCrossOrigin
public void setCrossOrigin(boolean crossOrigin) Whether or not the user's session with this authorization server is active for cross-origin requests. If set to true, the session cookie will include a SameSite policy of "None", thereby allowing the session cookie for cross-origin requests. Defaults to false. -
setSsoEnabled
public void setSsoEnabled(boolean ssoEnabled) Default is true. Is SSO enabled for this authorization server? -
setEmbeddedLoginEnabled
public void setEmbeddedLoginEnabled(boolean embeddedLoginEnabled) Default is false. Is embedded login enabled for this authorization server? -
setDomainDefaultRedirectUris
Optional. The default redirect URIs for authorization clients. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.DOMAINidentifier type.For example, for a new application with the domain "my-ecommerce-site.com", a default redirect URI of
https://{domain}would result in a redirect URI ofhttps://my-ecommerce-site.com. -
setDomainDefaultPostAuthSuccessRedirectUris
public void setDomainDefaultPostAuthSuccessRedirectUris(Set<String> domainDefaultPostAuthSuccessRedirectUris) A whitelist of default post-authentication redirect URIs. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theidentifier typeof DOMAIN. -
setDomainPrefixDefaultRedirectUris
Optional. The default redirect URIs for authorization clients. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.DOMAIN_PREFIXidentifier type.For example, for a new application with a domain prefix of "my-ecommerce-site", a default redirect URI of
https://{domain}.shopping.comwould result in a redirect URI ofhttps://my-ecommerce-site.shopping.com. -
setDomainPrefixDefaultPostAuthSuccessRedirectUris
public void setDomainPrefixDefaultPostAuthSuccessRedirectUris(Set<String> domainPrefixDefaultPostAuthSuccessRedirectUris) A whitelist of default post-authentication redirect URIs. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theidentifier typeof DOMAIN_PREFIX. -
setParameterDefaultRedirectUris
Optional. The default redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.PARAMETERidentifier type.For example, for a new application with the param "my-ecommerce-site", a default redirect URI of
https://my-domain.com/?application={identifier}would result in a redirect URI ofhttps://my-domain.com/?application=my-ecommerce-site. -
setParameterDefaultPostAuthSuccessRedirectUris
public void setParameterDefaultPostAuthSuccessRedirectUris(Set<String> parameterDefaultPostAuthSuccessRedirectUris) A whitelist of default post-authentication redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.PARAMETERidentifier type. -
setContextPathDefaultRedirectUris
Optional. The default redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.CONTEXT_PATHidentifier type.For example, for a new application with the param "my-ecommerce-site", a default redirect URI of
https://my-domain.com/{identifier}would result in a redirect URI ofhttps://my-domain.com/my-ecommerce-site. -
setContextPathDefaultPostAuthSuccessRedirectUris
public void setContextPathDefaultPostAuthSuccessRedirectUris(Set<String> contextPathDefaultPostAuthSuccessRedirectUris) A whitelist of default post-authentication redirect URIs for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.CONTEXT_PATHidentifier type. -
setTokenTimeoutSeconds
public void setTokenTimeoutSeconds(int tokenTimeoutSeconds) Default of 300 seconds. The period of time, in seconds, that an access token issued will be valid for. -
setDomainDefaultClientRedirectUri
Optional. The default client redirect URI. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theidentifier typeof DOMAIN.For example, for a new application with the domain "my-ecommerce-site.com", a default redirect URI of
https://{domain}would result in a redirect URI ofhttps://my-ecommerce-site.com. -
setDomainPrefixDefaultClientRedirectUri
Optional. The default client redirect URI. Supports the special variable {domain} that uses the application'sidentifier valuewhen it's of theidentifier typeof DOMAIN_PREFIX.For example, for a new application with a domain prefix of "my-ecommerce-site", a default redirect URI of
https://{domain}.shopping.comwould result in a redirect URI ofhttps://my-ecommerce-site.shopping.com. -
setParameterDefaultClientRedirectUri
Optional. The default redirect URI for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.PARAMETERidentifier type.For example, for a new application with the param "my-ecommerce-site", a default redirect URI of
https://my-domain.com/?application={identifier}would result in a redirect URI ofhttps://my-domain.com/?application=my-ecommerce-site. -
setContextPathDefaultClientRedirectUri
Optional. The default redirect URI for authorization clients. Supports the special variable {identifier} that uses the application'sidentifier valuewhen it's of theResolutionIdentifierType.CONTEXT_PATHidentifier type.For example, for a new application with the param "my-ecommerce-site", a default redirect URI of
https://my-domain.com/{identifier}would result in a redirect URI ofhttps://my-domain.com/my-ecommerce-site. -
setResetPasswordBaseUri
Optional. The reset password form's base URI. If blank, the default client redirect uri will be used instead.This is only needed in cross-origin auth scenarios where the client is on a different domain from the auth server and SSO is in use instead of embedded login, e.g., client is on
https://www.my-store.comand auth (where the form is) ishttps://www.my-auth-server.com. -
setDisabled
If set to true, no Authorization servers or Clients will be automatically created for this tenant. Note that the most specific configuration always wins. So if the 'default' value is disabled, and properties are defined for a specific tenant ID, the tenant ID properties will be used. -
setGrantTypes
Optional. The grant types to be used for the authorized client. If none are set, 'authorization_code' will be used. -
setAuthenticationMethods
Optional. The authentication methods to be used for the authorized client. If none are set, 'none' will be used. -
equals
-
canEqual
-
hashCode
public int hashCode() -
toString
-