Package org.oa4mp.server.loader.oauth2
Class OA2SE
- java.lang.Object
-
- edu.uiuc.ncsa.security.core.util.AbstractEnvironment
-
- org.oa4mp.server.api.ServiceEnvironmentImpl
-
- org.oa4mp.server.loader.oauth2.OA2SE
-
- All Implemented Interfaces:
edu.uiuc.ncsa.security.core.Logable,Serializable,ServiceEnvironment
public class OA2SE extends ServiceEnvironmentImpl
Created by Jeff Gaynor
on 3/27/14 at 4:16 PM- See Also:
- Serialized Form
-
-
Nested Class Summary
-
Nested classes/interfaces inherited from class org.oa4mp.server.api.ServiceEnvironmentImpl
ServiceEnvironmentImpl.MessagesProvider
-
-
Field Summary
Fields Modifier and Type Field Description protected javax.inject.Provider<AdminClientStore>acsprotected ClaimSourceclaimSourceprotected javax.inject.Provider<edu.uiuc.ncsa.security.util.json.JSONStore>jsonStoreProviderprotected edu.uiuc.ncsa.security.util.jwk.JSONWebKeysjsonWebKeysprotected KEConfigurationkeConfigurationstatic StringNO_KEY_IDThis is used in the default VI to indicate there is no set default key id.static edu.uiuc.ncsa.security.core.IdentifierSERVER_VI_IDprotected List<edu.uiuc.ncsa.security.core.Store>storeList-
Fields inherited from class org.oa4mp.server.api.ServiceEnvironmentImpl
agip, atip, casp, clientApprovalStore, clientStore, csp, mailUtil, paip, psp, tfp, transactionStore, tsp
-
-
Constructor Summary
Constructors Constructor Description OA2SE(edu.uiuc.ncsa.security.core.util.MyLoggingFacade logger, javax.inject.Provider<TransactionStore> tsp, javax.inject.Provider<TXStore> txStoreProvider, javax.inject.Provider<VIStore> voStoreProvider, javax.inject.Provider<ClientStore> csp, javax.inject.Provider<KEStore> keStoreProvider, int maxAllowedNewClientRequests, long agLifetime, long maxAGLifetime, long idTokenLifetime, long maxIDTokenLifetime, long maxATLifetime, long atLifetime, long rtLifetime, long maxRTLifetime, javax.inject.Provider<ClientApprovalStore> casp, edu.uiuc.ncsa.security.util.mail.MailUtilProvider mup, ServiceEnvironmentImpl.MessagesProvider messagesProvider, javax.inject.Provider<AGIssuer> agip, javax.inject.Provider<ATIssuer> atip, javax.inject.Provider<PAIssuer> paip, javax.inject.Provider<TokenForge> tfp, HashMap<String,String> constants, AuthorizationServletConfig ac, edu.uiuc.ncsa.security.servlet.UsernameTransformer usernameTransformer, boolean isPingable, javax.inject.Provider<PermissionsStore> psp, javax.inject.Provider<AdminClientStore> acs, int clientSecretLength, Collection<String> scopes, ClaimSource claimSource, LDAPConfiguration ldapConfiguration2, boolean isRefreshTokenEnabled, boolean twoFactorSupportEnabled, long maxClientRefreshTokenLifetime, edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys, String issuer, boolean utilServletEnabled, boolean oidcEnabled, CMConfigs cmConfigs, OA2QDLEnvironment qdlEnvironment, boolean rfc8693Enabled, boolean qdlStrictACLs, boolean safeGC, boolean cleanupLockingEnabled, boolean cleanupFailOnErrors, RFC8628ServletConfig rfc8628ServletConfig, boolean rfc8628Enabled, boolean printTSInDebug, long cleanupInterval, Collection<LocalTime> cleanupAlarms, String notifyACEventEmailAddresses, boolean rfc7636Required, boolean demoModeEnabled, long rtGracePeriod, boolean isMonitorEnabled, long monitorInterval, Collection<LocalTime> monitorAlarms, boolean clientCredentialFlowEnabled, edu.uiuc.ncsa.security.core.util.MetaDebugUtil debugger, boolean allowPromptNone, DIServiceConfig DIServiceConfig, KEConfiguration keConfiguration)
-
Method Summary
All Methods Instance Methods Concrete Methods Deprecated Methods Modifier and Type Method Description protected edu.uiuc.ncsa.security.util.jwk.JSONWebKeysdoNormalization(edu.uiuc.ncsa.security.core.util.IdentifiableMap<KERecord> identifiableMap, boolean signingKeysOnly)Converts a map ofKERecords toJSONWebKeys.protected edu.uiuc.ncsa.security.util.jwk.JSONWebKeysdoNormalization(edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys)longgetAccessTokenLifetime()Get the configured default access token lifetime for the serverAdminClientStore<AdminClient>getAdminClientStore()Returns theAdminClientStore.List<edu.uiuc.ncsa.security.core.Store>getAllStores()A list of all stores.longgetAuthorizationGrantLifetime()ClaimSourcegetClaimSource()Collection<LocalTime>getCleanupAlarms()longgetCleanupInterval()intgetClientSecretLength()CMConfigsgetCmConfigs()edu.uiuc.ncsa.security.core.util.MetaDebugUtilgetDebugger()DIServiceConfiggetDIServiceConfig()longgetIdTokenLifetime()Get the configured default ID token lifetime for the serverStringgetIssuer()edu.uiuc.ncsa.security.util.json.JSONStore<? extends edu.uiuc.ncsa.security.util.json.JSONEntry>getJSONStore()edu.uiuc.ncsa.security.util.jwk.JSONWebKeysgetJsonWebKeys()Deprecated.edu.uiuc.ncsa.security.util.jwk.JSONWebKeysgetJsonWebKeys(edu.uiuc.ncsa.security.core.Identifier clientID)For a given client, get the keys for the Virtual issuer (may be null implying use)edu.uiuc.ncsa.security.util.jwk.JSONWebKeysgetJsonWebKeys(VirtualIssuer vi)Get the valid keys for the Virtual issuer (may be null implying use server default).edu.uiuc.ncsa.security.util.jwk.JSONWebKeysgetJsonWebKeys(VirtualIssuer vi, boolean signingKeysOnly)Get the unexpired keys for the Virtual issuer.KEConfigurationgetKeConfiguration()KEStore<KERecord>getKEStore()LDAPConfigurationgetLdapConfiguration()longgetMaxATLifetime()longgetMaxAuthorizationGrantLifetime()longgetMaxClientRefreshTokenLifetime()longgetMaxIdTokenLifetime()longgetMaxRTLifetime()Collection<LocalTime>getMonitorAlarms()longgetMonitorInterval()StringgetNotifyACEventEmailAddresses()OA2QDLEnvironmentgetQDLEnvironment()longgetRefreshTokenLifetime()Get the configured default refresh token lifetime for the serverRFC8628ServletConfiggetRfc8628ServletConfig()longgetRtGracePeriod()Collection<String>getScopes()The scopes this server currently supports.edu.uiuc.ncsa.security.util.jwk.JSONWebKeysgetServerJWKS()If the server configuration has JWKs then this will be set at load time.TXStoregetTxStore()VirtualIssuergetVI(edu.uiuc.ncsa.security.core.Identifier clientID)Given the client id, look up the admin and determine what (if any) the VI is.VIStoregetVIStore()booleanhasCleanupAlarms()booleanhasKEStore()booleanhasMonitorAlarams()booleanhasMonitorInterval()booleanhasScopeHandler()booleanisAllowPromptNone()Allow prompt = none parameter in OIDC clients. https://github.com/ncsa/oa4mp/issues/236.booleanisCCFEnabled()Is the client credential flow enabled for this server?booleanisCleanupFailOnErrors()booleanisCleanupLockingEnabled()booleanisDemoModeEnabled()booleanisMonitorEnabled()booleanisOIDCEnabled()Returnstrueif this server has OIDC support enabled.booleanisPrintTSInDebug()booleanisQdlStrictACLs()booleanisRefreshTokenEnabled()booleanisRfc7636Required()booleanisRfc8628Enabled()Device authorization flow endpoints.booleanisRfc8693Enabled()Token exchange endpointbooleanisRTGracePeriodEnabled()booleanisSafeGC()booleanisServerVI(VirtualIssuer vi)Is this the default server virtual issuer?booleanisTwoFactorSupportEnabled()booleanisUseProxyForCerts()booleanisUtilServletEnabled()List<edu.uiuc.ncsa.security.core.Store>listStores()List the current stores in this environment.voidsetAccessTokenLifetime(long accessTokenLifetime)voidsetAllowPromptNone(boolean allowPromptNone)voidsetAuthorizationGrantLifetime(long authorizationGrantLifetime)voidsetCCFEnabled(boolean ccfEnabled)voidsetClaimSource(ClaimSource claimSource)voidsetCleanupLockingEnabled(boolean cleanupLockingEnabled)voidsetDebugger(edu.uiuc.ncsa.security.core.util.MetaDebugUtil debugger)voidsetDemoModeEnabled(boolean demoModeEnabled)voidsetJsonWebKeys(edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys)voidsetKeConfiguration(KEConfiguration keConfiguration)voidsetKEStore(KEStore<KERecord> keStore)voidsetLdapConfiguration(LDAPConfiguration ldapConfiguration2)voidsetMonitorAlarms(Collection<LocalTime> monitorAlarms)voidsetMonitorEnabled(boolean monitorEnabled)voidsetMonitorInterval(long monitorInterval)voidsetQDLEnvironment(OA2QDLEnvironment qdlEnvironment)voidsetRefreshTokenEnabled(boolean refreshTokenEnabled)voidsetRefreshTokenLifetime(long refreshTokenLifetime)voidsetRfc7636Required(boolean rfc7636Required)voidsetRfc8628Enabled(boolean rfc8628Enabled)voidsetRfc8693Enabled(boolean rfc8693Enabled)voidsetRtGracePeriod(long rtGracePeriod)voidsetSafeGC(boolean safeGC)voidsetScopes(Collection<String> scopes)protected voidsetServerJWKS(edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys)voidsetTxStore(TXStore txStore)voidsetUseProxyForCerts(boolean useProxyForCerts)voidsetUtilServletEnabled(boolean utilServletEnabled)-
Methods inherited from class org.oa4mp.server.api.ServiceEnvironmentImpl
getAgIssuer, getAtIssuer, getAuthorizationServletConfig, getClientApprovalStore, getClientApprovalThread, getClientStore, getKeyPair, getKeyPairQueue, getMailUtil, getMaxAllowedNewClientRequests, getMessages, getPaIssuer, getPermissionStore, getServiceAddress, getTokenForge, getTransactionStore, getUsernameTransformer, hasAuthorizationServletConfig, isPollingEnabled, setClientApprovalThread, setServiceAddress, setUsernameTransformer
-
Methods inherited from class edu.uiuc.ncsa.security.core.util.AbstractEnvironment
debug, error, getConstants, getMyLogger, info, isDebugOn, isPingable, setDebugOn, setPingable, warn
-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface edu.uiuc.ncsa.security.core.Logable
debug, error, info, isDebugOn, setDebugOn, warn
-
Methods inherited from interface org.oa4mp.server.api.ServiceEnvironment
getConstants, isPingable
-
-
-
-
Field Detail
-
keConfiguration
protected KEConfiguration keConfiguration
-
jsonStoreProvider
protected javax.inject.Provider<edu.uiuc.ncsa.security.util.json.JSONStore> jsonStoreProvider
-
acs
protected javax.inject.Provider<AdminClientStore> acs
-
SERVER_VI_ID
public static final edu.uiuc.ncsa.security.core.Identifier SERVER_VI_ID
-
NO_KEY_ID
public static final String NO_KEY_ID
This is used in the default VI to indicate there is no set default key id. Otherwise the default ID in the VI will be used.- See Also:
- Constant Field Values
-
jsonWebKeys
protected edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys
-
claimSource
protected ClaimSource claimSource
-
storeList
protected List<edu.uiuc.ncsa.security.core.Store> storeList
-
-
Constructor Detail
-
OA2SE
public OA2SE(edu.uiuc.ncsa.security.core.util.MyLoggingFacade logger, javax.inject.Provider<TransactionStore> tsp, javax.inject.Provider<TXStore> txStoreProvider, javax.inject.Provider<VIStore> voStoreProvider, javax.inject.Provider<ClientStore> csp, javax.inject.Provider<KEStore> keStoreProvider, int maxAllowedNewClientRequests, long agLifetime, long maxAGLifetime, long idTokenLifetime, long maxIDTokenLifetime, long maxATLifetime, long atLifetime, long rtLifetime, long maxRTLifetime, javax.inject.Provider<ClientApprovalStore> casp, edu.uiuc.ncsa.security.util.mail.MailUtilProvider mup, ServiceEnvironmentImpl.MessagesProvider messagesProvider, javax.inject.Provider<AGIssuer> agip, javax.inject.Provider<ATIssuer> atip, javax.inject.Provider<PAIssuer> paip, javax.inject.Provider<TokenForge> tfp, HashMap<String,String> constants, AuthorizationServletConfig ac, edu.uiuc.ncsa.security.servlet.UsernameTransformer usernameTransformer, boolean isPingable, javax.inject.Provider<PermissionsStore> psp, javax.inject.Provider<AdminClientStore> acs, int clientSecretLength, Collection<String> scopes, ClaimSource claimSource, LDAPConfiguration ldapConfiguration2, boolean isRefreshTokenEnabled, boolean twoFactorSupportEnabled, long maxClientRefreshTokenLifetime, edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys, String issuer, boolean utilServletEnabled, boolean oidcEnabled, CMConfigs cmConfigs, OA2QDLEnvironment qdlEnvironment, boolean rfc8693Enabled, boolean qdlStrictACLs, boolean safeGC, boolean cleanupLockingEnabled, boolean cleanupFailOnErrors, RFC8628ServletConfig rfc8628ServletConfig, boolean rfc8628Enabled, boolean printTSInDebug, long cleanupInterval, Collection<LocalTime> cleanupAlarms, String notifyACEventEmailAddresses, boolean rfc7636Required, boolean demoModeEnabled, long rtGracePeriod, boolean isMonitorEnabled, long monitorInterval, Collection<LocalTime> monitorAlarms, boolean clientCredentialFlowEnabled, edu.uiuc.ncsa.security.core.util.MetaDebugUtil debugger, boolean allowPromptNone, DIServiceConfig DIServiceConfig, KEConfiguration keConfiguration)
-
-
Method Detail
-
getKeConfiguration
public KEConfiguration getKeConfiguration()
-
setKeConfiguration
public void setKeConfiguration(KEConfiguration keConfiguration)
-
isCleanupFailOnErrors
public boolean isCleanupFailOnErrors()
-
isMonitorEnabled
public boolean isMonitorEnabled()
-
setMonitorEnabled
public void setMonitorEnabled(boolean monitorEnabled)
-
getMonitorInterval
public long getMonitorInterval()
-
setMonitorInterval
public void setMonitorInterval(long monitorInterval)
-
getMonitorAlarms
public Collection<LocalTime> getMonitorAlarms()
-
setMonitorAlarms
public void setMonitorAlarms(Collection<LocalTime> monitorAlarms)
-
isCleanupLockingEnabled
public boolean isCleanupLockingEnabled()
-
setCleanupLockingEnabled
public void setCleanupLockingEnabled(boolean cleanupLockingEnabled)
-
getCleanupAlarms
public Collection<LocalTime> getCleanupAlarms()
-
hasCleanupAlarms
public boolean hasCleanupAlarms()
-
getDebugger
public edu.uiuc.ncsa.security.core.util.MetaDebugUtil getDebugger()
-
setDebugger
public void setDebugger(edu.uiuc.ncsa.security.core.util.MetaDebugUtil debugger)
-
isDemoModeEnabled
public boolean isDemoModeEnabled()
-
setDemoModeEnabled
public void setDemoModeEnabled(boolean demoModeEnabled)
-
getNotifyACEventEmailAddresses
public String getNotifyACEventEmailAddresses()
-
getCleanupInterval
public long getCleanupInterval()
-
hasMonitorAlarams
public boolean hasMonitorAlarams()
-
hasMonitorInterval
public boolean hasMonitorInterval()
-
getRfc8628ServletConfig
public RFC8628ServletConfig getRfc8628ServletConfig()
-
isPrintTSInDebug
public boolean isPrintTSInDebug()
-
isSafeGC
public boolean isSafeGC()
-
setSafeGC
public void setSafeGC(boolean safeGC)
-
isQdlStrictACLs
public boolean isQdlStrictACLs()
-
getMaxATLifetime
public long getMaxATLifetime()
-
getMaxRTLifetime
public long getMaxRTLifetime()
-
hasKEStore
public boolean hasKEStore()
-
getVIStore
public VIStore getVIStore()
-
getTxStore
public TXStore getTxStore()
-
setTxStore
public void setTxStore(TXStore txStore)
-
getQDLEnvironment
public OA2QDLEnvironment getQDLEnvironment()
-
setQDLEnvironment
public void setQDLEnvironment(OA2QDLEnvironment qdlEnvironment)
-
getCmConfigs
public CMConfigs getCmConfigs()
-
getJSONStore
public edu.uiuc.ncsa.security.util.json.JSONStore<? extends edu.uiuc.ncsa.security.util.json.JSONEntry> getJSONStore()
-
isRfc8693Enabled
public boolean isRfc8693Enabled()
Token exchange endpoint- Returns:
-
setRfc8693Enabled
public void setRfc8693Enabled(boolean rfc8693Enabled)
-
isCCFEnabled
public boolean isCCFEnabled()
Is the client credential flow enabled for this server?- Returns:
-
setCCFEnabled
public void setCCFEnabled(boolean ccfEnabled)
-
isRfc8628Enabled
public boolean isRfc8628Enabled()
Device authorization flow endpoints.- Returns:
-
setRfc8628Enabled
public void setRfc8628Enabled(boolean rfc8628Enabled)
-
getAdminClientStore
public AdminClientStore<AdminClient> getAdminClientStore()
Description copied from interface:ServiceEnvironmentReturns theAdminClientStore.- Specified by:
getAdminClientStorein interfaceServiceEnvironment- Overrides:
getAdminClientStorein classServiceEnvironmentImpl- Returns:
-
isUtilServletEnabled
public boolean isUtilServletEnabled()
-
setUtilServletEnabled
public void setUtilServletEnabled(boolean utilServletEnabled)
-
getIssuer
public String getIssuer()
-
doNormalization
protected edu.uiuc.ncsa.security.util.jwk.JSONWebKeys doNormalization(edu.uiuc.ncsa.security.core.util.IdentifiableMap<KERecord> identifiableMap, boolean signingKeysOnly)
Converts a map ofKERecords toJSONWebKeys. Note this returns the set of unexpired keys if signingKeysOnly is false. Otherwise, it returns exactly the set of keys that are valid for signing.Why filter by dates? Because otherwise we need a complex set of metadata which will require updating on the fly to manage as expirations, not-before dates come and go. This is much easier.
- Parameters:
identifiableMap-signingKeysOnly- if true only keys with valid dates (so nbf < now) are returned.- Returns:
-
doNormalization
protected edu.uiuc.ncsa.security.util.jwk.JSONWebKeys doNormalization(edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys)
-
getJsonWebKeys
public edu.uiuc.ncsa.security.util.jwk.JSONWebKeys getJsonWebKeys(VirtualIssuer vi)
Get the valid keys for the Virtual issuer (may be null implying use server default). This is used in cases where there is no client ID, such as you are accessing the keys for an admin client directly.- Parameters:
vi-- Returns:
-
getJsonWebKeys
public edu.uiuc.ncsa.security.util.jwk.JSONWebKeys getJsonWebKeys(VirtualIssuer vi, boolean signingKeysOnly)
Get the unexpired keys for the Virtual issuer.Note that the unexpired kehys are shown on the discovery page, but for signing, only keys that have no expiration date are used.
- Parameters:
vi-signingKeysOnly- If true only keys used for signing are returned.- Returns:
-
getJsonWebKeys
public edu.uiuc.ncsa.security.util.jwk.JSONWebKeys getJsonWebKeys(edu.uiuc.ncsa.security.core.Identifier clientID)
For a given client, get the keys for the Virtual issuer (may be null implying use)- Parameters:
clientID-- Returns:
-
getJsonWebKeys
public edu.uiuc.ncsa.security.util.jwk.JSONWebKeys getJsonWebKeys()
Deprecated.Get the current server keys.- Returns:
-
setJsonWebKeys
public void setJsonWebKeys(edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys)
-
getServerJWKS
public edu.uiuc.ncsa.security.util.jwk.JSONWebKeys getServerJWKS()
If the server configuration has JWKs then this will be set at load time. Otherwise it will be null.- Returns:
-
setServerJWKS
protected void setServerJWKS(edu.uiuc.ncsa.security.util.jwk.JSONWebKeys jsonWebKeys)
-
isTwoFactorSupportEnabled
public boolean isTwoFactorSupportEnabled()
-
getMaxClientRefreshTokenLifetime
public long getMaxClientRefreshTokenLifetime()
-
getMaxIdTokenLifetime
public long getMaxIdTokenLifetime()
-
getIdTokenLifetime
public long getIdTokenLifetime()
Get the configured default ID token lifetime for the server- Returns:
-
isRefreshTokenEnabled
public boolean isRefreshTokenEnabled()
-
setRefreshTokenEnabled
public void setRefreshTokenEnabled(boolean refreshTokenEnabled)
-
getClientSecretLength
public int getClientSecretLength()
-
getScopes
public Collection<String> getScopes()
The scopes this server currently supports.- Returns:
-
setScopes
public void setScopes(Collection<String> scopes)
-
getClaimSource
public ClaimSource getClaimSource()
-
setClaimSource
public void setClaimSource(ClaimSource claimSource)
-
hasScopeHandler
public boolean hasScopeHandler()
-
getLdapConfiguration
public LDAPConfiguration getLdapConfiguration()
-
setLdapConfiguration
public void setLdapConfiguration(LDAPConfiguration ldapConfiguration2)
-
isOIDCEnabled
public boolean isOIDCEnabled()
Returnstrueif this server has OIDC support enabled.- Returns:
-
getAccessTokenLifetime
public long getAccessTokenLifetime()
Get the configured default access token lifetime for the server- Returns:
-
setAccessTokenLifetime
public void setAccessTokenLifetime(long accessTokenLifetime)
-
setRefreshTokenLifetime
public void setRefreshTokenLifetime(long refreshTokenLifetime)
-
getRefreshTokenLifetime
public long getRefreshTokenLifetime()
Get the configured default refresh token lifetime for the server- Returns:
-
getMaxAuthorizationGrantLifetime
public long getMaxAuthorizationGrantLifetime()
-
getAuthorizationGrantLifetime
public long getAuthorizationGrantLifetime()
-
setAuthorizationGrantLifetime
public void setAuthorizationGrantLifetime(long authorizationGrantLifetime)
-
getVI
public VirtualIssuer getVI(edu.uiuc.ncsa.security.core.Identifier clientID)
Given the client id, look up the admin and determine what (if any) the VI is. The returned value may be null,, meaning there is no VI. If the VI is disabled, it will not be returned either.
This has its own call here because it involves multiple store lookups. It cannot be done as a join in SQL or some such because there are no guarantees the stores are all SQL -- some may be file stores or even in another unrelated database.Note that this will throw an exception is the client is in multiple VIs.
- Parameters:
clientID-- Returns:
-
listStores
public List<edu.uiuc.ncsa.security.core.Store> listStores()
Description copied from interface:ServiceEnvironmentList the current stores in this environment. Used at bootstrapping for various types of introspection.- Specified by:
listStoresin interfaceServiceEnvironment- Overrides:
listStoresin classServiceEnvironmentImpl- Returns:
-
isRfc7636Required
public boolean isRfc7636Required()
-
setRfc7636Required
public void setRfc7636Required(boolean rfc7636Required)
-
getRtGracePeriod
public long getRtGracePeriod()
-
setRtGracePeriod
public void setRtGracePeriod(long rtGracePeriod)
-
isRTGracePeriodEnabled
public boolean isRTGracePeriodEnabled()
-
isUseProxyForCerts
public boolean isUseProxyForCerts()
-
setUseProxyForCerts
public void setUseProxyForCerts(boolean useProxyForCerts)
-
getAllStores
public List<edu.uiuc.ncsa.security.core.Store> getAllStores()
A list of all stores. This is used in bootstrapping the system and initializing it.- Returns:
-
isAllowPromptNone
public boolean isAllowPromptNone()
Allow prompt = none parameter in OIDC clients. https://github.com/ncsa/oa4mp/issues/236. This should be configurable.- Returns:
-
setAllowPromptNone
public void setAllowPromptNone(boolean allowPromptNone)
-
getDIServiceConfig
public DIServiceConfig getDIServiceConfig()
-
isServerVI
public boolean isServerVI(VirtualIssuer vi)
Is this the default server virtual issuer?- Parameters:
vi-- Returns:
-
-