23 Sep, 2014
1 commit
-
git-svn-id: https://svn.forgerock.org/openig/trunk@586 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
22 Sep, 2014
2 commits
-
git-svn-id: https://svn.forgerock.org/openig/trunk@585 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
This patch puts the sample filter in the doc samples, and shows a class alias resolver. git-svn-id: https://svn.forgerock.org/openig/trunk@584 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
19 Sep, 2014
1 commit
-
git-svn-id: https://svn.forgerock.org/openig/trunk@583 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
18 Sep, 2014
1 commit
-
If you can store all state on the user-agent, for example by using the JwtSession implementation, then perhaps OpenIG can be stateless enough that there is no need to do anything special when load balancing. If some of the state is stored on the server, then you need to configure the load balancer for session stickiness and to configure the container for session replication. Neither the load balancer configuration nor the container configuration are specific to OpenIG, so this patch explains what needs doing and points to the documentation for supported containers Apache Tomcat & Jetty. git-svn-id: https://svn.forgerock.org/openig/trunk@582 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
17 Sep, 2014
1 commit
-
This patch removes arbitrary use of exchange.session, but also shows using JwtSession where it could make sense, as in the federation tutorial. git-svn-id: https://svn.forgerock.org/openig/trunk@581 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
16 Sep, 2014
4 commits
-
Trivial fix reviewed by Guillaume. git-svn-id: https://svn.forgerock.org/openig/trunk@580 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@579 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@578 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@577 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
15 Sep, 2014
6 commits
-
git-svn-id: https://svn.forgerock.org/openig/trunk@575 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@574 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
It was misplaced in the openig-core module where it was used in openig-war module. git-svn-id: https://svn.forgerock.org/openig/trunk@573 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
Heap.get(String):Object gains type safety Heap.get(String, Class<T>):T Heap.getRequiredObject(JsonValue, Class<T>) has a shorter name Heap.resolve(JsonValue, Class<T>):T Heap.getObject(JsonValue, Class<T>) is replaced by a resolve variant that supports optional dependencies: Heap.resolve(JsonValue, Class<T>, boolean):T git-svn-id: https://svn.forgerock.org/openig/trunk@572 dbb9e58e-28e6-4ce0-90e8-f11d9605b710 -
Inline object declarations are a mean to ease understanding of Exchange processing. They permit to describe anonymously, inner objects when a reference to another heap object is required. That introduce, in the configuration files, some hierarchical support, easing the user to mentally represents his processing chain. This is done in a fully backward compatible way, without requiring any changes to existing object declarations (the one that requires other objects through references or names). The idea is to automatically extract inline declaration when the Heaplet is calling the get***Object() methods: if the provided JsonValue is a String, traditional object lookup is performed, but when the JsonValue represents a JSONObject (a Map), we try to turn this into a normal object declaration (just like what is done during heap initialisation). If the given JsonValue does not describe a valid declaration, a JsonValueException is thrown (again, just like the heap init process is doing). Notice that inline declarations do not require a 'name' attribute to be specified (like anonymous Java classes), so we generate a unique name based on the JsonPointer (represents the location of the node in the JSON structure). Notice that OPENIG-316 is partly resolved in this commit: HeapUtil methods have only been moved into the Heap interface: no additional type safety, no renaming. git-svn-id: https://svn.forgerock.org/openig/trunk@571 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
12 Sep, 2014
2 commits
-
git-svn-id: https://svn.forgerock.org/openig/trunk@570 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@569 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
11 Sep, 2014
1 commit
-
git-svn-id: https://svn.forgerock.org/openig/trunk@568 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
10 Sep, 2014
3 commits
-
git-svn-id: https://svn.forgerock.org/openig/trunk@567 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@566 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
OpenIG used to provide a default Session implementation based on the underlying Servlet container's HttpSession. This changeset intends to gives to the user the ability to change the session persistence strategy (in other words: changing the Session implementation). This can be done at the global level (in the config.json, declaring a SessionFactory object named 'Session') or on a per-route basis (with the new 'session' attribute). When an Exchanges comes into a route that declares a new session type, a new session is build (no existing session items are propagated) and replace the old session. When the exchange exits the route, the new session is closed (notify the session that it's time to persist its content) and is replaced by the old one. Really like a push/pop stack mechanism. Notice that the 2 sessions are completely separated (cannot access the old content from the new and vis-versa). First, that would defeat the purpose of different session persistence modes (if items are propagated, where should I persist them ?). Secondly, Session is not intended to share data between handlers/filters: the Exchange is basically a request-scoped Map that is designed for that purpose. The JWT based session is a session implementation whose persistence is done using an HTTP Cookie, the session's content being serialized as JSON (usable types are constrained, see list below) and used as the payload of an encrypted JSON Web Token (JWT). The use of the JWT session has a few constraints: * HTTP Cookies are size-limited to 4K -> Small objects can be stored * Only JSON compatible types are supported: * null * Java primitive types + their boxed equivalent * Strings (and any CharSequence) * List and Map (of the supported types, recursively) * Same client performing concurrent HTTP invocations (so within the same HTTP session) that will modify their own session content will see inconsistencies in the session. This is due to the fact that the JWT session is not shared, each concurrent Thread has its own instance and can modify it at will. At the end of the processing, each Thread will serialize its own session's content regardless of other Threads. git-svn-id: https://svn.forgerock.org/openig/trunk@565 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
09 Sep, 2014
1 commit
-
… parent configurations git-svn-id: https://svn.forgerock.org/openig/trunk@564 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
08 Sep, 2014
3 commits
-
git-svn-id: https://svn.forgerock.org/openig/trunk@563 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@562 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@561 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
05 Sep, 2014
6 commits
-
To keep backward compatibility, 'keystone' and 'truststore' are left unchanged but have been deprecated. We've added 2 new attributes to specify reference(s) to TrustManager(s) and KeyManager(s) declared as heap objects. Issues: OPENIG-305 git-svn-id: https://svn.forgerock.org/openig/trunk@560 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
This change eases references resolution when they are provided as a JSON String array (like ["RefOne", "RefTwo"]). git-svn-id: https://svn.forgerock.org/openig/trunk@559 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
The two referenced service implementations do not exist (anymore ?). And the service file name was incorrect (no HeapletService interface exist). git-svn-id: https://svn.forgerock.org/openig/trunk@558 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
KeyStore and related security objects are being more and more central to OpenIG: * Used by HttpClient * Needed for encryption / decryption This patch is a first step to provide a way to configure theses as usual heap objects (through JSON). KeyStore heap object is an abstraction around the keystore file (either JKS, PKCS12 or other depending on the platform capabilities). Specifying a password or not depends on he usage: * If KeyStore will be used to read private credentials (through a KeyManager for example), a password is required * If not (for a TrustManager), no password is required KeyManager and TrustManager are using a KeyStore heap object and are used within SSL mechanism (SSLContext) to provide a view on the KeyStore: * KeyManager when private credentials access is required. * TrustManager when only public information access is required Issues: OPENIG-295 Reviews: CR-4441 git-svn-id: https://svn.forgerock.org/openig/trunk@557 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
The previously introduced evaluate() method was a step in the right direction, allowing resolution of static (no references to ${exchange}) string JsonValue, returning a simple resolved String. While it works great, it's a shame that we don't benefit anymore of the JsonValue API, in particular the conversion methods (asURL(), ...). This fix uses a JsonTransformer to actually resolve any String wrapped JsonValue and creates a deep copy of the given JsonValue. git-svn-id: https://svn.forgerock.org/openig/trunk@556 dbb9e58e-28e6-4ce0-90e8-f11d9605b710 -
When a new heap object instance has to be created, we first have to find a Heaplet instance that will create the required object from the given JSON configuration. Heaplet instances are linked to the single object they created: they manage the heap object lifecycle with the start() and destroy() methods. The old behaviour was using Heaplet instances directly loaded and instantiated, meaning that a single Heaplet instance could be used to create multiple heap objects, somehow mixing states, which was very wrong. Now, HeapletFactory (instead of direct Heaplet) are found using the ServiceLoader discovery mechanism. They are responsible to create new Heaplet instances, meaning that we cannot anymore share a Heaplet instance for 2 or more heap objects. Heaplet class does not extends Indexed<Class> anymore (was only used because of the way Heaplets was looking for Heaplet instances). NestedHeaplet is now deprecated since its only duty was to implement the Indexed interface. All references to NestedHeaplet were replaced to GenericHeaplet (its parent class) in our code base to avoid ugly compiler warnings. As per OPENIG-302 comments, the HeapletFactory will be a short-lived concept since this additional layer introduction was the straw that broke the camel's back :) Issues: OPENIG-302 Reviews: CR-4457 git-svn-id: https://svn.forgerock.org/openig/trunk@555 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
04 Sep, 2014
3 commits
-
git-svn-id: https://svn.forgerock.org/openig/trunk@554 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
OPENIG-169: OpenIG should work when the war file is not deployed to the root context has been resolved as Won't Fix, so we should make this clear in the release notes, and not just in the install chapter. Thanks to Guillaume for review over IM. git-svn-id: https://svn.forgerock.org/openig/trunk@553 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
No material changes to the content. git-svn-id: https://svn.forgerock.org/openig/trunk@552 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
03 Sep, 2014
3 commits
-
git-svn-id: https://svn.forgerock.org/openig/trunk@551 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
git-svn-id: https://svn.forgerock.org/openig/trunk@550 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
-
…verFilter access token git-svn-id: https://svn.forgerock.org/openig/trunk@549 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
02 Sep, 2014
1 commit
-
- Renamed ACCESS_TOKEN_KEY to DEFAULT_ACCESS_TOKEN_KEY. - Target is now optional/customizable for user. Default to ${exchange.oauth2AccessToken}. git-svn-id: https://svn.forgerock.org/openig/trunk@548 dbb9e58e-28e6-4ce0-90e8-f11d9605b710
01 Sep, 2014
1 commit
-
Tested locally... this should be okay. git-svn-id: https://svn.forgerock.org/openig/trunk@547 dbb9e58e-28e6-4ce0-90e8-f11d9605b710