Package com.oracle.bmc.auth
Class AbstractFederationClientAuthenticationDetailsProviderBuilder<B extends AbstractFederationClientAuthenticationDetailsProviderBuilder<B,P>,P extends AbstractAuthenticationDetailsProvider>
- java.lang.Object
-
- com.oracle.bmc.auth.AbstractRequestingAuthenticationDetailsProvider.Builder<B>
-
- com.oracle.bmc.auth.AbstractFederationClientAuthenticationDetailsProviderBuilder<B,P>
-
- Type Parameters:
B- builder classP- provider class
- Direct Known Subclasses:
InstancePrincipalsAuthenticationDetailsProvider.InstancePrincipalsAuthenticationDetailsProviderBuilder,ResourcePrincipalAuthenticationDetailsProvider.ResourcePrincipalAuthenticationDetailsProviderBuilder
public abstract class AbstractFederationClientAuthenticationDetailsProviderBuilder<B extends AbstractFederationClientAuthenticationDetailsProviderBuilder<B,P>,P extends AbstractAuthenticationDetailsProvider> extends AbstractRequestingAuthenticationDetailsProvider.Builder<B>
Abstract builder base class for authentication details provider extendingAbstractRequestingAuthenticationDetailsProvider
-
-
Field Summary
Fields Modifier and Type Field Description static StringAUTHORIZATION_HEADER_VALUEThe Authorization header value to be sent for requests to the metadata service.protected ClientConfiguratorfederationClientMetadataConfiguratorConfigurator for metadata service clients used to discover region and certificates.protected StringfederationEndpointThe federation endpoint url.protected X509CertificateSupplierleafCertificateSupplierThe leaf certificate, or null if detecting from instance metadata.static StringMETADATA_BASE_URL_ENV_VAREnvironment variable used to overwrite the default metadata base url.static StringMETADATA_SERVICE_BASE_URLDefault base url of metadata service.static StringMETADATA_URL_OVERRIDEMetadata URL from environment variable, to use if present.protected StringmetadataBaseUrlBase url of metadata service.protected RegionregionDetected region.protected static ServiceSERVICEService instance for auth.protected StringtenancyIdTenancy OCI, or null if detecting from instance metadata.-
Fields inherited from class com.oracle.bmc.auth.AbstractRequestingAuthenticationDetailsProvider.Builder
additionalFederationClientConfigurators, federationClient, federationClientConfigurator, intermediateCertificateSuppliers, requestSignerCacheConfiguration, sessionKeySupplier
-
-
Constructor Summary
Constructors Constructor Description AbstractFederationClientAuthenticationDetailsProviderBuilder()
-
Method Summary
All Methods Static Methods Instance Methods Abstract Methods Concrete Methods Deprecated Methods Modifier and Type Method Description protected voidautoDetectCertificatesUsingMetadataUrl()Auto detects and configures the certificates needed using Instance metadata.protected StringautoDetectEndpointUsingMetadataUrl()Auto detects the endpoint that should be used when talking to OCI Auth, if no endpoint has been configured already.protected voidautoDetectUsingMetadataUrl()Auto-detect endpoint and certificate information using Instance metadata.Pbuild()Build a new AuthenticationDetailsProvider that uses the FederationClient.protected abstract PbuildProvider(SessionKeySupplier sessionKeySupplierToUse)Build the actual provider.BcircuitBreakerConfigurator(CircuitBreakerConfiguration circuitBreakerConfiguration)Configures the Circuit Breaker to use, if any.protected FederationClientcreateFederationClient(SessionKeySupplier sessionKeySupplier)Create the federation client.BfederationClientMetadataConfigurator(ClientConfigurator clientConfigurator)Configures the ClientConfigurator to set on the metadata service clients used by the federation flow to discover region information and fetch certificates, if any.BfederationEndpoint(String federationEndpoint)Configures the custom federationEndpoint to use.StringgetFederationEndpoint()X509CertificateSuppliergetLeafCertificateSupplier()StringgetMetadataBaseUrl()RegiongetRegion()StringgetTenancyId()BleafCertificateSupplier(X509CertificateSupplier leafCertificateSupplier)Configures the custom leafCertificateSupplier to use.BmetadataBaseUrl(String metadataBaseUrl)Configure the metadata endpoint to use when retrieving the instance data and principal for federation.protected Bpurpose(String purpose)Configure the purpose to be used.static <T> TsimpleRetry(Function<javax.ws.rs.client.WebTarget,T> retryOperation, String metadataServiceUrl, String endpoint)Deprecated.use the function without Guava parameters instead Retry logic to get endpoint from instance metadata servicestatic <T> TsimpleRetry(Function<javax.ws.rs.client.WebTarget,T> retryOperation, String metadataServiceUrl, String endpoint)Retry logic to get endpoint from instance metadata serviceBtenancyId(String tenancyId)Configures the tenancy id to use.-
Methods inherited from class com.oracle.bmc.auth.AbstractRequestingAuthenticationDetailsProvider.Builder
additionalFederationClientConfigurator, federationClientConfigurator, getRequestSignerCacheConfiguration, intermediateCertificateSuppliers, requestSignerCacheConfiguration, sessionKeySupplier
-
-
-
-
Field Detail
-
SERVICE
protected static final Service SERVICE
Service instance for auth.
-
METADATA_SERVICE_BASE_URL
public static final String METADATA_SERVICE_BASE_URL
Default base url of metadata service.- See Also:
- Constant Field Values
-
METADATA_BASE_URL_ENV_VAR
public static final String METADATA_BASE_URL_ENV_VAR
Environment variable used to overwrite the default metadata base url.- See Also:
- Constant Field Values
-
METADATA_URL_OVERRIDE
public static final String METADATA_URL_OVERRIDE
Metadata URL from environment variable, to use if present.
-
AUTHORIZATION_HEADER_VALUE
public static final String AUTHORIZATION_HEADER_VALUE
The Authorization header value to be sent for requests to the metadata service.- See Also:
- Constant Field Values
-
metadataBaseUrl
protected volatile String metadataBaseUrl
Base url of metadata service.
-
federationEndpoint
protected String federationEndpoint
The federation endpoint url.
-
leafCertificateSupplier
protected X509CertificateSupplier leafCertificateSupplier
The leaf certificate, or null if detecting from instance metadata.
-
federationClientMetadataConfigurator
protected ClientConfigurator federationClientMetadataConfigurator
Configurator for metadata service clients used to discover region and certificates.
-
tenancyId
protected String tenancyId
Tenancy OCI, or null if detecting from instance metadata.
-
region
protected Region region
Detected region.
-
-
Method Detail
-
metadataBaseUrl
public B metadataBaseUrl(String metadataBaseUrl)
Configure the metadata endpoint to use when retrieving the instance data and principal for federation.- Parameters:
metadataBaseUrl- the metadata base url- Returns:
- this builder
-
federationEndpoint
public B federationEndpoint(String federationEndpoint)
Configures the custom federationEndpoint to use.- Parameters:
federationEndpoint- the federation endpoint- Returns:
- this builder
-
leafCertificateSupplier
public B leafCertificateSupplier(X509CertificateSupplier leafCertificateSupplier)
Configures the custom leafCertificateSupplier to use.- Parameters:
leafCertificateSupplier-- Returns:
- this builder
-
federationClientMetadataConfigurator
public B federationClientMetadataConfigurator(ClientConfigurator clientConfigurator)
Configures the ClientConfigurator to set on the metadata service clients used by the federation flow to discover region information and fetch certificates, if any.- Parameters:
clientConfigurator- the metadata service client configurator- Returns:
- this builder
-
tenancyId
public B tenancyId(String tenancyId)
Configures the tenancy id to use.- Parameters:
tenancyId- the tenancy OCID- Returns:
- this builder
-
purpose
protected B purpose(String purpose)
Configure the purpose to be used.- Parameters:
purpose- the purpose string- Returns:
- this builder
-
circuitBreakerConfigurator
public B circuitBreakerConfigurator(CircuitBreakerConfiguration circuitBreakerConfiguration)
Configures the Circuit Breaker to use, if any.- Parameters:
circuitBreakerConfiguration- the circuit breaker to use- Returns:
- this builder
-
build
public P build()
Build a new AuthenticationDetailsProvider that uses the FederationClient.- Returns:
- A new provider instance.
-
createFederationClient
protected FederationClient createFederationClient(SessionKeySupplier sessionKeySupplier)
Create the federation client.- Parameters:
sessionKeySupplier- the session key supplier- Returns:
- the federation client
-
autoDetectUsingMetadataUrl
protected void autoDetectUsingMetadataUrl()
Auto-detect endpoint and certificate information using Instance metadata.
-
autoDetectEndpointUsingMetadataUrl
protected String autoDetectEndpointUsingMetadataUrl()
Auto detects the endpoint that should be used when talking to OCI Auth, if no endpoint has been configured already.- Returns:
- The auto-detected, or currently set, auth endpoint.
-
autoDetectCertificatesUsingMetadataUrl
protected void autoDetectCertificatesUsingMetadataUrl()
Auto detects and configures the certificates needed using Instance metadata.
-
buildProvider
protected abstract P buildProvider(SessionKeySupplier sessionKeySupplierToUse)
Build the actual provider.- Parameters:
sessionKeySupplierToUse- the session key supplier to use- Returns:
- authentication details provider
-
getMetadataBaseUrl
public String getMetadataBaseUrl()
-
getFederationEndpoint
public String getFederationEndpoint()
-
getLeafCertificateSupplier
public X509CertificateSupplier getLeafCertificateSupplier()
-
getTenancyId
public String getTenancyId()
-
getRegion
public Region getRegion()
-
simpleRetry
@Deprecated public static <T> T simpleRetry(Function<javax.ws.rs.client.WebTarget,T> retryOperation, String metadataServiceUrl, String endpoint)
Deprecated.use the function without Guava parameters instead Retry logic to get endpoint from instance metadata service- Parameters:
retryOperation-metadataServiceUrl-endpoint-- Returns:
- The function result
-
-