All Classes and Interfaces
Class
Description
A request-scope service that can be used by plugin request handlers to determine what media-type the server
has accepted to provide to a HTTP client.
Event fired at successful authentication using an OAuth access token.
Common base class for OAuth access token events.
A SCIM 2.0 representation of a user account.
Event fired when an account is created via the GraphQL interface.
Event fired when an account is created through SCIM.
Event fired when an account is deleted via the GraphQL interface.
Event fired when an account is deleted through SCIM.
Represents a configured account-domain.
Common base class for account events.
An AccountManager can be used to control user accounts.
Exception thrown when an account could not be found.
Event fired when one or more accounts are read via the GraphQL interface.
A
ScimEvent that occurs when a single user account information is read.A
ScimEvent that occurs when potentially several user account's information is read
via a SCIM search operation.Event fired when an account is updated via the GraphQL interface.
Event fired when an account is updated.
Returned from a ActionCompletionRequestHandler when the obligation is complete.
Represents an action kind.
Builder interface allowing the addition of actions to the representation being built.
An object which may be active.
Event fired when an account is activated.
This class represents the state of activation tasks.
An object representing the complex attribute Address in SCIM Core Schema RFC7643
This class represents an alarm raised in the system.
An AlarmDescription is a hierarchical representation of a textual description of an
Alarm.An ImpactedResourceGroup contains a set of String identifiers for impacted resources
grouped by some common category or trait.
When a sub-type of this alarm is thrown by a Data Source plugin, a corresponding alarm will be raised.
A handler of
Alarm objects.Alarm Handler Plugin Descriptor.
Uniquely identifies an alarm by specifying the
AlarmingResource that caused the alarm
and the AlarmType, specifying the type of the alarm (usually the type of failure that occurred at the resource).An identifier for the resource that signaled an alarm.
The perceived severity of an
Alarm.The type of an
Alarm.Represents a host-source, as specified by the Content Security Policy specification.
The anonymous request handler.
A crypto store containing asymmetric key material for decrypting data.
A crypto store containing asymmetric key material for encrypting data.
A crypto store containing certificate- and asymmetric key material for verifying signatures.
A crypto store containing certificate- and asymmetric key material for making signatures.
An Attribute is a collection of
AttributeValues, together with a name and, optionally, an authority.Attributes to be added to an account during an update operation.
Collector of Attributes.
A immutable container of
Attribute instances which allows appending.A
DataAccessProvider that is used to fetch attributes from a data source based on a query with the "subject"
as input.The deletions to be performed during an update operation.
Attribute name.
An AttributeName format (e.g., "json").
Most generic type of the attributes framework.
Union of
AttributeTransformer and AttributeValueTransformer.Attributes to be replaced during an update operation.
An
AttributeRepository is used to fetch attributes from a contained data source based on a query with the
"subject" as input.Collection of
Attribute instances that can be efficiently located by name.A utility class to make it possible to view existing
Attributes as a table of data.Alias for a function that can transform
Attribute instances.Group of operations that allow updating an account.
Object representing an Attribute value.
Collector of AttributeValues.
An Exception that occurs when an Attribute has an invalid value according to the schema is belongs to.
Alias for BiFunction that transforms
AttributeValue instances.A common interface for any event considered auditable, i.e.
Data class containing audit data.
Represents an authentication session.
This class represents all the currently authenticated sessions
This is a collection of session that are deemed to be fresh.
This class represents the authenticated state of the current session.
The Authentication Action Information Provider Service provides information relevant to the
current authentication action.
This class is used to produce results for authentication actions.
A common base class for authentication events, whether successful or failed.
Subtype of Attributes that contains.
An attribute transformer takes a collection of attributes and transforms them
into a new collection of attributes.
Collection of
AuthenticationAttributeTransformer instances.Common base class for authentication events.
Current requirements for the ongoing authentication flow.
The result of a successful authentication.
Builder interface to add content to an authentication step.
This class represents a configured authenticator in the current profile.
This service allows the plugin to map from ACR strings to configured authenticators as well as from
authenticator ID strings to
AuthenticatorDescriptor.An exception factory that can create exceptions unique to authenticators.
The Authenticator Information Provider Service provides information relevant to the
current Authenticator.
Authenticator Plugin descriptor.
The authentication request handler.
Represents the action of the operation being authorized.
Common base class for OAuth authorization code events.
Represents the decision made by a
AuthorizationManager.Interface that needs to be implemented by any authorization manager plugin descriptor.
Provides access to the typed authorization managers provided by a plugin
Represents the resource of the operation being authorized.
Represents the result of an authorization policy decision performed by an
AuthorizationManagerContains the information to present on the auto-login confirmation UI.
Abstract class for all backchannel authentication events.
This interface indicates that an authenticator that can fulfill Backchannel authentication requests
Describes the data structure that provides all information needed to fulfill a backchannel authentication request
This interface describes the plugin for an authenticator that is capable of both normal as well as
backchannel authentication requests.
Binary value attribute representation.
A
Bucket is a store for arbitrary data, available for plugins and procedures.A
DataAccessProvider for reading and storing arbitrary attributes.Interface that needs to be implemented by plugins that provide support for the Hypermedia Authentication
API (HAAPI).
A function type that allows checked Exceptions to be thrown.
A configured claim.
A Set of claims that can be used to verify claims requested by OAuth clients.
A plugin-provided service that can obtain claim values for a particular user and OAuth client.
Claims Provider Plugin Descriptor.
Utility class for dealing with Jakarta EE functionality that requires loading services from a
ClassLoader
that includes Curity Plugins' classes.Base class for events triggered by client authentication.
A crypto store containing the private key and certificate required for client authentication over SSL/TLS.
Builder interface to add content to a client-operation action.
Builder interface allowing the addition of actions to the representation of a completed polling step.
Builder interface to add content to a completed polling step.
Attribute whose value is a collection of objects, used to represent the Complex Attribute of SCIM.
Interface for Plugin configuration definitions.
Event fired when configuration has been changed in the system.
Exception thrown when an external service responds with an error indicating a conflict.
Subtype of Attributes that contains the consent that the user submitted.
Defines a consentor plugin to extend the consent phase.
An event that represents the completion, successful or unsuccessful, of the consent process performed by a
Consentor.Represents a completion action that needs to be completed before the consentor can continue.
A consentor completion that redirects to the "index" handler.
A consentor completion that redirects to a provided URL.
A consentor completion that returns a response body based on the provided
ResponseModel.The interface that consentor completion handlers must implement.
Consentor plugin service, obtainable via the consentor's configuration.
Descriptor for a consentor.
Represents the result of applying a consentor
Represents a pending result.
Represents a success result.
Represents an Unsuccessful result.
Represents a set of attributes provided by a consentor plugin.
Builder interface to add content to a consentor step.
Event posted when an OAuth authorization code is consumed.
Event posted when an OAuth device code is consumed.
Event posted when a DCR initial access token is consumed registering a dynamic client.
Annotation meant for handler methods (the ones corresponding to HTTP methods).
Definition of common Content-Type values.
Builder interface allowing the addition of continuation actions to the representation being built.
Builder interface allowing the addition of fields to a continuation form action being built.
A HTTP Cookie.
Event fired when an account is created.
An event that is fired when a new device is added.
Event fired when an SSO session is created.
Interface for UserDataAccessProvider implementations.
Common base class for all credential manager events.
A CryptoStore encapsulates certificate- and key material used for performing signing and cipher operations.
This interface serves as a trait to subtypes of
CryptoStore.Marker interface for a DataAccessProvider interface.
A Plugin descriptor that describes implementations of
DataAccessProvider for
Attributes, credentials,
Delegation,
nonce, sessions, Token
and AccountAttributes.Provides a default value for a boolean configuration item.
Provides a default value for a double configuration item.
Provides the default enum value that should be used for a method which returns a Java
enum or the
type argument of an Optional where that type is an enum.Provides a default value for a integer configuration item.
Provides a default value for a long configuration item.
Annotates the default option that should be used within a
OneOf
interface.Provides a default value for a String configuration item.
Provides a default value for a URI configuration item.
A delegation is an authorization grant given by the resource owner to a third-party to access
some resource.
Represents the consent result stored in a delegation.
The DelegationDataAccessProvider is responsible for communicating with a
Delegation data source.Common base class for delegation events.
The status of a
Delegation.An event that is fired when a device is deleted.
Event posted when a token introspected is not active.
Defines a description for a configuration item.
This class wraps
DeviceAttributes into a ComplexAttributeValue, allowing it
to be treated as part of an account (as multi-valued attribute).Device attributes.
Common base class for device code OAuth events.
Devices Data Access Provider.
Common base class for device events.
An event that is fired when an existing device is updated.
Email addresses for the User.
This is a container for the data model used for constructing emails.
An Emailer is the effective transport layer of an
EmailSender; responsible for delivering
emails to their intended recipients.EmailProvider Plugin defines an
Emailer plugin type that can be configured to be used by the EmailSender service.The EmailSender service sends
Emails.Entitlement for the user that represent a thing the
user has.
Errors that can be raised from the authentication service or one of its plug-ins.
High level interface for errors.
This class provides a view of the response model information present in a
Response, when there is an error
to be used by RepresentationFunction.applyError(ErrorRepresentationModel, ProblemRepresentationFactory).Root Server event type.
A listener of
Event or one of its sub-types.This object contains meta-data about a delivered
Event that is not explicitly a component of said event.The @Experimental annotation when applied to a class or a method indicates that the class or method is
subject to change.
A HTTP Cookie that can expire with or without being persisted on the client-side.
Exception thrown when receiving a bad or unexpected response from an external service.
When this alarm is thrown by a Data Source plugin, an
AlarmType.EXTERNAL_SERVICE_FAILED_AUTHENTICATION alarm will be raised.When this alarm is thrown by a Data Source plugin, an
AlarmType.EXTERNAL_SERVICE_FAILED_COMMUNICATION alarm will be raised.When this alarm is thrown by a Data Source plugin, an
AlarmType.EXTERNAL_SERVICE_FAILED_CONNECTION alarm will be raised.A failed authentication action event.
A failed authentication event; the failure case corresponding to
SuccessAuthenticationEvent.Event posted when client attestation token fails verification
Fired when a CredentialManager verifies credentials and decides on a non-match.
Event generated on backchannel authentication failure.
Event fired when a client fails to authenticate.
Represents a kind of text field.
A filter is defined as either an attribute expression, or a logical expression combining, or negating, other filters.
An attribute expression represents a comparison between a named attribute and a given value using some mechanism
defined by a given operator.
An attribute operator defines the comparison mechanism used in an attribute expression
between some named attribute and a given value.
A logical expression combines a pair of filters by applying some logical operator to them.
A logical operator defines the mechanism by which filters are sequenced together.
A logical expression negating its defined child filter.
Builder interface to add content to a form action.
Builder interface allowing the addition of fields to a form action being built.
Builder interface to add hidden fields to a form.
Builder interface to add options to a form's select field.
A generic formatted value.
Represents the action of the GraphQL operation being authorized.
Authorization manager for policy decisions enforced by GraphQL endpoints.
Represents the resource of the GraphQL operation being authorized.
Represents a GraphQL result error, i.e., an entry in the "errors" list.
Common interface for any event triggered by GraphQL actions.
Represents one argument of a field selection.
Base interface for all obligations enforced by the execution of a GraphQL operation.
This obligation type can be used to enforce authorization logic based on the top-level selections being made,
including their arguments.
This obligation type can be used to filter (i.e.
Defines a GraphQL operation, namely the type (e.g.
The operation type (query, mutation, or subscription).
Represents one selection via the selection field name and its arguments.
The selection set of a GraphQL operation, i.e.,
the set of top-level fields.
Constants used when creating HAAPI representations.
The top-level JSON field names.
Interface for validatable request models.
A simple HTTP Client that gets configured by the server configuration, possibly with a keystore.
All errors that occur while building or sending requests via a
HttpClient.Defines automatic redirection policy.
The HTTP protocol version.
A read-only view of a set of HTTP headers.
A Builder of
HttpHeaders instances.Represents an HTTP method.
Represents one HTTP request which can be sent to a server.
A request processor which obtains the request body from some source.
Builder of HTTP requests.
A server's response to a HTTP request.
A processor for response bodies, which determines the type of the response body returned from HttpResponse.
HTTP Status Code.
Common base class for OpenID Connect ID token events.
This is a container for the data model used for constructing images.
A informational message.
Common base class for DCR initial access token events.
Instant messaging address for the user.
This class can be injected in the constructors of the ObligationRequestHandlers for an authentication action obligation.
This class can be injected in the constructors of the ConsentorCompletionRequestHandler for a consentor action obligation.
Event posted when a token is introspected.
Event posted when an OAuth refresh token is issued.
Event posted when an OAuth authorization code is issued.
Event posted when a delegation is issued.
Event posted when an OAuth device code is issued.
Event posted when an OpenID Connect ID token is issued.
Event posted when a DCR initial access token is issued.
Event posted when an OAuth refresh token is issued.
This service provides a simple API to serialize and de-serialize JSON.
Exception used to report error that occur during serialization or de-serialization of JSON.
Exception thrown when a link could not be created because of an already existing link to another account.
Event fired when an account is linked.
Represents a link relation, as defined by
Web Linking specification.
Builder interface allowing the addition of links to the representation being built.
An
AttributeValue consisting of multiple AttributeValue instances.Marks an element as being part of a list item key.
A login authentication event.
An event triggered by a user logging out.
A managed object is an object that can be used by a plugin to manage the plugin life-cycle.
An
AttributeValue representing multiple Attribute instances, similar to a Map where the keys
are the names of the attributes, and the values the Attributes themselves.Representation of a message that should be presented to the user of the client application.
The meta object of SCIM.
The known metadata fields that can be used with a
MapAttributeValue.An Exception thrown if multiple cookies are included in a Request where only a single one was expected.
The name attribute of the SCIM core schema.
Defines the name of a configuration item.
This data source is responsible for storing one time tokens (Nonce).
A service that can issue and introspect
TokenAttributes instances that are meant to be used
no more than once (i.e., a nonce).A Immutable List which is guaranteed to contain at least one element.
The
@Nonnull annotation declares that a type or the return value of a method is never null.The @Nullable annotation, when applied to a type or the return value of a method, declares that the annotated
element might be null in some cases, therefore client code must check for null before using ditto value.
A function which may return a null value.
A Supplier that may return null.
Null attribute value.
Represents the action of the OAuth operation being authorized.
Authorization manager for policy decisions enforced by OAuth endpoints.
Represents the resource of the OAuth operation being authorized.
An OAuth client.
Common base class for OAuth events.
Base interface for all obligations enforced by the execution of an OAuth operation.
Represents an obligation that needs to be ensured when performing the authorized operation.
Marker interface for configuration values which may be one of a set of sub-configuration types.
Represents the name of a operation that is executed by a client application.
A Web Origin, according to rfc 6454.
Helper class for extracting the query (or in case of Pushed Authorization Requests content of POST body) parameter
values from the original request leading to the authentication service.
Fired when the CredentialManager has updated a password.
Constrains the values a configuration element of type
String may take.Builder interface to add content to a pending polling step.
An authentication obligation action event.
Builder interface to add content to a pending polling step.
Phone numbers for the user.
Photo associated with the user
A Plugin descriptor is used to inform the server of the characteristics of a plugin.
Interface allowing the setting of hints on a polling representation being built.
Interface with factory methods to create polling representations.
Constrains the Fraction Precision of the value the element can take.
An
AttributeValue representing a single value.An
AttributeValue whose value is a String.Builder interface allowing the addition of extra information to the representation of generic problem.
Constants used when creating problem representations.
The top-level JSON field names on top of the ones in BaseSpec.Fields.
A problem details object as defined in RFC-7807.
Builder interface allowing the addition of extra information to the representation of an invalid input problem.
Interface providing a set of factory methods to create different type of error representations,
based on the Problem Details for HTTP APIs specification.
Annotation that can be used to explicitly tell the server which content-type(s) a
RequestHandler
GET or POST handler should support.Content-Types
RequestHandler may produce to respond to HTTP Requests.Event that occurs when a new profile is added to the server.
Interface allowing the setting of properties on a representation being built.
Constrains an element's numeric value to within a certain range.
HTTP status codes that represent some sort of redirect.
Common base class for OAuth Refresh Token events.
Event posted when an OAuth client is dynamically registered (DCR).
The registration request handler.
The result of performing the registration of a new account.
Builder interface to add content to a registration step.
A RenderableEmail is a container of the data needed for constructing and sending an email.
Base interface for all resource representations.
Interface providing a set of factory methods to create different type of success and error representations.
Interface implemented by classes that produce representations (see
Representation) from
response model maps.This class provides a view of the response model information present in a
Response,
to be used by RepresentationFunction.A HTTP Request from the perspective of the server (as opposed to a HTTP client).
A request Cookie collection.
A HTTP Request handler.
Represents a set of request handlers.
A service providing the client that made the original request that started the current authentication flow.
Abstract class for obligatory action completion following an authentication process.
RequiredActionCompletion that contains acr for registration actionBase class for the SCIM types
Representation of a resource query which can be used to limit selected resources.
A query for specific attributes.
Enumeration of attributes to be excluded from a query result.
Enumeration of attributes to be included in a query result.
Pagination parameter of the query.
Sorting parameter of the query.
Builder of
ResourceQuery instances.Result of a resource query.
A configurable resource.
A HTTP Response from the perspective of the server (as opposed to a HTTP client).
The scope of a response model.
A HTTP Cookie that can be set on a
Response.A builder of response cookies.
A Response model contains information the server can use to provide a full HTTP response for a request
handled by a
RequestHandler.A simple
ResponseModel consisting of only view data information.A
ResponseModel which, besides view data information, contains a template.Event posted when an OAuth refresh token is revoked.
Event posted when a delegation is revoked.
Event posted when a delegation is revoked.
Event posted when a DCR initial access token is revoked.
Event posted when an OAuth refresh token is revoked.
Roles for the user that represent who the user is, e.g., "Student", "Faculty".
Represents the action of the SCIM operation being authorized.
Authorization manager for policy decisions enforced by SCIM endpoints.
Represents the action of the SCIM operation being authorized.
Common base class for any event triggered by SCIM actions.
Closed hierarchy of
Obligation supported by the SCIM endpoints policy enforcement.Allows deciding if a resource attributes can be updated or not
Allows deciding if a delegation can be updated or not
Allows for filtering of read attributes
Allows for filtering of delegations
Allows for the transformation of a resource query.
A ScopeClaim is a claim that can be authorized, and that is expanded from a Scope.
Generic scope (not specifically OAuth).
A Map of scopes which can be used to verify scopes requested by OAuth clients
as well as obtain sub-sets of scope configurations that belong to different Sets
(e.g.
A ScopeValue is a resolved scope, i.e.
Builder interface to add content to a selector action.
Instances of this type can be fully serialized as a Map.
A crypto store containing a trusted server certificate.
A session object, containing the session ID, time of expiration and serialized data.
This DataAccessProvider is responsible for storing and maintaining session for the server.
A session event.
This manager can be used in Authenticators to store data in a session.
A crypto store containing a signature trust anchor.
This is interface should be implemented by the signing consentor plugins.
This is a container for creating the Pending Result for Signing Consentor
Descriptor for a signing consentor.
Represents the result of applying a signing consentor.
Represents an Unsuccessful result.
Constrains a configuration element's size.
SMS Plugin descriptor.
Collection of
AuthenticationAttributeTransformer instances.A Standard HTTP cookie.
Event indicating Backchannel authentication was initiated.
Type that represents either a String (in case of one value) or
an Array (List) of Strings (in case of multiple values).
A successful authentication action event.
Event fired at successful authentication.
Event generated on successful backchannel authentication.
Event fired when a client is successfully authenticated.
Builder interface allowing the addition of continuation actions to the representation being built.
Fired when a CredentialManager has verified credentials successfully.
Event fired at successful SSO authentication.
Special annotation available for use on methods returning
String
(including Optional<String>) values.A crypto store containing symmetric key material for decrypting data.
A crypto store containing symmetric key material for encrypting data.
A crypto store containing symmetric key material for verifying signatures.
A crypto store containing symmetric key material for making signatures.
Base class for system level events.
The System Information Provider Service provides information relevant to the current system.
A marker interface that indicates that the implementer, a plug-in-provided service, is thread-safe.
A token that can be used to authorize access to resources without checking with an authorization server.
A data token containing a number of attributes, always including the
TokenAttributes.CREATED and TokenAttributes.EXPIRES attributes.Exception representing a problem during the issuance of a Token.
Common base class for OAuth Token events.
The status a token may have.
A factory that can create
TrustManager objects.Event fired when an account is unlinked.
An event that represents interactive user consent.
Event posted when an oauth-userinfo is successfully queried.
Common interface for any event triggered by a User Management GraphQL action.
Builder interface allowing the addition of user messages to the representation being built.
This is a manager object that provides methods for working with a username cookie.
The type of transformation to be applied to a cookie's value(s) when reading or writing it.
A warning message.
A Web Service Client is an HTTP Client that makes requests against a URI defined by configuration.
All errors that occur while building or sending requests via a
WebServiceClient.A factory that can create
WebServiceClient objects.DER encoded X.509 certificate, which must be base 64 encoded.