All Classes and Interfaces

Class
Description
A request-scope service that can be used by plugin request handlers to determine what media-type the server has accepted to provide to a HTTP client.
Event fired at successful authentication using an OAuth access token.
Common base class for OAuth access token events.
A SCIM 2.0 representation of a user account.
Event fired when an account is created via the GraphQL interface.
Event fired when an account is created through SCIM.
Event fired when an account is deleted via the GraphQL interface.
Event fired when an account is deleted through SCIM.
Represents a configured account-domain.
Common base class for account events.
An AccountManager can be used to control user accounts.
Exception thrown when an account could not be found.
Event fired when one or more accounts are read via the GraphQL interface.
A ScimEvent that occurs when a single user account information is read.
A ScimEvent that occurs when potentially several user account's information is read via a SCIM search operation.
Event fired when an account is updated via the GraphQL interface.
Event fired when an account is updated.
 
Returned from a ActionCompletionRequestHandler when the obligation is complete.
 
Represents an action kind.
Builder interface allowing the addition of actions to the representation being built.
Activatable<Status extends Enum<?>>
An object which may be active.
Event fired when an account is activated.
This class represents the state of activation tasks.
 
An object representing the complex attribute Address in SCIM Core Schema RFC7643
This class represents an alarm raised in the system.
An AlarmDescription is a hierarchical representation of a textual description of an Alarm.
An ImpactedResourceGroup contains a set of String identifiers for impacted resources grouped by some common category or trait.
When a sub-type of this alarm is thrown by a Data Source plugin, a corresponding alarm will be raised.
A handler of Alarm objects.
Alarm Handler Plugin Descriptor.
Uniquely identifies an alarm by specifying the AlarmingResource that caused the alarm and the AlarmType, specifying the type of the alarm (usually the type of failure that occurred at the resource).
An identifier for the resource that signaled an alarm.
The perceived severity of an Alarm.
The type of an Alarm.
Represents a host-source, as specified by the Content Security Policy specification.
The anonymous request handler.
A crypto store containing asymmetric key material for decrypting data.
A crypto store containing asymmetric key material for encrypting data.
A crypto store containing certificate- and asymmetric key material for verifying signatures.
A crypto store containing certificate- and asymmetric key material for making signatures.
An Attribute is a collection of AttributeValues, together with a name and, optionally, an authority.
Attributes to be added to an account during an update operation.
Collector of Attributes.
A immutable container of Attribute instances which allows appending.
A DataAccessProvider that is used to fetch attributes from a data source based on a query with the "subject" as input.
The deletions to be performed during an update operation.
Attribute name.
An AttributeName format (e.g., "json").
Most generic type of the attributes framework.
Attributes to be replaced during an update operation.
An AttributeRepository is used to fetch attributes from a contained data source based on a query with the "subject" as input.
Collection of Attribute instances that can be efficiently located by name.
A utility class to make it possible to view existing Attributes as a table of data.
Alias for a function that can transform Attribute instances.
Group of operations that allow updating an account.
Object representing an Attribute value.
Collector of AttributeValues.
An Exception that occurs when an Attribute has an invalid value according to the schema is belongs to.
Alias for BiFunction that transforms AttributeValue instances.
A common interface for any event considered auditable, i.e.
Data class containing audit data.
 
Represents an authentication session.
This class represents all the currently authenticated sessions This is a collection of session that are deemed to be fresh.
This class represents the authenticated state of the current session.
 
The Authentication Action Information Provider Service provides information relevant to the current authentication action.
 
This class is used to produce results for authentication actions.
 
 
 
A common base class for authentication events, whether successful or failed.
Subtype of Attributes that contains.
An attribute transformer takes a collection of attributes and transforms them into a new collection of attributes.
Collection of AuthenticationAttributeTransformer instances.
Common base class for authentication events.
Current requirements for the ongoing authentication flow.
The result of a successful authentication.
 
Builder interface to add content to an authentication step.
This class represents a configured authenticator in the current profile.
This service allows the plugin to map from ACR strings to configured authenticators as well as from authenticator ID strings to AuthenticatorDescriptor.
An exception factory that can create exceptions unique to authenticators.
The Authenticator Information Provider Service provides information relevant to the current Authenticator.
 
Authenticator Plugin descriptor.
The authentication request handler.
Represents the action of the operation being authorized.
 
Common base class for OAuth authorization code events.
Represents the decision made by a AuthorizationManager.
 
Interface that needs to be implemented by any authorization manager plugin descriptor.
Provides access to the typed authorization managers provided by a plugin
Represents the resource of the operation being authorized.
Represents the result of an authorization policy decision performed by an AuthorizationManager
 
Contains the information to present on the auto-login confirmation UI.
Abstract class for all backchannel authentication events.
This interface indicates that an authenticator that can fulfill Backchannel authentication requests
Describes the data structure that provides all information needed to fulfill a backchannel authentication request
 
This interface describes the plugin for an authenticator that is capable of both normal as well as backchannel authentication requests.
 
 
Binary value attribute representation.
A Bucket is a store for arbitrary data, available for plugins and procedures.
A DataAccessProvider for reading and storing arbitrary attributes.
Interface that needs to be implemented by plugins that provide support for the Hypermedia Authentication API (HAAPI).
A function type that allows checked Exceptions to be thrown.
A configured claim.
A Set of claims that can be used to verify claims requested by OAuth clients.
A plugin-provided service that can obtain claim values for a particular user and OAuth client.
Claims Provider Plugin Descriptor.
Utility class for dealing with Jakarta EE functionality that requires loading services from a ClassLoader that includes Curity Plugins' classes.
Base class for events triggered by client authentication.
 
A crypto store containing the private key and certificate required for client authentication over SSL/TLS.
Builder interface to add content to a client-operation action.
Builder interface allowing the addition of actions to the representation of a completed polling step.
Builder interface to add content to a completed polling step.
Attribute whose value is a collection of objects, used to represent the Complex Attribute of SCIM.
 
Interface for Plugin configuration definitions.
Event fired when configuration has been changed in the system.
Exception thrown when an external service responds with an error indicating a conflict.
Subtype of Attributes that contains the consent that the user submitted.
Defines a consentor plugin to extend the consent phase.
An event that represents the completion, successful or unsuccessful, of the consent process performed by a Consentor.
 
 
Represents a completion action that needs to be completed before the consentor can continue.
A consentor completion that redirects to the "index" handler.
A consentor completion that redirects to a provided URL.
A consentor completion that returns a response body based on the provided ResponseModel.
The interface that consentor completion handlers must implement.
 
 
Consentor plugin service, obtainable via the consentor's configuration.
Descriptor for a consentor.
Represents the result of applying a consentor
Represents a pending result.
Represents a success result.
Represents an Unsuccessful result.
Represents a set of attributes provided by a consentor plugin.
Builder interface to add content to a consentor step.
Event posted when an OAuth authorization code is consumed.
Event posted when an OAuth device code is consumed.
Event posted when a DCR initial access token is consumed registering a dynamic client.
Annotation meant for handler methods (the ones corresponding to HTTP methods).
Definition of common Content-Type values.
 
Builder interface allowing the addition of continuation actions to the representation being built.
Builder interface allowing the addition of fields to a continuation form action being built.
A HTTP Cookie.
Event fired when an account is created.
An event that is fired when a new device is added.
Event fired when an SSO session is created.
Interface for UserDataAccessProvider implementations.
 
Common base class for all credential manager events.
 
A CryptoStore encapsulates certificate- and key material used for performing signing and cipher operations.
This interface serves as a trait to subtypes of CryptoStore.
Marker interface for a DataAccessProvider interface.
A Plugin descriptor that describes implementations of DataAccessProvider for Attributes, credentials, Delegation, nonce, sessions, Token and AccountAttributes.
Provides a default value for a boolean configuration item.
Provides a default value for a double configuration item.
Provides the default enum value that should be used for a method which returns a Java enum or the type argument of an Optional where that type is an enum.
Provides a default value for a integer configuration item.
Provides a default value for a long configuration item.
Annotates the default option that should be used within a OneOf interface.
Provides a default value for a String configuration item.
 
Provides a default value for a URI configuration item.
A delegation is an authorization grant given by the resource owner to a third-party to access some resource.
Represents the consent result stored in a delegation.
The DelegationDataAccessProvider is responsible for communicating with a Delegation data source.
Common base class for delegation events.
The status of a Delegation.
An event that is fired when a device is deleted.
Event posted when a token introspected is not active.
Defines a description for a configuration item.
This class wraps DeviceAttributes into a ComplexAttributeValue, allowing it to be treated as part of an account (as multi-valued attribute).
Device attributes.
Common base class for device code OAuth events.
Devices Data Access Provider.
Common base class for device events.
An event that is fired when an existing device is updated.
 
 
 
 
Email addresses for the User.
This is a container for the data model used for constructing emails.
An Emailer is the effective transport layer of an EmailSender; responsible for delivering emails to their intended recipients.
EmailProvider Plugin defines an Emailer plugin type that can be configured to be used by the EmailSender service.
The EmailSender service sends Emails.
Entitlement for the user that represent a thing the user has.
Errors that can be raised from the authentication service or one of its plug-ins.
High level interface for errors.
 
 
This class provides a view of the response model information present in a Response, when there is an error to be used by RepresentationFunction.applyError(ErrorRepresentationModel, ProblemRepresentationFactory).
Root Server event type.
A listener of Event or one of its sub-types.
 
 
This object contains meta-data about a delivered Event that is not explicitly a component of said event.
 
The @Experimental annotation when applied to a class or a method indicates that the class or method is subject to change.
A HTTP Cookie that can expire with or without being persisted on the client-side.
Exception thrown when receiving a bad or unexpected response from an external service.
When this alarm is thrown by a Data Source plugin, an AlarmType.EXTERNAL_SERVICE_FAILED_AUTHENTICATION alarm will be raised.
When this alarm is thrown by a Data Source plugin, an AlarmType.EXTERNAL_SERVICE_FAILED_COMMUNICATION alarm will be raised.
When this alarm is thrown by a Data Source plugin, an AlarmType.EXTERNAL_SERVICE_FAILED_CONNECTION alarm will be raised.
A failed authentication action event.
A failed authentication event; the failure case corresponding to SuccessAuthenticationEvent.
Event posted when client attestation token fails verification
Fired when a CredentialManager verifies credentials and decides on a non-match.
Event generated on backchannel authentication failure.
Event fired when a client fails to authenticate.
Represents a kind of text field.
A filter is defined as either an attribute expression, or a logical expression combining, or negating, other filters.
An attribute expression represents a comparison between a named attribute and a given value using some mechanism defined by a given operator.
An attribute operator defines the comparison mechanism used in an attribute expression between some named attribute and a given value.
A logical expression combines a pair of filters by applying some logical operator to them.
A logical operator defines the mechanism by which filters are sequenced together.
A logical expression negating its defined child filter.
Builder interface to add content to a form action.
Builder interface allowing the addition of fields to a form action being built.
Builder interface to add hidden fields to a form.
Builder interface to add options to a form's select field.
A generic formatted value.
Represents the action of the GraphQL operation being authorized.
Authorization manager for policy decisions enforced by GraphQL endpoints.
Represents the resource of the GraphQL operation being authorized.
 
Represents a GraphQL result error, i.e., an entry in the "errors" list.
Common interface for any event triggered by GraphQL actions.
Represents one argument of a field selection.
Base interface for all obligations enforced by the execution of a GraphQL operation.
This obligation type can be used to enforce authorization logic based on the top-level selections being made, including their arguments.
 
This obligation type can be used to filter (i.e.
 
Defines a GraphQL operation, namely the type (e.g.
The operation type (query, mutation, or subscription).
Represents one selection via the selection field name and its arguments.
The selection set of a GraphQL operation, i.e., the set of top-level fields.
 
Constants used when creating HAAPI representations.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
The top-level JSON field names.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Interface for validatable request models.
A simple HTTP Client that gets configured by the server configuration, possibly with a keystore.
All errors that occur while building or sending requests via a HttpClient.
Defines automatic redirection policy.
The HTTP protocol version.
A read-only view of a set of HTTP headers.
A Builder of HttpHeaders instances.
Represents an HTTP method.
Represents one HTTP request which can be sent to a server.
A request processor which obtains the request body from some source.
Builder of HTTP requests.
A server's response to a HTTP request.
A processor for response bodies, which determines the type of the response body returned from HttpResponse.
HTTP Status Code.
 
Common base class for OpenID Connect ID token events.
This is a container for the data model used for constructing images.
A informational message.
 
Common base class for DCR initial access token events.
Instant messaging address for the user.
This class can be injected in the constructors of the ObligationRequestHandlers for an authentication action obligation.
This class can be injected in the constructors of the ConsentorCompletionRequestHandler for a consentor action obligation.
Event posted when a token is introspected.
Event posted when an OAuth refresh token is issued.
Event posted when an OAuth authorization code is issued.
Event posted when a delegation is issued.
Event posted when an OAuth device code is issued.
Event posted when an OpenID Connect ID token is issued.
Event posted when a DCR initial access token is issued.
Event posted when an OAuth refresh token is issued.
This service provides a simple API to serialize and de-serialize JSON.
Exception used to report error that occur during serialization or de-serialization of JSON.
Exception thrown when a link could not be created because of an already existing link to another account.
 
Event fired when an account is linked.
Represents a link relation, as defined by Web Linking specification.
Builder interface allowing the addition of links to the representation being built.
An AttributeValue consisting of multiple AttributeValue instances.
Marks an element as being part of a list item key.
A login authentication event.
An event triggered by a user logging out.
A managed object is an object that can be used by a plugin to manage the plugin life-cycle.
An AttributeValue representing multiple Attribute instances, similar to a Map where the keys are the names of the attributes, and the values the Attributes themselves.
 
Representation of a message that should be presented to the user of the client application.
 
 
The meta object of SCIM.
The known metadata fields that can be used with a MapAttributeValue.
An Exception thrown if multiple cookies are included in a Request where only a single one was expected.
 
 
The name attribute of the SCIM core schema.
Defines the name of a configuration item.
This data source is responsible for storing one time tokens (Nonce).
A service that can issue and introspect TokenAttributes instances that are meant to be used no more than once (i.e., a nonce).
A Immutable List which is guaranteed to contain at least one element.
The @Nonnull annotation declares that a type or the return value of a method is never null.
 
The @Nullable annotation, when applied to a type or the return value of a method, declares that the annotated element might be null in some cases, therefore client code must check for null before using ditto value.
A function which may return a null value.
A Supplier that may return null.
Null attribute value.
Represents the action of the OAuth operation being authorized.
 
Authorization manager for policy decisions enforced by OAuth endpoints.
Represents the resource of the OAuth operation being authorized.
 
An OAuth client.
Common base class for OAuth events.
Base interface for all obligations enforced by the execution of an OAuth operation.
Represents an obligation that needs to be ensured when performing the authorized operation.
Marker interface for configuration values which may be one of a set of sub-configuration types.
Represents the name of a operation that is executed by a client application.
A Web Origin, according to rfc 6454.
Helper class for extracting the query (or in case of Pushed Authorization Requests content of POST body) parameter values from the original request leading to the authentication service.
Fired when the CredentialManager has updated a password.
Constrains the values a configuration element of type String may take.
Builder interface to add content to a pending polling step.
An authentication obligation action event.
Builder interface to add content to a pending polling step.
Phone numbers for the user.
Photo associated with the user
A Plugin descriptor is used to inform the server of the characteristics of a plugin.
Interface allowing the setting of hints on a polling representation being built.
Interface with factory methods to create polling representations.
Constrains the Fraction Precision of the value the element can take.
An AttributeValue representing a single value.
 
An AttributeValue whose value is a String.
Builder interface allowing the addition of extra information to the representation of generic problem.
Constants used when creating problem representations.
The top-level JSON field names on top of the ones in BaseSpec.Fields.
 
 
 
 
 
 
 
 
 
 
 
A problem details object as defined in RFC-7807.
Builder interface allowing the addition of extra information to the representation of an invalid input problem.
Interface providing a set of factory methods to create different type of error representations, based on the Problem Details for HTTP APIs specification.
Annotation that can be used to explicitly tell the server which content-type(s) a RequestHandler GET or POST handler should support.
Content-Types RequestHandler may produce to respond to HTTP Requests.
Event that occurs when a new profile is added to the server.
Interface allowing the setting of properties on a representation being built.
Constrains an element's numeric value to within a certain range.
HTTP status codes that represent some sort of redirect.
 
Common base class for OAuth Refresh Token events.
Event posted when an OAuth client is dynamically registered (DCR).
The registration request handler.
The result of performing the registration of a new account.
Builder interface to add content to a registration step.
A RenderableEmail is a container of the data needed for constructing and sending an email.
Base interface for all resource representations.
Interface providing a set of factory methods to create different type of success and error representations.
Interface implemented by classes that produce representations (see Representation) from response model maps.
This class provides a view of the response model information present in a Response, to be used by RepresentationFunction.
A HTTP Request from the perspective of the server (as opposed to a HTTP client).
A request Cookie collection.
 
A HTTP Request handler.
Represents a set of request handlers.
A service providing the client that made the original request that started the current authentication flow.
Abstract class for obligatory action completion following an authentication process.
 
 
 
RequiredActionCompletion that contains acr for registration action
Base class for the SCIM types
Representation of a resource query which can be used to limit selected resources.
A query for specific attributes.
Enumeration of attributes to be excluded from a query result.
Enumeration of attributes to be included in a query result.
Pagination parameter of the query.
Sorting parameter of the query.
 
Builder of ResourceQuery instances.
Result of a resource query.
A configurable resource.
A HTTP Response from the perspective of the server (as opposed to a HTTP client).
The scope of a response model.
A HTTP Cookie that can be set on a Response.
A builder of response cookies.
A Response model contains information the server can use to provide a full HTTP response for a request handled by a RequestHandler.
A simple ResponseModel consisting of only view data information.
A ResponseModel which, besides view data information, contains a template.
Event posted when an OAuth refresh token is revoked.
Event posted when a delegation is revoked.
Event posted when a delegation is revoked.
Event posted when a DCR initial access token is revoked.
Event posted when an OAuth refresh token is revoked.
Roles for the user that represent who the user is, e.g., "Student", "Faculty".
Represents the action of the SCIM operation being authorized.
 
Authorization manager for policy decisions enforced by SCIM endpoints.
Represents the action of the SCIM operation being authorized.
 
Common base class for any event triggered by SCIM actions.
Closed hierarchy of Obligation supported by the SCIM endpoints policy enforcement.
Allows deciding if a resource attributes can be updated or not
 
Allows deciding if a delegation can be updated or not
 
Allows for filtering of read attributes
 
Allows for filtering of delegations
 
Allows for the transformation of a resource query.
 
A ScopeClaim is a claim that can be authorized, and that is expanded from a Scope.
Generic scope (not specifically OAuth).
A Map of scopes which can be used to verify scopes requested by OAuth clients as well as obtain sub-sets of scope configurations that belong to different Sets (e.g.
A ScopeValue is a resolved scope, i.e.
Builder interface to add content to a selector action.
Instances of this type can be fully serialized as a Map.
A crypto store containing a trusted server certificate.
A session object, containing the session ID, time of expiration and serialized data.
This DataAccessProvider is responsible for storing and maintaining session for the server.
A session event.
This manager can be used in Authenticators to store data in a session.
A crypto store containing a signature trust anchor.
This is interface should be implemented by the signing consentor plugins.
This is a container for creating the Pending Result for Signing Consentor
Descriptor for a signing consentor.
Represents the result of applying a signing consentor.
 
 
 
Represents an Unsuccessful result.
Constrains a configuration element's size.
SMS Plugin descriptor.
 
Collection of AuthenticationAttributeTransformer instances.
A Standard HTTP cookie.
Event indicating Backchannel authentication was initiated.
Type that represents either a String (in case of one value) or an Array (List) of Strings (in case of multiple values).
 
A successful authentication action event.
Event fired at successful authentication.
Event generated on successful backchannel authentication.
Event fired when a client is successfully authenticated.
Builder interface allowing the addition of continuation actions to the representation being built.
Fired when a CredentialManager has verified credentials successfully.
Event fired at successful SSO authentication.
Special annotation available for use on methods returning String (including Optional<String>) values.
A crypto store containing symmetric key material for decrypting data.
A crypto store containing symmetric key material for encrypting data.
A crypto store containing symmetric key material for verifying signatures.
A crypto store containing symmetric key material for making signatures.
Base class for system level events.
The System Information Provider Service provides information relevant to the current system.
A marker interface that indicates that the implementer, a plug-in-provided service, is thread-safe.
A token that can be used to authorize access to resources without checking with an authorization server.
A data token containing a number of attributes, always including the TokenAttributes.CREATED and TokenAttributes.EXPIRES attributes.
 
Exception representing a problem during the issuance of a Token.
Common base class for OAuth Token events.
The status a token may have.
A factory that can create TrustManager objects.
Event fired when an account is unlinked.
 
 
An event that represents interactive user consent.
Event posted when an oauth-userinfo is successfully queried.
Common interface for any event triggered by a User Management GraphQL action.
Builder interface allowing the addition of user messages to the representation being built.
This is a manager object that provides methods for working with a username cookie.
The type of transformation to be applied to a cookie's value(s) when reading or writing it.
A warning message.
 
A Web Service Client is an HTTP Client that makes requests against a URI defined by configuration.
All errors that occur while building or sending requests via a WebServiceClient.
A factory that can create WebServiceClient objects.
DER encoded X.509 certificate, which must be base 64 encoded.