Class AccountAttributes
Object
se.curity.identityserver.sdk.attribute.Attributes
se.curity.identityserver.sdk.attribute.scim.v2.ResourceAttributes<AccountAttributes>
se.curity.identityserver.sdk.attribute.AccountAttributes
- All Implemented Interfaces:
Iterable<Attribute>,AttributeContainer<Attributes>,SerializableAsMap
A SCIM 2.0 representation of a user account. Note that the keyword here is representation. For mutating
properties of an account (such as changing the password) and persisting the changes, always first check to see if a
method for doing that already exists in either the
AccountManager or the CredentialManager interfaces,
and if so those methods must be used.
Example creation of a user
AccountAttributes user = AccountAttributes.of("User")
.withPhoneNumbers(PhoneNumber.of("+46771793336", true))
.withGroups(Group.of("admins"))
.withEmails(
Email.of("barbara@jensen.com"),
Email.of("babs@scim.com").withType("work")
).withName(Name.of("Barbara Jensen"))
.withNickName("Babs");
This serializes into:
{
"emails": [
{
"value": "barbara@jensen.com"
},
{
"type": "work",
"value": "babs@scim.com"
}
],
"groups": [
{
"value": "admins"
}
],
"id": "73a6119e-6edb-49bb-a490-d858de770c6e",
"meta": {
"created": "2016-05-18T11:19:10.205+02:00[Europe/Stockholm]",
"lastModified": "2016-05-18T11:19:10.218+02:00[Europe/Stockholm]",
"resourceType": "User"
},
"name": {
"formatted": "Barbara Jensen"
},
"nickName": "Babs",
"phoneNumbers": [
{
"primary": true,
"value": "+46771793336"
}
],
"schemas": [
"urn:ietf:params:scim:schemas:core:2.0:User"
],
"userName": "User"
}
-
Field Summary
FieldsModifier and TypeFieldDescriptionstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final Stringstatic final StringFields inherited from class se.curity.identityserver.sdk.attribute.scim.v2.ResourceAttributes
EXTERNAL_ID, ID, META, SCHEMAS -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionaddAddress(Address address) Add a address to the user.Add a device to the user.Add an email to the user.addEntitlement(Entitlement entitlement) Add an entitlement to the user.Add a group to the user.Add instant messaging handle to the user.addLinkedAccount(LinkedAccount linkedAccount) Add aLinkedAccountto the user.addPhoneNumber(PhoneNumber phoneNumber) Add a phoneNumber to the user.Add photo to the user.Add a role to the user.addX509Certificates(X509Certificates x509Certificates) Add a certificate to the user.emailFrom(@Nullable AccountAttributes account) protected AccountAttributesfrom(Attributes attributes) Convert the given Attributes to an AccountAttributes.static AccountAttributesList of physical mailing addresses for the user.Get the devices associated with the user.A displayName for the user.The email addresses associated with the user.The entitlements the user has.A list of groups to which the user belongs, either through direct membership, through nested groups, or dynamically calculated.getIms()The instant messaging handles associated with the user.Get the accounts linked to this user.The users locale.getName()The name components of the user.A nickName for the user, a casual way to address the user in real life.The users password.Phone numbers associated with the user.A list of url's to photo resources.Indicates the user’s preferred written or spoken languages The format of the value is the same as the Accept-Language HTTP header.A url to the users online profile.getRoles()A list of roles for the user that collectively represent who the user is, e.g., "Student", "Faculty".The users time zone.getTitle()The user's title, such as "Vice President".A unique identifier of the user.Used to identify the relationship between the organization and the user.A list of certificates associated with the User.booleanisActive()A flag indicating if the user should be seen as active or not.static AccountAttributesstatic AccountAttributesCreate a user object with userName.static AccountAttributesCreate an account with all the mandatory fields.static AccountAttributesCreate an object with attributes.removeAddress(Address address) Remove a address from the user.removeDevice(Device device) Remove device from the user.removeEmail(Email email) Remove an email from the user account.removeEntitlement(Entitlement entitlement) Remove an entitlement from the user account.removeGroup(Group group) Remove a group from the user.Remove instant handle messaging handle.removeLinkedAccounts(LinkedAccount linkedAccount) RemoveLinkedAccountfrom the user.removePhoneNumber(PhoneNumber phoneNumber) Remove a phoneNumber from the user.removePhoto(Photo photo) Remove photo from the user.removeRole(Role role) Remove a role from the user.removeX509Certificates(X509Certificates x509Certificates) Remove certificate from the user.replaceDevice(Device device) Add an arbitrary attribute to the user.withActive(boolean active) Update the object with the active flag.withAddresses(Address... addresses) Update object with addresses.withDevices(Device... devices) Update the object with devices.withDisplayName(String displayName) Update the object with displayName.withEmails(Email... emails) Update the object with emails.withEntitlements(Entitlement... entitlements) Update the object with entitlements.withGroups(Group... groups) Update the object with groups.withIms(InstantMessaging... ims) Update the object with im handles.withLinkedAccounts(LinkedAccount... linkedAccounts) Update the object with linked accounts.withLocale(String locale) Update the object with locale.Update the user with the name components.withNickName(String nickName) Update the object with nickName.withPassword(String password) Update the object with password.withPhoneNumbers(PhoneNumber... phoneNumbers) Update the object with phoneNumbers.withPhotos(Photo... photos) Update the object with photos.withPreferredLanguage(String preferredLanguage) Update the object with preferredLanguage.withProfileUrl(String profileUrl) Update the object with profileUrl.Update the object with roles.withTimeZone(String timezone) Update the object with timezone.Update the object with title.withUserType(String userType) Update the object with userType.withX509Certificates(X509Certificates certificates) Update the object with certificates.Methods inherited from class se.curity.identityserver.sdk.attribute.scim.v2.ResourceAttributes
addSchema, append, filter, getBooleanValue, getExternalId, getId, getListOfUniqueStringsValue, getMeta, getSchemas, getStringValue, getStringValue, logFailedAttributeValidation, logFailedAttributeValidation, removeAttribute, with, withExternalId, withId, withMeta, withSchemas, wrapMethods inherited from class se.curity.identityserver.sdk.attribute.Attributes
append, asMap, contains, empty, equals, fromMap, get, getAll, getMandatoryAttribute, getMandatoryValue, getValuesOfType, hashCode, isEmpty, iterator, keys, of, of, of, of, of, removeAttributes, retainAttributes, size, stream, toMap, toStringMethods inherited from class java.lang.Object
clone, finalize, getClass, notify, notifyAll, wait, wait, waitMethods inherited from interface se.curity.identityserver.sdk.attribute.AttributeContainer
contains, getOptionalValue, getOptionalValue, retainAttributeMethods inherited from interface java.lang.Iterable
forEach, spliterator
-
Field Details
-
USER_NAME
- See Also:
-
NAME
- See Also:
-
DISPLAY_NAME
- See Also:
-
NICK_NAME
- See Also:
-
PROFILE_URL
- See Also:
-
TITLE
- See Also:
-
PREFERRED_LANGUAGE
- See Also:
-
USER_TYPE
- See Also:
-
LOCALE
- See Also:
-
TIMEZONE
- See Also:
-
PASSWORD
- See Also:
-
EMAILS
- See Also:
-
PHONE_NUMBERS
- See Also:
-
IMS
- See Also:
-
PHOTOS
- See Also:
-
ADDRESSES
- See Also:
-
GROUPS
- See Also:
-
ENTITLEMENTS
- See Also:
-
ROLES
- See Also:
-
X509_CERTIFICATES
- See Also:
-
ACTIVE
- See Also:
-
CORE_USER_SCHEMA
- See Also:
-
RESOURCE_TYPE
- See Also:
-
EXTENSION_BASE
- See Also:
-
DEVICES
- See Also:
-
LINKED_ACCOUNTS
- See Also:
-
MULTI_VALUED_ATTRIBUTES
-
-
Constructor Details
-
AccountAttributes
-
-
Method Details
-
fromMap
-
of
Create an account with all the mandatory fields.- Parameters:
userName- user namepassword- passwordprimaryEmail- primary email- Returns:
- account
-
emailFrom
-
getUserName
A unique identifier of the user.This is a mandatory value
- Returns:
- the userName
-
getName
The name components of the user.- Returns:
- Name, null if not set
-
getDisplayName
A displayName for the user. Should be the full name of the user, if available.- Returns:
- the displayName, or null if not set.
-
getNickName
A nickName for the user, a casual way to address the user in real life. I.e. Bob for Robert.- Returns:
- the nickName, or null if not set.
-
getTitle
The user's title, such as "Vice President".- Returns:
- the title, or null if not found.
-
getPreferredLanguage
Indicates the user’s preferred written or spoken languages The format of the value is the same as the Accept-Language HTTP header.- Returns:
- the preferredLanguage, or null if not found.
-
getUserType
Used to identify the relationship between the organization and the user. Typical values used might be "Contractor", "Employee", "Intern", "Temp", "External", and "Unknown", but any value may be used.- Returns:
- the userType, or null if not found.
-
getProfileUrl
A url to the users online profile.- Returns:
- the profileUrl, or null if not found.
-
getLocale
The users locale.- Returns:
- the locale, or null if not found.
-
getTimeZone
The users time zone.Example: "America/Los_Angeles"
- Returns:
- the timeZone, or null if not found.
-
isActive
public boolean isActive()A flag indicating if the user should be seen as active or not.- Returns:
- true if the value is found, and set to true. False otherwise.
-
getPassword
The users password.- Returns:
- the password, or null if not found
-
getEmails
The email addresses associated with the user.- Returns:
- list of emails, empty if not found.
-
addEmail
Add an email to the user.- Parameters:
email- to add- Returns:
- copy of the user with the email added
-
removeEmail
Remove an email from the user account.- Parameters:
email- to remove- Returns:
- copy of the user with the email removed
-
getEntitlements
The entitlements the user has.- Returns:
- list of entitlements, empty if not found.
-
addEntitlement
Add an entitlement to the user.- Parameters:
entitlement- to add- Returns:
- copy of the user with the entitlement added
-
removeEntitlement
Remove an entitlement from the user account.- Parameters:
entitlement- to remove- Returns:
- copy of the user with the entitlement removed
-
getIms
The instant messaging handles associated with the user.- Returns:
- list of IMs, empty if not found.
-
addIms
Add instant messaging handle to the user.Example: @twobotechnologies
- Parameters:
im- instant messaging handle to add- Returns:
- copy of the user with the handle added
-
removeIms
Remove instant handle messaging handle.- Parameters:
im- instant messaging handle to remove- Returns:
- copy of the user with the handle removed
-
getPhotos
A list of url's to photo resources.- Returns:
- list of photos, empty if not found
-
addPhoto
Add photo to the user.- Parameters:
photo- photo to add- Returns:
- copy of the user with the photo added
-
removePhoto
Remove photo from the user.- Parameters:
photo- photo to remove- Returns:
- copy of the user with the photo removed
-
getPhoneNumbers
Phone numbers associated with the user.- Returns:
- list of phoneNumbers, empty if not found
-
addPhoneNumber
Add a phoneNumber to the user.- Parameters:
phoneNumber- phoneNumber to add- Returns:
- copy of the user with the phoneNumber added
-
removePhoneNumber
Remove a phoneNumber from the user.- Parameters:
phoneNumber- phoneNumber to remove- Returns:
- copy of the user with the phoneNumber removed
-
getGroups
A list of groups to which the user belongs, either through direct membership, through nested groups, or dynamically calculated.- Returns:
- list of groups, empty if not found
-
addGroup
Add a group to the user.- Parameters:
group- group to add- Returns:
- copy of the user with the group added
-
removeGroup
Remove a group from the user.- Parameters:
group- group to add- Returns:
- copy of the user with the group remove
-
getRoles
A list of roles for the user that collectively represent who the user is, e.g., "Student", "Faculty".- Returns:
- list of roles, empty if not found
-
addRole
Add a role to the user.- Parameters:
role- to be added- Returns:
- copy of the user with the role added
-
removeRole
Remove a role from the user.- Parameters:
role- to be removed- Returns:
- copy of the user with the role removed
-
getAddresses
List of physical mailing addresses for the user.- Returns:
- list of addresses, empty if not found
-
addAddress
Add a address to the user.- Parameters:
address- to be added- Returns:
- copy of the user with the address added
-
removeAddress
Remove a address from the user.- Parameters:
address- to be removed- Returns:
- copy of the user with the address removed
-
getX509certificates
A list of certificates associated with the User. DER and Base64 encoded.- Returns:
- list of base64 encoded certificates, empty if not found
-
addX509Certificates
Add a certificate to the user.- Parameters:
x509Certificates- to be added, DER and Base64 encoded- Returns:
- copy of the user with the certificate added
-
removeX509Certificates
Remove certificate from the user.- Parameters:
x509Certificates- to be removed- Returns:
- copy of the user, with the certificate removed
-
getDevices
Get the devices associated with the user.- Returns:
- list of devices, empty if not found
-
addDevice
Add a device to the user.- Parameters:
device- to be added- Returns:
- copy of the user with the device added
-
replaceDevice
-
removeDevice
Remove device from the user.- Parameters:
device- to be removed- Returns:
- copy of the user, with the device removed
-
getLinkedAccounts
Get the accounts linked to this user.- Returns:
- list of accounts, empty if not found
-
addLinkedAccount
Add aLinkedAccountto the user. NOTE that for adding new linked accounts and persisting them on the account theAccountManager.link(AccountAttributes, AccountDomain, SubjectAttributes, boolean)method MUST be used.- Parameters:
linkedAccount- to be added- Returns:
- copy of the user with the linkedAccount added
-
removeLinkedAccounts
RemoveLinkedAccountfrom the user. NOTE that for removing linked accounts and persisting the changes on the account theAccountManager.deleteLink(AccountAttributes, AccountDomain, SubjectAttributes)orAccountManager.deleteLinks(AccountAttributes)method MUST be used.- Parameters:
linkedAccount- to be removed- Returns:
- copy of the user, with the linkedAccount removed
-
with
Add an arbitrary attribute to the user. can contain anything anAttributecan contain. The attribute will be accessible through theAttributes.get(String)method.This can be used to add extensions to the user account.
AccountAttributes user = AccountAttributes.of("User"); user = user.with(Attribute.of("foo", "bar")); assert "bar".equals(user.get("foo").getValue());- Specified by:
within interfaceAttributeContainer<Attributes>- Overrides:
within classResourceAttributes<AccountAttributes>- Parameters:
attribute- attribute to add or to override- Returns:
- copy of the user with the attribute set.
-
of
Create an object with attributes.- Parameters:
attributes- to add to the user object- Returns:
- AccountAttributes with the attributes
-
of
-
from
Convert the given Attributes to an AccountAttributes.- Specified by:
fromin classResourceAttributes<AccountAttributes>- Parameters:
attributes- representing the new AccountAttributes- Returns:
- AccountAttributes with the attributes
-
of
Create a user object with userName.- Parameters:
id- id of the accountuserName- for the account- Returns:
- AccountAttributes with the userName set
-
withAddresses
Update object with addresses.- Parameters:
addresses- to add to the user- Returns:
- copy of the AccountAttributes, with the added addresses
-
withEmails
Update the object with emails.- Parameters:
emails- to add to the user- Returns:
- copy of the AccountAttributes, with the added emails
-
withEntitlements
Update the object with entitlements.- Parameters:
entitlements- to add to the user- Returns:
- copy of the AccountAttributes, with the added entitlements
-
withGroups
Update the object with groups.- Parameters:
groups- to add to the user- Returns:
- copy of the AccountAttributes, with the added groups
-
withIms
Update the object with im handles.- Parameters:
ims- to add to the user- Returns:
- copy of the AccountAttributes, with the added im handles
-
withPhoneNumbers
Update the object with phoneNumbers.- Parameters:
phoneNumbers- to add to the user- Returns:
- copy of the AccountAttributes, with the added phoneNumbers
-
withPhotos
Update the object with photos.- Parameters:
photos- to add to the user- Returns:
- copy of the AccountAttributes, with the added photos
-
withRoles
Update the object with roles.- Parameters:
roles- to add to the user- Returns:
- copy of the AccountAttributes, with the added roles
-
withX509Certificates
Update the object with certificates.- Parameters:
certificates- to add to the user- Returns:
- copy of the AccountAttributes, with the added certificates
-
withName
Update the user with the name components.- Parameters:
name- to add or override- Returns:
- copy of the AccountAttributes, with the new name
-
withDisplayName
Update the object with displayName.- Parameters:
displayName- to add or override- Returns:
- copy of the AccountAttributes, with the new displayName
-
withNickName
Update the object with nickName.- Parameters:
nickName- to add or override- Returns:
- copy of the AccountAttributes, with the new nickName
-
withTitle
Update the object with title.- Parameters:
title- to add or override- Returns:
- copy of the AccountAttributes, with the new title
-
withUserType
Update the object with userType.- Parameters:
userType- to add or override- Returns:
- copy of the AccountAttributes, with the new userType
-
withProfileUrl
Update the object with profileUrl.- Parameters:
profileUrl- to add or override- Returns:
- copy of the AccountAttributes, with the new profileUrl
-
withPreferredLanguage
Update the object with preferredLanguage.- Parameters:
preferredLanguage- to add or override- Returns:
- copy of the AccountAttributes, with the new preferredLanguage
-
withLocale
Update the object with locale.- Parameters:
locale- to add or override- Returns:
- copy of the AccountAttributes, with the new locale
-
withTimeZone
Update the object with timezone.- Parameters:
timezone- to add or override- Returns:
- copy of the AccountAttributes, with the new timezone
-
withPassword
Update the object with password. NOTE that actually changing the password of an account should always be done through aCredentialManageras setting or updating passwords involve hashing and possibly other requirements.- Parameters:
password- to add or override- Returns:
- copy of the AccountAttributes, with the new password
-
withActive
Update the object with the active flag.- Parameters:
active- to add or override- Returns:
- copy of the AccountAttributes, with the new active
-
withDevices
Update the object with devices.Will add the
DEVICESto the schemas if it's not already there- Parameters:
devices- to add- Returns:
- copy of AccountAttributes with the added schema and devices
-
withLinkedAccounts
Update the object with linked accounts. NOTE that for adding new linked accounts and persisting them on the account theAccountManager.link(AccountAttributes, AccountDomain, SubjectAttributes, boolean)method MUST be used.Will add the
LINKED_ACCOUNTSto the schemas if it's not already there- Parameters:
linkedAccounts- to add- Returns:
- copy of AccountAttributes with the added schema and linkedAccounts
-