openapi: 3.2.0 info: title: Jans Config Configuration – Config API contact: name: Contact url: https://github.com/JanssenProject/jans/discussions license: name: License url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: OAS Version servers: - url: https://jans.local.io description: The Jans server tags: - name: Configuration – Config API paths: /api/v1/api-config: get: tags: - Configuration – Config API summary: Gets config-api configuration properties description: Gets config-api configuration properties. operationId: get-config-api-properties responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/ApiAppConfiguration' '401': description: Unauthorized '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/config/properties.readonly - oauth2: - https://jans.io/oauth/config/properties.write - oauth2: - https://jans.io/oauth/config/properties.admin - oauth2: - https://jans.io/oauth/config/read-all - oauth2: - https://jans.io/oauth/config/write-all patch: tags: - Configuration – Config API summary: Partially modifies config-api configuration properties description: Partially modifies config-api Configuration properties. operationId: patch-config-api-properties requestBody: description: String representing patch-document. content: application/json-patch+json: schema: type: array items: $ref: '#/components/schemas/JsonPatch' examples: Request json example: description: Request json example value: '' responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/ApiAppConfiguration' '401': description: Unauthorized '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/config/properties.write - oauth2: - https://jans.io/oauth/config/properties.admin - oauth2: - https://jans.io/oauth/config/write-all components: schemas: AssetDirMapping: type: object properties: directory: type: string description: Relative path to asset base directory. type: type: array description: List of file extention that are stored in directory. items: type: string description: List of file extention that are stored in directory. description: type: string description: Description of assets stored in directory. jansServiceModule: type: array description: List of supported service module where asset can be uploaded. items: type: string description: List of supported service module where asset can be uploaded. description: Asset type mapped to server directory. CedarlingConfiguration: type: object properties: enabled: type: boolean description: Specify if Cedraling is enabled policySources: type: array description: List of Policy Sources items: $ref: '#/components/schemas/PolicySource' logType: type: string description: 'Log type: off, memory, std_out' enum: - 'OFF' - MEMORY - STD_OUT logLevel: type: string description: System Log Level enum: - FATAL - ERROR - WARN - INFO - DEBUG - TRACE externalPolicyStoreUri: type: string description: External policy store URI maxEntries: type: integer description: maximum number of entries in policy store file format: int32 description: Cedar Configuration for authorization. AgamaConfiguration: type: object properties: allowedDomain: type: array description: List of allowed domains to download Agama Project. items: type: string description: List of allowed domains to download Agama Project. mandatoryAttributes: type: array description: List of attributes required to create the Agama Flow. items: type: string description: List of attributes required to create the Agama Flow. optionalAttributes: type: array description: List of attributes that are optional. items: type: string description: List of attributes that are optional. description: Agama configuration details. ApiAppConfiguration: type: object properties: serviceName: type: string description: Config API service name. configOauthEnabled: type: boolean description: OAuth authentication enable/disable flag. Default value `true`. protectionMode: type: string description: Protection mode for the Lock server (OAuth or Cedarling) enum: - oauth - cedarling disableLoggerTimer: type: boolean description: Flag to enable/disable timer to dynamically reflect log configuration changes. Default value `true`Default value `false`. disableAuditLogger: type: boolean description: Flag to enable/disable request audit. Default value `false`. customAttributeValidationEnabled: type: boolean description: Flag to enable/disable check if custom attribue is declared in schema. Default value `true`. acrValidationEnabled: type: boolean description: Flag to enable/disable check if acr customScript is enabled. Default value `true`. returnClientSecretInResponse: type: boolean description: Flag to enable/disable sending clientSecret in response. Default value `true`. returnEncryptedClientSecretInResponse: type: boolean description: Flag to enable/disable sending encrypted clientSecret in response. Default value `true`. apiApprovedIssuer: type: array description: List of approved external Auth server to validate token. items: type: string description: List of approved external Auth server to validate token. apiProtectionType: type: string description: Name of supported API protection mechansim. Supported type is `OAuth2`. apiClientId: type: string description: Config-API client ID. apiClientPassword: type: string description: Config-API client password. endpointInjectionEnabled: type: boolean authIssuerUrl: type: string description: Issuer Identifier of Jans OpenID Connect Provider. authOpenidConfigurationUrl: type: string description: Jans OpenID Connect Provider Well-Known Configuration URL. authOpenidIntrospectionUrl: type: string description: Jans URL of the OpenID Connect Provider's OAuth 2.0 Authorization Endpoint. authOpenidTokenUrl: type: string description: Jans URL of the OpenID Connect Provider's OAuth 2.0 Token Endpoint. authOpenidRevokeUrl: type: string description: Jans URL of the OpenID Connect Provider's OAuth 2.0 Revoke Token Endpoint. exclusiveAuthScopes: type: array description: List of oAuth scope that can be validity for an access tokens only by underlying Jans Auth server. items: type: string description: List of oAuth scope that can be validity for an access tokens only by underlying Jans Auth server. corsConfigurationFilters: type: array description: CORS configuration filter properties. items: $ref: '#/components/schemas/CorsConfigurationFilter' loggingLevel: type: string description: Specify logging level of Loggers. Default level is `INFO`. loggingLayout: type: string description: Log4j logging layout. Default value `TEXT`. externalLoggerConfiguration: type: string description: The path to the external log4j2 logging configuration. disableJdkLogger: type: boolean description: Choose whether to disable JDK loggers. disableExternalLoggerConfiguration: type: boolean maxCount: type: integer description: Maximum number of results per page in search endpoints. format: int32 acrExclusionList: type: array description: List of ACR values that should be excluded from active validation check. items: type: string description: List of ACR values that should be excluded from active validation check. userExclusionAttributes: type: array description: User attribute that should not be returned in response. items: type: string description: User attribute that should not be returned in response. userMandatoryAttributes: type: array description: List of User mandatory attribute for user creation request. items: type: string description: List of User mandatory attribute for user creation request. agamaConfiguration: $ref: '#/components/schemas/AgamaConfiguration' auditLogConf: $ref: '#/components/schemas/AuditLogConf' dataFormatConversionConf: $ref: '#/components/schemas/DataFormatConversionConf' cedarlingConfiguration: $ref: '#/components/schemas/CedarlingConfiguration' plugins: type: array description: Details of enabled plugins. items: $ref: '#/components/schemas/PluginConf' assetMgtConfiguration: $ref: '#/components/schemas/AssetMgtConfiguration' PluginConf: type: object properties: name: type: string description: Name of the plugin. description: type: string description: Description of the plugin. className: type: string description: Plugin application class. AssetMgtConfiguration: type: object properties: assetMgtEnabled: type: boolean description: Flag indicating if asset management functionality is enabled. assetServerUploadEnabled: type: boolean description: Flag indicating if asset upload to server is enabled. fileExtensionValidationEnabled: type: boolean description: Flag indicating if file extension validation is enabled. moduleNameValidationEnabled: type: boolean description: Flag indicating if service module name extension validation is enabled. assetDirMapping: type: array description: Asset type mapped to server directory. items: $ref: '#/components/schemas/AssetDirMapping' description: Asset management configuration details. DataFormatConversionConf: type: object properties: enabled: type: boolean description: Flag to enable and disable data conversion. ignoreHttpMethod: type: array description: HTTP methods for which data conversion is to be disabled. items: type: string description: HTTP methods for which data conversion is to be disabled. description: Configuration for data-type converstion. CorsConfigurationFilter: type: object properties: filterName: type: string corsEnabled: type: boolean corsAllowedOrigins: type: string corsAllowedMethods: type: string corsAllowedHeaders: type: string corsExposedHeaders: type: string corsSupportCredentials: type: boolean corsLoggingEnabled: type: boolean corsPreflightMaxAge: type: integer format: int32 corsRequestDecorate: type: boolean description: CORS configuration filter properties. AuditLogConf: type: object properties: enabled: type: boolean description: Flag to enable and disable audit log. logData: type: boolean description: Flag to enable and disable loggin g data. ignoreHttpMethod: type: array description: HTTP methods for which audit is disabled. items: type: string description: HTTP methods for which audit is disabled. ignoreAnnotation: type: array description: Annotation for which audit is disabled. items: type: string description: Annotation for which audit is disabled. ignoreObjectMapping: type: array description: Object for which audit is disabled. items: $ref: '#/components/schemas/ObjectDetails' headerAttributes: type: array description: List of header HTTP attributes whose value is to be logged. items: type: string description: List of header HTTP attributes whose value is to be logged. auditLogFilePath: type: string description: Audit log file location. auditLogFileName: type: string description: Audit log file name. auditLogDateFormat: type: string description: Date format in audit log file. description: Audit Log configuration details. ObjectDetails: type: object properties: name: type: string description: Name of the object. text: type: array description: List of string text that is to be ignored . items: type: string description: List of string text that is to be ignored . description: Object for which audit is disabled. JsonPatch: type: object PolicySource: type: object properties: enabled: type: boolean description: Specify if policy source is enabled authorizationToken: type: string description: Authorization token to access URI policyStoreUri: type: string description: URI to policy store. Policy store can be either json/zip description: List of Policy Sources securitySchemes: oauth2: type: oauth2 flows: clientCredentials: tokenUrl: https://{op-hostname}/.../token scopes: https://jans.io/oauth/jans-auth-server/config/properties.readonly: View Auth Server properties related information https://jans.io/oauth/jans-auth-server/config/properties.write: Manage Auth Server properties related information https://jans.io/oauth/config/attributes.readonly: View attribute related information https://jans.io/oauth/config/attributes.write: Manage attribute related information https://jans.io/oauth/config/attributes.delete: Delete attribute related information https://jans.io/oauth/config/acrs.readonly: View ACRS related information https://jans.io/oauth/config/acrs.write: Manage ACRS related information https://jans.io/oauth/config/database/ldap.readonly: View LDAP database related information https://jans.io/oauth/config/database/ldap.write: Manage LDAP database related information https://jans.io/oauth/config/database/ldap.delete: Delete LDAP database related information https://jans.io/oauth/config/scripts.readonly: View cache scripts information https://jans.io/oauth/config/scripts.write: Manage scripts related information https://jans.io/oauth/config/scripts.delete: Delete scripts related information https://jans.io/oauth/config/cache.readonly: View cache related information https://jans.io/oauth/config/cache.write: Manage cache related information https://jans.io/oauth/config/smtp.readonly: View SMTP related information https://jans.io/oauth/config/smtp.write: Manage SMTP related information https://jans.io/oauth/config/smtp.delete: Delete SMTP related information https://jans.io/oauth/config/logging.readonly: View logging related information https://jans.io/oauth/config/logging.write: Manage logging related information https://jans.io/oauth/config/jwks.readonly: View JWKS related information https://jans.io/oauth/config/jwks.write: Manage JWKS related information https://jans.io/oauth/config/jwks.delete: Delete JWKS related information https://jans.io/oauth/config/openid/clients.readonly: View clients related information https://jans.io/oauth/config/openid/clients.write: Manage clients related information https://jans.io/oauth/config/openid/clients.delete: Delete clients related information https://jans.io/oauth/config/scopes.readonly: View scope related information https://jans.io/oauth/config/scopes.write: Manage scope related information https://jans.io/oauth/config/scopes.delete: Delete scope related information https://jans.io/oauth/config/stats.readonly: View server with basic statistic https://jans.io/oauth/config/organization.readonly: View organization configuration information https://jans.io/oauth/config/organization.write: Manage organization configuration information https://jans.io/oauth/config/agama.readonly: View Agama Flow related information https://jans.io/oauth/config/agama.write: Manage Agama Flow related information https://jans.io/oauth/config/agama.delete: Delete Agama Flow related information https://jans.io/oauth/jans-auth-server/session.readonly: View Session related information https://jans.io/oauth/jans-auth-server/session.delete: Delete Session information https://jans.io/oauth/config/read-all: Super admin read access to all configuration resources https://jans.io/oauth/config/write-all: Super admin write access to all configuration resources https://jans.io/oauth/config/delete-all: Super admin delete access to all configuration resources https://jans.io/oauth/config/openid/openid.readonly: View OpenID functionality https://jans.io/oauth/config/openid/openid.write: Manage OpenID functionality https://jans.io/oauth/config/openid/openid.delete: Delete OpenID functionality https://jans.io/oauth/config/uma.readonly: View UMA functionality https://jans.io/oauth/config/uma.write: Manage UMA functionality https://jans.io/oauth/config/uma.delete: Delete UMA functionality https://jans.io/oauth/config/plugin.readonly: View Plugin information https://jans.io/oauth/config/properties.readonly: View Config-API related configuration properties https://jans.io/oauth/config/properties.write: Manage Config-API related configuration properties https://jans.io/oauth/client/authorizations.readonly: View ClientAuthorizations https://jans.io/oauth/client/authorizations.delete: Revoke ClientAuthorizations https://jans.io/oauth/config/asset.readonly: View Jans Assets https://jans.io/oauth/config/asset.write: Manage Jans Assets https://jans.io/oauth/config/asset.delete: Delete Jans Assets https://jans.io/oauth/config/token.readonly: View Token details https://jans.io/oauth/config/token.write: Manage Token details https://jans.io/oauth/config/token.delete: Delete Token details https://jans.io/oauth/config/data.readonly: View Config-API related data https://jans.io/oauth/config/ssa.readonly: View SSA details https://jans.io/oauth/config/ssa.write: Manage SSA details https://jans.io/oauth/config/ssa.delete: Delete SSA details https://jans.io/oauth/jans-auth-server/config/properties.admin: Admin scope for Auth Server properties https://jans.io/oauth/config/attributes.admin: Admin for Attribute management https://jans.io/oauth/config/acrs.admin: Admin for ACRS management https://jans.io/oauth/config/database.admin: Admin for Database config management https://jans.io/oauth/config/scripts.admin: Admin for Scripts management https://jans.io/oauth/config/cache.admin: Admin for Cache management https://jans.io/oauth/config/message.admin: Admin for Message management https://jans.io/oauth/config/smtp.admin: Admin for SMTP management https://jans.io/oauth/config/logging.admin: Admin for Logging management https://jans.io/oauth/config/jwks.admin: Admin for JWKS management https://jans.io/oauth/config/openid/clients.admin: Admin for clients management https://jans.io/oauth/config/token.admin: Admin for Token management https://jans.io/oauth/config/scopes.admin: Admin for scope management https://jans.io/oauth/config/stats.admin: Admin for statistic management https://jans.io/oauth/config/organization.admin: Admin for organization configuration management https://jans.io/oauth/config/agama.admin: Admin for Agama flow management https://jans.io/oauth/jans-auth-server/session.admin: Admin for Session management https://jans.io/oauth/config/uma.admin: Admin for UMA management https://jans.io/oauth/config/plugin.admin: Admin for Plugin management https://jans.io/oauth/config/properties.admin: Admin for Config-API management https://jans.io/oauth/client/authorizations.admin: Admin for Client Authorizations management https://jans.io/oauth/config/asset.admin: Admin for Jans Assets management https://jans.io/auth/ssa.admin: Admin for SSA management https://jans.io/oauth/config/health.admin: Admin for Health API management