openapi: 3.2.0 info: title: Jans Config API - Lock Lock - Configuration API contact: name: Gluu Support url: https://support.gluu.org email: support@gluu.org license: name: Apache 2.0 url: https://github.com/JanssenProject/jans/blob/main/LICENSE version: 1.0.0 servers: - url: https://jans.io/ description: The Jans server tags: - name: Lock - Configuration paths: /lock/lockConfig: get: tags: - Lock - Configuration summary: Gets Lock configuration properties operationId: get-lock-properties responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/AppConfiguration' '401': description: Unauthorized '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/lock-config.readonly - oauth2: - https://jans.io/oauth/lock-config.write - oauth2: - https://jans.io/oauth/config/lock.admin - oauth2: - https://jans.io/oauth/lock/read-all - oauth2: - https://jans.io/oauth/config/read-all - oauth2: - https://jans.io/oauth/config/write-all put: tags: - Lock - Configuration summary: Update Lock configuration properties operationId: put-lock-properties requestBody: description: GluuAttribute object content: application/json: schema: $ref: '#/components/schemas/AppConfiguration' examples: Request example: description: Request example value: '' responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/AppConfiguration' '401': description: Unauthorized '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/lock-config.write - oauth2: - https://jans.io/oauth/config/lock.admin - oauth2: - https://jans.io/oauth/lock/write-all - oauth2: - https://jans.io/oauth/config/write-all patch: tags: - Lock - Configuration summary: Partially modifies Lock configuration properties description: Partially modifies Lock configuration properties. operationId: patch-lock-properties requestBody: description: String representing patch-document. content: application/json-patch+json: schema: type: array items: $ref: '#/components/schemas/JsonPatch' examples: Request json example: description: Request json example value: '' responses: '200': description: Ok content: application/json: schema: $ref: '#/components/schemas/AppConfiguration' '401': description: Unauthorized '500': description: InternalServerError security: - oauth2: - https://jans.io/oauth/lock-config.write - oauth2: - https://jans.io/oauth/config/lock.admin - oauth2: - https://jans.io/oauth/lock/write-all - oauth2: - https://jans.io/oauth/config/write-all components: schemas: GrpcConfiguration: type: object properties: serverMode: type: string description: gRPC server mode enum: - disabled - bridge - plain_server - tls_server grpcPort: type: integer description: Specify grpc port format: int32 useTls: type: boolean description: Use TLS for gRPC communication tlsCertChainFilePath: type: string description: TLS Cert Chain File Path tlsPrivateKeyFilePath: type: string description: TLS Private Key File Path description: gRPC server configuration CedarlingConfiguration: type: object properties: enabled: type: boolean description: Specify if Cedraling is enabled policySources: type: array description: List of Policy Sources items: $ref: '#/components/schemas/PolicySource' logType: type: string description: 'Log type: off, memory, std_out' enum: - 'OFF' - MEMORY - STD_OUT logLevel: type: string description: System Log Level enum: - FATAL - ERROR - WARN - INFO - DEBUG - TRACE externalPolicyStoreUri: type: string description: External policy store URI maxEntries: type: integer description: maximum number of entries in policy store file format: int32 description: Cedarling configuration JsonPatch: type: object AppConfiguration: type: object properties: baseDN: type: string description: Entry Base distinguished name (DN) that identifies the starting point of a search baseEndpoint: type: string description: Lock base endpoint URL openIdIssuer: type: string description: OpenID issuer URL protectionMode: type: string description: Protection mode for the Lock server (OAuth or Cedarling) enum: - oauth - cedarling auditPersistenceMode: type: string description: Audit persistence mode enum: - internal - config-api cedarlingConfiguration: $ref: '#/components/schemas/CedarlingConfiguration' grpcConfiguration: $ref: '#/components/schemas/GrpcConfiguration' statEnabled: type: boolean description: Active stat enabled statTimerIntervalInSeconds: type: integer description: Statistical data capture time interval format: int32 tokenChannels: type: array description: List of token channel names items: type: string description: List of token channel names clientId: type: string description: Lock Client ID clientPassword: type: string description: Lock client password disableJdkLogger: type: boolean description: Choose whether to disable JDK loggers disableExternalLoggerConfiguration: type: boolean loggingLevel: type: string description: Specify the logging level of loggers loggingLayout: type: string description: Logging layout used for Jans Authorization Server loggers externalLoggerConfiguration: type: string description: The path to the external log4j2 logging configuration metricReporterInterval: type: integer description: The interval for metric reporter in seconds format: int32 metricReporterKeepDataDays: type: integer description: The days to keep metric reported data format: int32 metricReporterEnabled: type: boolean description: Enable metric reporter cleanServiceInterval: type: integer description: Time interval for the Clean Service in seconds format: int32 messageConsumerType: type: string description: PubSub consumer service errorReasonEnabled: type: boolean cleanServiceBatchChunkSize: type: integer description: Each clean up iteration fetches chunk of expired data per base dn and removes it from storage format: int32 PolicySource: type: object properties: enabled: type: boolean description: Specify if policy source is enabled authorizationToken: type: string description: Authorization token to access URI policyStoreUri: type: string description: URI to policy store. Policy store can be either json/zip description: List of Policy Sources securitySchemes: oauth2: type: oauth2 flows: clientCredentials: tokenUrl: https://{op-hostname}/.../token scopes: https://jans.io/oauth/lock/read-all: View Lock related information https://jans.io/oauth/lock/write-all: View Lock related information https://jans.io/oauth/lock-config.readonly: View Lock configuration related information https://jans.io/oauth/lock-config.write: Manage Lock configuration related information https://jans.io/oauth/lock/audit.readonly: View Lock audit related information https://jans.io/oauth/lock/audit.write: View Lock audit related information https://jans.io/oauth/lock/health.readonly: View Lock health related information https://jans.io/oauth/lock/health.write: Manage Lock health related information https://jans.io/oauth/lock/log.readonly: View Lock log related information https://jans.io/oauth/lock/log.write: Manage Lock log health related information https://jans.io/oauth/lock/telemetry.readonly: View Lock telemetry related information https://jans.io/oauth/lock/telemetry.write: Manage Lock telemetry related information https://jans.io/oauth/config/lock.admin: Lock Admin access to manage all Lock configuration related information https://jans.io/oauth/config/read-all: Super admin read access to all configuration resources https://jans.io/oauth/config/write-all: Super admin write access to all configuration resources https://jans.io/oauth/config/delete-all: Super admin delete access to all configuration resources jans_stat: Auth Server Stats Authorization Scope