Interface Condition
-
- All Superinterfaces:
Cloneable
@SupportedAll @Deprecated public interface Condition extends Cloneable
Deprecated.The classCondition
defines an interface to allow pluggable condition. These are used to control policy decisions based on parameters such as time, authentication level of the user session and IP address from which the user is making the request. A condition computes aConditionDecision
based on the state of condition object as set bysetProperties
method call and the environment passed in a map of key/value pairs.ConditionDecision
encapsulates whether aPolicy
applies for the request andAdvice
messages generated by the condition. The following Condition implementation are provided with the Policy framework:- AuthLevelCondition
- LEAuthLevelCondition
- AuthSchemeCondition
- IPCondition
- SimpleTimeCondition
- SessionCondition
- SessionPropertyCondition
- AuthenticateToRealmCondition
- AuthenticateToServiceCondition
- LDAPFilterCondition
- See Also:
ConditionDecision
-
-
Field Summary
Fields Modifier and Type Field Description static String
AM_IDENTITY_NAME
Deprecated.Key that is used in aAMIdentityMembershipCondition
to specify the uuid(s) ofAMIdentiy
objects to which the policy would apply.static String
APPLICATION_IDLE_TIMEOUT
Deprecated.Key that is used to specify the application idle time outstatic String
APPLICATION_NAME
Deprecated.Key that is used to specify application name for the resources protected by the policystatic String
AUTH_LEVEL
Deprecated.Key that is used to define the minimum authentication level in anAuthLevelCondition
or the maximum authentication level in aLEAuthLevelCondition
of a policy being evaluated.static String
AUTH_LEVEL_CONDITION_ADVICE
Deprecated.Key that is used identify the advice messages fromAuthLevelCondition
.static String
AUTH_SCHEME
Deprecated.Key that is used to define the authentication scheme in anAuthSchemeCondition
of a policy.static String
AUTH_SCHEME_CONDITION_ADVICE
Deprecated.Key that is used identify the advice messages fromAuthSchemeCondition
static String
AUTH_TREE_CONDITION_ADVICE
Deprecated.static String
AUTHENTICATE_TO_REALM
Deprecated.Key used inAuthenticateToRealmCondition
to specify the realm for which the user should authenticate for the policy to apply.static String
AUTHENTICATE_TO_REALM_CONDITION_ADVICE
Deprecated.Key that is used identify the advice messages fromAuthenticateToRealmCondition
static String
AUTHENTICATE_TO_SERVICE
Deprecated.Key that is used inAuthenticateToServiceCondition
to specify the authentication chain for which the user should authenticate for the policy to apply.static String
AUTHENTICATE_TO_SERVICE_CONDITION_ADVICE
Deprecated.Key that is used identify the advice messages fromAuthenticateToServiceCondition
static String
DNS_NAME
Deprecated.Key that is used in anIPCondition
to define the DNS name values for which a policy applies.static String
END_DATE
Deprecated.Key that is used in aSimpleTimeCondition
to define the end of date range for which a policy applies.The value corresponding to the key has to be aSet
that has just one element which is aString
that corresponds to the pattern described below.static String
END_DAY
Deprecated.Key that is used in aSimpleTimeCondition
to define the end of day of week range for which a policy applies.static String
END_IP
Deprecated.Key that is used inIPCondition
to define the end of IP address range for which a policy applies.static String
END_TIME
Deprecated.Key that is used in aSimpleTimeCondition
to define the end of time range during which a policy applies.The value corresponding to the key has to be aSet
that has just one element which is aString
that conforms to the pattern described here.static String
ENFORCEMENT_TIME_ZONE
Deprecated.Key that is used in aSimpleTimeCondition
to define the time zone basis to evaluate the policy.static String
INVOCATOR_PRINCIPAL_UUID
Deprecated.Key that is passed in theenv
parameter while invokinggetConditionDecision
method of anAMIdentityMembershipCondition
.static String
LDAP_FILTER
Deprecated.Key that is used in aLDAPFilterCondition
to define the ldap filter that should be satisfied by the ldap entry of the user for the condition to be satisifed The value should be aSet
with only one element.static String
MAX_SESSION_TIME
Deprecated.Key that is used inSessionCondition
to define the maximum session time in minutes for which a policy applies.static String
REQUEST_AUTH_LEVEL
Deprecated.Key that is used to define the authentication level of the request.static String
REQUEST_AUTH_SCHEMES
Deprecated.Key that is used to define the name of authentication scheme of the request.static String
REQUEST_AUTHENTICATED_TO_REALMS
Deprecated.Key that is used to identify the names of authenticated realms in the request.static String
REQUEST_AUTHENTICATED_TO_SERVICES
Deprecated.Key that is used to identify the names of authentication chains in the request.static String
REQUEST_DNS_NAME
Deprecated.Key that is used to define request DNS name that is passed in theenv
parameter while invokinggetConditionDecision
method of anIPCondition
.static String
REQUEST_IP
Deprecated.Key that is used to define request IP address that is passed in theenv
parameter while invokinggetConditionDecision
method of anIPCondition
.static String
REQUEST_TIME_ZONE
Deprecated.Key that is used to define the time zone that is passed in theenv
parameter while invokinggetConditionDecision
method of aSimpleTimeCondition
Value for the key should be aTimeZone
object.static String
START_DATE
Deprecated.Key that is used in aSimpleTimeCondition
to define the start of date range for which a policy applies.static String
START_DAY
Deprecated.Key that is used in aSimpleTimeCondition
to define the start of day of week range for which a policy applies.static String
START_IP
Deprecated.Key used inIPCondition
to define the start of IP address range for which a policy applies.static String
START_TIME
Deprecated.Key that is used inSimpleTimeCondition
to define the beginning of time range during which a policy applies.static String
TERMINATE_SESSION
Deprecated.Key inSessionCondition
that is used to define the option to terminate the session if the session exceeds the maximum session time.static String
TRANSACTION_CONDITION_ADVICE
Deprecated.Key that is used to identify the advice messages fromTransactionCondition
static String
VALUE_CASE_INSENSITIVE
Deprecated.Key that is passed in theenv
parameter while invokinggetConditionDecision
method of aSessionPropertyCondition
to indicate if a case insensitive match needs to done of the property value against same name property in the user's single sign on token.
-
Method Summary
All Methods Instance Methods Abstract Methods Deprecated Methods Modifier and Type Method Description Object
clone()
Deprecated.Returns a copy of this object.ConditionDecision
getConditionDecision(SSOToken token, Map<String,Set<String>> env)
Deprecated.Gets the decision computed by this condition object, based on theMap
of environment parametersString
getDisplayName(String property, Locale locale)
Deprecated.Gets the display name for the property name.Map<String,Set<String>>
getProperties()
Deprecated.Gets the properties of the conditionList<String>
getPropertyNames()
Deprecated.Returns a list of property names for the condition.Syntax
getPropertySyntax(String property)
Deprecated.Returns the syntax for a property nameSet<String>
getValidValues(String property)
Deprecated.Returns a set of valid values given the property name.void
setProperties(Map<String,Set<String>> properties)
Deprecated.Sets the properties of the condition.
-
-
-
Field Detail
-
AUTH_LEVEL
static final String AUTH_LEVEL
Deprecated.Key that is used to define the minimum authentication level in anAuthLevelCondition
or the maximum authentication level in aLEAuthLevelCondition
of a policy being evaluated. In case ofAuthLevelCondition
policy would apply if the request authentication level is at least the level defined in condition while in case ofLEAuthLevelCondition
policy would apply if the request authentication level is less than or equal to the level defined in the condition. The value should be aSet
with only one element. The element should be aString
, parse-able as an integer or a realm qualified integer like "sun:1" where "sun" is a realm name.":" needs to used a delimiter between realm name and the level.- See Also:
setProperties(Map)
, Constant Field Values
-
REQUEST_AUTH_LEVEL
static final String REQUEST_AUTH_LEVEL
Deprecated.Key that is used to define the authentication level of the request. Its passed down in theenv
Map to thegetConditionDecision
call of anAuthLevelCondition
orLEAuthLevelCondition
for condition evaluation.The value should be an Integer or a
Set
ofString
s. If it is aSet
ofString
s, each element of the set has to be parseable as integer or should be a realm qualified integer like "sun:1". If theenv
parameter is null or does not define value forREQUEST_AUTH_LEVEL
, the value forREQUEST_AUTH_LEVEL
is obtained from the single sign on token of the user
-
AUTH_SCHEME
static final String AUTH_SCHEME
Deprecated.Key that is used to define the authentication scheme in anAuthSchemeCondition
of a policy. Policy would apply if the authentication scheme of the request is same as defined in the condition. The value should be aSet
with only one element. The element should be aString
, the authentication scheme name.- See Also:
setProperties(Map)
, Constant Field Values
-
APPLICATION_NAME
static final String APPLICATION_NAME
Deprecated.Key that is used to specify application name for the resources protected by the policy- See Also:
- Constant Field Values
-
APPLICATION_IDLE_TIMEOUT
static final String APPLICATION_IDLE_TIMEOUT
Deprecated.Key that is used to specify the application idle time out- See Also:
- Constant Field Values
-
REQUEST_AUTH_SCHEMES
static final String REQUEST_AUTH_SCHEMES
Deprecated.Key that is used to define the name of authentication scheme of the request. Its passed down as part of theenv
Map togetConditionDecision
of anAuthSchemeCondition
for condition evaluation. Value for the key should be aSet
with each element being aString
. If theenv
parameter is null or does not define value forREQUEST_AUTH_SCHEMES
, the value forREQUEST_AUTH_SCHEMES
is obtained from the single sign on token of the user
-
AUTHENTICATE_TO_REALM
static final String AUTHENTICATE_TO_REALM
Deprecated.Key used inAuthenticateToRealmCondition
to specify the realm for which the user should authenticate for the policy to apply. The value should be aSet
with only one element. The should be aString
, the realm name.- See Also:
setProperties(Map)
, Constant Field Values
-
REQUEST_AUTHENTICATED_TO_REALMS
static final String REQUEST_AUTHENTICATED_TO_REALMS
Deprecated.Key that is used to identify the names of authenticated realms in the request. Its passed down as part of theenv
Map togetConditionDecision
of anAuthenticateToRealmCondition
for condition evaluation. Value for the key should be aSet
with each element being aString
If theenv
parameter is null or does not define value forREQUEST_AUTHENTICATED_TO_REALMS
, the value forREQUEST_AUTHENTICATED_TO_REALMS
is obtained from the single sign on token of the user
-
AUTHENTICATE_TO_SERVICE
static final String AUTHENTICATE_TO_SERVICE
Deprecated.Key that is used inAuthenticateToServiceCondition
to specify the authentication chain for which the user should authenticate for the policy to apply. The value should be aSet
with only one element. The should be aString
, the realm name.- See Also:
setProperties(Map)
, Constant Field Values
-
REQUEST_AUTHENTICATED_TO_SERVICES
static final String REQUEST_AUTHENTICATED_TO_SERVICES
Deprecated.Key that is used to identify the names of authentication chains in the request. Its passed down as part of theenv
Map togetConditionDecision
of anAuthenticateToServiceCondition
for condition evaluation. Value for the key should be aSet
with each element being aString
. If theenv
parameter is null or does not define value forREQUEST_AUTHENTICATED_TO_SERVICES
, the value forREQUEST_AUTHENTICATED_TO_SERVICES
is obtained from the single sign on token of the user
-
AUTH_SCHEME_CONDITION_ADVICE
static final String AUTH_SCHEME_CONDITION_ADVICE
Deprecated.Key that is used identify the advice messages fromAuthSchemeCondition
- See Also:
- Constant Field Values
-
AUTHENTICATE_TO_SERVICE_CONDITION_ADVICE
static final String AUTHENTICATE_TO_SERVICE_CONDITION_ADVICE
Deprecated.Key that is used identify the advice messages fromAuthenticateToServiceCondition
- See Also:
- Constant Field Values
-
AUTH_LEVEL_CONDITION_ADVICE
static final String AUTH_LEVEL_CONDITION_ADVICE
Deprecated.Key that is used identify the advice messages fromAuthLevelCondition
.- See Also:
- Constant Field Values
-
AUTH_TREE_CONDITION_ADVICE
static final String AUTH_TREE_CONDITION_ADVICE
Deprecated.- See Also:
- Constant Field Values
-
AUTHENTICATE_TO_REALM_CONDITION_ADVICE
static final String AUTHENTICATE_TO_REALM_CONDITION_ADVICE
Deprecated.Key that is used identify the advice messages fromAuthenticateToRealmCondition
- See Also:
- Constant Field Values
-
TRANSACTION_CONDITION_ADVICE
static final String TRANSACTION_CONDITION_ADVICE
Deprecated.Key that is used to identify the advice messages fromTransactionCondition
- See Also:
- Constant Field Values
-
START_IP
static final String START_IP
Deprecated.Key used inIPCondition
to define the start of IP address range for which a policy applies. The value corresponding to the key has to be aSet
that has just one element which is aString
that conforms to the pattern described here. If a value is defined for START_IP, a value should also be defined for END_IP. The patterns for IP Version 4 is : n.n.n.n where n would take any integer value between 0 and 255 inclusive. Some sample values are: 122.100.85.45 145.64.55.35 15.64.55.35 The patterns for IP Version 6 is: x:x:x:x:x:x:x:x where x are the hexadecimal values of the eight 16-bit pieces of the address Some sample values are: FEDC:BA98:7654:3210:FEDC:BA98:7654:3210 1080:0:0:0:8:800:200C:417A
-
END_IP
static final String END_IP
Deprecated.Key that is used inIPCondition
to define the end of IP address range for which a policy applies. The value corresponding to the key has to be aSet
that has just one element which is aString
that conforms to the pattern described here. If a value is defined for END_IP, a value should also be defined for START_IP. The patterns is : n.n.n.n where n would take any integer value between 0 and 255 inclusive. Some sample values are 122.100.85.45 145.64.55.35 15.64.55.35 The patterns for IP Version 6 is: x:x:x:x:x:x:x:x where x are the hexadecimal values of the eight 16-bit pieces of the address Some sample values are: FEDC:BA98:7654:3210:FEDC:BA98:7654:3210 1080:0:0:0:8:800:200C:417A
-
DNS_NAME
static final String DNS_NAME
Deprecated.Key that is used in anIPCondition
to define the DNS name values for which a policy applies. The value corresponding to the key has to be aSet
where each element is aString
that conforms to the patterns described here. The patterns is :ccc.ccc.ccc.ccc *.ccc.ccc.ccc
where c is any valid character for DNS domain/host name. There could be any number of.ccc
components. Some sample values are:www.sun.com finace.yahoo.com *.yahoo.com
- See Also:
setProperties(Map)
, Constant Field Values
-
REQUEST_IP
static final String REQUEST_IP
Deprecated.Key that is used to define request IP address that is passed in theenv
parameter while invokinggetConditionDecision
method of anIPCondition
. Value for the key should be aString
that is a string representation of IP of the client, For IP version 4: The form is n.n.n.n where n is a value between 0 and 255 inclusive. For IP version 6: The form is x:x:x:x:x:x:x:x where x is the hexadecimal values of the eight 16-bit pieces of the address
-
REQUEST_DNS_NAME
static final String REQUEST_DNS_NAME
Deprecated.Key that is used to define request DNS name that is passed in theenv
parameter while invokinggetConditionDecision
method of anIPCondition
. Value for the key should be a set of strings representing the DNS names of the client, in the formccc.ccc.ccc
for IP version 4. For IP version 6, the form would bex:x:x:x:x:x:x:x
If theenv
parameter is null or does not define value forREQUEST_DNS_NAME
, the value forREQUEST_DNS_NAME
is obtained from the single sign on token of the user
-
LDAP_FILTER
static final String LDAP_FILTER
Deprecated.Key that is used in aLDAPFilterCondition
to define the ldap filter that should be satisfied by the ldap entry of the user for the condition to be satisifed The value should be aSet
with only one element. The element should be aString
.- See Also:
setProperties(Map)
, Constant Field Values
-
MAX_SESSION_TIME
static final String MAX_SESSION_TIME
Deprecated.Key that is used inSessionCondition
to define the maximum session time in minutes for which a policy applies. The value corresponding to the key has to be aSet
that has just one element which is a string and parse-able as anInteger
.- See Also:
- Constant Field Values
-
TERMINATE_SESSION
static final String TERMINATE_SESSION
Deprecated.Key inSessionCondition
that is used to define the option to terminate the session if the session exceeds the maximum session time. The value corresponding to the key has to be aSet
that has just one element which is a string. The option is on if the string value is equal totrue
.- See Also:
- Constant Field Values
-
START_TIME
static final String START_TIME
Deprecated.Key that is used inSimpleTimeCondition
to define the beginning of time range during which a policy applies. The value corresponding to the key has to be aSet
that has just one element which is aString
that conforms to the pattern described here. If a value is defined forSTART_TIME
, a value should also be defined forEND_TIME
. The patterns is:HH:mm
Some sample values are08:25 18:45
- See Also:
setProperties(Map)
,END_TIME
, Constant Field Values
-
END_TIME
static final String END_TIME
Deprecated.Key that is used in aSimpleTimeCondition
to define the end of time range during which a policy applies.The value corresponding to the key has to be aSet
that has just one element which is aString
that conforms to the pattern described here. If a value is defined forEND_TIME
, a value should also be defined forSTART_TIME
. The patterns is:HH:mm
Some sample values are08:25 18:45
- See Also:
setProperties(Map)
,START_TIME
, Constant Field Values
-
START_DAY
static final String START_DAY
Deprecated.Key that is used in aSimpleTimeCondition
to define the start of day of week range for which a policy applies. The value corresponding to the key has to be aSet
that has just one element which is aString
that is one of the valuesSun, Mon, Tue, Wed, Thu, Fri, Sat.
If a value is defined forSTART_DAY
, a value should also be defined forEND_DAY
. Some sample values areSun Mon
- See Also:
setProperties(Map)
,END_DAY
, Constant Field Values
-
END_DAY
static final String END_DAY
Deprecated.Key that is used in aSimpleTimeCondition
to define the end of day of week range for which a policy applies. Its defined in aSimpleTimeCondition
associated with the policy. The value corresponding to the key has to be aSet
that has just one element which is aString
that is one of the valuesSun, Mon, Tue, Wed, Thu, Fri, Sat.
If a value is defined forEND_DAY
, a value should also be defined forSTART_DAY
. Some sample values areSun Mon
- See Also:
setProperties(Map)
,START_DAY
, Constant Field Values
-
START_DATE
static final String START_DATE
Deprecated.Key that is used in aSimpleTimeCondition
to define the start of date range for which a policy applies. The value corresponding to the key has to be aSet
that has just one element which is aString
that corresponds to the pattern described below. If a value is defined forSTART_DATE
, a value should also be defined forEND_DATE
. The pattern isyyyy:MM:dd Some sample values are 2001:02:26 2002:12:31
- See Also:
setProperties(Map)
,END_DATE
, Constant Field Values
-
END_DATE
static final String END_DATE
Deprecated.Key that is used in aSimpleTimeCondition
to define the end of date range for which a policy applies.The value corresponding to the key has to be aSet
that has just one element which is aString
that corresponds to the pattern described below. If a value is defined forEND_DATE
, a value should also be defined forSTART_DATE
. The pattern isyyyy:MM:dd Some sample values are 2001:02:26 2002:12:31
- See Also:
setProperties(Map)
,START_DATE
, Constant Field Values
-
ENFORCEMENT_TIME_ZONE
static final String ENFORCEMENT_TIME_ZONE
Deprecated.Key that is used in aSimpleTimeCondition
to define the time zone basis to evaluate the policy. The value corresponding to the key has to be a one elementSet
where the element is aString
that is one of the standard timezone IDs supported by java or aString
of the patternGMT[+|-]hh[[:]mm]
here. If the value is not a valid time zone id and does not match the patternGMT[+|-]hh[[:]mm]
, it would default to GMT- See Also:
TimeZone
, Constant Field Values
-
REQUEST_TIME_ZONE
static final String REQUEST_TIME_ZONE
Deprecated.Key that is used to define the time zone that is passed in theenv
parameter while invokinggetConditionDecision
method of aSimpleTimeCondition
Value for the key should be aTimeZone
object. This would be used only if theENFORCEMENT_TIME_ZONE
is not defined for theSimpleTimeCondition
-
VALUE_CASE_INSENSITIVE
static final String VALUE_CASE_INSENSITIVE
Deprecated.Key that is passed in theenv
parameter while invokinggetConditionDecision
method of aSessionPropertyCondition
to indicate if a case insensitive match needs to done of the property value against same name property in the user's single sign on token.- See Also:
- Constant Field Values
-
INVOCATOR_PRINCIPAL_UUID
static final String INVOCATOR_PRINCIPAL_UUID
Deprecated.Key that is passed in theenv
parameter while invokinggetConditionDecision
method of anAMIdentityMembershipCondition
. The value specifies the uuid(s) for which the policy would apply. The value should be aSet
. Each element of theSet
should be a String, the uuid of theAMIdentity
objet.- See Also:
- Constant Field Values
-
AM_IDENTITY_NAME
static final String AM_IDENTITY_NAME
Deprecated.Key that is used in aAMIdentityMembershipCondition
to specify the uuid(s) ofAMIdentiy
objects to which the policy would apply. These uuid(s) are specified in the condition at policy definition time. The value should be aSet
Each element of theSet
should be a String, the uuid of the invocator.- See Also:
- Constant Field Values
-
-
Method Detail
-
getPropertyNames
List<String> getPropertyNames()
Deprecated.Returns a list of property names for the condition.- Returns:
- list of property names
-
getPropertySyntax
Syntax getPropertySyntax(String property)
Deprecated.Returns the syntax for a property name- Parameters:
property
- property name- Returns:
Syntax
for the property name- See Also:
Syntax
-
getDisplayName
String getDisplayName(String property, Locale locale) throws PolicyException
Deprecated.Gets the display name for the property name. Thelocale
variable could be used by the plugin to customize the display name for the given locale. Thelocale
variable could benull
, in which case the plugin must use the default locale.- Parameters:
property
- property namelocale
- locale for which the property name must be customized- Returns:
- display name for the property name.
- Throws:
PolicyException
- If the display name could not be retrieved.
-
getValidValues
Set<String> getValidValues(String property) throws PolicyException
Deprecated.Returns a set of valid values given the property name. This method is called if the property Syntax is either the SINGLE_CHOICE or MULTIPLE_CHOICE.- Parameters:
property
- property name- Returns:
- Set of valid values for the property.
- Throws:
PolicyException
- if unable to get the Syntax.
-
setProperties
void setProperties(Map<String,Set<String>> properties) throws PolicyException
Deprecated.Sets the properties of the condition. This influences theConditionDecision
that would be computed by a call to methodgetConditionDecision(Map)
and theAdvice
messages generated included in theConditionDecision
.ConditionDecision
encapsulates whether a policy applies for the request and advice messages generated by the condition. For example, for aSimpleTimeCondition
, the properties would defineStartTime
andEndTime
, to define the time range during which the policy applies- Parameters:
properties
- the properties of the condition that would influence theConditionDecision
returned by a call to methodgetConditionDecision(Map)
. Keys of the properties have to be String. Value corresponding to each key have to be aSet
ofString
elements. Each implementation of Condition could add further restrictions on the keys and values of thisMap
.- Throws:
PolicyException
- for any abnormal condition- See Also:
ConditionDecision
-
getProperties
Map<String,Set<String>> getProperties()
Deprecated.Gets the properties of the condition- Returns:
- properties of the condition
- See Also:
setProperties(java.util.Map<java.lang.String, java.util.Set<java.lang.String>>)
-
getConditionDecision
ConditionDecision getConditionDecision(SSOToken token, Map<String,Set<String>> env) throws PolicyException, SSOException
Deprecated.Gets the decision computed by this condition object, based on theMap
of environment parameters- Parameters:
token
- single-sign-onSSOToken
of the userenv
- request specific environmentMap
of key/value pairs For example this would contain IP address of remote client for anIPCondition
.- Returns:
- the condition decision.
The condition decision encapsulates whether a
Policy
applies for the request andadvice
messages generated by the condition. Policy framework continues evaluating aPolicy
only if it applies to the request as indicated by theConditionDecision
. Otherwise, further evaluation of thePolicy
is skipped. However, theAdvice
messages encapsulated in theConditionDecision
are aggregated and passed up, encapsulated in thePolicyDecision
. - Throws:
PolicyException
- if the decision could not be computedSSOException
- if SSO token is not valid- See Also:
ConditionDecision
-
clone
Object clone()
Deprecated.Returns a copy of this object.- Returns:
- a copy of this object
-
-