Session-less REST Endpoints
Configures protected session-less endpoints of the Loginapp REST API. These endpoints require authentication credentials attached to each request, but don't require previous authentication with a flow.
These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/.
For most of the session-less protected REST APIs, there is a corresponding flow-based API in the protected self-service REST APIs. Whenever possible, prefer the flow-based variant over the session-less configured here.
userSelfServiceSettings) Configures session-less user self-service REST endpoints.
These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/.
userTokenSettings) Configures session-less token REST endpoints related to user tokens.
These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/tokens/.
requestAuthentication) This property is only effective for the protected Loginapp REST API outside of the "self-service" sub-path.
accessController) This property is only effective for the protected Loginapp REST API outside of the "self-service" sub-path.
usernameTransformers) Transformation is done for:
- Resource URLs: the user id in the REST resource URL (e.g. in self-registration) is transformed before further processing is done.
- Authentication: for protected calls, the username of the provided credential (request credential policy) is transformed before passing it to the configured authenticator.
linkResponseRewritingEnabled) If a 'Base URI' is configured, links are rewritten according to the configured value. Otherwise, links are rewritten according to the external view provided by the WAF (if configured an a WAF environment cookie is present).
baseUri) This property is useful in test environments where you want links contained in REST responses to be relative to the configured base URI. Note that configuring this property will take precedence over link rewriting based on the WAF environment cookie.
In order to produce correct links, the property must be configured up to and including the /rest subpath. IAM will automatically append public to the configured value for calls to the public API and protected for calls to the protected API of the Loginapp (or oauth2 for OAuth 2.0/OpenId Connect endpoints).
Example:
- Property value:
http://myhost:8090/test/rest - The response from the REST call to
/<loginapp-uri>/rest/public/users/registerwill contain a link tohttp://myhost:8090/test/rest/protected/my/self
type: SessionlessRestEndpoints
id: SessionlessRestEndpoints-xxxxxx
displayName:
comment:
properties:
accessController:
baseUri:
linkResponseRewritingEnabled: true
requestAuthentication:
userSelfServiceSettings:
userTokenSettings:
usernameTransformers: