TAN Batch Task
In order to understand the following task description, it is important to understand, that a user can have zero, one, or two token lists or matrix cards at the same time: The active token list is the one being used for authentication. The next token list is a new token list waiting to become active. It is generated some time before the current active token list expires so it can be sent to the user. The new token list becomes active, if the current token list expires or is removed. Depending on configuration, just using the new token list will also activate it.
When executed, this task looks at all users with the configured token list iterator plug-in and does the following tasks. The process is done only for active users returned by the token list iterator:
- Remove expired token lists or matrix cards.
- Remove empty token lists.
- If the user has no active list but a valid new token list, the new token list is made the active token list.
- Generate new token lists or new matrix cards where necessary. This is the case if at least one of the following conditions is true:
- If the current token list or matrix card of the user is about to expire and there is no "next token list".
- If there is no token list at all.
- If there is no "next token list" and the corresponding flag ("order new list flag") is set. - Newly generated token lists are rendered by calling the configured token list renderer.
tokenListPersister) tokenListIterator) maximumValidityDays) remainingDaysThreshold) The value is only relevant when the property maximum-validity-days is not -1.
deliverySecurityGap) Setting this property to zero (0) disables this feature.
tokenTypeName) tokenLength) tokensPerList) hashFunctionPlugin) The hash function used to hash the generated tokens. It must be the same (or hash value compatible) as used when generating the token lists.
tokenListRenderer) languageAttributeName) If this property is not defined, the user's language is not taken into account when rendering token lists!
deleteOldTokenLists) If this property is set to TRUE, the plugin must have permission to delete files from the directory.
workingDirectory) If this property is defined, the token lists are not directly generated into the output directory (see other property) but they are generated into this working directory and are moved to the output directory once they are done.
This helps to solve problems with processes automatically reading the rendered token lists and reading partial token lists during the generation process. Make sure that the working directory and the output directory reside in the same file system (if not the moving of the generated file will not be atomic).
The directory is either absolute or relative to the JVMs current directory.
outputDirectory) This property is not required if the renderer plugin (see separate property) does not write on the outputstream (e.g. sends it somewhere else). It is required otherwise.
Note: If this property is not defined and the used renderer plugin writes on the output stream, then the result (e.g. a PDF file) is lost.
fileNamePrefix) Do not use the prefix "pwd-" if password- reports are stored in the same directory. This prefix is the default for password letters (and not configurable in older plugin versions).
This property is optional to be backwards compatible. It is strongly recommended to define a prefix.
fileNameSuffix) generationDateExportProperty) The generation date of the current token list is extracted from the token list data during the task and stored as date object (date and time) using the configured persister.
validityDateExportProperty) The validity date of the current token list is computed using the generation date and the configured validity of the token list and stored as date object (date and time) using the configured persister.
serialNumberExportProperty) The serial number of the current token list is extracted from the token list data during the task and stored as string using the configured persister.
remainingTokensExportProperty) The remaining number of tokens on the current token list is extracted from the token list data during the task and stored as integer number using the configured persister.
aggregateReport) maxNoOfCardsToPrintPerDay) Example: if the property is set to 500 but 1000 new cards are to be produced, the generation dates of the cards are set in a way, that the cards expire in blocks of 500 on 2 different days.
Please note:
- Setting this property doubles the runtime of the task. Consider to only set it before bulk generation of matrix cards.
- The actual amount of cards to be printed on a given day could exceed the value of this property due to: 'delivery security gap' configuration, explicitly (manually) ordered cards or used up cards.
- The mechanism does not work retroactive, i.e. the expiration or print date of existing cards will not be altered.
shiftDirection) Shifting into the past reduces the validity period, shifting into the future extends the validity period.
type: TanBatchTask
id: TanBatchTask-xxxxxx
displayName:
comment:
properties:
aggregateReport:
deleteOldTokenLists: false
deliverySecurityGap: 0
fileNamePrefix:
fileNameSuffix:
generationDateExportProperty:
hashFunctionPlugin:
languageAttributeName:
maxNoOfCardsToPrintPerDay:
maximumValidityDays: -1
outputDirectory:
remainingDaysThreshold:
remainingTokensExportProperty:
serialNumberExportProperty:
shiftDirection: PAST
tokenLength:
tokenListIterator:
tokenListPersister:
tokenListRenderer:
tokenTypeName:
tokensPerList:
validityDateExportProperty:
workingDirectory: