Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Nuwan Bandara
On Thu, Oct 10, 2013 at 11:50 AM, Asela Pathberiya wrote: > > On Tue, Sep 24, 2013 at 11:39 AM, Venura Kahawala wrote: > >> Hi, >> >> We are in the process of moving the below UI features out from the IS >> management console. >> >> 1. My Profiles >> 2. Account Recovery >> 3. My Authorized apps

[Architecture] [SS] Supporting permission schemes for different RDBMS types in Relation Storage Provisioning Manager

2013-10-09 Thread Prabath Abeysekera
Hi, *Requirement:* With the immediate upcoming release, Storage Server supports provisioning a good stack of RDBMS types such as SQLServer, Postgres, Oracle, etc in addition to MySQL. Each one of those above mentioned RDBMS types exposes its own permission models that usually consist of a few ove

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Dulanja Liyanage
Ah, but i guess the jaggery app and the Authentication Framework would be in the same machine, then this won't be a prob if we use LAN address for the POST On Thu, Oct 10, 2013 at 11:51 AM, Dulanja Liyanage wrote: > The problem of sending a POST outside of the internal network is anyone > can g

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Dulanja Liyanage
The problem of sending a POST outside of the internal network is anyone can grab the credentials during wire transfer (if not secured with HTTPS) or at transits (even if secured with HTTPS). Then we need to consider about encryption. On Wed, Oct 9, 2013 at 10:09 PM, Johann Nallathamby wrote: >

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Asela Pathberiya
On Tue, Sep 24, 2013 at 11:39 AM, Venura Kahawala wrote: > Hi, > > We are in the process of moving the below UI features out from the IS > management console. > > 1. My Profiles > 2. Account Recovery > 3. My Authorized apps > 4. OpenID > 5. My SCIM Providers > 6. Multifactor Authentication > 7. S

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Johann Nallathamby
Hi Chris, On Thu, Oct 10, 2013 at 6:17 AM, Chris Haddad wrote: > Johann, I think apim store/publishers are just examples. The goal is to > not reuse those specific components, but provide similar login auth/role > functionality to all app server apps. > > May be I was not clear. This is what e

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Nuwan Bandara
Hi Prabath, On Wed, Oct 9, 2013 at 10:18 PM, Prabath Siriwardena wrote: > How do we do this inAPI - Store / Publisher ? Can we host the API Store / > Publisher in a different Application Server and still points to the same > user base behind the API Manager..? > In the case of a different app s

Re: [Architecture] Issues with new solar base search introduce in registry 4.6.0 (to be released)

2013-10-09 Thread Ruchira Wageesha
> However, some of the search queries executed against the new Solr-based > search for RXT Assets introduced in G-Reg 4.6.0 does not return results due > to some limitations in Solr. > Senaka, regarding this it seems you are using Solr 1.4.1 which seems to be quite old compared to its current relea

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Chris Haddad
Johann, I think apim store/publishers are just examples. The goal is to not reuse those specific components, but provide similar login auth/role functionality to all app server apps. For example, I was writing a carbon-framework app to demo multitenancy, and would like to obtain a set of login

Re: [Architecture] Issues with new solar base search introduce in registry 4.6.0 (to be released)

2013-10-09 Thread Senaka Fernando
Hi Sumedha, You still can continue to use the older filter/search APIs of G-Reg and it does support some-level of pagination too, IINM. However, some of the search queries executed against the new Solr-based search for RXT Assets introduced in G-Reg 4.6.0 does not return results due to some limita

Re: [Architecture] [Cloud] Filtering applications based on subscription

2013-10-09 Thread Ashansa Perera
Hi Chris, please find my comments inline for your first reply. On Wed, Oct 9, 2013 at 8:49 PM, Chris Haddad wrote: > What is your definition of tenant, and the relationship to app owner? > Tenant is an organization in Cloud as same as SLive and App Factory creates a set of roles for a tenant at

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Johann Nallathamby
I still think it would be a valid requirement that needs to work out of the box. On Wed, Oct 9, 2013 at 10:37 PM, Johann Nallathamby wrote: > Hi Prabath, > > AFAIK there are a few concerns regarding this. For instance the publisher > and store authenticate users with the Key Manager using Web s

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Johann Nallathamby
Hi Prabath, AFAIK there are a few concerns regarding this. For instance the publisher and store authenticate users with the Key Manager using Web services and the web service URLs are configured in api-manager.xml. So we need to install some APIM components to get this done. Also since APIM uses

Re: [Architecture] Issues with new solar base search introduce in registry 4.6.0 (to be released)

2013-10-09 Thread Sumedha Rubasinghe
Senaka, Search options mentioned by Nuwan were supported in previous API Store & Publisher. We cannot be breaking this feature we used to support. Wasn't this captured @ product planning? On Wed, Oct 9, 2013 at 7:37 PM, Nuwan Bandara wrote: > Hi All, > > The problem at hand is that we cannot d

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Prabath Siriwardena
How do we do this inAPI - Store / Publisher ? Can we host the API Store / Publisher in a different Application Server and still points to the same user base behind the API Manager..? Thanks & regards, -Prabath On Wed, Oct 9, 2013 at 7:32 PM, Venura Kahawala wrote: > Hi, > > I'm now implementin

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Johann Nallathamby
Hi Venura, This should be done using the application authentication framework we have. As we will be migrating our carbon authenticators also to this it is best to use this framework. All you need to do is get the username and password of the user (if you are using Basic Authentication) and do a

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Chris Haddad
Yes, the my-identity app should run on app server, and basic features (password management, pwd recovery) should work without identity server. If identity server is present, then additional features (sso, scim) should be available, and the user store must be consistent between any available ma

Re: [Architecture] [Cloud] Filtering applications based on subscription

2013-10-09 Thread Chris Haddad
Amila, from a user experience perspective, I want to sign into wso2 cloud and view available platform services and capabilities. I hope you are not suggesting two distinct and separate user interfaces. Toggling between two cloud development portals will degrade the experience /Chris +1.678.43

Re: [Architecture] [Cloud] Filtering applications based on subscription

2013-10-09 Thread Chris Haddad
What is your definition of tenant, and the relationship to app owner? Where are you planning to show types that may become available with a subscription? What specific types are assigned to iPaas / apaas? And can a user 'hide types that may be not highly relevant (eg php for a java dev shop

Re: [Architecture] Issues with new solar base search introduce in registry 4.6.0 (to be released)

2013-10-09 Thread Nuwan Bandara
Well at the moment we don't have enough time to fix search / indexing issues, we have other store specific things to attend and was expecting the search to work OOTB :( Regards, /Nuwan On Wed, Oct 9, 2013 at 7:51 PM, Senaka Fernando wrote: > Hi Nuwan, > > If you extend the RXTIndexer with your

Re: [Architecture] Issues with new solar base search introduce in registry 4.6.0 (to be released)

2013-10-09 Thread Senaka Fernando
Hi Nuwan, If you extend the RXTIndexer with your own, you should be able to get solr to Index what you want using some asset specific fields. These fields can then be used when you pass the search criteria. This AFAIU should let you achieve case-insensitivity and also being able to search for "cra

[Architecture] Issues with new solar base search introduce in registry 4.6.0 (to be released)

2013-10-09 Thread Nuwan Bandara
Hi All, The problem at hand is that we cannot do proper searching with new solar based searching which comes with GReg. Imagine you have a API called "importantBusinessAPI", and if I search for "business" keyword this wont pop up in the search results. Also, If you have "This is a crappy API fo

Re: [Architecture] Separating 'My Identity' functionality from management console

2013-10-09 Thread Venura Kahawala
Hi, I'm now implementing the log in functionality for the My-Identity app. As per my understanding current user management functionality implemented within jaggery uses OSGI services. This is correct if the mentioned application is only deployed within the IS server and therefore my-identity app i

Re: [Architecture] [Cloud] Filtering applications based on subscription

2013-10-09 Thread Amila Maha Arachchi
Hi Ashansa, On Wed, Oct 9, 2013 at 5:09 PM, Ashansa Perera wrote: > Hi all, > > For cloud we have subscriptions for aPaaS and iPaaS and both would be > powered by AppFactory. > > So the user story for application creation would be > - If the tenant is subscribed only to aPaaS (or iPaaS), wh

[Architecture] [Cloud] Filtering applications based on subscription

2013-10-09 Thread Ashansa Perera
Hi all, For cloud we have subscriptions for aPaaS and iPaaS and both would be powered by AppFactory. So the user story for application creation would be - If the tenant is subscribed only to aPaaS (or iPaaS), when he logs in only the application types related to aPaaS ( iPaas) would be listed

Re: [Architecture] Payload Factory improvements for JSON transformations

2013-10-09 Thread Kasun Indrasiri
On Wed, Oct 9, 2013 at 12:00 PM, Ravi Undupitiya wrote: > We managed to get these scenarios working, the only limitations were the > ones due to the way Jettison handles anonymous classes. > > We're going to test generic json-path evaluator by giving the property > mediator ability to evaluate js

Re: [Architecture] Selling/re-selling access to Message Broker( and gadgets)

2013-10-09 Thread Srinath Perera
Idea is definitely possible. We chat about similar idea sometime back "Proposal: Support Event Stream Subscriptions from API Store", http://mail.wso2.org/mailarchive/architecture/2013-January/010440.html, but we have not implemented this yet. WSO2 UES/ Gadget Server has secure Gadegt that you can

Re: [Architecture] [C5] Adding deployers to deployment engine

2013-10-09 Thread Kishanthan Thangarajah
On Wed, Oct 9, 2013 at 12:04 PM, Afkham Azeez wrote: > No, this is violating whiteboard pattern. The way to do it is, each > deployer should implement an interface, and an implementation of that > interface should be registered as an OSGi service. You should not have a > CarbonDeploymentService