Re: [Architecture] [APIM][Intern Project]- Application Level Mutual TLS support for API Manager

2020-11-19 Thread Sanjeewa Malalgoda
ll take more >> consideration on those matters before proceeding further. >> >> Thank You, >> Dulangi >> >> >> On Thu, Nov 19, 2020 at 12:43 PM Sanjeewa Malalgoda >> wrote: >> >>> As I understand, mutual TLS has nothing to do with the place w

Re: [Architecture] [APIM] - Event Based API Deployment architecture.

2020-11-19 Thread Sanjeewa Malalgoda
t; WSO2 Inc.; http://wso2.com > lean.enterprise.middleware > > mobile: *+94779109091* > -- *Sanjeewa Malalgoda* Software Architect | Associate Director, Engineering - WSO2 Inc. (m) +94 712933253 | (e) sanje...@wso2.com | (b) Blogger <http://sanjeewamalalgoda.blogspot.com>, Medium <

Re: [Architecture] [APIM][Intern Project]- Application Level Mutual TLS support for API Manager

2020-11-18 Thread Sanjeewa Malalgoda
(m) +94766697385 | Email: dula...@wso2.com > <http://wso2.com/signature> > ___ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > -- *Sanjeewa Malalgoda* Software Architect | Associate

Re: [Architecture] [Dev] [Vote] Release of WSO2 API Manager 3.2.0 RC6

2020-08-24 Thread Sanjeewa Malalgoda
product and vote. > > [+] Stable - go ahead and release > [-] Broken - do not release (explain why) > > Thanks, > WSO2 API Manager Team > > -- > *Arshardh Ifthikar* > Senior Software Engineer | WSO2 Inc. > > Email: arsha...@wso2.com > Mobile: +94777218551 >

Re: [Architecture] [APIM] Admin REST API to check user role existence

2020-05-11 Thread Sanjeewa Malalgoda
>>>> [1] - [APIM-3.0] Publisher rest API to check a role name existence >>>> >>>> Thanks & Regards, >>>> *S.Meruja* |Software Engineer | WSO2 Inc. >>>> (m) +94779650506 | Email: mer...@wso2.com >>>> Linkedin: https://www.link

Re: [Architecture] [APIM] [APIM-Analytics] Removing APIM database(AM_DB) dependency for analytics

2020-04-24 Thread Sanjeewa Malalgoda
ptimization etc. And most importantly we can completely decouple. I feel its something to consider before make a decision on api. Thoughts? > > On Thu, Apr 23, 2020 at 12:52 PM Sanjeewa Malalgoda > wrote: > >> When I looked at some other solutions I found we can do the

Re: [Architecture] [APIM] [APIM-Analytics] Removing APIM database(AM_DB) dependency for analytics

2020-04-23 Thread Sanjeewa Malalgoda
ew REST > API to the analytics webapp to get the required information. > > Appreciate your thoughts on the above. > > Regards, > Ruwini > -- > Ruwini Wijesiri > Senior Software Engineer, > WSO2 Inc. > > Mobile : +94716133480 > > <ht

Re: [Architecture] [APIM] Tryout console for the API Publisher

2020-04-21 Thread Sanjeewa Malalgoda
; consider how to migrate APIs from previous versions. >> > We have a way to update the RXT field at runtime. For example [1]. We > did this for all newly added RXT fields. > > [1] https://github.com/wso2/product-apim/issues/3525 > >> >> @Sanjeewa Malalgoda , @

Re: [Architecture] [APIM] Support for API Products from API Controller

2020-04-17 Thread Sanjeewa Malalgoda
>> Comparison of “Using existing commands” and “Using a new set of >>> commands” >>> >>> Using existing commands >>> >>> Using a new set of commands >>> >>>- >>> >>>Advantage >>> >>> C

Re: [Architecture] [APIM] Multiple Key Manager support

2020-04-16 Thread Sanjeewa Malalgoda
oken. >>>> >>>>- Generated Token from Oauth Providers contains a specific change >>>>related to the Token. >>>> >>>> So two OAuth providers can co-exist (within a single tenant space) if >>> their issued tokens can be separate

Re: [Architecture] [APIM] Multiple Key Manager support

2020-04-15 Thread Sanjeewa Malalgoda
plication >> >>- Oauth Application will remove from Respective Oauth Provider >>assigned. >> >> >> I appreciate any thoughts and feedback on this. >> > > Are we only supporting this for subscriptions within the same tenant? > >> >> >>

Re: [Architecture] [Dev] [Vote] Release of WSO2 API Manager 3.1.0 RC3

2020-03-23 Thread Sanjeewa Malalgoda
;>>>>> >>>>>>>>>>>>>>> Hi all, >>>>>>>>>>>>>>> >>>>>>>>>>>>>>> We are pleased to announce the third release candidate of >>>>>>>

Re: [Architecture] [APIM] Service discovery with Kubernetes

2020-02-14 Thread Sanjeewa Malalgoda
isn't a >> need of saving the other service endpoints. >> >>> >>> Please go through the description and I highly appreciate your thoughts >>> on this $subject. >>> >>> Thanks!. >>> >>> >>> >>> -- >>> Methusha Thu

Re: [Architecture] Private Jet Mode for WSO2 API Manager with Kubernetes

2020-02-14 Thread Sanjeewa Malalgoda
74078049 | (w) +94112145345 | (e) pubu...@wso2.com >>> <http://wso2.com/signature> >>> >>> >> >> -- >> *Manjula Rathnayaka* | Senior Technical Lead | WSO2 Inc. >> (m) +94 77 743 1987 | (w) +94 11 214 5345 | (e) manju...@wso2.com >> G

Re: [Architecture] [APIM] Support Global OAuth2 Scopes and Attaching Multiple Scopes per API Resource

2020-01-20 Thread Sanjeewa Malalgoda
n. > > It would be best to release global scope feature along with the current > scope behavior and depend on the usage we can decide whether we > discontinue the local scope feature. > I think current local scope feature will be there anyway. This will come on top of that. Thanks

Re: [Architecture] [APIM] Support Global OAuth2 Scopes and Attaching Multiple Scopes per API Resource

2020-01-19 Thread Sanjeewa Malalgoda
schema: >>>> $ref: '#/definitions/Error' >>>> >>>> >>>> #- >>>> >>>> # Update a global scope >>>> >>>> #--

Re: [Architecture] [APIM] [3.x] Global View for Scopes

2020-01-02 Thread Sanjeewa Malalgoda
type: string >>>> version: >>>> type: string >>>> >>>> provider: >>>> type: string >>>> >>>> resources: >>>> type: array >>>> >

Re: [Architecture] Fine Grained Access Control for GraphQL APIs - Role Specific Depth Allocation

2019-11-22 Thread Sanjeewa Malalgoda
t; > Here we would maintain these depth-related and complexity-related values > per API. These policy related details will be appended to the existing > local entry which is maintained per API after encoding with base64. Then at > the gateway level, we can read these API level policies

Re: [Architecture] Creating a Policy Hub for the Microgateway

2019-10-28 Thread Sanjeewa Malalgoda
ities available in the > Ballerina Central. Regarding the user groups, when the support is provided > through the ballerina central in the future we will be able to inherit it > as well. > > Thanks. > > On Wed, Oct 23, 2019 at 3:29 PM Sanjeewa Malalgoda > wrote: > >> Hi All,

Re: [Architecture] Creating a Policy Hub for the Microgateway

2019-10-23 Thread Sanjeewa Malalgoda
_ >>>>>> Architecture mailing list >>>>>> Architecture@wso2.org >>>>>> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >>>>>> >>>>> >>>>> >>>&

Re: [Architecture] [APIM-3.0] Publisher rest API to check a role name existence

2019-08-12 Thread Sanjeewa Malalgoda
>>>>>>>>>> It is a HEAD method (*/roles/{roleName}*) which will return a >>>>>>>>>>>> 200 status code if the given role name exists and a 404 status >>>>>>>>>>>> code if the >>>>>>>>>>>&g

Re: [Architecture] OAS 3 as default API definition

2019-08-12 Thread Sanjeewa Malalgoda
h v3 as we are releasing a major version for APIM. >> >>> >> Thank you! >> -- >> *Pubudu Gunatilaka* | Associate Technical Lead | WSO2 Inc. >> (m) +94774078049 | (w) +94112145345 | (e) pubu...@wso2.com >> <http://wso2.com/signature> >> >> >

Re: [Architecture] HoneyPot APIs for API Manager - New Feature of APIM product

2019-05-09 Thread Sanjeewa Malalgoda
g] > > [1]. https://blog.rapid7.com/2016/12/06/introduction-to-honeypots/ > > Thank you and regards, > *Nadee Poornima* > Software Engineer - Support Team | WSO2 > > Email : nad...@wso2.com > Mobile : +94713441341 > MyBlog: https://medium.com/nadees-tech-stories > > &l

Re: [Architecture] [Microgateway] API Manager JWT Token Revocation Feature

2019-02-28 Thread Sanjeewa Malalgoda
; grant type that allows you to exchange an OAuth token for a self contained >> (JWT) token? >> >>> >>> Will it be under consideration in this implementation? >>> >>> On Wed, Feb 13, 2019 at 12:52 AM Nuwan Dias wrote: >>> >>>&g

Re: [Architecture] [Microgateway] API Manager JWT Token Revocation Feature

2019-02-28 Thread Sanjeewa Malalgoda
r we support a scenario like that today. What is the > grant type that allows you to exchange an OAuth token for a self contained > (JWT) token? > >> >> Will it be under consideration in this implementation? >> >> On Wed, Feb 13, 2019 at 12:52 AM Nuwan Dias wrote:

Re: [Architecture] [Microgateway] API Manager JWT Token Revocation Feature

2019-02-12 Thread Sanjeewa Malalgoda
o feel that we need to introduce a config to switch on >> enabling/disabling this feature so that we can also use the microgateways >> in the current mode. >> >> On Thu, Feb 7, 2019 at 3:58 PM Sanjeewa Malalgoda >> wrote: >> >>> Hi All, >>> I'm ini

[Architecture] [Microgateway] API Manager JWT Token Revocation Feature

2019-02-07 Thread Sanjeewa Malalgoda
deployed micro services and send revoked JWT list. Each of these methods will have their own advantages and disadvantages. Lets use this mail to discuss those in detail and come to conclusion. Thanks, sanjeewa. -- *Sanjeewa Malalgoda* Software Architect | Associate Director, Engineering - WSO2 Inc. (m

[Architecture] [Microgateway] Communicate with external system during microgateway startup and while running

2019-02-07 Thread Sanjeewa Malalgoda
. This capability will help us to do some additional stuff when we implement solutions. As example we can think of generating UUID during server startup and send it to some external system for tracking purpose. Thanks, sanjeewa. -- *Sanjeewa Malalgoda* Software Architect | Associate Director

Re: [Architecture] API Manager integration with Istio

2019-01-17 Thread Sanjeewa Malalgoda
rg > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > -- *Sanjeewa Malalgoda* Software Architect | Associate Director, Engineering - WSO2 Inc. (m) +94 712933253 | (e) sanje...@wso2.com | (b) Blogger <http://sanjeewamalalgoda.blogspot.com>, Medium <https://medium.co

[Architecture] API Manager integration with Istio

2019-01-15 Thread Sanjeewa Malalgoda
in phased approach. First we will do introspection call which validates access token. Then we can think of throttling, usage data monitoring etc. We will create repo named istio-apim and start our work there. If you have any suggestions to above proposal please let us know. Thanks, sanjeewa. -- *Sanjeewa

Re: [Architecture] Solution Design : Support for HTTP2 on the Microgateway

2018-12-20 Thread Sanjeewa Malalgoda
using the server push feature in the microgateway > since there's no much use cases of it with the microgateway. > > Thank you > Best Regards, > > *Varuni Punchihewa* > Intern - Software Engineering | *WSO2* > *Tel:* +94 71 699 5861 > <http://wso2.com/signature> >

Re: [Architecture] Fwd: Developer-First Microgateway Creation

2018-10-29 Thread Sanjeewa Malalgoda
setup command is executed. If a user needs to add a custom policy, the user >>>> can add it to the policy directory in the Microgateway. >>>> >>>> Your comments and suggestions on this feature will be highly >>>> appreciated. >>>> >

Re: [Architecture] Fwd: Developer-First Microgateway Creation

2018-10-29 Thread Sanjeewa Malalgoda
/signature> >> ___ >> Architecture mailing list >> Architecture@wso2.org >> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >> > > > -- > Malintha Amarasinghe > *WSO2, Inc. - lean | enterprise | midd

Re: [Architecture] Solution Design : Support for HTTP2 on the Microgateway

2018-10-26 Thread Sanjeewa Malalgoda
___ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > -- *Sanjeewa Malalgoda* Software Architect | Associate Director, Engineering - WSO2 Inc. (m) +94 712933253 | (e) sanje...@wso2.c

Re: [Architecture] why wso2 token call return oauth token whereas I configured wso2 to return jwt token

2018-10-26 Thread Sanjeewa Malalgoda
gt;> >>> >>> >>> >>> >>> >>> >>> >>> >>> best regards, >>> >>> >>> Nicolas Maujean >>> >>> ___ &

Re: [Architecture] Project 194: Distributed Throttling for Micro-gateway

2018-10-25 Thread Sanjeewa Malalgoda
gt; >>> >>> >>> >>> >>> >>> >>> -- >>> >>> *Jayanie Bogahawatte* >>> *Software Engineering Intern* >>> WSO2 (University of Moratuwa) >>> *mobile *: *+94 777563324* | *email *: jaya...@w

Re: [Architecture] API schema based request/response validator for Microgateway.

2018-10-23 Thread Sanjeewa Malalgoda
gt;> For that swagger-model-validator for Node.js can be convert in to >>>>> Ballerina. >>>>> >>>>> >>>>> >>>>> Fig 1: Validating a request >>>>> >>>>>

Re: [Architecture] API schema based request/response validator for Microgateway.

2018-09-15 Thread Sanjeewa Malalgoda
Fig 2: Validating >>>> a response >>>> >>>> >>>> Thank you! >>>> >>>> -- >>>> >>>> *Shalki Wenushika* >>>> *Software engineering Intern* >>>> WSO2 (University of Morat

Re: [Architecture] [Dev] Dev][VOTE] Release of WSO2 API Manager 2.6.0 RC3

2018-09-15 Thread Sanjeewa Malalgoda
gt; Chamila Adhikarinayake >>> Associate Technical Lead >>> WSO2, Inc. >>> Mobile - +94712346437 >>> Email - chami...@wso2.com >>> Blog - http://helpfromadhi.blogspot.com/ >>> >> >> >> >> -- >> Regards, >> Chamil

Re: [Architecture] Project 240: Communication channel between API Providers and API Consumers

2018-09-05 Thread Sanjeewa Malalgoda
On Wed, Sep 5, 2018 at 3:16 PM Bhathiya Jayasekara wrote: > Hi Sanjeewa, > > On Wed, Sep 5, 2018 at 1:11 PM Sanjeewa Malalgoda > wrote: > >> >> >> On Wed, Sep 5, 2018 at 12:58 PM Wasura Wattearachchi >> wrote: >> >>> Hi All, >>> &g

Re: [Architecture] Project 240: Communication channel between API Providers and API Consumers

2018-09-05 Thread Sanjeewa Malalgoda
cations, you can go through the document which I have > attached below. It will be hugely appreciated if you can provide your > feedback. > > > Until then I will analyze API Manager 3.0 more and will start writing User > Stories. > > > Thank you! > -- >

Re: [Architecture] Updating 5 star rating to 10 star rating

2018-09-04 Thread Sanjeewa Malalgoda
it should return same response as get do. Thanks, sanjeewa > >> thanks, >> Chanaka >> -- >> Chanaka Jayasena >> Associate Tech Lead, >> email: chan...@wso2.com; cell: +94 77 4464006 >> blog: http://chanaka3d.blogspot.com >> >

Re: [Architecture] API Manager - Store - UX plan for 3.0

2018-09-04 Thread Sanjeewa Malalgoda
>14. Expand each section of Production keys. >15. Expand "subscribe to available application" >16. Expand the "subscribe to a new application" >17. Go through the express mode >18. Go to application page. >19. View applicatio

Re: [Architecture] [APIM][300][Store] Feature to change password of an user

2018-08-20 Thread Sanjeewa Malalgoda
O2, Inc. http://wso2.com >> email : nuw...@wso2.com >> Phone : +94 777 775 729 >> ___ >> Architecture mailing list >> Architecture@wso2.org >> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >> > > > -- > Mush

Re: [Architecture] [APIM] REST API Support for Dynamic SSL Certificate Installation Feature.

2018-07-10 Thread Sanjeewa Malalgoda
>>> >>> *Menaka Jayawardena* >>> Senior Software Engineer >>> WSO2 Inc. >>> >>> Phone: +94 71 350 5470 >>> LinkedIn : https://lk.linkedin.com/in/menakajayawardena >>> Blog : https://menakamadushanka.wordpress.com/

Re: [Architecture] [APIM Store REST API] [3.0] Add Application Info in SubscriptionDTO

2018-07-04 Thread Sanjeewa Malalgoda
; Would appreciate your comments and thoughts on this. > > > [1] > https://github.com/wso2/carbon-apimgt/blob/master/components/apimgt/org.wso2.carbon.apimgt.rest.api.store/src/main/resources/store-api.yaml#L3668 > [2] [Dev] [APIM_REST_API] What are the properties to

Re: [Architecture] APIM Micro Gateway Cli Functionality and Structure

2018-05-28 Thread Sanjeewa Malalgoda
e. > Yes, lets keep this simple for this release and improve it in future. > > >> On Mon, May 28, 2018 at 5:30 PM Isuru Haththotuwa <isu...@wso2.com> >> wrote: >> >>> >>> >>> On Mon, May 28, 2018 at 5:03 PM, Sanjeewa Malalgoda <sa

Re: [Architecture] APIM Micro Gateway Cli Functionality and Structure

2018-05-28 Thread Sanjeewa Malalgoda
e generated. This archive will embeds bre, generated balx which > someone can take and run without configuring anything. > - This command also outputs APIs which have updated and commands > which are available to run in target folder >- *micro-gw run (wit

Re: [Architecture] [APIM][API-Manager gateway] Attaching Labels for APIs

2018-05-06 Thread Sanjeewa Malalgoda
gt; -- >>>>> Chamin Dias >>>>> Mobile : 0716097455 >>>>> Email : cham...@wso2.com >>>>> LinkedIn : https://www.linkedin.com/in/chamindias >>>>> >>>>> ___ >>>>> Architecture m

Re: [Architecture] Remove Application and user access token concept from API Manager

2018-03-29 Thread Sanjeewa Malalgoda
nager 3.0 we did not introduce such a concept anyway. Are you > suggesting we remove this from 2.x as well? > > On Thu, 29 Mar 2018 at 1:17 pm, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> Hi All, >> In API Manager we have application access token and user a

[Architecture] Remove Application and user access token concept from API Manager

2018-03-29 Thread Sanjeewa Malalgoda
token with write(access add photo) scope. In oauth spec also we cannot see this type of differentiation. So considering all these shall we remove application access token concept from API Manager? Any limitations with this? Thanks, sanjeewa. -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779

Re: [Architecture] [APIM v3] Base path for /userinfo endpoint

2018-03-29 Thread Sanjeewa Malalgoda
+WSO2+Identity+Server >>> >>> Thank you! >>> -- >>> *Pubudu Gunatilaka* >>> Committer and PMC Member - Apache Stratos >>> Senior Software Engineer >>> WSO2, Inc.: http://wso2.com >>> mobile : +94774078049 <%2B94772207163&g

[Architecture] [Announce] WSO2 API Manager 3.0.0-M22 Released!

2018-03-15 Thread Sanjeewa Malalgoda
<https://stackoverflow.com/questions/tagged/wso2-am> Reporting Issues We encourage you to report issues, improvements and feature requests regarding WSO2 API Manager through WSO2 API Manager GIT Issues <https://github.com/wso2/product-apim/issues>. ~ WSO2 API Manager Team ~ -- *San

Re: [Architecture] [APIM] Json Schema Validation

2018-03-15 Thread Sanjeewa Malalgoda
enabled, at the point of generating API synapse >configuration, we can add the schema to a local entry which the name of the >local entry will be UUID + api+ resource version. >- We can add a property to hold the local entry name related with UUID > and add a class mediator

Re: [Architecture] Improving audit logs related with user management tasks

2018-03-13 Thread Sanjeewa Malalgoda
t >>> [3] https://docs.google.com/document/d/1Ls0VuLsJaQtQAPgR3Nkw >>> trcbFUvVZuPW_gXA7bV5mmo/edit?usp=sharing >>> >>> Thanks. >>> >>> Regards, >>> Megala >>> -- >>> Megala Uthayakumar >>> >>> Seni

Re: [Architecture] [MB4] Restful Admin API's for Message Broker

2018-03-07 Thread Sanjeewa Malalgoda
ed. Therefore > we are planning to use following response format. > > HTTP/1.1 200 OK > { > "numberOfMessagesDeleted": 0 > } > > > On Thu, Mar 8, 2018 at 10:41 AM, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> If purging is handle by

Re: [Architecture] [MB4] Restful Admin API's for Message Broker

2018-03-07 Thread Sanjeewa Malalgoda
;>>> Hi Eranda, >>>>>>> >>>>>>> >>>>>>> On Wed, Jan 10, 2018 at 6:47 PM, Eranda Rajapakshe <eran...@wso2.com >>>>>>> > wrote: >>>>>>> >>>>&

Re: [Architecture] [BMB] Full In-memory operating mode for message broker

2018-02-26 Thread Sanjeewa Malalgoda
lt;https://wso2.com/signature> >>> >> >> >> >> -- >> *Pamod Sylvester * >> >> *WSO2 Inc.; http://wso2.com <http://wso2.com>* >> cell: +94 77 7779495 <077%20777%209495> >> > > > > -- >

Re: [Architecture] [IS] REST endpoint for Claim Management in IS

2018-02-12 Thread Sanjeewa Malalgoda
; RESTful design guidelines and usability in mind. >> Thanks >> >> On Tue, Feb 13, 2018 at 11:28 AM, Sanjeewa Malalgoda <sanje...@wso2.com> >> wrote: >> >>> It looks like claims are attributes of dialect. In that case when user >>> create/update

Re: [Architecture] [IS] REST endpoint for Claim Management in IS

2018-02-12 Thread Sanjeewa Malalgoda
2018 at 10:37 AM, Chiran Wijesekara <chir...@wso2.com> >>>>>> wrote: >>>>>> >>>>>>> Hi all, >>>>>>> >>>>>>> we have decided to create a REST endpoint for the purpose of claim >>>>&

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-08 Thread Sanjeewa Malalgoda
- page 10 - https://go.forrester.com/wp-content/uploads/Forrester- > 2018-Predictions.pdf > > > Regards, > Chamila de Alwis > Committer and PMC Member - Apache Stratos > Associate Technical Lead | WSO2 > +94 77 220 7163 <077%20220%207163> > Blog: https://medium.com/@ch

Re: [Architecture] Clearly defining what operations users can perform on a shared application in APIM

2018-02-08 Thread Sanjeewa Malalgoda
Has ability to delete/update Apps shared with >>> them. The reason for this is to address practical issues that take place >>> when the App owner leaves an organization and there needs to be some way to >>> delete/update such an Application. >>> >> >> +

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-08 Thread Sanjeewa Malalgoda
Sanjeewa, > > On Tue, Feb 6, 2018 at 12:33 PM, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> >> >> On Mon, Feb 5, 2018 at 11:29 PM, Ishara Karunarathna <isha...@wso2.com> >> wrote: >> >>> HI Sanjeewa, >>> >>> Pseu

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-05 Thread Sanjeewa Malalgoda
ide other organizational rules. So if a particular organization has >> a policy to retain user data for 6 months and the user has consented to >> that, the user only has the "right to be forgotten" after the 6 months has >> passed. Until then the organization has the

Re: [Architecture] Can we ship Identity Management / Identity Governance features with APIM by default.

2018-02-04 Thread Sanjeewa Malalgoda
IAM feature list of APIM. >> >> WDYT ? >> >> Thanks, >> Asela. >> >> -- >> Thanks & Regards, >> Asela >> >> ATL >> Mobile : +94 777 625 933 <+94%2077%20762%205933> >> +358 449 228 979 >>

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-02 Thread Sanjeewa Malalgoda
of flexibility not needed at all? > > > > On Fri, Feb 2, 2018 at 11:11 AM, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> Nuwan, All, >> When we are calling with external systems such as scim we will use user >> ID. But internal flow manly goe

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-01 Thread Sanjeewa Malalgoda
anks and Regards > > On Thu, Feb 1, 2018 at 6:05 PM, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> Hi All, >> Recently we evaluated GDPR requirement(right to be forgotten) for API >> Manager 3.0.0 development. Our primary focus was to find a way to implemen

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-01 Thread Sanjeewa Malalgoda
gt; such as inability to change a username, problems with the same user in >> different cases, etc. Meaning that APIM v3 was already GDPR compliant in >> that sense. It we now have to build an addition layer to make the code GDPR >> compliant, we've basically lost our design obj

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-01 Thread Sanjeewa Malalgoda
ge a username, problems with the same user in >> different cases, etc. Meaning that APIM v3 was already GDPR compliant in >> that sense. It we now have to build an addition layer to make the code GDPR >> compliant, we've basically lost our design objective of using user ids >> inste

[Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-01 Thread Sanjeewa Malalgoda
to do same for light weight auth framework as well. ​​ I would like to know others opinion on this before move forward. Thanks, sanjeewa. -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779 <http://sanjeewamalalgoda.blogspot.com/>blog :http://sanjeewamalalgoda.blo

Re: [Architecture] OpenAPI 3.0 support for API Manager 2.2.0

2018-01-25 Thread Sanjeewa Malalgoda
ile >>>>>>>>>> updating API >>>>>>>>>>source via Swagger Editor in API Publisher. >>>>>>>>>>5. Swagger UI in APIM 2.2.0 has been upgraded to 3.x version >>>>>>>>>>so that

Re: [Architecture] [APIM] CLI support for Importing and Exporting Applications

2018-01-25 Thread Sanjeewa Malalgoda
p -f qa/sampleApp.zip --preserveOwner >>>>>> --addSubscriptions -e prod >>>>>> >>>>>> >>>>>> >>>>>> <https://github.com/randilu/WatchOver/new/master?

Re: [Architecture] [APIM][C5] Multi-Environment API Overview Feature

2018-01-24 Thread Sanjeewa Malalgoda
le : +94 76 667 8752 <+94%2076%20667%208752> >> Web : http://wso2.com >> <http://wso2.com/signature> >> > > > > -- > *Renuka Fernando* > Software Engineering Intern | WSO2 Inc > > Email : r

Re: [Architecture] [RRT] Improving caching based on cache-control and ETag headers

2018-01-11 Thread Sanjeewa Malalgoda
n the timeout >>>> configuration. >>>> >>>> 4. *Include an ‘Age’ header with the response* >>>> Cache mediator should return the true TTL value of a response without >>>> altering the value of the cache-control ma

Re: [Architecture] [MB4] Restful Admin API's for Message Broker

2018-01-10 Thread Sanjeewa Malalgoda
ts define proper response codes as well(201 to created, 202 accepted etc). What is the plan to expose this API to outside? Is it MSF4J? If that is the case you can start with swagger definition and move forward. Thanks, sanjeewa. >> Regards, >> Asitha >> >> -- >> *Asith

Re: [Architecture] Scope Registration API for carbon-auth

2018-01-09 Thread Sanjeewa Malalgoda
carbon-auth >>> APIs and intercepts requests and applies permission checks. >>>- Keeping the security interceptor at the product level so each >>>product can implement their own security interceptor. >>> >>> Thanks! >>> >>> >&

[Architecture] Scope Registration API for carbon-auth

2018-01-08 Thread Sanjeewa Malalgoda
identity server team had experiences with this API they can provide suggestions for API and implementation. We will expose this as MSF4J based API from carbon auth run time. Lets use this thread to discuss all aspects of scope registration and finalize implementation. Thanks, sanjeewa. -- *Sanjeewa

Re: [Architecture] Gateway cache in APIM all in one active/active deployment without clustering

2017-12-15 Thread Sanjeewa Malalgoda
budu Gunatilaka* >> Committer and PMC Member - Apache Stratos >> Senior Software Engineer >> WSO2, Inc.: http://wso2.com >> mobile : +94774078049 <%2B94772207163> >> >> > > > -- > Susankha Nirmala > Senior Software Engineer > WSO2, Inc.: http://wso2.com &

Re: [Architecture] Concurrency controlling for API Manager

2017-12-05 Thread Sanjeewa Malalgoda
unning requests etc (and there are more >>>>> techniques). Thus, caching, concurrency control etc is an aspect of Level >>>>> 2. And we strive towards Level 2 support. >>>>> >>>>> But this does not imply that each of our products are

Re: [Architecture] [APIM][C5] Multi Environment support with API difference for API Manager

2017-11-06 Thread Sanjeewa Malalgoda
t;>>>> >>>>> [1] https://github.com/wso2/carbon-apimgt/issues/4690 >>>>> [2] https://github.com/wso2/carbon-apimgt/pull/4679 >>>>> >>>>> >>>>> Appreciate any suggestions. >>>>> Than

Re: [Architecture] [C5][APIM] Context Loading in API Gateway

2017-10-30 Thread Sanjeewa Malalgoda
512> >>> WSO2, Inc. | http://wso2.com/ >>> Lean . Enterprise . Middleware >>> >>> ___ >>> Architecture mailing list >>> Architecture@wso2.org >>> https://mail.wso2.org/cgi-bin/mailman/lis

Re: [Architecture] [APIM] Extensibility of API Security Handler

2017-10-30 Thread Sanjeewa Malalgoda
? > If we have federated users then anyway we might need to use extension for do certain things. Yes in APIM 3Xx we will not remove any of the existing capabilities. And we will specifically check federated user scenario. Thanks, sanjeewa. > > Regards, > Johann. > > On Mon, O

Re: [Architecture] Securing Product Apis and Product artifacts in Stream Processor

2017-10-25 Thread Sanjeewa Malalgoda
ny authentication mechanism. Thanks, sanjeewa. > > > > > More information on the solution can be found at [1] > > > [1] https://docs.google.com/a/wso2.com/document/d/1vFP_GZcuLzJrk > RDV3mCfuSDkwC8eKClmp4zt-lUs1Ro/edit?usp=sharing > > -- > Best Regards, > *Nivea

Re: [Architecture] [APIM] Extensibility of API Security Handler

2017-10-16 Thread Sanjeewa Malalgoda
user present in user store connected. So if its federated user then populate standard claims will be failed and we need to handle it. Thanks, sanjeewa. > > Thanks & Regards, > Johann. > > -- > > *Johann Dilantha Nallathamby* > Senior Lead Solutions Engineer > WSO2, Inc. &

Re: [Architecture] [APIM][C5] Shall we add gateway health check capability

2017-10-10 Thread Sanjeewa Malalgoda
;>>> >>>>>> ___ >>>>>> Architecture mailing list >>>>>> Architecture@wso2.org >>>>>> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >>>&

Re: [Architecture] Using Java Agent API for Latency and other Measurements

2017-10-06 Thread Sanjeewa Malalgoda
PereraWSO2 <https://www.google.com/+IsuruPereraWSO2/about> > > ___ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >

Re: [Architecture] [IAM] Adding/Reloading X509 Certificates at Runtime without Restart

2017-10-06 Thread Sanjeewa Malalgoda
s this something we see valuable that can be added to IS 5.4.0 or 5.5.0? > > [1] https://wso2.org/jira/browse/IDENTITY-1131 > [2] https://github.com/wso2/carbon-identity/pull/1511 > > Thanks & Regards, > Johann. > > -- > > *Johann Dilantha Nallathamby* > Senio

Re: [Architecture] [APIM] Supporting Thrift protocol for GW-KM communication with Load Balancing

2017-09-03 Thread Sanjeewa Malalgoda
a > > ATL > Mobile : +94 777 625 933 <077%20762%205933> > +358 449 228 979 > > http://soasecurity.org/ > http://xacmlinfo.org/ > -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779 <http://sanjeewamalalgoda.blogspot.com/>blog :htt

Re: [Architecture] [APIM] Threat Protection for API Manager

2017-08-22 Thread Sanjeewa Malalgoda
g All User Supplied Input >> >> >> >> Design Details >> >> Number of User Interfaces is going to be added to the API Manager as >> admin users should have a way to enable/disable/create threat protection >> policies. >> >> Threat prot

Re: [Architecture] [C5][APIM] Offline micro Gateway with API Key

2017-07-31 Thread Sanjeewa Malalgoda
On Tue, Aug 1, 2017 at 6:12 AM, Isuru Haththotuwa <isu...@wso2.com> wrote: > On Mon, Jul 31, 2017 at 2:51 PM, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> >> >> On Fri, Jul 28, 2017 at 1:12 PM, Sabeena Kumrawadu <sabe...@wso2.com> >> w

Re: [Architecture] [C5][APIM] Offline micro Gateway with API Key

2017-07-31 Thread Sanjeewa Malalgoda
nt for the design is much appreciated. > > Thank you, > Best Regards. > > -- > *Sabeena Kumarawadu* | Software Engineering Intern > WSO2 Lanka (Pvt) Ltd. > #20, Palm Grove, Colombo 03, Sri Lanka > Mobile: +94 71 0372856 <071%20037%202856> &g

Re: [Architecture] [DEV] Can we bind custom interceptors in msf4j2.3.0-m2

2017-06-08 Thread Sanjeewa Malalgoda
sses that extends >>>>>> ABCRequestInterceptor >>>>>> >>>>>> But , we bind the interceptor as >>>>>> >>>>>> @RequestInterceptor(ABCRequestInterceptor.class) >>>>>> >>>>>

Re: [Architecture] [APIM][C5] SSO Feature for Publisher/Store Login

2017-05-23 Thread Sanjeewa Malalgoda
;> send necessary scopes in the beginning. >> >> And I have following questions regarding this. >> >> 1. How do you configure this IDPs other than WSO2 identity server >> 2. How do you handle logout ? >> > I think we can revoke token when user logout happens. Thank

Re: [Architecture] [APIM][C5] SSO Feature for Publisher/Store Login

2017-05-21 Thread Sanjeewa Malalgoda
..@wso2.com > Mobile: 0719143658 <071%20914%203658> > [image: http://wso2.com/signature] <http://wso2.com/signature> > -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779 <http://sanjeewamalalgoda.blogspot.com/>blog :http://sanjeewamalalgoda.blogspot.com/ <ht

Re: [Architecture] [APIM][C5] Removing "Blocked" state from API lifecycle

2017-05-21 Thread Sanjeewa Malalgoda
> > On Fri, May 19, 2017 at 6:37 PM, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> One other issue i see with ballerina editing or setting throttling tiers >> is, business API owners need to handle that complexity. >> Usually developers will deve

Re: [Architecture] [APIM][C5] Removing "Blocked" state from API lifecycle

2017-05-19 Thread Sanjeewa Malalgoda
tensible API lifecycle states in c5 implementation? >>>>> If we have any user who doesn't want this blocked state can remove from >>>>> state configuration and who wants this blocked state can keep this state >>>>> in >>>>> configuration. >>>

Re: [Architecture] [APIM][C5] Subesource access permissions in store

2017-05-19 Thread Sanjeewa Malalgoda
e comment > permission to a moderator role(api owner or a configurable moderator role)? > > On Fri, May 19, 2017 at 11:22 AM, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> Can anyone point me any site/forum which allow you to edit others >> comment(not appro

Re: [Architecture] [APIM][C5] Subesource access permissions in store

2017-05-18 Thread Sanjeewa Malalgoda
t;state" to the comment, need to implement a > workflow, a callback mechanism, a workflow cleanup, etc. But if we just > write a piece of code which allows a pre-configured role to remove, edit > comments, I think the implementation is much simpler. > > On Fri, May 19, 2017 at 10:52 A

Re: [Architecture] [APIM][C5] Subesource access permissions in store

2017-05-18 Thread Sanjeewa Malalgoda
On Fri, May 19, 2017 at 10:43 AM, Bhathiya Jayasekara <bhath...@wso2.com> wrote: > Hi Sanjeewa, > > On Thu, May 18, 2017 at 5:09 PM, Sanjeewa Malalgoda <sanje...@wso2.com> > wrote: > >> I don't think its worth to get complete permission model for comments as >

Re: [Architecture] [APIM][C5] Subesource access permissions in store

2017-05-18 Thread Sanjeewa Malalgoda
gt;>>>>>>>> >>>>>>>>>>> Or should we be doing an explicit permission validation? Do we >>>>>>>>>>> have any drawbacks in doing this check? >>>>>>>>>>> >>>>>>>>>>>

  1   2   3   >