Re: [Architecture] [Iam-dev] Admin portal for Identity Server

2020-06-06 Thread gayan gunawardana
/forced-password-reset/ Thanks, Gayan On Mon, May 18, 2020 at 1:15 PM gayan gunawardana wrote: > Thanks Maduranga! I will try latest. > > On Mon, May 18, 2020 at 11:40 AM Maduranga Siriwardena > wrote: > >> Hi Gayan, >> >> M19 milestone of the Identity Serv

Re: [Architecture] [Iam-dev] Admin portal for Identity Server

2020-05-18 Thread gayan gunawardana
Thanks Maduranga! I will try latest. On Mon, May 18, 2020 at 11:40 AM Maduranga Siriwardena wrote: > Hi Gayan, > > M19 milestone of the Identity Server 5.11.0 is also released couple > of days ago. > > Regards, > Maduranga > > On Fri, May 15, 2020, 7:04 PM gayan gu

Re: [Architecture] [Iam-dev] Admin portal for Identity Server

2020-05-15 Thread gayan gunawardana
feedback on 5.11.0-m18 at [2] > > [1] https://wso2.com/identity-and-access-management/product-roadmap/ > [2] https://github.com/wso2/product-is/releases > > Cheers, > Ruwan A > > On Fri, May 15, 2020 at 5:54 PM gayan gunawardana > wrote: > >> Hi IAM Team, &g

[Architecture] Admin portal for Identity Server

2020-05-15 Thread gayan gunawardana
Hi IAM Team, React based new User-portal released with IS 5.10.0 is really great. Similar way is there a plan in road map to release Admin-portal where admin users can manage identities of other users ? -- Gayan ___ Architecture mailing list Architectu

Re: [Architecture] [APIM] Multiple Key Manager support

2020-04-14 Thread gayan gunawardana
a CPU intensive task and might introduce some security vulnerabilities as well. 3. For same set of words different people can come up with different Regular expressions. Also having flexibility to write own validation might introduce some open ended problems for simple requirement. > > Thanks > &

Re: [Architecture] [APIM] Multiple Key Manager support

2020-04-14 Thread gayan gunawardana
Hi Tharindu, In #6 Validating the Token, regex validation may work for reference access tokens to find corresponding Oauth provider but can we utilize regex validation for self-contained access tokens. Is it possible mediate token generation and append specific prefix to identify Oauth provider or

Re: [Architecture] [APIM] Mutual SSL with Load Balancer

2019-10-08 Thread gayan gunawardana
pimgt/blob/master/components/apimgt/org.wso2.carbon.apimgt.gateway/src/main/java/org/wso2/carbon/apimgt/gateway/handlers/security/APIAuthenticationHandler.java#L288 Thanks, Gayan On Thu, Sep 26, 2019 at 4:25 PM gayan gunawardana wrote: > > > On Thu, Sep 26, 2019 at 3:56 PM Piraveena Paral

Re: [Architecture] [APIM] Mutual SSL with Load Balancer

2019-09-26 Thread gayan gunawardana
* > Software Engineer | WSO2 Inc. > *(m)* +94776099594 | *(e)* pirave...@wso2.com > > > > On Thu, Sep 26, 2019 at 7:44 PM gayan gunawardana > wrote: > >> Hi Piraveena, >> >> Thanks for detail response. >> However I am referring to APIM synapse endpoints

Re: [Architecture] [APIM] Mutual SSL with Load Balancer

2019-09-26 Thread gayan gunawardana
thenticator+with+SSL+Termination > > Thanks, > Piraveena > *Piraveena Paralogarajah* > Software Engineer | WSO2 Inc. > *(m)* +94776099594 | *(e)* pirave...@wso2.com > > > > On Wed, Sep 25, 2019 at 11:47 AM gayan gunawardana < > gmgunaward...@gmail.com> wrote: >

Re: [Architecture] [APIM] Mutual SSL with Load Balancer

2019-09-24 Thread gayan gunawardana
On Wed, Sep 25, 2019 at 6:49 AM Asela Pathberiya wrote: > > > On Wed, Sep 25, 2019 at 10:47 AM gayan gunawardana < > gmgunaward...@gmail.com> wrote: > >> Hi APIM team, >> >> Is there any recommended deployment pattern to implement [1] if SSL >> termi

[Architecture] [APIM] Mutual SSL with Load Balancer

2019-09-24 Thread gayan gunawardana
Hi APIM team, Is there any recommended deployment pattern to implement [1] if SSL termination happen from load balancer ? [1] https://docs.wso2.com/display/AM260/Securing+APIs+with+Mutual+SSL -- Gayan ___ Architecture mailing list Architecture@wso2.or

Re: [Architecture] [IAM] Hierarchical Tenancy

2019-08-22 Thread gayan gunawardana
is the general direction of > tenant model improvement. > > Cheers, > Ruwan A > > > On Thu, Aug 22, 2019 at 12:29 PM gayan gunawardana < > gmgunaward...@gmail.com> wrote: > >> Hi IAM Team, >> >> Does WSO2 Identity Server road

[Architecture] [IAM] Hierarchical Tenancy

2019-08-21 Thread gayan gunawardana
Hi IAM Team, Does WSO2 Identity Server road map have $subject ? & is there any plan to remove current multi-tenancy model in near future release ? Thanks, Gayan ___ Architecture mailing list Architecture@wso2.org https://mail.wso2.org/cgi-bin/mailman/li

Re: [Architecture] [IAM][New Feature] Claim Transformation for Provisioning Use Cases

2019-03-11 Thread gayan gunawardana
Reference-userObject > [2] > https://docs.wso2.com/display/IS570/Configuring+User-Age-Based+Adaptive+Authentication > Thanks a lot for Information > > Cheers, > Ruwan > > On Mon, Mar 11, 2019 at 12:12 PM gayan gunawardana < > gmgunaward...@gmail.com> wrote: > &

Re: [Architecture] [IAM][New Feature] Claim Transformation for Provisioning Use Cases

2019-03-10 Thread gayan gunawardana
On Wed, Feb 20, 2019 at 2:40 PM Darshana Gunawardana wrote: > Hi Johann, > > If we are considering a provisioning scenarios in a authentication flow > (JIT flows), we should be able use scripting capabilities in adaptive > authentication to inject\modify a claim with transformation. > This is gre

Re: [Architecture] API Manager integration with Istio

2019-01-17 Thread gayan gunawardana
This is a great initiative. Small clarification, can there be overlapping features between Service Mesh and APIM such as rate limiting, end user authentication [1][2] ? [1] https://istio.io/docs/tasks/policy-enforcement/rate-limiting/ [2] https://istio.io/help/ops/security/end-user-auth/ Thanks,

Re: [Architecture] [IS] Circuit Breaker on user store LDAP+JDBC

2018-10-15 Thread gayan gunawardana
Hi Ruwan, This is a very good initiative and I have few things to clarify. On Sun, Oct 14, 2018 at 8:38 AM Ruwan Abeykoon wrote: > Hi Devs, > > *Why ${subject} **? * > *I*mplement "Circuit Breaker" pattern in user store manager is becoming > an essential part when it comes to multi tenant and mu

Re: [Architecture] [IAM] Tenant wise default authentication sequence leveraging adaptive authentication

2018-09-04 Thread gayan gunawardana
Hi Indunil, In conclusion this will introduce "Local and Outbound Authentication Configuration" to resident IDP UI and that will be the default authentication sequence for tenant . Is my understanding correct ? Any way this will be very useful because some organizations don't want to change their

Re: [Architecture] [IAM] SCIM 2.0 Outbound Connector

2018-03-07 Thread Gayan Gunawardana
need two separate outbound >>> connectors. It could mean we use one connector but that single connector >>> supports both of the protocols at the same time. >>> >>> thanks, >>> Dimuthu >>> >>> >>> On Mon, Feb 12, 2018 at 3:26

Re: [Architecture] [IAM] SCIM 2.0 Outbound Connector

2018-02-12 Thread Gayan Gunawardana
a > > On Mon, Feb 12, 2018 at 11:59 AM, Gayan Gunawardana > wrote: > >> Hi Isuranga, >> >> Could you be able to move *identity-outbound-**provisioning-scim2* to >> *identity-outbound-provisioning-scim* by having configuration option for >> SCIM 1.1 and 2.0 ?

Re: [Architecture] [IAM] SCIM 2.0 Outbound Connector

2018-02-11 Thread Gayan Gunawardana
being swallowed in the client >> without passing them back to the connector [1]. In that case, the >> provisioning connector might not know if the request has been success or >> not and act accordingly. >> >> [1] https://github.com/wso2-extensions/identity-client-scim2/

Re: [Architecture] [IAM] SCIM 2.0 Outbound Connector

2018-02-03 Thread Gayan Gunawardana
gt;>>> wso2-extensions organization? >>>>>>>>> >>>>>>>>> 1. *identity-outbound-provisioning-scim2* >>>>>>>>> >>>>>>>>> For the outbound connector >>>>>>>>>

[Architecture] What is the most suitable way to invoke DCR endpoints from native mobile application

2017-12-18 Thread Gayan Gunawardana
from DCR specification but the problem is how to store this initial access token securely in mobile application. WDYT? Thanks, Gayan -- Gayan Gunawardana Senior Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933

Re: [Architecture] [IS] Supplementary OSGi service for adding new claims to ID Token

2017-11-20 Thread Gayan Gunawardana
gt; > > *Email : hasi...@wso2.com * > > *Mobile : +94713850143 <+94%2071%20385%200143>[image: > http://wso2.com/signature] <http://wso2.com/signature>* > > ___ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > > -- Gayan Gunawardana Senior Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Architecture@wso2.org https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Re: [Architecture] [IS] Supplementary OSGi service for adding new claims to ID Token

2017-11-20 Thread Gayan Gunawardana
h >> *Mobile* : +94776099594 <+94%2077%20609%209594> >> <http://wso2.com/signature> >> > > > > -- > > *Hasini Witharana* > Software Engineering Intern | WSO2 > > > *Email : hasi...@wso2.com * > > *Mobile : +94713850143 <+94%2071

Re: [Architecture] [IAM] SCIM 2.0 Outbound Connector

2017-10-16 Thread Gayan Gunawardana
On Mon, Oct 16, 2017 at 1:21 PM, Isuranga Perera wrote: > Hi Gayan, > > In that case, I'll try to create an SDK from swagger and use it as the > client. > That would be great. > > Best Regards > > On Mon, Oct 16, 2017 at 9:12 AM, Gayan Gunawardana wrote

Re: [Architecture] [IAM] SCIM 2.0 Outbound Connector

2017-10-15 Thread Gayan Gunawardana
/ProvisioningClient.java On Sun, Oct 15, 2017 at 11:16 PM, Gayan Gunawardana wrote: > > > On Sun, Oct 15, 2017 at 8:39 PM, Johann Nallathamby > wrote: > >> *[+ IsharaK, Omindu, Farasath]* >> >> On Sun, Oct 15, 2017 at 7:34 PM, Isuranga Perera < >> isurangamper...@g

Re: [Architecture] [IAM] SCIM 2.0 Outbound Connector

2017-10-15 Thread Gayan Gunawardana
github.com/HansageeSJ/scim-client >> [3] https://wso2.org/jira/browse/IDENTITY-5695 >> >> Appreciate any suggestions. >> >> >> Best Regards >> Isuranga Perera >> >> On Fri, Oct 13, 2017 at 9:42 AM, Gayan Gunawardana >> wrote: >> >

Re: [Architecture] [IAM] SCIM 2.0 Outbound Connector

2017-10-12 Thread Gayan Gunawardana
>> >> > > > -- > Thanks & Regards, > > *Johann Dilantha Nallathamby* > Senior Lead Solutions Engineer > WSO2, Inc. > lean.enterprise.middleware > > Mobile - *+9476950* > Blog - *http://nallaa.wordpress.com <http://nallaa.wordpress.co

Re: [Architecture] [IS] IS 5.5.0 += Adaptive Authentication

2017-05-29 Thread Gayan Gunawardana
gt; >>* Evaluates if this step is applicable on the current authentication >> context. >> >> .. >> >>*/ >> >> boolean isApplicable(StepConfig stepConfig, AuthenticationContext >> context); >> >> } >> >> >>

[Architecture] Validate Authorization headers for Oauth endpoints

2017-04-24 Thread Gayan Gunawardana
check the context inside authenticator canHandle. *#option 01 * Increase the priority of newly added authenticator and check existence of oauth application from client key. WDYT? -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933

Re: [Architecture] Configure token expiry time based on the Service provider (APIM application)

2017-04-24 Thread Gayan Gunawardana
t;> >> >> -- >> Thanks & Regards, >> Asela >> >> ATL >> Mobile : +94 777 625 933 <+94%2077%20762%205933> >> +358 449 228 979 >> >> http://soasecurity.org/ >> http://xacmlinfo.org/ >> > > > > -- > >

Re: [Architecture] [IS-6.0.0] SCIM list resources with multiple user stores

2017-03-26 Thread Gayan Gunawardana
om/vindula.jayawardana> >>>> <http://lk.linkedin.com/pub/vindula-jayawardana/a7/315/53b> >>>> <https://plus.google.com/u/0/+VindulaJayawardana/posts> >>>> <https://twitter.com/vindulajay> >>>> >>>> *“Respect is h

Re: [Architecture] [C5][IS 6.0.0] Password Policy Validation

2017-03-23 Thread Gayan Gunawardana
On Fri, Mar 24, 2017 at 7:08 AM, Isura Karunaratne wrote: > Hi Gayan, > > > > On Thu, Mar 23, 2017 at 11:56 PM, Gayan Gunawardana > wrote: > >> Hi All, >> >> We are in the process of Implementing password policy validation feature >> for IS 6.0.

[Architecture] [C5][IS 6.0.0] Password Policy Validation

2017-03-23 Thread Gayan Gunawardana
, default password policies and custom password policies then you can keep both configurations are enabled. If you want to enable only custom policy then you can disable default policies. Appreciate your suggestions regarding this. Thanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc

Re: [Architecture] [C5][IS 6.0.0] Email Verification for Existing User

2017-03-20 Thread Gayan Gunawardana
gt; E: hasan...@wso2.com > M :0718407133| http://wso2.com <http://wso2.com/> > -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Architecture@wso2.org https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Re: [Architecture] [C5][IS 6.0.0][admin-portal] User Onboarding - Ask Password with email verification

2017-03-20 Thread Gayan Gunawardana
com/in/dinalidabarera> >> Mobile: +94770198933 <+94%2077%20019%208933> >> >> >> >> >> <https://lk.linkedin.com/in/dinalidabarera> >> >> >> >> >> >> >> >> >> >> >> >> >&g

Re: [Architecture] [C5][IS 6.0.0] User List UI for IS 6.0.0

2017-03-19 Thread Gayan Gunawardana
ds, >> >> Nuwandi Wickramasinghe >> >> Software Engineer >> >> WSO2 Inc. >> >> Web : http://wso2.com >> >> Mobile : 0719214873 >> >> ___ >> Architecture mailing list >> Archite

Re: [Architecture] [C5][IS 6.0.0] Add and Update Group UI for IS 6.0.0

2017-03-19 Thread Gayan Gunawardana
date. > >> >> >> -- >> >> *Kasun Gajasinghe*Associate Technical Lead, WSO2 Inc. >> email: kasung AT spamfree wso2.com >> linked-in: http://lk.linkedin.com/in/gajasinghe >> blog: http://kasunbg.org >> phone: +1 650-745-4499 <(650)%20745-4499>, 77 678 0813 >> >> > > >

Re: [Architecture] Define Username Claim in Domain Level

2017-03-19 Thread Gayan Gunawardana
not need to define it separately in domain-config.yaml right ? > > >>> Shall we add a method to User[1] class to retrieve username? >>> >> +1 to have a method in User.java >> >>> >>> [1] - https://github.com/wso2/carbon-identity-mgt/blob/master/com &g

Re: [Architecture] [C5][IS 6.0.0] Password History Validation

2017-03-18 Thread Gayan Gunawardana
On Thu, Mar 16, 2017 at 8:44 PM, Sagara Gunathunga wrote: > > > On Sun, Mar 12, 2017 at 7:44 AM, Gayan Gunawardana wrote: > >> Hi All, >> >> We are in the process of implementing password history validation feature >> for IS 6.0.0. Architecture of this fe

Re: [Architecture] [C5][IS 6.0.0]Admin Forced Password Reset Via Offline for Existing Users

2017-03-15 Thread Gayan Gunawardana
gt; > E: hasan...@wso2.com > M :0718407133| http://wso2.com <http://wso2.com/> > > On Wed, Mar 15, 2017 at 10:55 PM, Farasath Ahamed > wrote: > >> >> >> On Wednesday, March 15, 2017, Dilan Udara Ariyaratne >> wrote: >> >>> >>>

Re: [Architecture] [C5][IS 6.0.0] Password History Validation

2017-03-15 Thread Gayan Gunawardana
Hi Imesh, On Wed, Mar 15, 2017 at 10:19 AM, Imesh Gunaratne wrote: > On Sun, Mar 12, 2017 at 7:44 AM, Gayan Gunawardana wrote: > >> >> CREATE TABLE IF NOT EXISTS IDN_PASSWORD_HISTORY_DATA ( >> ID INTEGER NOT NULL AUTO_INCREMENT, >> USER_UNIQUE_ID VARCHAR(

Re: [Architecture] Define Username Claim in Domain Level

2017-03-14 Thread Gayan Gunawardana
uot;). >>> >> So, it will always be http://wso2.org/claims/username, not configurable? >> >>> >>> Shall we add a method to User[1] class to retrieve username? >>> >> +1 to have a method in User.java >> >>> >>> [1] - https://

[Architecture] Define Username Claim in Domain Level

2017-03-13 Thread Gayan Gunawardana
user from identity store so we need to set value got from out side to appropriate claim. In that case there should be a way to identify username claim. WDYT? Thanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 80

Re: [Architecture] [C5][IS 6.0.0]Admin Forced Password Reset Via Offline for Existing Users

2017-03-13 Thread Gayan Gunawardana
t; [1] https://github.com/wso2-dev-ux/product-is/blob/master/ > Wireframes/admin-portal/v3/3.32%20%20Reset%20password% > 20with%20offline%20OTP%20-%20password%20generated.png > > Thanks, > > Hasanthi Dissanayake > > Software Engineer | WSO2 > > E: hasan...@wso2.com > M

Re: [Architecture] [C5][IS 6.0.0] Password History Validation

2017-03-12 Thread Gayan Gunawardana
On Mon, Mar 13, 2017 at 9:03 AM, Isura Karunaratne wrote: > Hi Gayan, > > > On Sun, Mar 12, 2017 at 7:44 AM, Gayan Gunawardana wrote: > >> Hi All, >> >> We are in the process of implementing password history validation feature >> for IS 6.0.0. Arch

Re: [Architecture] Claim dialect must have two special attributes indicating "userid" claim URI and "role" claim URI.

2017-03-11 Thread Gayan Gunawardana
On Sun, Mar 12, 2017 at 11:36 AM, Johann Nallathamby wrote: > > > On Sun, Mar 12, 2017 at 8:15 AM, Gayan Gunawardana wrote: > >> >> >> On Sun, Mar 12, 2017 at 7:09 AM, Johann Nallathamby >> wrote: >> >>> >>> >&g

Re: [Architecture] [C5][IS 6.0.0] Password History Validation

2017-03-11 Thread Gayan Gunawardana
tory record. We need to use the particular > algorithm to do the comparison, not the system configured one. > +1 > > Cheers, > Ruwan > > > On Sun, Mar 12, 2017 at 7:44 AM, Gayan Gunawardana wrote: > >> Hi All, >> >> We are in the process of impl

Re: [Architecture] Claim dialect must have two special attributes indicating "userid" claim URI and "role" claim URI.

2017-03-11 Thread Gayan Gunawardana
;> >>>> -- >>>> *Thanuja Lakmal* >>>> Senior Software Engineer >>>> WSO2 Inc. http://wso2.com/ >>>> *lean.enterprise.middleware* >>>> Mobile: +94715979891 +94758009992 >>>> >>> >>> >>>

[Architecture] [C5][IS 6.0.0] Password History Validation

2017-03-11 Thread Gayan Gunawardana
perty. [1] [Architecture] Force Password Reset and Password History validation Thanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Architecture@wso2

Re: [Architecture] [IS-6.0.0] SCIM list resources with multiple user stores

2017-03-06 Thread Gayan Gunawardana
n? If so >>> +1 for using a param. Else, we can include the domain name as a part of >>> the username (IINM we support this in C4 as well), so searching only in a >>> particular domain will look like below. >>> >>> /scim/v2/Users?filter=userName+EQ+FOOD

[Architecture] [IS-6.0.0] SCIM list resources with multiple user stores

2017-03-02 Thread Gayan Gunawardana
serName+EQ+vindula&domain= @Ishara, Johann, Ayoma appreciate your input. Thanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Archi

Re: [Architecture] Paginate and Filter Entries in IS 6.0.0

2017-03-01 Thread Gayan Gunawardana
On Thu, Mar 2, 2017 at 10:24 AM, Thanuja Jayasinghe wrote: > Hi Gayan, > > On Thu, Mar 2, 2017 at 9:58 AM, Gayan Gunawardana wrote: > >> >> Hi All, >> >> How listUsers, listGroups methods should behave when domain is not >> specified ? >> >

[Architecture] Paginate and Filter Entries in IS 6.0.0

2017-03-01 Thread Gayan Gunawardana
provide paginated, filtered result. IMO behavior of *1* is correct but *2, 3, 4 need to be *consistent. I think *2, 3 *also behave as *4*. Please correct me If I am wrong. Thanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71

Re: [Architecture] How to identifying a self sign-up request

2017-03-01 Thread Gayan Gunawardana
gt; >> >> Thanks, >> Omindu >> >> -- >> Omindu Rathnaweera >> Software Engineer, WSO2 Inc. >> Mobile: +94 771 197 211 <+94%2077%20119%207211> >> > > > > -- > > *Johann Dilantha Nallathamby* > Technical Lead & Product Lead of WSO2 Identity Server > Governance Technologies Team > WSO2, Inc. > lean.enterprise.middleware > > Mobile - *+9476950* > Blog - *http://nallaa.wordpress.com <http://nallaa.wordpress.com>* > -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Architecture@wso2.org https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Re: [Architecture] [IS 6.0.0] [SCIM 2.0] Extend SCIM2.0 meta data in the SCIM response to include User Life cycle State

2017-03-01 Thread Gayan Gunawardana
ate":"CREATED"}*} > > +1 to have enterprise user extension for "state" attribute. What are the available values for "state" attribute and also check "active" attribute in standard schema. > Appreciate your ideas. > > [1] https://github.

Re: [Architecture] IdentityStore APIs in C5

2017-02-27 Thread Gayan Gunawardana
>> On Mon, Feb 27, 2017 at 10:06 AM, Ruwan Abeykoon wrote: >> >>> Hi All, >>> +1 to have an exception hierarchy, which carries information for >>> specific errors. >>> >>> I think we should follow the way Java IO exceptions are done. >>&

[Architecture] IdentityStore APIs in C5

2017-02-26 Thread Gayan Gunawardana
hanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Architecture@wso2.org https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

[Architecture] WSO2 Identity Server 6.0.0-M2 Released !

2017-02-24 Thread Gayan Gunawardana
| Subscribe | Mail Archive <http://wso2.org/mailarchive/dev/> - User Forum : StackOverflow <http://stackoverflow.com/questions/tagged/wso2is> Reporting IssuesWe encourage you to report issues, improvements and feature requests regarding WSO2 Identity Server through public WSO2 Identity Server JIRA <https://wso2.org/jira/browse/IDENTITY>. ~ The WSO2 Identity Server Team ~ -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Architecture@wso2.org https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Re: [Architecture] [IAM] [IS6.0.0] How to handle Special claims ?

2017-02-18 Thread Gayan Gunawardana
On Mon, Feb 13, 2017 at 7:33 AM, Sagara Gunathunga wrote: > > > On Sun, Feb 12, 2017 at 8:31 AM, Johann Nallathamby > wrote: > >> >> >> On Fri, Feb 10, 2017 at 1:15 AM, Gayan Gunawardana >> wrote: >> >>> >>> >>> On Thu, Fe

Re: [Architecture] [IAM] [IS6.0.0] How to handle Special claims ?

2017-02-09 Thread Gayan Gunawardana
>> Email: is...@wso2.com >> Mob : +94 772 254 810 <+94%2077%20225%204810> >> Blog : http://isurad.blogspot.com/ >> >> >> >> > > > -- > Omindu Rathnaweera > Software Engineer, WSO2 Inc. > Mobile: +94 771 197 211 <+94%2077%20119%207211>

Re: [Architecture] C5 User Core Delete User Operation

2017-02-08 Thread Gayan Gunawardana
g conflict when a new user add with same username. > > Regards, > Darshana > >> And in our implementation we have inactive, and disable option for that >> to handle not permanently delete case. >> >> -Ishara >> >> On Wed, Feb 8, 2017 at 12:10 PM, Darsha

[Architecture] C5 User Core Delete User Operation

2017-02-08 Thread Gayan Gunawardana
tly affected to SCIM implementation according to [1]. [1]https://tools.ietf.org/html/rfc7644#section-3.6 Thanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architect

Re: [Architecture] [IS] [C5] Check Whether User Exist in User Stores

2017-02-02 Thread Gayan Gunawardana
On Fri, Feb 3, 2017 at 8:32 AM, Johann Nallathamby wrote: > > > On Thu, Feb 2, 2017 at 11:38 PM, Gayan Gunawardana wrote: > >> >> >> On Thu, Feb 2, 2017 at 7:59 PM, Indunil Upeksha Rathnayake < >> indu...@wso2.com> wrote: >> >>> Hi, >

Re: [Architecture] [IS] [C5] Check Whether User Exist in User Stores

2017-02-02 Thread Gayan Gunawardana
st to /Me end point and consider 409 as user already exist. IMO API level better option would be to build some custom implementation on top of /Me end point to check whether user exist. > >> Thanks & regards, >> -Prabath >> >> >> On Wed, Feb 1, 2017 at 2:41 A

Re: [Architecture] [IS] [C5] Check Whether User Exist in User Stores

2017-02-01 Thread Gayan Gunawardana
; >> > > > -- > Thanks & Regards, > Prabath > > Twitter : @prabath > LinkedIn : http://www.linkedin.com/in/prabathsiriwardena > > Mobile : +1 650 625 7950 <(650)%20625-7950> > > http://facilelogin.com > > __

Re: [Architecture] C5 User Management APIs with SCIM 2.0

2017-01-23 Thread Gayan Gunawardana
his in two steps. >> 1. Convert these identity management APIs to use the SCIM request >> response format. >> 2. Implement as SCIM extensions. >> >> So +1 to start with the step 1 and later go with 2 >> Thanks, >> Ishara >> >> On Mon, J

Re: [Architecture] C5 User Management APIs with SCIM 2.0

2017-01-22 Thread Gayan Gunawardana
Attaching missing images. ​ ​ On Sun, Jan 22, 2017 at 11:49 PM, Gayan Gunawardana wrote: > SCIM Overview and Concept > SCIM stands for “Simplified Cloud Identity Management” and later it has > been changed to “System for Cross-domain Identity Management”. SCIM was > originally d

[Architecture] C5 User Management APIs with SCIM 2.0

2017-01-22 Thread Gayan Gunawardana
UserAdmin, RemoteUserStoreManagerService, UserInformationRecoveryService with standard SCIM APIs. Much appreciate your suggestions and feedbacks. Thanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (7

Re: [Architecture] [Dev] [IS] [C5] Self sign-up in C5 User Portal

2017-01-07 Thread Gayan Gunawardana
t;>>>>> -- >>>>>>> Ishara Karunarathna >>>>>>> Associate Technical Lead >>>>>>> WSO2 Inc. - lean . enterprise . middleware | wso2.com >>>>>>> >>>>>>> email: isha...@wso2.com, bl

Re: [Architecture] [IS] What are the REST APIs in WSO2IS-5.3.0 that need to be secured?

2016-11-13 Thread Gayan Gunawardana
;> Ishara Karunarathna >>>>>> Associate Technical Lead >>>>>> WSO2 Inc. - lean . enterprise . middleware | wso2.com >>>>>> >>>>>> email: isha...@wso2.com, blog: isharaaruna.blogspot.com, mobile: >>>>

Re: [Architecture] Identity Server 5.3.0 New Feature - Prompt for missing predefined user attributes in the authentication flow

2016-11-01 Thread Gayan Gunawardana
t;>> >>>>> 6. In *handlePostAuthentication()*, it checks the property set in >>>>> step 2 and identifies this as the response of post authentication >>>>> extension >>>>> task therefore calls the post authentication extension. >&

Re: [Architecture] [IS] What are the REST APIs in WSO2IS-5.3.0 that need to be secured?

2016-10-20 Thread Gayan Gunawardana
anks! >>>> -Ayesha >>>> >>>> -- >>>> *Ayesha Dissanayaka* >>>> Software Engineer, >>>> WSO2, Inc : http://wso2.com >>>> <http://www.google.com/url?q=http%3A%2F%2Fwso2.com&sa=D&sntz=1&usg=AFQjCNEZvyc0uMD

Re: [Architecture] Monitor Logged In Users/Sessions

2016-07-09 Thread Gayan Gunawardana
INT, month INT, day INT, hour INT, minute INT, action INT, userName STRING, userstoreDomain STRING, IP STRING, region STRING, tenantDomain STRING, rememberMeFlag BOOLEAN, userAgent STRING, _tenantId INT, _timestamp LONG -i", primaryKeys "sessionId" *We have to consider having mult

Re: [Architecture] Monitor Logged In Users/Sessions

2016-07-03 Thread Gayan Gunawardana
On Mon, Jul 4, 2016 at 9:31 AM, Selvaratnam Uthaiyashankar wrote: > > > >> >> On Fri, Jul 1, 2016 at 7:32 PM, Selvaratnam Uthaiyashankar < >> shan...@wso2.com> wrote: >> >>> >>> >>> On Mon, Jun 27, 2016 at 3:53 PM, Gayan Gu

Re: [Architecture] Monitor Logged In Users/Sessions

2016-07-02 Thread Gayan Gunawardana
Hi Shankar, I will remove private information and send descriptive mail to architecture. On Fri, Jul 1, 2016 at 7:32 PM, Selvaratnam Uthaiyashankar wrote: > > > On Mon, Jun 27, 2016 at 3:53 PM, Gayan Gunawardana wrote: > >> Hi All, >> >> This feature will provid

[Architecture] Monitor Logged In Users/Sessions

2016-06-27 Thread Gayan Gunawardana
EN we have the same problem), so we should figure out a general schema for IDN_USER_SESSION_DATA that can be used for all types of users. Thanks, Gayan -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (7

Re: [Architecture] [IS] Supporting user information recovery scenarios in IS user portal

2016-06-26 Thread Gayan Gunawardana
;>>>>> Username recovery is supported only with an email notification. >>>>>>>>>>> Thus, the visibility of this option would be decided on required >>>>>>>>>>> email transport configurations >>>>>>>&

Re: [Architecture] [Dev][IS] Improvements in handling incorrect login attempts

2016-06-17 Thread Gayan Gunawardana
are* >> >> >> ___ >> Architecture mailing list >> Architecture@wso2.org >> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >> >> > > > -- > Isura Dilhara Karunaratne > Sen

Re: [Architecture] Identity Management Recovery API improvements.

2016-06-13 Thread Gayan Gunawardana
>>> "key": "f75da810-3478-47f4-80e5-c37556392015" >>>> >>>> } >>>> >>>> >>>> >>>> >>>> >>>> *Reset Password.* >>>> >>>> PUT /accountrecovery/rest/notificat

Re: [Architecture] [IS] Regenerating client secret/key and revoking an oauth app in OAuth 2.0 implementation

2016-06-03 Thread Gayan Gunawardana
ise . Middleware* > > > ___ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > > -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.c

[Architecture] [IDENTITY-3352] SCIM Dumb Mode Outbound Provisioning

2015-09-20 Thread Gayan Gunawardana
in connected IDPs with a unique ID specific to each IDP (SCIM_ID, username etc), IDP name, Local unique id, Local user name. For both smart mode and dumb mode we keep this data which will help us to implement a distributed user view of the user in future. -- Gayan Gunawardana Software Engineer

Re: [Architecture] User store configuration for Service Providers

2015-08-29 Thread Gayan Gunawardana
but it isn't a major requirement. > > [1] https://wso2.org/jira/browse/IDENTITY-3110 > > On Sun, Aug 30, 2015 at 8:40 AM, Gayan Gunawardana wrote: > >> Hi All, >> >> In WSO2 Identity Server 5.0.0 we can register Service Providers to >> consume different proto

[Architecture] User store configuration for Service Providers

2015-08-29 Thread Gayan Gunawardana
-A utilize only Oauth and SP-B utilize only SAML. There are two user stores like a.com and b.com. Now requirement is users in a.com can consume Oauth but not SAML similarly users in b.com can consume SAML but not Oauth. WDYT ? -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com

[Architecture] How to set SCIM specific claims while Adding users via SCIM

2015-08-14 Thread Gayan Gunawardana
SCIM specific claims functionality from SCIMUserOperationListener and put it some where else. Please mention your concerns and suggestions. -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933

Re: [Architecture] Supporting OpenID-Connect with different OAuth2 grant types.

2015-02-16 Thread Gayan Gunawardana
8/002981.html > [2] https://wso2.org/jira/browse/IDENTITY-3055 > +1 for [2] since client credentials grant type has nothing to do with resource owner. > > Thanks, > Asela. > -- > Thanks & Regards, > Asela > > ATL > Mobile : +94 777 625 933 > +35

Re: [Architecture] Supporting OpenId-Connect Session Management

2014-12-12 Thread Gayan Gunawardana
ds, > Asela > > ATL > Mobile : +94 777 625 933 > +358 449 228 979 > ___ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > -- Gay

Re: [Architecture] APIM Support for getting Authorization header from query String

2014-11-23 Thread Gayan Gunawardana
ific reason. >> > What would be the particular use case to send access token in query String. This is a bad practice according to many real world use cases [1]. [1] http://www.thread-safe.com/2013/10/latest-facebook-security-vulnerability.html -- Gayan Gunawardana Software

Re: [Architecture] HTTP PATCH method implementation for SCIM end points

2014-11-10 Thread Gayan Gunawardana
Hi Asela, Thanks for pointing. I have already updated redmine ticket linked to [1]. [1] https://wso2.org/jira/browse/IDENTITY-1891 On Mon, Nov 10, 2014 at 5:50 PM, Asela Pathberiya wrote: > On Mon, Nov 10, 2014 at 5:48 PM, Gayan Gunawardana wrote: > > Hi Asela, > > > > C

Re: [Architecture] HTTP PATCH method implementation for SCIM end points

2014-11-10 Thread Gayan Gunawardana
Asela. > > On Sun, Jul 27, 2014 at 9:10 PM, Gayan Gunawardana wrote: > > Hi All, > > > > Review notes > > > > Participants : Prabath, Chamath, Prasad, Thanuja, Isura, Pulasthi, Gayan > > > > > > 1. Move jax rs custom patch implementation to [1]

[Architecture] OpenID connect ID Token Implementation

2014-09-06 Thread Gayan Gunawardana
-encryption-31 -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Architecture@wso2.org https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Re: [Architecture] XACML Policy Validator Toolkit for IS

2014-08-14 Thread Gayan Gunawardana
> shan...@wso2.com> wrote: > >> Shouldn't this policy validate go to policy editor? Why do we have it as >> a separate link? >> >> For example, I am editing a policy in policy editor. Should I copy the >> policy from there, click another link, paste there and

[Architecture] XACML Policy Validator Toolkit for IS

2014-08-11 Thread Gayan Gunawardana
need to check the validity of a policy without saving the policy. ​ -- Gayan Gunawardana Software Engineer; WSO2 Inc.; http://wso2.com/ Email: ga...@wso2.com Mobile: +94 (71) 8020933 ___ Architecture mailing list Architecture@wso2.org https://mail.wso

Re: [Architecture] HTTP PATCH method implementation for SCIM end points

2014-07-27 Thread Gayan Gunawardana
:22 PM, Gayan Gunawardana wrote: > Hi All, > > I have completed the feature. Can we have a review tomorrow. > > Thanks, > Gayan > > > On Mon, Jul 21, 2014 at 5:41 PM, Gayan Gunawardana wrote: > >> Hi Johan, >> >> According to offline chat we h

Re: [Architecture] HTTP PATCH method implementation for SCIM end points

2014-07-24 Thread Gayan Gunawardana
Hi All, I have completed the feature. Can we have a review tomorrow. Thanks, Gayan On Mon, Jul 21, 2014 at 5:41 PM, Gayan Gunawardana wrote: > Hi Johan, > > According to offline chat we had, we can ignore Use-Case 03 and Use-Case > 04. > > For Use-Case 01 I have added extra

Re: [Architecture] HTTP PATCH method implementation for SCIM end points

2014-07-21 Thread Gayan Gunawardana
addresses. Thanks, Gayan On Mon, Jul 14, 2014 at 11:28 AM, Gayan Gunawardana wrote: > Hi Ishara, > > While looking at patch operation for Users, I have encountered following > issues. > > Use-Case 01 : changing a User's primary email > Issue : Currently there i

Re: [Architecture] HTTP PATCH method implementation for SCIM end points

2014-07-13 Thread Gayan Gunawardana
user store in inbound provisioning UI). >> > In this case if no user store is selected, users can be provisioned to any > user store, if its selected users will be provisioned only to that user > store . > > This is how it works. > @Darshana Please add if something missing.

Re: [Architecture] HTTP PATCH method implementation for SCIM end points

2014-07-11 Thread Gayan Gunawardana
minor change. It should be dumb mode not dump mode Thanks, Gayan On Fri, Jul 11, 2014 at 1:45 PM, Gayan Gunawardana wrote: > Hi Ishara, > > Could you please elaborate more about dump mode in SCIMUserManager and how > the changes should be reflected to dump mode. > > Thanks

Re: [Architecture] HTTP PATCH method implementation for SCIM end points

2014-07-11 Thread Gayan Gunawardana
Hi Ishara, Could you please elaborate more about dump mode in SCIMUserManager and how the changes should be reflected to dump mode. Thanks, Gayan On Thu, Jul 10, 2014 at 9:20 AM, Gayan Gunawardana wrote: > Hi, > > There are around 10 use-cases under [1] here *3.2.2 Modifying with pa

  1   2   >