Re: [Architecture] [APIM][Intern Project]- Application Level Mutual TLS support for API Manager

2020-11-19 Thread Sanjeewa Malalgoda
r feedback. We'll take more >> consideration on those matters before proceeding further. >> >> Thank You, >> Dulangi >> >> >> On Thu, Nov 19, 2020 at 12:43 PM Sanjeewa Malalgoda >> wrote: >> >>> As I understand, mutual TLS has nothing to

Re: [Architecture] [APIM] - Event Based API Deployment architecture.

2020-11-19 Thread Sanjeewa Malalgoda
al Lead > WSO2 Inc.; http://wso2.com > lean.enterprise.middleware > > mobile: *+94779109091* > -- *Sanjeewa Malalgoda* Software Architect | Associate Director, Engineering - WSO2 Inc. (m) +94 712933253 | (e) sanje...@wso2.com | (b) Blogger <http://sanjeewamalalgoda.blogspot.com>, Medi

Re: [Architecture] [APIM][Intern Project]- Application Level Mutual TLS support for API Manager

2020-11-18 Thread Sanjeewa Malalgoda
Inc. > (m) +94766697385 | Email: dula...@wso2.com > <http://wso2.com/signature> > ___ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > -- *Sanjeewa Malalgoda* Software Architect |

Re: [Architecture] [Dev] [Vote] Release of WSO2 API Manager 3.2.0 RC6

2020-08-24 Thread Sanjeewa Malalgoda
product and vote. > > [+] Stable - go ahead and release > [-] Broken - do not release (explain why) > > Thanks, > WSO2 API Manager Team > > -- > *Arshardh Ifthikar* > Senior Software Engineer | WSO2 Inc. > > Email: arsha...@wso2.com > Mobile: +9477721855

Re: [Architecture] [APIM] Admin REST API to check user role existence

2020-05-11 Thread Sanjeewa Malalgoda
on this and correct me if I am wrong. >>>> >>>> [1] - [APIM-3.0] Publisher rest API to check a role name existence >>>> >>>> Thanks & Regards, >>>> *S.Meruja* |Software Engineer | WSO2 Inc. >>>> (m) +94779650506 | Email: mer...

Re: [Architecture] [APIM] [APIM-Analytics] Removing APIM database(AM_DB) dependency for analytics

2020-04-23 Thread Sanjeewa Malalgoda
specific indexing optimization etc. And most importantly we can completely decouple. I feel its something to consider before make a decision on api. Thoughts? > > On Thu, Apr 23, 2020 at 12:52 PM Sanjeewa Malalgoda > wrote: > >> When I looked at some other solutions I

Re: [Architecture] [APIM] [APIM-Analytics] Removing APIM database(AM_DB) dependency for analytics

2020-04-23 Thread Sanjeewa Malalgoda
easily add a new REST > API to the analytics webapp to get the required information. > > Appreciate your thoughts on the above. > > Regards, > Ruwini > -- > Ruwini Wijesiri > Senior Software Engineer, > WSO2 Inc. > > Mobile : +94716133480 &

Re: [Architecture] [APIM] Tryout console for the API Publisher

2020-04-21 Thread Sanjeewa Malalgoda
to >> consider how to migrate APIs from previous versions. >> >We have a way to update the RXT field at runtime. For example [1]. We > did this for all newly added RXT fields. > > [1] https://github.com/wso2/product-apim/issues/3525 > >> >> @Sanjeewa Mala

Re: [Architecture] [APIM] Support for API Products from API Controller

2020-04-16 Thread Sanjeewa Malalgoda
;> >>> Comparison of “Using existing commands” and “Using a new set of >>> commands” >>> >>> Using existing commands >>> >>> Using a new set of commands >>> >>>- >>> >>>Advantage >>> >

Re: [Architecture] [APIM] Multiple Key Manager support

2020-04-16 Thread Sanjeewa Malalgoda
rough Gateway. This will show what >> will be the endpoint shows in the UI to use. >> >>> >>> >>>> 6. Validating the Token. >>>> >>>>- Generated Token from Oauth Providers contains a specific change >>>>related to the

Re: [Architecture] [APIM] Multiple Key Manager support

2020-04-15 Thread Sanjeewa Malalgoda
. Delete the Application >> >>- Oauth Application will remove from Respective Oauth Provider >>assigned. >> >> >> I appreciate any thoughts and feedback on this. >> > > Are we only supporting this for subscriptions within the same tenant? > >> &

Re: [Architecture] [Dev] [Vote] Release of WSO2 API Manager 3.1.0 RC3

2020-03-23 Thread Sanjeewa Malalgoda
;>>>>> >>>>>>>>>>>>>>> Hi all, >>>>>>>>>>>>>>> >>>>>>>>>>>>>>> We are pleased to announce the third release candidate of >>>>>>>

Re: [Architecture] [APIM] Service discovery with Kubernetes

2020-02-14 Thread Sanjeewa Malalgoda
there isn't a >> need of saving the other service endpoints. >> >>> >>> Please go through the description and I highly appreciate your thoughts >>> on this $subject. >>> >>> Thanks!. >>> >>> >>> >>> -- >>> Me

Re: [Architecture] Private Jet Mode for WSO2 API Manager with Kubernetes

2020-02-14 Thread Sanjeewa Malalgoda
+94774078049 | (w) +94112145345 | (e) pubu...@wso2.com >>> <http://wso2.com/signature> >>> >>> >> >> -- >> *Manjula Rathnayaka* | Senior Technical Lead | WSO2 Inc. >> (m) +94 77 743 1987 | (w) +94 11 214 5345 | (e) manju...@wso2.com >&

Re: [Architecture] [APIM] Support Global OAuth2 Scopes and Attaching Multiple Scopes per API Resource

2020-01-20 Thread Sanjeewa Malalgoda
ome to conclusion. > > It would be best to release global scope feature along with the current > scope behavior and depend on the usage we can decide whether we > discontinue the local scope feature. > I think current local scope feature will be there anyway. This will come on

Re: [Architecture] [APIM] Support Global OAuth2 Scopes and Attaching Multiple Scopes per API Resource

2020-01-19 Thread Sanjeewa Malalgoda
>>>> Requested Global Scope does not exist. >>>> schema: >>>> $ref: '#/definitions/Error' >>>> >>>> >>>> #----- >&g

Re: [Architecture] [APIM] [3.x] Global View for Scopes

2020-01-02 Thread Sanjeewa Malalgoda
name: >>>> type: string >>>> version: >>>> type: string >>>> >>>> provider: >>>> type: string >>>> >>>> resources: >>>>

Re: [Architecture] Fine Grained Access Control for GraphQL APIs - Role Specific Depth Allocation

2019-11-22 Thread Sanjeewa Malalgoda
*}* > > Here we would maintain these depth-related and complexity-related values > per API. These policy related details will be appended to the existing > local entry which is maintained per API after encoding with base64. Then at > the gateway level, we can read these API leve

Re: [Architecture] Creating a Policy Hub for the Microgateway

2019-10-27 Thread Sanjeewa Malalgoda
vailable in the > Ballerina Central. Regarding the user groups, when the support is provided > through the ballerina central in the future we will be able to inherit it > as well. > > Thanks. > > On Wed, Oct 23, 2019 at 3:29 PM Sanjeewa Malalgoda > wrote: > >> Hi All,

Re: [Architecture] Creating a Policy Hub for the Microgateway

2019-10-23 Thread Sanjeewa Malalgoda
t; ___ >>>>>> Architecture mailing list >>>>>> Architecture@wso2.org >>>>>> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >>>>>> >>>>> >>>>> >>

Re: [Architecture] [APIM-3.0] Publisher rest API to check a role name existence

2019-08-12 Thread Sanjeewa Malalgoda
>>>>>>>>> >>>>>>>>>>>> It is a HEAD method (*/roles/{roleName}*) which will return a >>>>>>>>>>>> 200 status code if the given role name exists and a 404 status >>>>>>>>>>>> code if the &

Re: [Architecture] OAS 3 as default API definition

2019-08-11 Thread Sanjeewa Malalgoda
o with v3 as we are releasing a major version for APIM. >> >>> >> Thank you! >> -- >> *Pubudu Gunatilaka* | Associate Technical Lead | WSO2 Inc. >> (m) +94774078049 | (w) +94112145345 | (e) pubu...@wso2.com >> <http://wso2.com/signature> >> >>

Re: [Architecture] HoneyPot APIs for API Manager - New Feature of APIM product

2019-05-09 Thread Sanjeewa Malalgoda
g] > > [1]. https://blog.rapid7.com/2016/12/06/introduction-to-honeypots/ > > Thank you and regards, > *Nadee Poornima* > Software Engineer - Support Team | WSO2 > > Email : nad...@wso2.com > Mobile : +94713441341 > MyBlog: https://medium.com/nadees-tech-stories > > &l

Re: [Architecture] [Microgateway] API Manager JWT Token Revocation Feature

2019-02-28 Thread Sanjeewa Malalgoda
t;> grant type that allows you to exchange an OAuth token for a self contained >> (JWT) token? >> >>> >>> Will it be under consideration in this implementation? >>> >>> On Wed, Feb 13, 2019 at 12:52 AM Nuwan Dias wrote: >>> >>>&g

Re: [Architecture] [Microgateway] API Manager JWT Token Revocation Feature

2019-02-28 Thread Sanjeewa Malalgoda
we support a scenario like that today. What is the > grant type that allows you to exchange an OAuth token for a self contained > (JWT) token? > >> >> Will it be under consideration in this implementation? >> >> On Wed, Feb 13, 2019 at 12:52 AM Nuwan Dias w

Re: [Architecture] [Microgateway] API Manager JWT Token Revocation Feature

2019-02-12 Thread Sanjeewa Malalgoda
>> I also feel that we need to introduce a config to switch on >> enabling/disabling this feature so that we can also use the microgateways >> in the current mode. >> >> On Thu, Feb 7, 2019 at 3:58 PM Sanjeewa Malalgoda >> wrote: >> >>> Hi All, >&

[Architecture] [Microgateway] API Manager JWT Token Revocation Feature

2019-02-07 Thread Sanjeewa Malalgoda
l all deployed micro services and send revoked JWT list. Each of these methods will have their own advantages and disadvantages. Lets use this mail to discuss those in detail and come to conclusion. Thanks, sanjeewa. -- *Sanjeewa Malalgoda* Software Architect | Associate Director, Engineering - WSO2 In

[Architecture] [Microgateway] Communicate with external system during microgateway startup and while running

2019-02-07 Thread Sanjeewa Malalgoda
. This capability will help us to do some additional stuff when we implement solutions. As example we can think of generating UUID during server startup and send it to some external system for tracking purpose. Thanks, sanjeewa. -- *Sanjeewa Malalgoda* Software Architect | Associate Director

Re: [Architecture] API Manager integration with Istio

2019-01-17 Thread Sanjeewa Malalgoda
rg > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > -- *Sanjeewa Malalgoda* Software Architect | Associate Director, Engineering - WSO2 Inc. (m) +94 712933253 | (e) sanje...@wso2.com | (b) Blogger <http://sanjeewamalalgoda.blogspot.com>, Medium <https://medium.co

[Architecture] API Manager integration with Istio

2019-01-15 Thread Sanjeewa Malalgoda
es in phased approach. First we will do introspection call which validates access token. Then we can think of throttling, usage data monitoring etc. We will create repo named istio-apim and start our work there. If you have any suggestions to above proposal please let us know. Thanks, sanjeewa. -- *San

Re: [Architecture] Solution Design : Support for HTTP2 on the Microgateway

2018-12-20 Thread Sanjeewa Malalgoda
won't be using the server push feature in the microgateway > since there's no much use cases of it with the microgateway. > > Thank you > Best Regards, > > *Varuni Punchihewa* > Intern - Software Engineering | *WSO2* > *Tel:* +94 71 699 5861 > <http://wso2.c

Re: [Architecture] Fwd: Developer-First Microgateway Creation

2018-10-29 Thread Sanjeewa Malalgoda
setup command is executed. If a user needs to add a custom policy, the user >>>> can add it to the policy directory in the Microgateway. >>>> >>>> Your comments and suggestions on this feature will be highly >>>> appreciated. >>>> >

Re: [Architecture] Fwd: Developer-First Microgateway Creation

2018-10-29 Thread Sanjeewa Malalgoda
/signature> >> ___ >> Architecture mailing list >> Architecture@wso2.org >> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >> > > > -- > Malintha Amarasinghe > *WSO2, Inc. - lean | enterprise | midd

Re: [Architecture] Solution Design : Support for HTTP2 on the Microgateway

2018-10-25 Thread Sanjeewa Malalgoda
___ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > -- *Sanjeewa Malalgoda* Software Architect | Associate Director, Engineering - WSO2 Inc. (m) +94 712933253 | (e) sanje...@wso2.c

Re: [Architecture] why wso2 token call return oauth token whereas I configured wso2 to return jwt token

2018-10-25 Thread Sanjeewa Malalgoda
;>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> best regards, >>> >>> >>> Nicolas Maujean >>> >>> __

Re: [Architecture] Project 194: Distributed Throttling for Micro-gateway

2018-10-25 Thread Sanjeewa Malalgoda
gt; >>> >>> >>> >>> >>> >>> >>> -- >>> >>> *Jayanie Bogahawatte* >>> *Software Engineering Intern* >>> WSO2 (University of Moratuwa) >>> *mobile *: *+94 777563324* | *email *: jaya...@w

Re: [Architecture] API schema based request/response validator for Microgateway.

2018-10-23 Thread Sanjeewa Malalgoda
gt;>> >>>>> For that swagger-model-validator for Node.js can be convert in to >>>>> Ballerina. >>>>> >>>>> >>>>> >>>>> Fig 1: Validating a request >>>>> >>>>>

Re: [Architecture] API schema based request/response validator for Microgateway.

2018-09-15 Thread Sanjeewa Malalgoda
;> Fig 2: Validating >>>> a response >>>> >>>> >>>> Thank you! >>>> >>>> -- >>>> >>>> *Shalki Wenushika* >>>> *Software engineering Intern* >>>> WSO2 (University of

Re: [Architecture] [Dev] Dev][VOTE] Release of WSO2 API Manager 2.6.0 RC3

2018-09-15 Thread Sanjeewa Malalgoda
t;> Regards, >>> Chamila Adhikarinayake >>> Associate Technical Lead >>> WSO2, Inc. >>> Mobile - +94712346437 >>> Email - chami...@wso2.com >>> Blog - http://helpfromadhi.blogspot.com/ >>> >> >> >> >> -- >> Re

Re: [Architecture] Project 240: Communication channel between API Providers and API Consumers

2018-09-05 Thread Sanjeewa Malalgoda
On Wed, Sep 5, 2018 at 3:16 PM Bhathiya Jayasekara wrote: > Hi Sanjeewa, > > On Wed, Sep 5, 2018 at 1:11 PM Sanjeewa Malalgoda > wrote: > >> >> >> On Wed, Sep 5, 2018 at 12:58 PM Wasura Wattearachchi >> wrote: >> >>> Hi All, >>> &g

Re: [Architecture] Project 240: Communication channel between API Providers and API Consumers

2018-09-05 Thread Sanjeewa Malalgoda
arifications, you can go through the document which I have > attached below. It will be hugely appreciated if you can provide your > feedback. > > > Until then I will analyze API Manager 3.0 more and will start writing User > Stories. > > > Thank you! > --

Re: [Architecture] Updating 5 star rating to 10 star rating

2018-09-04 Thread Sanjeewa Malalgoda
need it should return same response as get do. Thanks, sanjeewa > >> thanks, >> Chanaka >> -- >> Chanaka Jayasena >> Associate Tech Lead, >> email: chan...@wso2.com; cell: +94 77 4464006 >> blog: http://chanaka3d.blogspot.com >>

Re: [Architecture] API Manager - Store - UX plan for 3.0

2018-09-04 Thread Sanjeewa Malalgoda
>14. Expand each section of Production keys. >15. Expand "subscribe to available application" >16. Expand the "subscribe to a new application" >17. Go through the express mode >18. Go to application page. >19. View applicatio

Re: [Architecture] Design First APIs on APIM v3.0

2018-09-04 Thread Sanjeewa Malalgoda
email : nuw...@wso2.com >>>> Phone : +94 777 775 729 >>>> >>> >>> >>> >>> -- >>> Regards, >>> Uvindra >>> >>> Mobile: 33962 >>> ___ >>> Archi

Re: [Architecture] [APIM][300][Store] Feature to change password of an user

2018-08-21 Thread Sanjeewa Malalgoda
f we send a temporary password we will need to ask to change the >>>> password. >>>> >>>> Hi Vithursa, >>>> >>>> I would suggest having another required property call *retypeNewPassword >>>> *for new password verification. >>>>

Re: [Architecture] [APIM][300][Store] Feature to change password of an user

2018-08-20 Thread Sanjeewa Malalgoda
O2, Inc. http://wso2.com >> email : nuw...@wso2.com >> Phone : +94 777 775 729 >> ___ >> Architecture mailing list >> Architecture@wso2.org >> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >> > > > -- > Mush

Re: [Architecture] [APIM] REST API Support for Dynamic SSL Certificate Installation Feature.

2018-07-10 Thread Sanjeewa Malalgoda
a >>> >>> -- >>> >>> *Menaka Jayawardena* >>> Senior Software Engineer >>> WSO2 Inc. >>> >>> Phone: +94 71 350 5470 >>> LinkedIn : https://lk.linkedin.com/in/menakajayawardena >>> Blog : https://m

Re: [Architecture] [APIM Store REST API] [3.0] Add Application Info in SubscriptionDTO

2018-07-04 Thread Sanjeewa Malalgoda
; Would appreciate your comments and thoughts on this. > > > [1] > https://github.com/wso2/carbon-apimgt/blob/master/components/apimgt/org.wso2.carbon.apimgt.rest.api.store/src/main/resources/store-api.yaml#L3668 > [2] [Dev] [APIM_REST_API] What are the properties to

Re: [Architecture] [APIM][Micro-Gateway][Analytics] Analytics for Micro-gateway

2018-07-02 Thread Sanjeewa Malalgoda
t;> indicating >>>>>>> that fact and delete the copy you received and in addition, you should >>>>>>> not >>>>>>> print, copy, re-transmit, disseminate, or otherwise use the information >>>>

Re: [Architecture] APIM Micro Gateway Cli Functionality and Structure

2018-05-28 Thread Sanjeewa Malalgoda
se and improve it in future. > > >> On Mon, May 28, 2018 at 5:30 PM Isuru Haththotuwa >> wrote: >> >>> >>> >>> On Mon, May 28, 2018 at 5:03 PM, Sanjeewa Malalgoda >>> wrote: >>> >>>> >>>> >>>> On M

Re: [Architecture] APIM Micro Gateway Cli Functionality and Structure

2018-05-28 Thread Sanjeewa Malalgoda
is archive will embeds bre, generated balx which > someone can take and run without configuring anything. > - This command also outputs APIs which have updated and commands > which are available to run in target folder >- *micro-gw run (with

Re: [Architecture] [APIM][API-Manager gateway] Attaching Labels for APIs

2018-05-06 Thread Sanjeewa Malalgoda
mindias >>>>> >>>>> ___ >>>>> Architecture mailing list >>>>> Architecture@wso2.org >>>>> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >>>>> >>>>

Re: [Architecture] Remove Application and user access token concept from API Manager

2018-03-29 Thread Sanjeewa Malalgoda
not introduce such a concept anyway. Are you > suggesting we remove this from 2.x as well? > > On Thu, 29 Mar 2018 at 1:17 pm, Sanjeewa Malalgoda > wrote: > >> Hi All, >> In API Manager we have application access token and user access token >> concept. Application acce

[Architecture] Remove Application and user access token concept from API Manager

2018-03-29 Thread Sanjeewa Malalgoda
token with write(access add photo) scope. In oauth spec also we cannot see this type of differentiation. So considering all these shall we remove application access token concept from API Manager? Any limitations with this? Thanks, sanjeewa. -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779

Re: [Architecture] [APIM v3] Base path for /userinfo endpoint

2018-03-29 Thread Sanjeewa Malalgoda
ions: >>> /api/auth/connect/v1.0/userinfo >>> >>> Appreciate your thoughts? >>> >>> [1] - https://docs.wso2.com/display/IS450/OpenID+Connect+Basic+Cli >>> ent+Profile+with+WSO2+Identity+Server >>> >>> Thank you! >>

[Architecture] [Announce] WSO2 API Manager 3.0.0-M22 Released!

2018-03-15 Thread Sanjeewa Malalgoda
w <https://stackoverflow.com/questions/tagged/wso2-am> Reporting Issues We encourage you to report issues, improvements and feature requests regarding WSO2 API Manager through WSO2 API Manager GIT Issues <https://github.com/wso2/product-apim/issues>. ~ WSO2 API Manager Team ~ --

Re: [Architecture] [APIM] Json Schema Validation

2018-03-15 Thread Sanjeewa Malalgoda
generating API synapse >configuration, we can add the schema to a local entry which the name of the >local entry will be UUID + api+ resource version. >- We can add a property to hold the local entry name related with UUID >and add a class mediator inside each resource

Re: [Architecture] Improving audit logs related with user management tasks

2018-03-13 Thread Sanjeewa Malalgoda
uLsJaQtQAPgR3Nkw >>> trcbFUvVZuPW_gXA7bV5mmo/edit?usp=sharing >>> >>> Thanks. >>> >>> Regards, >>> Megala >>> -- >>> Megala Uthayakumar >>> >>> Senior Software Engineer >>> Mobile : 0779967122 <077%20

Re: [Architecture] [MB4] Restful Admin API's for Message Broker

2018-03-07 Thread Sanjeewa Malalgoda
planning to use following response format. > > HTTP/1.1 200 OK > { > "numberOfMessagesDeleted": 0 > } > > > On Thu, Mar 8, 2018 at 10:41 AM, Sanjeewa Malalgoda > wrote: > >> If purging is handle by background task and completes sometime after >

Re: [Architecture] [MB4] Restful Admin API's for Message Broker

2018-03-07 Thread Sanjeewa Malalgoda
Thanks for the explanation. >>>>>> >>>>>> On Wed, Jan 10, 2018 at 10:29 PM, Asitha Nanayakkara >>>>> > wrote: >>>>>> >>>>>>> Hi Eranda, >>>>>>> >>>>>>> >>&

Re: [Architecture] APIM3 Security For Exposed REST APIs

2018-02-26 Thread Sanjeewa Malalgoda
hich is >>> for internal server communications. This is planned to secure by mutual ssl. >>> >>> Thank you! >>> -- >>> *Pubudu Gunatilaka* >>> Committer and PMC Member - Apache Stratos >>> Senior Software Engineer >>> WSO2, Inc.:

Re: [Architecture] [BMB] Full In-memory operating mode for message broker

2018-02-26 Thread Sanjeewa Malalgoda
>> >> -- >> *Pamod Sylvester * >> >> *WSO2 Inc.; http://wso2.com <http://wso2.com>* >> cell: +94 77 7779495 <077%20777%209495> >> > > > > -- > *Hasitha Abeykoon* > Associate Technical Lead; WSO2, Inc.; http://wso2.com >

Re: [Architecture] [IS] REST endpoint for Claim Management in IS

2018-02-12 Thread Sanjeewa Malalgoda
claims > and mappings to ones under Attributes. > > Thanks. > > On Tue, Feb 13, 2018 at 11:50 AM, Chiran Wijesekara > wrote: > >> Hi Prasanna, >> Appreciate your suggestion. However, It was done in such a way with the >> RESTful design guidelines and usability in

Re: [Architecture] [IS] REST endpoint for Claim Management in IS

2018-02-12 Thread Sanjeewa Malalgoda
irankavinda123/claim_manag >>>>>> ement_service_endpoint/1.0.0 >>>>>> Thanks. >>>>>> >>>>>> >>>>>> On Thu, Feb 8, 2018 at 10:37 AM, Chiran Wijesekara >>>>>> wrote: >>>

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-08 Thread Sanjeewa Malalgoda
go.forrester.com/wp-content/uploads/Forrester- > 2018-Predictions.pdf > > > Regards, > Chamila de Alwis > Committer and PMC Member - Apache Stratos > Associate Technical Lead | WSO2 > +94 77 220 7163 <077%20220%207163> > Blog: https://medium.com/@chamilad > > &g

Re: [Architecture] Clearly defining what operations users can perform on a shared application in APIM

2018-02-08 Thread Sanjeewa Malalgoda
; them. The reason for this is to address practical issues that take place >>> when the App owner leaves an organization and there needs to be some way to >>> delete/update such an Application. >>> >> >> +1 >> >>> >>> >>>

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-08 Thread Sanjeewa Malalgoda
b 6, 2018 at 12:33 PM, Sanjeewa Malalgoda > wrote: > >> >> >> On Mon, Feb 5, 2018 at 11:29 PM, Ishara Karunarathna >> wrote: >> >>> HI Sanjeewa, >>> >>> Pseudonym user ID (User ID) is not only limited to GDPR requirements >>>

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-05 Thread Sanjeewa Malalgoda
tional rules. So if a particular organization has >> a policy to retain user data for 6 months and the user has consented to >> that, the user only has the "right to be forgotten" after the 6 months has >> passed. Until then the organization has the right to hold on to

Re: [Architecture] Can we ship Identity Management / Identity Governance features with APIM by default.

2018-02-04 Thread Sanjeewa Malalgoda
>> WDYT ? >> >> Thanks, >> Asela. >> >> -- >> Thanks & Regards, >> Asela >> >> ATL >> Mobile : +94 777 625 933 <+94%2077%20762%205933> >> +358 449 228 979 >> >> http://soasecu

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-02 Thread Sanjeewa Malalgoda
ot needed at all? > > > > On Fri, Feb 2, 2018 at 11:11 AM, Sanjeewa Malalgoda > wrote: > >> Nuwan, All, >> When we are calling with external systems such as scim we will use user >> ID. But internal flow manly goes with user name. Each time when rest API >>

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-01 Thread Sanjeewa Malalgoda
external system(two boxes >> connected to green box) we will change pseudo name to real user name. I >> have done a quick test with this implementation and now everything(logs, db >> entries, files etc) getting recorded with pseudo name. So whenever we need >> to delete user

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-01 Thread Sanjeewa Malalgoda
name, problems with the same user in >> different cases, etc. Meaning that APIM v3 was already GDPR compliant in >> that sense. It we now have to build an addition layer to make the code GDPR >> compliant, we've basically lost our design objective of using user ids >> i

Re: [Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-01 Thread Sanjeewa Malalgoda
n >> different cases, etc. Meaning that APIM v3 was already GDPR compliant in >> that sense. It we now have to build an addition layer to make the code GDPR >> compliant, we've basically lost our design objective of using user ids >> instead of usernames. >> >&

[Architecture] [GDPR] API Manager 3.0.0 GDPR Support

2018-02-01 Thread Sanjeewa Malalgoda
to do same for light weight auth framework as well. ​​ I would like to know others opinion on this before move forward. Thanks, sanjeewa. -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779 <http://sanjeewamalalgoda.blogspot.com/>blog :http://sanjeewamalalgoda.blo

Re: [Architecture] OpenAPI 3.0 support for API Manager 2.2.0

2018-01-25 Thread Sanjeewa Malalgoda
graded to 3.x >>>>>>>>>>version so that it will be supporting OpenAPI 3.0 spec while >>>>>>>>>> updating API >>>>>>>>>>source via Swagger Editor in API Publisher. >>>>>>>>>>

Re: [Architecture] [APIM] CLI support for Importing and Exporting Applications

2018-01-25 Thread Sanjeewa Malalgoda
gt;>> apimcli import-app -f staging/sampleApp.zip -e prod -u admin -p >>>>>> admin >>>>>> apimcli import-app -f qa/sampleApp.zip --preserveOwner >>>>>> --addSubscriptions -e prod >>>>>> >>

Re: [Architecture] [APIM][C5] Multi-Environment API Overview Feature

2018-01-24 Thread Sanjeewa Malalgoda
2> >> Web : http://wso2.com >> <http://wso2.com/signature> >> > > > > -- > *Renuka Fernando* > Software Engineering Intern | WSO2 Inc > > Email : ren...@wso2.com > Mobile : +94 76 667 8752 <076%20667%208752> > Web : http://wso2.com > <

Re: [Architecture] [RRT] Improving caching based on cache-control and ETag headers

2018-01-11 Thread Sanjeewa Malalgoda
eout >>>> configuration. >>>> >>>> 4. *Include an ‘Age’ header with the response* >>>> Cache mediator should return the true TTL value of a response without >>>> altering the value of the cache-control max-age header returne

Re: [Architecture] [MB4] Restful Admin API's for Message Broker

2018-01-10 Thread Sanjeewa Malalgoda
y of creating exchange, destination or consumer tag before we create it. Then we might need http head method as well. If you need to update que details then you have to use put as well. Ex: enable/disable auto delete after we create it first time. Also lets define proper response codes as well(201 to cr

Re: [Architecture] Scope Registration API for carbon-auth

2018-01-09 Thread Sanjeewa Malalgoda
ission checks. >>>- Keeping the security interceptor at the product level so each >>>product can implement their own security interceptor. >>> >>> Thanks! >>> >>> >>> On Tue, Jan 9, 2018 at 10:31 AM, Ishara Karunarathna >

[Architecture] Scope Registration API for carbon-auth

2018-01-08 Thread Sanjeewa Malalgoda
identity server team had experiences with this API they can provide suggestions for API and implementation. We will expose this as MSF4J based API from carbon auth run time. Lets use this thread to discuss all aspects of scope registration and finalize implementation. Thanks, sanjeewa. -- *Sanjeewa

Re: [Architecture] Gateway cache in APIM all in one active/active deployment without clustering

2017-12-15 Thread Sanjeewa Malalgoda
- Apache Stratos >> Senior Software Engineer >> WSO2, Inc.: http://wso2.com >> mobile : +94774078049 <%2B94772207163> >> >> > > > -- > Susankha Nirmala > Senior Software Engineer > WSO2, Inc.: http://wso2.com > lean.enterprise.middleware > > Mobile : +94 77 593 2146 <077%20593%202146> &

Re: [Architecture] Concurrency controlling for API Manager

2017-12-05 Thread Sanjeewa Malalgoda
oncurrency control etc is an aspect of Level >>>>> 2. And we strive towards Level 2 support. >>>>> >>>>> But this does not imply that each of our products are required to >>>>> support caching, long running request etc.. Which of these advanced >>&

Re: [Architecture] [APIM][C5] Multi Environment support with API difference for API Manager

2017-11-06 Thread Sanjeewa Malalgoda
;>>>> [2] https://github.com/wso2/carbon-apimgt/pull/4679 >>>>> >>>>> >>>>> Appreciate any suggestions. >>>>> Thanks >>>>> >>>>> Best regards >>>>> >>>>> -- >>>>

Re: [Architecture] [C5][APIM] Context Loading in API Gateway

2017-10-30 Thread Sanjeewa Malalgoda
nterprise . Middleware >>> >>> ___ >>> Architecture mailing list >>> Architecture@wso2.org >>> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >>> >>> >> >>

Re: [Architecture] [APIM] Extensibility of API Security Handler

2017-10-30 Thread Sanjeewa Malalgoda
ted users then anyway we might need to use extension for do certain things. Yes in APIM 3Xx we will not remove any of the existing capabilities. And we will specifically check federated user scenario. Thanks, sanjeewa. > > Regards, > Johann. > > On Mon, Oct 16, 2017 at

Re: [Architecture] [APIM][C5] API Manager entities(APIs/Applications/Docs etc..) permission model and group sharing.

2017-10-27 Thread Sanjeewa Malalgoda
; > This communication may contain privileged or other > confidential information and is intended exclusively for the addressee/s. > If you are not the intended recipient/s, or believe that you may > have received this communication in error, please reply to the > sender indicating that fact and delete the copy you received and in > addi

Re: [Architecture] Securing Product Apis and Product artifacts in Stream Processor

2017-10-25 Thread Sanjeewa Malalgoda
ism. Thanks, sanjeewa. > > > > > More information on the solution can be found at [1] > > > [1] https://docs.google.com/a/wso2.com/document/d/1vFP_GZcuLzJrk > RDV3mCfuSDkwC8eKClmp4zt-lUs1Ro/edit?usp=sharing > > -- > Best Regards, > *Niveathika Rajendran,* >

Re: [Architecture] [APIM] Extensibility of API Security Handler

2017-10-16 Thread Sanjeewa Malalgoda
ent in user store connected. So if its federated user then populate standard claims will be failed and we need to handle it. Thanks, sanjeewa. > > Thanks & Regards, > Johann. > > -- > > *Johann Dilantha Nallathamby* > Senior Lead Solutions Engineer > WSO2, Inc. &g

Re: [Architecture] CORS support for MSF4J

2017-10-10 Thread Sanjeewa Malalgoda
4j/issues/424>) >2. > > Have to change swagger2MSF4J ><https://github.com/sanjeewa-malalgoda/swagger2MSF4J> to have @OPTION >annotation method for all resources. >3. > >OPTION method has to be defined in swagger for all resources > > Option one

Re: [Architecture] [APIM][C5] Shall we add gateway health check capability

2017-10-10 Thread Sanjeewa Malalgoda
t;>> Architecture@wso2.org >>>>>> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture >>>>>> >>>>>> >>>>> >>>>> >>>>> -- >>>>> *Imesh Gunaratne* >>>>> Software

Re: [Architecture] Using Java Agent API for Latency and other Measurements

2017-10-06 Thread Sanjeewa Malalgoda
com/+IsuruPereraWSO2/about> > > _______ > Architecture mailing list > Architecture@wso2.org > https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture > > -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779 <http://s

Re: [Architecture] [IAM] Adding/Reloading X509 Certificates at Runtime without Restart

2017-10-06 Thread Sanjeewa Malalgoda
something we see valuable that can be added to IS 5.4.0 or 5.5.0? > > [1] https://wso2.org/jira/browse/IDENTITY-1131 > [2] https://github.com/wso2/carbon-identity/pull/1511 > > Thanks & Regards, > Johann. > > -- > > *Johann Dilantha Nallathamby* > Senior L

Re: [Architecture] [APIM] Supporting Thrift protocol for GW-KM communication with Load Balancing

2017-09-03 Thread Sanjeewa Malalgoda
t; ATL > Mobile : +94 777 625 933 <077%20762%205933> > +358 449 228 979 > > http://soasecurity.org/ > http://xacmlinfo.org/ > -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779 <http://sanjeewamalalgoda.blogspot.com/>blog :http://sanjeewamalalgoda.b

Re: [Architecture] [APIM] Threat Protection for API Manager

2017-08-22 Thread Sanjeewa Malalgoda
>>- >> >>Set correct permissions to local schema files (disallow write access) >>- >> >>IP whitelisting/blacklisting >>- >> >>Rate Limiting >>- >> >>Escaping All User Supplied Input >>

Re: [Architecture] [C5][APIM] Offline micro Gateway with API Key

2017-07-31 Thread Sanjeewa Malalgoda
On Tue, Aug 1, 2017 at 6:12 AM, Isuru Haththotuwa wrote: > On Mon, Jul 31, 2017 at 2:51 PM, Sanjeewa Malalgoda > wrote: > >> >> >> On Fri, Jul 28, 2017 at 1:12 PM, Sabeena Kumrawadu >> wrote: >> >>> Hi all, >>> >>> API

Re: [Architecture] [C5][APIM] Offline micro Gateway with API Key

2017-07-31 Thread Sanjeewa Malalgoda
ch appreciated. > > Thank you, > Best Regards. > > -- > *Sabeena Kumarawadu* | Software Engineering Intern > WSO2 Lanka (Pvt) Ltd. > #20, Palm Grove, Colombo 03, Sri Lanka > Mobile: +94 71 0372856 <071%20037%202856> > Email: sabe...@wso2.com > [image: http:/

Re: [Architecture] [DEV] Can we bind custom interceptors in msf4j2.3.0-m2

2017-06-08 Thread Sanjeewa Malalgoda
. >>>>>> We have a class called ABCRequestInterceptor which implements >>>>>> RequestInterceptor >>>>>> and there can be classes that extends >>>>>> ABCRequestInterceptor >>>>>> >>>

Re: [Architecture] [APIM][C5] SSO Feature for Publisher/Store Login

2017-05-23 Thread Sanjeewa Malalgoda
t; >> And I have following questions regarding this. >> >> 1. How do you configure this IDPs other than WSO2 identity server >> 2. How do you handle logout ? >> > I think we can revoke token when user logout happens. Thanks, sanjeewa. > >> -Ishara >> &

Re: [Architecture] [APIM][C5] SSO Feature for Publisher/Store Login

2017-05-21 Thread Sanjeewa Malalgoda
Mobile: 0719143658 <071%20914%203658> > [image: http://wso2.com/signature] <http://wso2.com/signature> > -- *Sanjeewa Malalgoda* WSO2 Inc. Mobile : +94713068779 <http://sanjeewamalalgoda.blogspot.com/>blog :http://sanjeewamalalgoda.blogspot.com/ <http://sanjeewamalalgod

  1   2   3   >