2 * ============LICENSE_START=======================================================
4 * ================================================================================
5 * Copyright (C) 2017 AT&T Intellectual Property. All rights reserved.
6 * ================================================================================
7 * Licensed under the Apache License, Version 2.0 (the "License");
8 * you may not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
11 * http://www.apache.org/licenses/LICENSE-2.0
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS,
15 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
18 * ============LICENSE_END=========================================================
21 package org.onap.policy.rest;
23 import com.att.research.xacml.util.XACMLProperties;
26 * These are XACML Properties that are relevant to the RESTful API interface for
27 * the PDP, PAP and AC interfaces.
31 public class XACMLRestProperties extends XACMLProperties {
33 * A unique identifier for the PDP servlet instance. Usually set to the URL
34 * it is running as in the J2EE container.
36 * Eg. http://localhost:8080/pdp/
38 public static final String PROP_PDP_ID = "xacml.rest.pdp.id";
40 * A PDP servlet's configuration directory. Holds the pip and policy
41 * configuration data as well as the local policy cache.
43 * Eg: /opt/app/xacml/config
45 public static final String PROP_PDP_CONFIG = "xacml.rest.pdp.config";
46 // Resilience feature-
47 public static final String PROP_PDP_WEBAPPS = "xacml.rest.pdp.webapps";
48 //Closed Loop JSON table
49 public static final String PROP_ADMIN_CLOSEDLOOP = "xacml.rest.admin.closedLoopJSON";
51 * Set this property to true or false if the PDP servlet should register
52 * itself upon startup with the PAP servlet.
54 public static final String PROP_PDP_REGISTER = "xacml.rest.pdp.register";
56 * Number of seconds the PDP will sleep while retrying registration with the
57 * PAP. This value must be greater or equal to 5.
59 public static final String PROP_PDP_REGISTER_SLEEP = "xacml.rest.pdp.register.sleep";
61 * Number of retry attempts at registration with the PAP. A value of -1
62 * indicates infinite retries.
64 public static final String PROP_PDP_REGISTER_RETRIES = "xacml.rest.pdp.register.retries";
66 * Max content length accepted for an incoming POST XML/JSON request.
67 * Default is 32767 bytes.
69 public static final String PROP_PDP_MAX_CONTENT = "xacml.rest.pdp.maxcontent";
71 * Custom HTTP header used by PDP to send the value of the PROP_PDP_ID
73 public static final String PROP_PDP_HTTP_HEADER_ID = "X-XACML-PDP-ID";
75 * Custom HHTP header used by PDP to send its heartbeat value.
77 public static final String PROP_PDP_HTTP_HEADER_HB = "X-XACML-PDP-HB";
79 * Custom HTTP header used by PDP to send the value of the
80 * X-XACML-PDP-JMX-PORT
82 public static final String PROP_PDP_HTTP_HEADER_JMX_PORT = "X-XACML-PDP-JMX-PORT";
84 * The URL of the PAP servlet. Used by PDP servlet's to communicate. Because
85 * administrators can set whatever context they want to run the PAP servlet,
86 * it isn't easy to determine a return URL for the PAP servlet. This is
87 * especially true upon initialization.
89 public static final String PROP_PAP_URL = "xacml.rest.pap.url";
91 * A comma divided list of urls pointing to avaiable PAP urls.
92 * If one or more fail, the other servers in the list can
93 * handle the requests.
95 public static final String PROP_PAP_URLS = "xacml.rest.pap.urls";
96 public static final String PROP_PAP_FAILED_URLS = "xacml.rest.pap.failedUrls";
97 public static final String PROP_PAP_SUCCEEDED_URLS = "xacml.rest.pap.succeededUrls";
98 //public static final String PROP_PAP_FAILED_URL_TIME = "xacml.rest.pap.failedUrlTime";
101 * Upon startup, have the PAP servlet send latest configuration information
102 * to all the PDP nodes it knows about.
104 public static final String PROP_PAP_INITIATE_PDP_CONFIG = "xacml.rest.pap.initiate.pdp";
106 * The interval the PAP servlet uses to send heartbeat requests to the PDP
109 public static final String PROP_PAP_HEARTBEAT_INTERVAL = "xacml.rest.pap.heartbeat.interval";
111 * Timeout value used by the PAP servlet when trying to check the heartbeat
114 public static final String PROP_PAP_HEARTBEAT_TIMEOUT = "xacml.rest.pap.heartbeat.timeout";
116 * This is the domain you can setup for your organization, it should be a URI.
119 public static final String PROP_PAP_DOMAIN = "xacml.rest.pap.domain";
122 * Local path to where user workspaces exist. The user workspace contains temporary files, the
123 * user's clone of the GIT repository, anything specific to the user, etc.
125 public static final String PROP_PAP_WORKSPACE = "xacml.rest.pap.workspace";
128 * Local path to where the GIT repository exists.
130 * Eg. /opt/app/xacml/repository
132 public static final String PROP_PAP_REPOSITORY = "xacml.rest.pap.repository";
135 * Database driver property
137 public static final String PROP_PAP_DB_DRIVER = "javax.persistence.jdbc.driver";
142 public static final String PROP_PAP_DB_URL = "javax.persistence.jdbc.url";
147 public static final String PROP_PAP_DB_USER = "javax.persistence.jdbc.user";
152 public static final String PROP_PAP_DB_PASSWORD = "javax.persistence.jdbc.password";
155 * Time in ms which a Policy DB transaction will wait to get the transaction lock object
157 public static final String PROP_PAP_TRANS_WAIT = "xacml.rest.pap.transaction.waitms";
160 * Policy DB transaction timeout in ms after it has obtained the transaction lock object
162 public static final String PROP_PAP_TRANS_TIMEOUT = "xacml.rest.pap.transaction.timeoutms";
165 * Policy Audit transaction timeout in ms after it has obtained the transaction lock object
167 public static final String PROP_PAP_AUDIT_TIMEOUT = "xacml.rest.pap.audit.timeoutms";
170 * Value determines direction of audit. Value=true will synch the file system to contents of the DB.
171 * Value=false will synch the DB to the contents of the file system.
173 public static final String PROP_PAP_AUDIT_FLAG = "xacml.rest.pap.filesystem.audit";
176 * Value for enable/disable of audit functionality
178 public static final String PROP_PAP_RUN_AUDIT_FLAG = "xacml.rest.pap.run.audit.flag";
181 * Controls how long the timeout will be when a pap sends a notification to another pap
183 public static final String PROP_PAP_NOTIFY_TIMEOUT = "xacml.rest.pap.notify.timeoutms";
185 * Value for Enable/Disable of AutoPush Flag.
187 public static final String PROP_PAP_PUSH_FLAG = "xacml.rest.pap.autopush.flag";
190 * Properties file for the AutoPush Functionality.
192 public static final String PROP_PAP_PUSH_FILE = "xacml.rest.pap.autopush.file";
195 * Local path to where the GIT repository exists.
197 * Eg. /opt/app/xacml/repository
199 public static final String PROP_ADMIN_REPOSITORY = "xacml.rest.admin.repository";
201 * Local path to where user workspaces exist. The user workspace contains
202 * temporary files, the user's clone of the GIT repository, anything
203 * specific to the user, etc.
205 public static final String PROP_ADMIN_WORKSPACE = "xacml.rest.admin.workspace";
207 * This is the domain you can setup for your organization, it should be a
212 public static final String PROP_ADMIN_DOMAIN = "xacml.rest.admin.domain";
214 * PROP_ADMIN_USER_NAME is simply a name for the logged in user.
216 * AC authentication is out the scope of the web application itself. It is
217 * up to the developer to setup authentication as they please in the J2EE
218 * container used to run the web application. Whatever authentication
219 * mechanism they use, they should then set the attribute into the
220 * HttpSession object. The Admin Console will be able to read that value
221 * (default to "guest") in.
223 * ((HttpServletRequest)
224 * request).getSession().setAttribute("xacml.rest.admin.user.name",
228 public static final String PROP_ADMIN_USER_NAME = "xacml.rest.admin.user.name";
231 * PROP_ADMIN_USER_ID is an id for the logged in user.
235 * @see #PROP_ADMIN_USER_NAME for more information.
237 public static final String PROP_ADMIN_USER_ID = "xacml.rest.admin.user.id";
240 * PROP_ADMIN_USER_EMAIL is a user's email address.
242 * @see #PROP_ADMIN_USER_NAME for more information.
244 public static final String PROP_ADMIN_USER_EMAIL = "xacml.rest.admin.user.email";
246 * Directory path containing sub-directories where the Subscriber servlet
247 * puts files sent through data feeds.
249 public static final String PROP_SUBSCRIBER_INCOMING = "xacml.subscriber.incoming";
251 * The specific data feed name for the Subscriber servlet to register for.
253 public static final String PROP_SUBSCRIBER_FEED = "xacml.subscriber.feed";
255 * Value for the log time frame that is to be stored in the database any
256 * logs after this time frame will be removed.
258 public static final String PROP_LOG_TIMEFRAME = "xacml.log.timeframe";
260 * Value for the DB connections used to store the log files.
262 public static final String PROP_LOG_DB_DRIVER = "xacml.log.db.driver";
263 public static final String PROP_LOG_DB_URL = "xacml.log.db.url";
264 public static final String PROP_LOG_DB_USER = "xacml.log.db.user";
265 public static final String PROP_LOG_DB_PASSWORD = "xacml.log.db.password";
267 * Value for JMX port for the PDP
269 public static final String PROP_PDP_JMX_PORT = "xacml.jmx.port";
272 * Value for refresh rate
274 public static final String PROP_REFRESH_RATE = "xacml.refresh.rate";
276 // added for Security between Policy Components.
279 * PROP_PAP_USERID is the PAP Unique User ID
281 public static final String PROP_PAP_USERID = "xacml.rest.pap.userid";
283 * PROP_PAP_PASS is the PAP password
285 public static final String PROP_PAP_PASS = "xacml.rest.pap.password";
287 * PROP_PAP_PASS is the PAP password
289 public static final String PROP_CONFIG_URL = "xacml.rest.config.url";
291 * PROP_PDP_USERID is the PDP Unique User ID
293 public static final String PROP_PDP_USERID = "xacml.rest.pdp.userid";
295 * PROP_PDP_PASS is the PDP password
297 public static final String PROP_PDP_PASS = "xacml.rest.pdp.password";
299 * PROP_PDP_IDFILE is the PDP Authentication File
301 public static final String PROP_PDP_IDFILE = "xacml.rest.pdp.idfile";
303 * PROP_PEP_IDFILE is the Client Authentication File
305 public static final String PROP_PEP_IDFILE = "xacml.rest.pep.idfile";
307 * webapps Location of the PAP-REST server
309 public static final String PROP_PAP_WEBAPPS= "xacml.rest.config.webapps";
311 * Value for Notification Option
313 public static final String PROP_NOTIFICATION_TYPE = "NOTIFICATION_TYPE";
315 * Value for Notification DMaaP servers
317 public static final String PROP_NOTIFICATION_SERVERS = "NOTIFICATION_SERVERS";
319 * Value for Notification Delay
321 public static final String PROP_NOTIFICATION_DELAY= "NOTIFICATION_DELAY";
323 * Value for Notification Topic
325 public static final String PROP_NOTIFICATION_TOPIC= "NOTIFICATION_TOPIC";
327 * Value for Notification Topic
329 public static final String PROP_UEB_API_KEY= "UEB_API_KEY";
331 * Value for Notification Topic
333 public static final String PROP_UEB_API_SECRET= "UEB_API_SECRET";
335 * Closedloop Fault Policy Template Version
337 public static final String TemplateVersion_Fault= "xacml.rest.closedLoopFault";
339 * Closedloop PM Policy Template Version
341 public static final String TemplateVersion_PM= "xacml.rest.closedLoopPM";
343 * Value for model properties file
345 public static final String PROP_ADMIN_MICROSERVICE = "xacml.rest.admin.microServiceModel";
347 * MicroService Policy Template Version
349 public static final String TemplateVersion_MS= "xacml.rest.microServices";
351 * Firewall Policy Template Version
353 public static final String TemplateVersion_FW= "xacml.rest.firewallPolicy";
355 * Size of SelectList for Users in MS
358 public static final String PROP_USER_SELECTLIST_WINDOW_SIZE= "xacml.user.column.count";
360 * Audit function in pap admin to Update userinfo table to syncronize with Roles table
362 public static final String PROP_ROLES_USERINFO_AUDIT= "xacml.audit.userInfo";
364 * test Environment LoginId
366 public static final String PROP_TEST_ENVIRONMENT_LOGINID= "xacml.testEnvironment.loginId";
368 * Size of of the page length for sqlcontainer
371 public static final String PROP_SQLCONTAINER_PAGE_LENGTH= "xacml.sqlcontainer.page.length";
373 * add values used to connect to restful api
376 public static final String PROP_RESTFUL_INTERFACE= "xacm.restful.interface.file";
378 * add pattern to identify what values are designed as required
381 public static final String PROP_XCORE_REQUIRED_PATTERN= "xacm.xcor.required.pattern";
383 * Time before a cache value is evicted
386 public static final String PROP_CACHE_LIVE_TIME= "xacm.cache.live.time";
388 * Highest value allowed in priority
391 public static final String PROP_PRIORITY_COUNT= "xacml.max.priority.count";
393 * The name of the PAP. Must be unique across the system
395 public static final String PAP_RESOURCE_NAME="xacml.rest.pap.resource.name";
397 * The name of the site in which the PAP resides
399 public static final String PAP_SITE_NAME="site_name";
401 * The node type of the PAP - really a no-op since it's value is pap
403 public static final String PAP_NODE_TYPE="node_type";
405 * A list of the groups of resources/nodes on which the PAP is dependent. The members of a
406 * group are comma-separated and the groups are separated with semicolons.
408 public static final String PAP_DEPENDENCY_GROUPS="dependency_groups";
410 * The (optional) period of time in seconds between executions of the integrity audit.
411 * Value < 0 : Audit does not run (default value if property is not present = -1)
412 * Value = 0 : Audit runs continuously
413 * Value > 0 : The period of time in seconds between execution of the audit on a particular node
415 public static final String PAP_INTEGRITY_AUDIT_PERIOD_SECONDS = "integrity_audit_period_seconds";
417 * The name of the Admin. Must be unique across the system
419 public static final String ADMIN_RESOURCE_NAME="xacml.rest.admin.resource.name";
421 * The name of the PDP. Must be unique across the system
423 public static final String PDP_RESOURCE_NAME="xacml.rest.pdp.resource.name";
425 * Audit function in pap admin to Update userinfo table to syncronize with Roles table
427 public static final String PROP_AUTOMATIC_POLICYPUSH= "xacml.automatic.push";
429 * Add Limit for Onap Portal Dashboard tab data
431 public static final String PROP_ONAP_LOGLIMIT = "xacml.onap.dashboard.logTableLimit";
432 public static final String PROP_ONAP_SYSTEMALERTLIMIT = "xacml.onap.dashboard.systemAlertTableLimit";
434 * Diff of the policies for the Firewall Feature.
436 public static final String PROP_FW_GETURL = "FW_GETURL";
437 public static final String PROP_FW_AUTHOURL = "FW_AUTHOURL";
438 public static final String PROP_FW_PROXY = "FW_PROXY";
439 public static final String PROP_FW_PORT = "FW_PORT";
442 * The number of Risk Levels allowed
444 public static final String ADMIN_RISK_LEVEL_COUNT="xacml.risk.level.count";
446 * The maxium Level displayed on the UI for Micro Services
448 public static final String PROP_MODEL_LEVEL = "xacml.model.level";
451 * Value for Incoming Notification tries
454 public static final String PROP_PAP_INCOMINGNOTIFICATION_TRIES = "xacml.rest.pap.incomingnotification.tries";