001package ca.cdr.api.model.json; 002 003/*- 004 * #%L 005 * Smile CDR - CDR 006 * %% 007 * Copyright (C) 2016 - 2026 Smile CDR, Inc. 008 * %% 009 * All rights reserved. 010 * #L% 011 */ 012 013import ca.cdr.api.model.enm.Oauth2ClientAuthenticationMethodEnum; 014import com.fasterxml.jackson.annotation.JsonProperty; 015import com.fasterxml.jackson.annotation.JsonPropertyOrder; 016import io.swagger.v3.oas.annotations.media.Schema; 017 018import java.io.Serializable; 019import java.util.Date; 020 021import static ca.cdr.api.model.json.OAuth2ServerJson.ISSUER; 022import static ca.cdr.api.model.json.OAuth2ServerJson.MODULE_ID; 023import static ca.cdr.api.model.json.OAuth2ServerJson.NAME; 024import static ca.cdr.api.model.json.OAuth2ServerJson.NODE_ID; 025import static ca.cdr.api.model.json.OAuth2ServerJson.PID; 026 027@Schema(name = "OAuth2Server", description = "An OAuth2/OpenID Connect server definition") 028@JsonPropertyOrder( 029 value = {PID, NODE_ID, MODULE_ID, ISSUER, NAME}, 030 alphabetic = true) 031public class OAuth2ServerJson implements IModelJson, Serializable { 032 public static final String PID = "pid"; 033 public static final String NAME = "name"; 034 public static final String ISSUER = "issuer"; 035 public static final String NODE_ID = "nodeId"; 036 public static final String MODULE_ID = "moduleId"; 037 038 @JsonProperty(value = PID) 039 @Schema(description = "The internal persistence ID for this provider.", accessMode = Schema.AccessMode.READ_ONLY) 040 private Long myPid; 041 042 @JsonProperty(value = NAME) 043 @Schema(description = "A user friendly name/description of this provider.") 044 private String myName; 045 046 @JsonProperty(value = ISSUER) 047 @Schema(description = "The issuer URL.") 048 private String myIssuer; 049 050 @JsonProperty(value = "tokenIntrospectionClientId") 051 @Schema( 052 description = 053 "The client ID to use when performing token introspection against this provider. The client ID and client secret may also be used for client authentication during code exchange if the `federationClientAuthenticationMethod` is set to a client secret method.") 054 private String myTokenIntrospectionClientId; 055 056 @JsonProperty(value = "tokenIntrospectionClientSecret") 057 @Schema( 058 description = 059 "The client secret to use when performing token introspection against this provider. The client ID and client secret may also be used for client authentication during code exchange if the `federationClientAuthenticationMethod` is set to a client secret method.") 060 private String myTokenIntrospectionClientSecret; 061 062 @JsonProperty(value = NODE_ID) 063 @Schema(description = "The Node ID for the security module that this definition applies to.") 064 private String myNodeId; 065 066 @JsonProperty(value = MODULE_ID) 067 @Schema(description = "The security Module ID that this definition applies to.") 068 private String myModuleId; 069 070 @JsonProperty(value = "validationJwkText") 071 @Schema( 072 description = 073 "A JSON document containing the JWK Set containing the public key used to validate signed tokens issued by this server. This is not required for federated server definitions but is required otherwise. This field does not need to be populated if the JWKS can be fetched using the well-known OpenID Connect configuration URL.") 074 private String myValidationJwkText; 075 076 @JsonProperty(value = "validationJwkFile") 077 @Schema( 078 description = 079 "A local file path / classpath to use to supply the JWK Set containing the public key used to validate signed tokens issued by this server. This field applies only to non-federated providers. This field does not need to be populated if the JWKS can be fetched using the well-known OpenID Connect configuration URL.") 080 private String myValidationJwkFile; 081 082 @JsonProperty(value = "federationRegistrationId") 083 @Schema( 084 description = 085 "A unique identifier for the federation between Smile CDR and the federated provider. If this is left blank, a unique value will be automatically created by Smile CDR. You may choose to use a more descriptive value however, as it will appear in URLs and log statements. Since this value will appear in URL paths, only letters and numbers should be used with no whitespace.") 086 private String myFederationRegistrationId; 087 088 @JsonProperty(value = "federationRequestScopes") 089 @Schema( 090 description = 091 "When requesting authorization against the federated provider, this setting controls which OAuth2 scopes will be requested. Note that the scopes requested by the security module from the federated provider are independent from the scopes requested by the SMART application that is authorizing against Smile CDR. In a typical flow, a SMART on FHIR application will request SMART scopes from Smile CDR, and Smile CDR will in turn request a different set of appropriate scopes from the federated provider.") 092 private String myFederationRequestScopes; 093 094 @JsonProperty(value = "federationAuthorizationUrl") 095 @Schema( 096 description = 097 "The URL to redirect the requesting user to in order to request user authentication/authorization with the federated provider.") 098 private String myFederationAuthorizationUrl; 099 100 @JsonProperty(value = "federationTokenUrl") 101 @Schema( 102 description = 103 "This field is used in two ways. It is the service URL used by the SMART Outbound Security module for code exchange when requesting a token from the federated provider. It is also used in the system-to-system flow, as the token_endpoint for the client credentials flow, to retrieve a token from the remote payer. In the system-to-system flow this field takes precedence over `authWellKnownConfigUrl`: when it is set, no `.well-known` discovery request is made.") 104 private String myFederationTokenUrl; 105 106 @JsonProperty(value = "federationUserInfoUrl") 107 @Schema(description = "The service URL used by the SMART Outbound Security module for requesting user details.") 108 private String myFederationUserInfoUrl; 109 110 @JsonProperty(value = "federationJwkSetUrl") 111 @Schema(description = "The URL from which to obtain the federated provider's token signing public key.") 112 private String myFederationJwkSetUrl; 113 114 @JsonProperty(value = "federationAuthScriptText") 115 @Schema( 116 description = 117 "When using Federated OAuth2/OIDC Login, a script is used to bridge between the user authorization details received from the federated provider and the requested authorization details in the originating SMART on FHIR application. This script is used to assign appropriate permissions and inject any other required details into the user session. It may obtain all required information by inspecting the access token details, or it may make additional service calls to fetch information.") 118 private String myFederationAuthScriptText; 119 120 @JsonProperty(value = "federationUserMappingScriptText") 121 @Schema( 122 description = 123 "When using Federated OAuth2/OIDC Login, an optional script that is used to create Smile CDR user name from the federated login details.") 124 private String myFederationUserMappingScriptText; 125 126 @JsonProperty(value = "clientAuthenticationMethod") 127 @Schema( 128 description = 129 "The OIDC client authentication mechanism to use during federated OIDC login when performing code exchange between Smile CDR and the federated provider.") 130 private Oauth2ClientAuthenticationMethodEnum myClientAuthenticationMethod; 131 132 @JsonProperty(value = "clientAuthenticationKeystoreId") 133 @Schema( 134 description = 135 "If the client authentication method is set to `PRIVATE_KEY_JWT`, this property specifies the [Keystore ID](/docs/smart/oidc_keystores.html) to use for signing the credential JWT.") 136 private String myClientAuthenticationKeystoreId; 137 138 @JsonProperty(value = "fhirEndpointUrl") 139 @Schema(description = "The FHIR Endpoint URL associated to this OIDC Server. P2P specific-optional") 140 private String myFhirEndpointUrl; 141 142 @JsonProperty(value = "authWellKnownConfigUrl") 143 @Schema( 144 description = 145 "The auth well-known configuration URL associated to this OIDC Server to retrieve fhir data. P2P specific-optional. In the system-to-system flow, this URL is fetched exactly as configured, including any query string, when `federationTokenUrl` is not set, and its token_endpoint is used. If neither this field nor `federationTokenUrl` is set, discovery uses `{fhirEndpointUrl}/.well-known/smart-configuration`.") 146 private String myAuthWellKnownConfigUrl; 147 148 @JsonProperty(value = "notes") 149 @Schema(description = "Registration URL, etc. P2P specific-optional") 150 private String myNotes; 151 152 @JsonProperty(value = "customTokenParams") 153 @Schema(description = "Customized token parameters for this OIDC Server. P2P specific-optional") 154 private String myCustomTokenParams; 155 156 @JsonProperty(value = "responseType") 157 @Schema(description = "The response type for the associated OIDC Server. P2P specific-optional") 158 private String myResponseType; 159 160 @JsonProperty(value = "organizationId") 161 @Schema( 162 description = 163 "The identification code used to specify an organization or business. (i.e. Payer ID/A five digit standardized industry identify used by payers). P2P specific-optional") 164 private String myOrganizationId; 165 166 @JsonProperty(value = "audience") 167 @Schema(description = "The audience parameter. Defines the intended consumer of the token. P2P specific-optional") 168 private String myAudience; 169 170 @JsonProperty(value = "archivedAt") 171 @Schema(description = "The time at which this module was archived, if it has been.") 172 private Date myArchivedAt; 173 174 public String getIssuer() { 175 return myIssuer; 176 } 177 178 public OAuth2ServerJson setIssuer(String theIssuer) { 179 myIssuer = theIssuer; 180 return this; 181 } 182 183 public String getModuleId() { 184 return myModuleId; 185 } 186 187 public OAuth2ServerJson setModuleId(String theModuleId) { 188 myModuleId = theModuleId; 189 return this; 190 } 191 192 public String getName() { 193 return myName; 194 } 195 196 public void setName(String theName) { 197 myName = theName; 198 } 199 200 public String getNodeId() { 201 return myNodeId; 202 } 203 204 public OAuth2ServerJson setNodeId(String theNodeId) { 205 myNodeId = theNodeId; 206 return this; 207 } 208 209 public Long getPid() { 210 return myPid; 211 } 212 213 public void setPid(Long thePid) { 214 myPid = thePid; 215 } 216 217 public String getTokenIntrospectionClientId() { 218 return myTokenIntrospectionClientId; 219 } 220 221 public void setTokenIntrospectionClientId(String theTokenIntrospectionClientId) { 222 myTokenIntrospectionClientId = theTokenIntrospectionClientId; 223 } 224 225 public String getTokenIntrospectionClientSecret() { 226 return myTokenIntrospectionClientSecret; 227 } 228 229 public void setTokenIntrospectionClientSecret(String theTokenIntrospectionClientSecret) { 230 myTokenIntrospectionClientSecret = theTokenIntrospectionClientSecret; 231 } 232 233 public String getValidationJwkText() { 234 return myValidationJwkText; 235 } 236 237 public void setValidationJwkText(String theValidationJwkText) { 238 myValidationJwkText = theValidationJwkText; 239 } 240 241 public String getValidationJwkFile() { 242 return myValidationJwkFile; 243 } 244 245 public void setValidationJwkFile(String theValidationJwkFile) { 246 myValidationJwkFile = theValidationJwkFile; 247 } 248 249 public String getFederationRegistrationId() { 250 return myFederationRegistrationId; 251 } 252 253 public void setFederationRegistrationId(String theFederationRegistrationId) { 254 myFederationRegistrationId = theFederationRegistrationId; 255 } 256 257 public String getFederationRequestScopes() { 258 return myFederationRequestScopes; 259 } 260 261 public void setFederationRequestScopes(String theFederationRequestScopes) { 262 myFederationRequestScopes = theFederationRequestScopes; 263 } 264 265 public String getFederationAuthorizationUrl() { 266 return myFederationAuthorizationUrl; 267 } 268 269 public void setFederationAuthorizationUrl(String theFederationAuthorizationUrl) { 270 myFederationAuthorizationUrl = theFederationAuthorizationUrl; 271 } 272 273 public String getClientAuthenticationKeystoreId() { 274 return myClientAuthenticationKeystoreId; 275 } 276 277 public void setClientAuthenticationKeystoreId(String theClientAuthenticationKeystoreId) { 278 myClientAuthenticationKeystoreId = theClientAuthenticationKeystoreId; 279 } 280 281 public String getFederationTokenUrl() { 282 return myFederationTokenUrl; 283 } 284 285 public void setFederationTokenUrl(String theTokenUrl) { 286 myFederationTokenUrl = theTokenUrl; 287 } 288 289 public String getFederationUserInfoUrl() { 290 return myFederationUserInfoUrl; 291 } 292 293 public void setFederationUserInfoUrl(String theFederationUserInfoUrl) { 294 myFederationUserInfoUrl = theFederationUserInfoUrl; 295 } 296 297 public String getFederationJwkSetUrl() { 298 return myFederationJwkSetUrl; 299 } 300 301 public void setFederationJwkSetUrl(String theFederationJwkSetUrl) { 302 myFederationJwkSetUrl = theFederationJwkSetUrl; 303 } 304 305 public String getFederationAuthScriptText() { 306 return myFederationAuthScriptText; 307 } 308 309 public void setFederationAuthScriptText(String theFederationAuthScriptText) { 310 myFederationAuthScriptText = theFederationAuthScriptText; 311 } 312 313 public String getFederationUserMappingScriptText() { 314 return myFederationUserMappingScriptText; 315 } 316 317 public void setFederationUserMappingScriptText(String theFederationUserMappingScriptText) { 318 myFederationUserMappingScriptText = theFederationUserMappingScriptText; 319 } 320 321 public void setClientAuthenticationMethod(Oauth2ClientAuthenticationMethodEnum theClientAuthenticationMethod) { 322 myClientAuthenticationMethod = theClientAuthenticationMethod; 323 } 324 325 public Oauth2ClientAuthenticationMethodEnum getClientAuthenticationMethod() { 326 return myClientAuthenticationMethod; 327 } 328 329 public String getFhirEndpointUrl() { 330 return myFhirEndpointUrl; 331 } 332 333 public void setFhirEndpointUrl(String theFhirEndpointUrl) { 334 myFhirEndpointUrl = theFhirEndpointUrl; 335 } 336 337 public String getAuthWellKnownConfigUrl() { 338 return myAuthWellKnownConfigUrl; 339 } 340 341 public void setAuthWellKnownConfigUrl(String theAuthWellKnownConfigUrl) { 342 myAuthWellKnownConfigUrl = theAuthWellKnownConfigUrl; 343 } 344 345 public String getNotes() { 346 return myNotes; 347 } 348 349 public void setNotes(String theNotes) { 350 myNotes = theNotes; 351 } 352 353 public String getCustomTokenParams() { 354 return myCustomTokenParams; 355 } 356 357 public void setCustomTokenParams(String theCustomTokenParams) { 358 myCustomTokenParams = theCustomTokenParams; 359 } 360 361 public String getResponseType() { 362 return myResponseType; 363 } 364 365 public void setResponseType(String theResponseType) { 366 myResponseType = theResponseType; 367 } 368 369 public String getOrganizationId() { 370 return myOrganizationId; 371 } 372 373 public void setOrganizationId(String theOrganizationId) { 374 myOrganizationId = theOrganizationId; 375 } 376 377 public String getAudience() { 378 return myAudience; 379 } 380 381 public void setAudience(String theAudience) { 382 myAudience = theAudience; 383 } 384 385 public void setArchivedAt(Date theArchivedAt) { 386 myArchivedAt = theArchivedAt; 387 } 388 389 public Date getArchivedAt() { 390 return myArchivedAt; 391 } 392}