001package ca.cdr.api.model.json;
002
003/*-
004 * #%L
005 * Smile CDR - CDR
006 * %%
007 * Copyright (C) 2016 - 2026 Smile CDR, Inc.
008 * %%
009 * All rights reserved.
010 * #L%
011 */
012
013import ca.cdr.api.model.enm.Oauth2ClientAuthenticationMethodEnum;
014import com.fasterxml.jackson.annotation.JsonProperty;
015import com.fasterxml.jackson.annotation.JsonPropertyOrder;
016import io.swagger.v3.oas.annotations.media.Schema;
017
018import java.io.Serializable;
019import java.util.Date;
020
021import static ca.cdr.api.model.json.OAuth2ServerJson.ISSUER;
022import static ca.cdr.api.model.json.OAuth2ServerJson.MODULE_ID;
023import static ca.cdr.api.model.json.OAuth2ServerJson.NAME;
024import static ca.cdr.api.model.json.OAuth2ServerJson.NODE_ID;
025import static ca.cdr.api.model.json.OAuth2ServerJson.PID;
026
027@Schema(name = "OAuth2Server", description = "An OAuth2/OpenID Connect server definition")
028@JsonPropertyOrder(
029                value = {PID, NODE_ID, MODULE_ID, ISSUER, NAME},
030                alphabetic = true)
031public class OAuth2ServerJson implements IModelJson, Serializable {
032        public static final String PID = "pid";
033        public static final String NAME = "name";
034        public static final String ISSUER = "issuer";
035        public static final String NODE_ID = "nodeId";
036        public static final String MODULE_ID = "moduleId";
037
038        @JsonProperty(value = PID)
039        @Schema(description = "The internal persistence ID for this provider.", accessMode = Schema.AccessMode.READ_ONLY)
040        private Long myPid;
041
042        @JsonProperty(value = NAME)
043        @Schema(description = "A user friendly name/description of this provider.")
044        private String myName;
045
046        @JsonProperty(value = ISSUER)
047        @Schema(description = "The issuer URL.")
048        private String myIssuer;
049
050        @JsonProperty(value = "tokenIntrospectionClientId")
051        @Schema(
052                        description =
053                                        "The client ID to use when performing token introspection against this provider. The client ID and client secret may also be used for client authentication during code exchange if the `federationClientAuthenticationMethod` is set to a client secret method.")
054        private String myTokenIntrospectionClientId;
055
056        @JsonProperty(value = "tokenIntrospectionClientSecret")
057        @Schema(
058                        description =
059                                        "The client secret to use when performing token introspection against this provider. The client ID and client secret may also be used for client authentication during code exchange if the `federationClientAuthenticationMethod` is set to a client secret method.")
060        private String myTokenIntrospectionClientSecret;
061
062        @JsonProperty(value = NODE_ID)
063        @Schema(description = "The Node ID for the security module that this definition applies to.")
064        private String myNodeId;
065
066        @JsonProperty(value = MODULE_ID)
067        @Schema(description = "The security Module ID that this definition applies to.")
068        private String myModuleId;
069
070        @JsonProperty(value = "validationJwkText")
071        @Schema(
072                        description =
073                                        "A JSON document containing the JWK Set containing the public key used to validate signed tokens issued by this server. This is not required for federated server definitions but is required otherwise. This field does not need to be populated if the JWKS can be fetched using the well-known OpenID Connect configuration URL.")
074        private String myValidationJwkText;
075
076        @JsonProperty(value = "validationJwkFile")
077        @Schema(
078                        description =
079                                        "A local file path / classpath to use to supply the JWK Set containing the public key used to validate signed tokens issued by this server. This field applies only to non-federated providers. This field does not need to be populated if the JWKS can be fetched using the well-known OpenID Connect configuration URL.")
080        private String myValidationJwkFile;
081
082        @JsonProperty(value = "federationRegistrationId")
083        @Schema(
084                        description =
085                                        "A unique identifier for the federation between Smile CDR and the federated provider. If this is left blank, a unique value will be automatically created by Smile CDR. You may choose to use a more descriptive value however, as it will appear in URLs and log statements. Since this value will appear in URL paths, only letters and numbers should be used with no whitespace.")
086        private String myFederationRegistrationId;
087
088        @JsonProperty(value = "federationRequestScopes")
089        @Schema(
090                        description =
091                                        "When requesting authorization against the federated provider, this setting controls which OAuth2 scopes will be requested. Note that the scopes requested by the security module from the federated provider are independent from the scopes requested by the SMART application that is authorizing against Smile CDR. In a typical flow, a SMART on FHIR application will request SMART scopes from Smile CDR, and Smile CDR will in turn request a different set of appropriate scopes from the federated provider.")
092        private String myFederationRequestScopes;
093
094        @JsonProperty(value = "federationAuthorizationUrl")
095        @Schema(
096                        description =
097                                        "The URL to redirect the requesting user to in order to request user authentication/authorization with the federated provider.")
098        private String myFederationAuthorizationUrl;
099
100        @JsonProperty(value = "federationTokenUrl")
101        @Schema(
102                        description =
103                                        "This field is used in two ways. It is the service URL used by the SMART Outbound Security module for code exchange when requesting a token from the federated provider. It is also used in the system-to-system flow, as the token_endpoint for the client credentials flow, to retrieve a token from the remote payer. In the system-to-system flow this field takes precedence over `authWellKnownConfigUrl`: when it is set, no `.well-known` discovery request is made.")
104        private String myFederationTokenUrl;
105
106        @JsonProperty(value = "federationUserInfoUrl")
107        @Schema(description = "The service URL used by the SMART Outbound Security module for requesting user details.")
108        private String myFederationUserInfoUrl;
109
110        @JsonProperty(value = "federationJwkSetUrl")
111        @Schema(description = "The URL from which to obtain the federated provider's token signing public key.")
112        private String myFederationJwkSetUrl;
113
114        @JsonProperty(value = "federationAuthScriptText")
115        @Schema(
116                        description =
117                                        "When using Federated OAuth2/OIDC Login, a script is used to bridge between the user authorization details received from the federated provider and the requested authorization details in the originating SMART on FHIR application. This script is used to assign appropriate permissions and inject any other required details into the user session. It may obtain all required information by inspecting the access token details, or it may make additional service calls to fetch information.")
118        private String myFederationAuthScriptText;
119
120        @JsonProperty(value = "federationUserMappingScriptText")
121        @Schema(
122                        description =
123                                        "When using Federated OAuth2/OIDC Login, an optional script that is used to create Smile CDR user name from the federated login details.")
124        private String myFederationUserMappingScriptText;
125
126        @JsonProperty(value = "clientAuthenticationMethod")
127        @Schema(
128                        description =
129                                        "The OIDC client authentication mechanism to use during federated OIDC login when performing code exchange between Smile CDR and the federated provider.")
130        private Oauth2ClientAuthenticationMethodEnum myClientAuthenticationMethod;
131
132        @JsonProperty(value = "clientAuthenticationKeystoreId")
133        @Schema(
134                        description =
135                                        "If the client authentication method is set to `PRIVATE_KEY_JWT`, this property specifies the [Keystore ID](/docs/smart/oidc_keystores.html) to use for signing the credential JWT.")
136        private String myClientAuthenticationKeystoreId;
137
138        @JsonProperty(value = "fhirEndpointUrl")
139        @Schema(description = "The FHIR Endpoint URL associated to this OIDC Server. P2P specific-optional")
140        private String myFhirEndpointUrl;
141
142        @JsonProperty(value = "authWellKnownConfigUrl")
143        @Schema(
144                        description =
145                                        "The auth well-known configuration URL associated to this OIDC Server to retrieve fhir data. P2P specific-optional. In the system-to-system flow, this URL is fetched exactly as configured, including any query string, when `federationTokenUrl` is not set, and its token_endpoint is used. If neither this field nor `federationTokenUrl` is set, discovery uses `{fhirEndpointUrl}/.well-known/smart-configuration`.")
146        private String myAuthWellKnownConfigUrl;
147
148        @JsonProperty(value = "notes")
149        @Schema(description = "Registration URL, etc. P2P specific-optional")
150        private String myNotes;
151
152        @JsonProperty(value = "customTokenParams")
153        @Schema(description = "Customized token parameters for this OIDC Server. P2P specific-optional")
154        private String myCustomTokenParams;
155
156        @JsonProperty(value = "responseType")
157        @Schema(description = "The response type for the associated OIDC Server. P2P specific-optional")
158        private String myResponseType;
159
160        @JsonProperty(value = "organizationId")
161        @Schema(
162                        description =
163                                        "The identification code used to specify an organization or business. (i.e. Payer ID/A five digit standardized industry identify used by payers). P2P specific-optional")
164        private String myOrganizationId;
165
166        @JsonProperty(value = "audience")
167        @Schema(description = "The audience parameter. Defines the intended consumer of the token. P2P specific-optional")
168        private String myAudience;
169
170        @JsonProperty(value = "archivedAt")
171        @Schema(description = "The time at which this module was archived, if it has been.")
172        private Date myArchivedAt;
173
174        public String getIssuer() {
175                return myIssuer;
176        }
177
178        public OAuth2ServerJson setIssuer(String theIssuer) {
179                myIssuer = theIssuer;
180                return this;
181        }
182
183        public String getModuleId() {
184                return myModuleId;
185        }
186
187        public OAuth2ServerJson setModuleId(String theModuleId) {
188                myModuleId = theModuleId;
189                return this;
190        }
191
192        public String getName() {
193                return myName;
194        }
195
196        public void setName(String theName) {
197                myName = theName;
198        }
199
200        public String getNodeId() {
201                return myNodeId;
202        }
203
204        public OAuth2ServerJson setNodeId(String theNodeId) {
205                myNodeId = theNodeId;
206                return this;
207        }
208
209        public Long getPid() {
210                return myPid;
211        }
212
213        public void setPid(Long thePid) {
214                myPid = thePid;
215        }
216
217        public String getTokenIntrospectionClientId() {
218                return myTokenIntrospectionClientId;
219        }
220
221        public void setTokenIntrospectionClientId(String theTokenIntrospectionClientId) {
222                myTokenIntrospectionClientId = theTokenIntrospectionClientId;
223        }
224
225        public String getTokenIntrospectionClientSecret() {
226                return myTokenIntrospectionClientSecret;
227        }
228
229        public void setTokenIntrospectionClientSecret(String theTokenIntrospectionClientSecret) {
230                myTokenIntrospectionClientSecret = theTokenIntrospectionClientSecret;
231        }
232
233        public String getValidationJwkText() {
234                return myValidationJwkText;
235        }
236
237        public void setValidationJwkText(String theValidationJwkText) {
238                myValidationJwkText = theValidationJwkText;
239        }
240
241        public String getValidationJwkFile() {
242                return myValidationJwkFile;
243        }
244
245        public void setValidationJwkFile(String theValidationJwkFile) {
246                myValidationJwkFile = theValidationJwkFile;
247        }
248
249        public String getFederationRegistrationId() {
250                return myFederationRegistrationId;
251        }
252
253        public void setFederationRegistrationId(String theFederationRegistrationId) {
254                myFederationRegistrationId = theFederationRegistrationId;
255        }
256
257        public String getFederationRequestScopes() {
258                return myFederationRequestScopes;
259        }
260
261        public void setFederationRequestScopes(String theFederationRequestScopes) {
262                myFederationRequestScopes = theFederationRequestScopes;
263        }
264
265        public String getFederationAuthorizationUrl() {
266                return myFederationAuthorizationUrl;
267        }
268
269        public void setFederationAuthorizationUrl(String theFederationAuthorizationUrl) {
270                myFederationAuthorizationUrl = theFederationAuthorizationUrl;
271        }
272
273        public String getClientAuthenticationKeystoreId() {
274                return myClientAuthenticationKeystoreId;
275        }
276
277        public void setClientAuthenticationKeystoreId(String theClientAuthenticationKeystoreId) {
278                myClientAuthenticationKeystoreId = theClientAuthenticationKeystoreId;
279        }
280
281        public String getFederationTokenUrl() {
282                return myFederationTokenUrl;
283        }
284
285        public void setFederationTokenUrl(String theTokenUrl) {
286                myFederationTokenUrl = theTokenUrl;
287        }
288
289        public String getFederationUserInfoUrl() {
290                return myFederationUserInfoUrl;
291        }
292
293        public void setFederationUserInfoUrl(String theFederationUserInfoUrl) {
294                myFederationUserInfoUrl = theFederationUserInfoUrl;
295        }
296
297        public String getFederationJwkSetUrl() {
298                return myFederationJwkSetUrl;
299        }
300
301        public void setFederationJwkSetUrl(String theFederationJwkSetUrl) {
302                myFederationJwkSetUrl = theFederationJwkSetUrl;
303        }
304
305        public String getFederationAuthScriptText() {
306                return myFederationAuthScriptText;
307        }
308
309        public void setFederationAuthScriptText(String theFederationAuthScriptText) {
310                myFederationAuthScriptText = theFederationAuthScriptText;
311        }
312
313        public String getFederationUserMappingScriptText() {
314                return myFederationUserMappingScriptText;
315        }
316
317        public void setFederationUserMappingScriptText(String theFederationUserMappingScriptText) {
318                myFederationUserMappingScriptText = theFederationUserMappingScriptText;
319        }
320
321        public void setClientAuthenticationMethod(Oauth2ClientAuthenticationMethodEnum theClientAuthenticationMethod) {
322                myClientAuthenticationMethod = theClientAuthenticationMethod;
323        }
324
325        public Oauth2ClientAuthenticationMethodEnum getClientAuthenticationMethod() {
326                return myClientAuthenticationMethod;
327        }
328
329        public String getFhirEndpointUrl() {
330                return myFhirEndpointUrl;
331        }
332
333        public void setFhirEndpointUrl(String theFhirEndpointUrl) {
334                myFhirEndpointUrl = theFhirEndpointUrl;
335        }
336
337        public String getAuthWellKnownConfigUrl() {
338                return myAuthWellKnownConfigUrl;
339        }
340
341        public void setAuthWellKnownConfigUrl(String theAuthWellKnownConfigUrl) {
342                myAuthWellKnownConfigUrl = theAuthWellKnownConfigUrl;
343        }
344
345        public String getNotes() {
346                return myNotes;
347        }
348
349        public void setNotes(String theNotes) {
350                myNotes = theNotes;
351        }
352
353        public String getCustomTokenParams() {
354                return myCustomTokenParams;
355        }
356
357        public void setCustomTokenParams(String theCustomTokenParams) {
358                myCustomTokenParams = theCustomTokenParams;
359        }
360
361        public String getResponseType() {
362                return myResponseType;
363        }
364
365        public void setResponseType(String theResponseType) {
366                myResponseType = theResponseType;
367        }
368
369        public String getOrganizationId() {
370                return myOrganizationId;
371        }
372
373        public void setOrganizationId(String theOrganizationId) {
374                myOrganizationId = theOrganizationId;
375        }
376
377        public String getAudience() {
378                return myAudience;
379        }
380
381        public void setAudience(String theAudience) {
382                myAudience = theAudience;
383        }
384
385        public void setArchivedAt(Date theArchivedAt) {
386                myArchivedAt = theArchivedAt;
387        }
388
389        public Date getArchivedAt() {
390                return myArchivedAt;
391        }
392}