001/*-
002 * #%L
003 * Smile CDR - CDR
004 * %%
005 * Copyright (C) 2016 - 2026 Smile CDR, Inc.
006 * %%
007 * All rights reserved.
008 * #L%
009 */
010package ca.cdr.api.model.json.oauth;
011
012import ca.uhn.fhir.model.api.IModelJson;
013import ca.uhn.fhir.rest.server.exceptions.InternalErrorException;
014import com.fasterxml.jackson.annotation.JsonAnySetter;
015import com.fasterxml.jackson.annotation.JsonIgnoreProperties;
016import com.fasterxml.jackson.annotation.JsonProperty;
017import io.swagger.v3.oas.annotations.media.Schema;
018import tools.jackson.core.JacksonException;
019import tools.jackson.databind.ObjectMapper;
020import tools.jackson.databind.json.JsonMapper;
021
022import java.lang.reflect.Field;
023import java.util.ArrayList;
024import java.util.HashMap;
025import java.util.List;
026import java.util.Map;
027
028@JsonIgnoreProperties(ignoreUnknown = true)
029@Schema(
030                name = "OpenIdWellKnownOpenIdConfigurationResponse",
031                description = "This object represents the response from an Identity Provider's .well-known endpoint.")
032public class OpenIdWellKnownOpenIdConfigurationResponseJson implements IModelJson {
033
034        /* CHECKSTYLE.OFF: RegexpSingleLine - these json property names are spec compliant and should not be changed */
035
036        /**
037         * Authorization server's issuer identifier url
038         */
039        @JsonProperty(value = "issuer", required = true)
040        private String myIssuer;
041
042        /**
043         * URL of the authorization server's authorization endpoint
044         * REQUIRED unless no grant types are supported that use authorization endpoint
045         */
046        @JsonProperty("authorization_endpoint")
047        private String myAuthorizationEndpoint;
048
049        /**
050         * URL of the auth server's token endpoint
051         * REQUIRED unless only the implicit grant type is supported
052         */
053        @JsonProperty("token_endpoint")
054        private String myTokenEndpoint;
055
056        /**
057         * JSON array of subject identifier types that this OP supports
058         * (pairwise, public)
059         */
060        @JsonProperty(value = "subject_types_supported", required = true)
061        private List<String> mySubjectTypesSupported;
062
063        /**
064         * URL of the auth server's JWK Set document
065         */
066        @JsonProperty(value = "jwks_uri", required = false)
067        private String myJwkUri;
068
069        /**
070         * URL of the auth server's OAuth 2.0 Dynamic Client Registration Endpoint
071         */
072        @JsonProperty(value = "registration_endpoint", required = false)
073        private String myDynamicClientRegistrationEndpoint;
074
075        /**
076         * JSON array containing a list of the OAuth 2.0 "scopes" values that this auth
077         * server supports.
078         * RECOMMENDED
079         */
080        @JsonProperty("scopes_supported")
081        private List<String> mySupportedScopes;
082
083        /**
084         * JSON array containing a list of the oauth 2.0 "response_type" values
085         * that this auth server supports.
086         */
087        @JsonProperty(value = "response_types_supported", required = true)
088        private List<String> mySupportedResponseTypes;
089
090        /**
091         * JSON array containing a list of the oauth 2.0 "response_mode" values that this
092         * auth server supports
093         */
094        @JsonProperty(value = "response_modes_supported", required = false)
095        private List<String> mySupportedResponseModes;
096
097        /**
098         * JSON array containing a list of the oauth
099         * 2.0 grant type values that this auth server supports
100         */
101        @JsonProperty(value = "grant_types_supported", required = false)
102        private List<String> mySupportedGrantTypes;
103
104        /**
105         * JSON array containing a list of the client authentication methods supported by this token
106         * endpoint
107         */
108        @JsonProperty(value = "token_endpoint_auth_methods_supported", required = false)
109        private List<String> mySupportedAuthenticationMethods;
110
111        /**
112         * JSON array of list of the JWS Signing algorithms supported by
113         * the token endpoint for the signature on the JWT used
114         * to authenticate the client at the token endpoint
115         */
116        @JsonProperty(value = "token_endpoint_auth_signing_alg_values_supported", required = false)
117        private List<String> mySupportedJWSSigningAlgorithms;
118
119        /**
120         * URL of the auth server's oauth 2.0
121         * revocation endpoint
122         */
123        @JsonProperty(value = "revocation_endpoint", required = false)
124        private String myRevocationEndpoint;
125
126        /**
127         * JSON array of client auth methods supported by this
128         * revocation endpoint.
129         */
130        @JsonProperty(value = "revocation_endpoint_auth_methods_supported", required = false)
131        private List<String> mySupportedAuthMethodsForRevocation;
132
133        /**
134         * JSON array of the JWS signing algorithms supported by the
135         * revocation endpoint for the signature on the JWT used to authenticate the client.
136         */
137        @JsonProperty(value = "revocation_endpoint_auth_signing_alg_values_supported", required = false)
138        private List<String> myRevocationEndpointSigningAlgorithms;
139
140        /**
141         * URL of the auth server's oauth2.0 introspection endpoint
142         */
143        @JsonProperty(value = "introspection_endpoint", required = false)
144        private String myIntrospectionEndpoint;
145
146        /**
147         * JSON array of the client auth methods supported by this introspection
148         * endpoint.
149         */
150        @JsonProperty(value = "introspection_endpoint_auth_methods_supported", required = false)
151        private List<String> mySupportedIntrospectionEndpointAuthMethods;
152
153        /**
154         * User info url.
155         * RECOMMENDED
156         */
157        @JsonProperty("userinfo_endpoint")
158        private String myUserInfoEndpoint;
159
160        /**
161         * JSON array of signing algs supported for id token
162         */
163        @JsonProperty(value = "id_token_signing_alg_values_supported", required = true)
164        private List<String> mySupportedIdTokenSigningAlgs;
165
166        /**
167         * JSON array containing a list of proof key for code exchange (PCKE flow) code
168         * challenge methods supported by this auth server
169         */
170        @JsonProperty(value = "code_challenge_methods_supported", required = false)
171        private List<String> myCodeChallengeMethodsSupported;
172
173        /* CHECKSTYLE.ON: RegexpSingleLine */
174
175        /**
176         * We will store all unknown properties in a map during deserialization;
177         * if these properties are not in fact "unknown" but part of the spec,
178         * please add them above, but leave this map.
179         */
180        private final Map<String, Object> myUnknownProperties = new HashMap<>();
181
182        public String getIssuer() {
183                return myIssuer;
184        }
185
186        public void setIssuer(String theIssuer) {
187                myIssuer = theIssuer;
188        }
189
190        public String getAuthorizationEndpoint() {
191                return myAuthorizationEndpoint;
192        }
193
194        public void setAuthorizationEndpoint(String theAuthorizationEndpoint) {
195                myAuthorizationEndpoint = theAuthorizationEndpoint;
196        }
197
198        public String getTokenEndpoint() {
199                return myTokenEndpoint;
200        }
201
202        public void setTokenEndpoint(String theTokenEndpoint) {
203                myTokenEndpoint = theTokenEndpoint;
204        }
205
206        public String getJwkUri() {
207                return myJwkUri;
208        }
209
210        public void setJwkUri(String theJwkUri) {
211                myJwkUri = theJwkUri;
212        }
213
214        public String getDynamicClientRegistrationEndpoint() {
215                return myDynamicClientRegistrationEndpoint;
216        }
217
218        public void setDynamicClientRegistrationEndpoint(String theDynamicClientRegistrationEndpoint) {
219                myDynamicClientRegistrationEndpoint = theDynamicClientRegistrationEndpoint;
220        }
221
222        public List<String> getSupportedScopes() {
223                if (mySupportedScopes == null) {
224                        mySupportedScopes = new ArrayList<>();
225                }
226                return mySupportedScopes;
227        }
228
229        public void setSupportedScopes(List<String> theSupportedScopes) {
230                mySupportedScopes = theSupportedScopes;
231        }
232
233        public void addSupportedScope(String theScope) {
234                getSupportedScopes().add(theScope);
235        }
236
237        public List<String> getSupportedResponseTypes() {
238                if (mySupportedResponseTypes == null) {
239                        mySupportedResponseTypes = new ArrayList<>();
240                }
241                return mySupportedResponseTypes;
242        }
243
244        public void setSupportedResponseTypes(List<String> theSupportedResponseTypes) {
245                mySupportedResponseTypes = theSupportedResponseTypes;
246        }
247
248        public void addSupportedResponseType(String theResponseType) {
249                getSupportedResponseTypes().add(theResponseType);
250        }
251
252        public List<String> getSupportedResponseModes() {
253                if (mySupportedResponseModes == null) {
254                        mySupportedResponseModes = new ArrayList<>();
255                }
256                return mySupportedResponseModes;
257        }
258
259        public void setSupportedResponseModes(List<String> theSupportedResponseModes) {
260                mySupportedResponseModes = theSupportedResponseModes;
261        }
262
263        public void addSupportedResponseMode(String theMode) {
264                getSupportedResponseModes().add(theMode);
265        }
266
267        public List<String> getSupportedGrantTypes() {
268                if (mySupportedGrantTypes == null) {
269                        mySupportedGrantTypes = new ArrayList<>();
270                }
271                return mySupportedGrantTypes;
272        }
273
274        public void setSupportedGrantTypes(List<String> theSupportedGrantTypes) {
275                mySupportedGrantTypes = theSupportedGrantTypes;
276        }
277
278        public void addSupportedGrantType(String theGrantType) {
279                getSupportedGrantTypes().add(theGrantType);
280        }
281
282        public List<String> getSupportedAuthenticationMethods() {
283                if (mySupportedAuthenticationMethods == null) {
284                        mySupportedAuthenticationMethods = new ArrayList<>();
285                }
286                return mySupportedAuthenticationMethods;
287        }
288
289        public void setSupportedAuthenticationMethods(List<String> theSupportedAuthenticationMethods) {
290                mySupportedAuthenticationMethods = theSupportedAuthenticationMethods;
291        }
292
293        public void addSupportedAuthenticationMethod(String theMethod) {
294                getSupportedAuthenticationMethods().add(theMethod);
295        }
296
297        public List<String> getSupportedJWSSigningAlgorithms() {
298                if (mySupportedJWSSigningAlgorithms == null) {
299                        mySupportedJWSSigningAlgorithms = new ArrayList<>();
300                }
301                return mySupportedJWSSigningAlgorithms;
302        }
303
304        public void setSupportedJWSSigningAlgorithms(List<String> theSupportedJWSSigningAlgorithms) {
305                mySupportedJWSSigningAlgorithms = theSupportedJWSSigningAlgorithms;
306        }
307
308        public void addSupportedJWSSigningAlgorithm(String theAlg) {
309                getSupportedJWSSigningAlgorithms().add(theAlg);
310        }
311
312        public String getRevocationEndpoint() {
313                return myRevocationEndpoint;
314        }
315
316        public void setRevocationEndpoint(String theRevocationEndpoint) {
317                myRevocationEndpoint = theRevocationEndpoint;
318        }
319
320        public List<String> getSupportedAuthMethodsForRevocation() {
321                if (mySupportedAuthMethodsForRevocation == null) {
322                        mySupportedAuthMethodsForRevocation = new ArrayList<>();
323                }
324                return mySupportedAuthMethodsForRevocation;
325        }
326
327        public void setSupportedAuthMethodsForRevocation(List<String> theSupportedAuthMethodsForRevocation) {
328                mySupportedAuthMethodsForRevocation = theSupportedAuthMethodsForRevocation;
329        }
330
331        public void addSupportedAuthMethodForRevocation(String theMethod) {
332                getSupportedAuthenticationMethods().add(theMethod);
333        }
334
335        public List<String> getRevocationEndpointSigningAlgorithms() {
336                if (myRevocationEndpointSigningAlgorithms == null) {
337                        myRevocationEndpointSigningAlgorithms = new ArrayList<>();
338                }
339                return myRevocationEndpointSigningAlgorithms;
340        }
341
342        public void setRevocationEndpointSigningAlgorithms(List<String> theRevocationEndpointSigningAlgorithms) {
343                myRevocationEndpointSigningAlgorithms = theRevocationEndpointSigningAlgorithms;
344        }
345
346        public void addRevocationEndpointSigningAlgorithm(String theAlg) {
347                getRevocationEndpointSigningAlgorithms().add(theAlg);
348        }
349
350        public String getIntrospectionEndpoint() {
351                return myIntrospectionEndpoint;
352        }
353
354        public void setIntrospectionEndpoint(String theIntrospectionEndpoint) {
355                myIntrospectionEndpoint = theIntrospectionEndpoint;
356        }
357
358        public List<String> getSupportedIntrospectionEndpointAuthMethods() {
359                if (mySupportedIntrospectionEndpointAuthMethods == null) {
360                        mySupportedIntrospectionEndpointAuthMethods = new ArrayList<>();
361                }
362                return mySupportedIntrospectionEndpointAuthMethods;
363        }
364
365        public void setSupportedIntrospectionEndpointAuthMethods(
366                        List<String> theSupportedIntrospectionEndpointAuthMethods) {
367                mySupportedIntrospectionEndpointAuthMethods = theSupportedIntrospectionEndpointAuthMethods;
368        }
369
370        public void addSupportedIntrospectionEndpointAuthMethod(String theMethod) {
371                getSupportedIntrospectionEndpointAuthMethods().add(theMethod);
372        }
373
374        public String getUserInfoEndpoint() {
375                return myUserInfoEndpoint;
376        }
377
378        public void setUserInfoEndpoint(String theUserInfoEndpoint) {
379                myUserInfoEndpoint = theUserInfoEndpoint;
380        }
381
382        public List<String> getSupportedIdTokenSigningAlgs() {
383                if (mySupportedIdTokenSigningAlgs == null) {
384                        mySupportedIdTokenSigningAlgs = new ArrayList<>();
385                }
386                return mySupportedIdTokenSigningAlgs;
387        }
388
389        public void setSupportedIdTokenSigningAlgs(List<String> theSupportedIdTokenSigningAlgs) {
390                mySupportedIdTokenSigningAlgs = theSupportedIdTokenSigningAlgs;
391        }
392
393        public void addSupportedIdTokenSigningAlg(String theAlg) {
394                getSupportedIdTokenSigningAlgs().add(theAlg);
395        }
396
397        public List<String> getCodeChallengeMethodsSupported() {
398                if (myCodeChallengeMethodsSupported == null) {
399                        myCodeChallengeMethodsSupported = new ArrayList<>();
400                }
401                return myCodeChallengeMethodsSupported;
402        }
403
404        public void setCodeChallengeMethodsSupported(List<String> theCodeChallengeMethodsSupported) {
405                myCodeChallengeMethodsSupported = theCodeChallengeMethodsSupported;
406        }
407
408        public void addCodeChallengeMethodSupported(String theCode) {
409                getCodeChallengeMethodsSupported().add(theCode);
410        }
411
412        public List<String> getSubjectTypesSupported() {
413                if (mySubjectTypesSupported == null) {
414                        mySubjectTypesSupported = new ArrayList<>();
415                }
416                return mySubjectTypesSupported;
417        }
418
419        public void setSubjectTypesSupported(List<String> theSubjectTypesSupported) {
420                mySubjectTypesSupported = theSubjectTypesSupported;
421        }
422
423        public void addSubjectTypeSupported(String theType) {
424                getSubjectTypesSupported().add(theType);
425        }
426
427        @JsonAnySetter
428        public void add(String theProp, Object theVal) {
429                myUnknownProperties.put(theProp, theVal);
430        }
431
432        Map<String, Object> getUnknownProperties() {
433                return myUnknownProperties;
434        }
435
436        Map<String, Object> toMap() {
437                Map<String, Object> map = new HashMap<>();
438                Field[] fields = OpenIdWellKnownOpenIdConfigurationResponseJson.class.getDeclaredFields();
439
440                try {
441                        for (Field field : fields) {
442                                if (field.isAnnotationPresent(JsonProperty.class)) {
443                                        Object value = field.get(this);
444                                        if (value != null) {
445                                                // we want the names to be whatever's in the json annotation
446                                                JsonProperty jsonProperty = field.getAnnotation(JsonProperty.class);
447                                                String name = jsonProperty.value();
448                                                map.put(name, value);
449                                        }
450                                }
451                        }
452                } catch (IllegalAccessException ex) {
453                        throw new InternalErrorException(ex);
454                }
455
456                map.putAll(myUnknownProperties);
457
458                return map;
459        }
460
461        @Override
462        public String toString() {
463                ObjectMapper mapper = JsonMapper.builderWithJackson2Defaults().build();
464                Map<String, Object> map = toMap();
465
466                try {
467                        return mapper.writeValueAsString(map);
468                } catch (JacksonException ex) {
469                        throw new InternalErrorException(ex);
470                }
471        }
472}
473
474/**
475 * @deprecated Use ca.cdr.api.model.json.oauth.OpenIdWellKnownOpenIdConfigurationResponseJson
476 */
477@Deprecated(since = "2025.11.R01", forRemoval = true)
478class OpenIdWellKnownOpenIdConfigurationResponse extends OpenIdWellKnownOpenIdConfigurationResponseJson {}