Authorization Domain layout
The src/authorizationDomain directory represents an authorization domain, mirroring the structure of the single-file YAML domain representation used by ADS.
Each section (metadata, attributes, and attributeCache) corresponds to a YAML file with the same name. For example, identity.yaml. The policy field corresponds to the alfaSpecifications folder and the attributeConnectors field corresponds to the attributeConnectors folder.
To exclude a field from the domain, omit the corresponding file or folder.
An empty file will generate a section with the YAML value null, which is invalid for all sections.
-
metadata.yamlDefines the value of the
metadatafield in the single-file domain representation. For example:metadata.yamlstatus: under developmentcreatedBy: BobapprovedBy: AlicenoteIf applicable, the Git commit ID, message, and author will be automatically added to the metadata.
-
alfaSpecifications/This directory corresponds to the
policyfield in the single-file domain representation. All files within this directory are processed as ALFA policies. -
attributes.yamlDefines the value of the
attributesfield in the single-file domain representation. For example:attributes.yamlacme.role:xacmlId: acme.rolecategory: AccessSubjectdatatype: stringacme.resource.identity:xacmlId: acme.resource.identitycategory: Resourcedatatype: string -
attributeConnectors/connector_1.yamlDefines the settings for the attribute connector identified as
connector_1. All configuration settings can be included in this file. For example:connector_1.yamlclassName: com.axiomatics.attributeconnector.parser.json.ConnectorModuleprovidedAttributes:- attributeName: user.role- attributeName: resource.location- attributeName: user.locationconfiguration:identifier: ourConnectorsource:json:value: |{"users": {"martin": {"role": "manager","location": "stockholm"},"cecilia": {"role": "consultant","location": "london"}},"resources": {"2": {"location": "stockholm"},"1": {"location": "london"}}}mappings:- attributeName: user.rolejsonPath: $.users['##1##'].rolekeys:- attributeName: user.identity- attributeName: user.locationjsonPath: $.users['##1##'].locationkeys:- attributeName: user.identity- attributeName: resource.locationjsonPath: $.resources['##1##'].locationkeys:- attributeName: resource.identityAlternatively, you can define the
configurationStringvalue in a separate file (see below) if it is large or complex. -
attributeConnectors/connector_2.yamlIf this file omits the
configurationStringfield, its value is read from a file namedconnector_2.configurationString.*(see below). This additional file is optional, but it's an error if multiple files match the pattern. -
attributeConnectors/connector_2.configurationString.xmlThe file extension is ignored, so use any extension that's convenient for editing.
noteThis file is ignored if there is no corresponding
connector_2.yamlfile or ifconnector_2.yamlalready includes aconfigurationStringfield. -
attributeCache.yamlDefines the value of the
attributeCachefield in the single-file domain representation. For example:attributeCache.yamlacme.role:timeToLive: 1 daymaxItems: 1000acme.resource.identity:timeToLive: 15 minutesmaxItems: 1000 -
decisionParameters.yamlDefines the value of the
decisionParametersfield in the single-file domain representation. For example:decisionParameters.yamlpartialEvaluationThreshold: 3