Is it posible create UMA policies using JSON policy API?

Tagged: ,

This topic has 0 replies, 1 voice, and was last updated 5 years, 4 months ago by tomoko.

  • Author
    Posts
  • #18323
     tomoko
    Participant

    Hello:
    Using the “json/policies?_action=create” I can create Policies, ok.
    But I would like to create UMA policies. The reason I use the “policies?_action=create” (not the uma/policies?_action=create) API is because with that API an administrator can create policies, and the UMA API needs the user to be logged in.

    After creating a UMA resourceSet, I can create a policies to share them sending a json object, but then, I dont see the policie in the Share section of the user, although I see the policy is create in the Policies section in the Authorization section.

    I see UMA policies created, via the UMA flow, produces policies with a patern like uma://*, and some other details(in the name of the polici is like ‘resSetName – userCreator – resSetID-StrangeNumber”). I am trying to reproduce them, but with no 100% sucess.
    My test:
    curl \
    –request POST \
    –header “iPlanetDirectoryPro: AMADMINCOOKIE….” \
    –header “Content-Type: application/json” \
    –data ‘{
    “name”: “resourceSetName – test1 – fce47941-a975-4456-b2b0-e51a189680190-987654321”,
    “active”: true,
    “description”: “”,
    “applicationName”: “clientagent”,
    “actionValues”: {
    “SCOPEWRITE”: true,
    “SCOPEREAD”: true
    },
    “resources”: [
    “uma://fce47941-a975-4456-b2b0-e51a189680190”
    ],
    “subject”: {
    “type”: “JwtClaim”,
    “claimName”: “sub”,
    “claimValue”: “id=receiveruser,ou=user,o=umarealm,ou=services,dc=ldap1,dc=ldap2,dc=ldap3”
    },
    “resourceTypeUuid”: “fce47941-a975-4456-b2b0-e51a189680190”
    }’ \
    http://myhost.mydomain.com:8080/piam/json/umarealm/policies?_action=create

    Any ideas welcome.

    Another question: UMA Policies cann include the evalution of Environment conditions like Time and Date? Any example?
    Thanks a lot

Viewing 1 post (of 1 total)

You must be logged in to reply to this topic.

©2022 ForgeRock - we provide an identity and access platform to secure every online relationship for the enterprise market, educational sector and even entire countries. Click to view our privacy policy and terms of use.

Log in with your credentials

Forgot your details?