Changes for page Communication between models
Last modified by Erik Bakker on 2024/09/05 14:00
From version 6.1
edited by Erik Bakker
on 2022/07/26 08:31
on 2022/07/26 08:31
Change comment:
There is no comment for this version
To version 11.1
edited by Erik Bakker
on 2022/07/26 13:40
on 2022/07/26 13:40
Change comment:
There is no comment for this version
Summary
-
Page properties (3 modified, 0 added, 0 removed)
Details
- Page properties
-
- Title
-
... ... @@ -1,1 +1,1 @@ 1 - expert-create-your-transformations-xpath-expert1 +API Gateway Security - External IDP - Default language
-
... ... @@ -1,0 +1,1 @@ 1 +en - Content
-
... ... @@ -1,5 +1,5 @@ 1 1 {{container}}{{container layoutStyle="columns"}}((( 2 - Within the crash course,we already explainedXPathconceptually.Inthatsamemicrolearning,welookedatsome more uncomplicatedcases of using XPathwithin your transformation. If you need to brushup on that knowledge, pleasecheck outthis[[microlearning>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course Platform.crashcourse-platform-create-transformation-xpath-basic.WebHome||target="blank"]].Inthe intermediatemicrolearning on this subject, we builtupon that knowledge. Please check out this[[microlearning>>doc:Main.eMagizAcademy.Microlearnings.Intermediate Level.Createyour transformations.intermediate-create-your-transformations-xpath-intermediate.WebHome||target="blank"]]if you needa refresheron that.Inthe [[microlearning>>doc:Main.eMagizAcademy.Microlearnings.Advanced Level.Createyourtransformations.advanced-create-your-transformations-xpath-advanced.WebHome||target="blank"]]that followed, we builtuponthatknowledgeandlookedat someconcrete,practicalexamplesthat couldbeusefulinyour project. In thismicrolearning, wewill wraptheconceptfXPath by lookingatthreecomplexXPathalternatives that aresometimes neededwhendealingwith messages in eMagiz.2 +In the crash course on the API Gateway we discussed the various options available to [[secure>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course API Gateway.crashcourse-api-gateway-security.WebHome||target="blank"]] your API Gateway properly. In this microlearning, we will expand our knowledge on that topic by looking at a special case of securing your API Gateway. That case is special as you use an external identity provider (IDP) to govern the roles and users that have rights on your API Gateway. 3 3 4 4 Should you have any questions, please get in touch with [[academy@emagiz.com>>mailto:academy@emagiz.com]]. 5 5 ... ... @@ -6,86 +6,54 @@ 6 6 == 1. Prerequisites == 7 7 8 8 * Expert knowledge of the eMagiz platform 9 -* [[XPath Basic>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course Platform.crashcourse-platform-create-transformation-xpath-basic.WebHome||target="blank"]] 10 -* [[XPath Intermediate>>doc:Main.eMagiz Academy.Microlearnings.Intermediate Level.Create your transformations.intermediate-create-your-transformations-xpath-intermediate.WebHome||target="blank"]] 11 -* [[XPath Advanced>>doc:Main.eMagiz Academy.Microlearnings.Advanced Level.Create your transformations.advanced-create-your-transformations-xpath-advanced.WebHome||target="blank"]] 12 12 13 - 14 14 == 2. Key concepts == 15 15 16 -This microlearning focuses on morecomplexXPath operations.12 +This microlearning focuses on using an external IDP to validate whether a user is authorized to execute a certain action on your API Gateway and what configuration is needed in eMagiz to make this work. 17 17 18 -With XPath Advanced, we mean learning that XPath options are complex but could benefit you in your daily work. 14 +* The Token and Issuer URL of the external IDP need to be known 15 +* Users and Roles under User Management need to be manually configured and maintained to keep them in sync with the external IDP 19 19 20 - Someofthemore complexXPathoptions are:17 +== 3. External IDP == 21 21 22 -* dateTime calculation 23 -* Filter list 24 -* XPath on JSON 25 -* SpEL notation for XPath 19 +In the crash course on the API Gateway we discussed the various options available to [[secure>>doc:Main.eMagiz Academy.Microlearnings.Crash Course.Crash Course API Gateway.crashcourse-api-gateway-security.WebHome||target="blank"]] your API Gateway properly. In this microlearning, we will expand our knowledge on that topic by looking at a special case of securing your API Gateway. That case is special as you use an external identity provider (IDP) to govern the roles and users that have rights on your API Gateway. 26 26 21 +When selecting the option OAuth2.0 (or OpenID Connect) you have the option to use the IDP provided by eMagiz which makes the configuration easy or you could use an external IDP which you have control over and want to use for this purposes. 27 27 23 +In this microlearning we will highlight what you need to configure in Design and Deploy to make this work within the tooling of eMagiz. 28 28 29 -== 3. XPath Advanced==25 +=== 3.1 Design === 30 30 31 - Within thecrashcourse, we already explained XPath conceptually.In that same microlearning, wealsolookedatsomemoreuncomplicated casesof usingXPath within your transformation.Ifyou need tobrush up on that knowledge, pleasecheck out this[[microlearning>>doc:Main.eMagiz Academy.Microlearnings.CrashCourse.CrashCoursePlatform.crashcourse-platform-create-transformation-xpath-basic.WebHome||target="blank"]]. Inheintermediatemicrolearningon this subject,we builtuponthat knowledge.Pleasecheckout this [[microlearning>>doc:Main.eMagiz Academy.Microlearnings.IntermediateLevel.Createyourtransformations.intermediate-create-your-transformations-xpath-intermediate.WebHome||target="blank"]]ifyou needarefresheron that.In this microlearning,wewillbuilduponthat knowledgeandlookatsomeconcrete,practicalexamplesthat could beusefulin yourproject.27 +On the security level of the API Gateway in Design you need to select the desired option, for example OAuth2.0. Instead of not filling in the token and issuer URL, indicating that you want to use the eMagiz IDP, you need to fill these in to reference the IDP of your choice. Below you see an example of how this could be configured. 32 32 33 - Someof themoremplex XPathoptions:29 +[[image:Main.Images.Microlearning.WebHome@expert-securing-data-traffic-api-gw-security-external-idp-security-config-design.png]] 34 34 35 -* dateTime calculation 36 -* Filter list 37 -* XPath on JSON 38 -* SpEL notation for XPath 31 +Note that the environmentID in this example should be replaced with an actual environmentID that references your environment. 39 39 40 -=== 3. 1dateTime calculation===33 +=== 3.2 Deploy === 41 41 42 - Sometimeswesee thatdateTimecalculationis neededwithina transformationtodeterminea specificaction.Asthese calculationsarenot nativelysupportedwithinthe eMagizplatform,you need to useXPath'sfunctionality to calculate thenewvaliddate (ordateTime).35 +Normally, eMagiz will automatically update the User Management information based on the configuration in Design. However, because the identity check is not done by eMagiz but by an external party you need to manually enter the roles and users and configure the scope correctly on role level. 43 43 44 -T heXPath standardoffersseveral functionsto calculate with dateTimevalues. Thetwomost usedoptionsaredayTimeDuration andyearMonthDuration.Withthehelp of the dayTimeDuration,youcanadd, subtract,multiple,ordivideeconds, minutes,hours,anddaysregarding theoriginalvalue.The yearMonthDurationworksimilarlybutthenformonths and years.Anexampleof such an XPath is: <xsl:value-ofxmlns:xs="http://www.w3.org/2001/XMLSchema" select="CDM:StartDate+ xs:dayTimeDuration('P1D')* xs:yearMonthDuration('P1M')"/>.Inhisexample,XPathadds oneday andsubtractsonemonth from theinput date. Note thatmakingthis work requirestheadditionalnamespaceto bedefined.Thereforeyou needa custom snippet withinourtransformation or a customtransformation to make thiswork. Furthermore, note thatthe P1D and P1M couldalso befilledwiththe helpofparameters to make them dynamicin nature.37 +To do so navigate to User Management in Deploy and add the users you want manually by pressing the New button and providing them with a name. Do subsequently the same for the roles. On role level do not forget to correctly enter the scope to make the call work. Note that the help text on the scope level gently reminds you what you need to do to make this work. 45 45 46 - Somexampleshatwe sawduringtheyears:39 +[[image:Main.Images.Microlearning.WebHome@expert-securing-data-traffic-api-gw-security-external-idp-scope-configuration.png]] 47 47 48 -* https://my.emagiz.com/p/question/172825635700358186 49 -* https://my.emagiz.com/p/question/172825635700352588 41 +{{warning}}When implementing this you would be the first to do so with this setup. This means there might be some unexpected behavior when configuring this.{{/warning}} 50 50 51 -=== 3.2 Filter list === 52 - 53 -Sometimes you have a large message which contains a certain list within it. However, logic dictates that you can only send the message if at least one entry in the list for which attribute A is filled and attribute B equals type C. To make that happen in XPath, we first need to navigate to the list within the message. As we previously learned, there are two options to do so. One is to use // to navigate to the entity somewhere in the tree directly. The other is to start at the root and walk the tree from there. In this example, we use the latter. That results in the following XPath example: /root/list[attributeB = 'type C']/attributeA !=''. With this XPath, you filter the list on the specified check and subsequently check whether one of those entries that remains has an attributeA which is filled in. 54 - 55 -=== 3.3 XPath on JSON === 56 - 57 -With the release of build number .50, we expanded our offering on JSON messages to resemble much of the functionality we previously offered for XML messages. As a result, you can use XPath expressions on JSON messages within the following components (related to XPath): 58 - 59 -* XPath header enricher 60 -* XPath transformer 61 -* XPath router 62 - 63 -To activate the functionality, simply link the JSON source factory support object to one of these components to achieve the desired result. For more information, check out: https://emagiz.github.io/docs/release-notes/build50. 64 - 65 -=== 3.4 SpEL notation for XPath === 66 - 67 -Sometimes you want to perform an XPath operation but store the header via a standard message header enricher component. As a result, you need a valid SpEL expression to help you in this cause. To do so, you need to know the correct notation for an XPath expression when using the SpEL language. An example of the correct notation is: #xpath(payload,'/root/entity/attribute') 68 - 69 69 == 4. Assignment == 70 70 71 -Check out which of the XPaths we have discussed today can be found within your project. 72 -This assignment can be completed within the (Academy) project you created/used in the previous assignment. 45 +No assignment 73 73 74 74 == 5. Key takeaways == 75 75 76 -Some of the more complex XPath options are: 49 +* The Token and Issuer URL of the external IDP need to be known 50 +* Users and Roles under User Management need to be manually configured and maintained to keep them in sync with the external IDP 51 +* When implementing this you would be the first to do so with this setup. 77 77 78 -* dateTime calculation 79 -* Filter list 80 -* XPath on JSON 81 -* SpEL notation for XPath 82 - 83 83 == 6. Suggested Additional Readings == 84 84 85 -If you are interested in this topic and want more information on it, please read the help text provided by eMagizand read more information on the following link:55 +If you are interested in this topic and want more information, please read the help text provided by eMagiz. 86 86 87 -* https://www.w3schools.com/xml/xpath_intro.asp 88 - 89 89 == 7. Silent demonstration video == 90 90 91 91 As this is more of theoretical microlearning, there is no video accompanying the microlearning.)))((({{toc/}}))){{/container}}{{/container}}