Manages the lifecycle of a Kademi account (organisation): creation, admin domain and URL resolution, and moving an account between parent organisations. Also captures an account's apps and settings as an AccountConfigSnapshot, diffs two snapshots into a ConfigDiff, and applies that diff to bring one account's configuration into line with another - used when deploying configuration between environments such as development and production. Stores per-tenant environment variables and secrets read by scripts and apps, and keeps a list of config items to ignore when diffing. Reached from server-side scripts as AccountManager.THIS(). May overlap with OrganisationManager, since account management responsibilities are being moved here over time.
Group: Managers
Properties
| Property | Returns | Description |
|---|---|---|
| autoApplySupportedTypeIds | List<String> | Config item type ids, such as 'settings', that at least one currently active app declares support for automatically applying during a configuration deployment. |
| defaultAdminMenu | String | The default admin menu identifier configured for the whole server, used when an organisation has not customised its own admin menu. |
| environmentVarsPath | String | Relative content-storage path where this tenant's environment variables are persisted. |
| envVariables | Properties | The current tenant's environment variables, loaded from content storage and cached briefly to avoid repeated reads under load. |
| secretNames | List<String> | Names of the secret properties stored for the current tenant, without their values. |
| secrets | Properties | The current tenant's secret values, loaded from content storage and cached briefly to avoid repeated reads under load. Secret property names are always prefixed with 'secret.'. |
| thisAdminDomain | String | Full external admin domain, including the '.admin.' segment and primary domain, for the current tenant organisation. |
| xstream | XStream |
Methods
newAccountBuilder() · createAccount(NewAccountBuilder b) · createStandardAdminGroup() · createAccount(String company, Profile profile) · findAdminDomain(String adminDomain) · moveAccountParent(String newParentOrgId) · currentAdminUrl(String path, Profile loginProfile) · fullAdminDomain(String adminDomain) · getThisAdminDomain() · adminUrl(String adminDomain, String path, Profile loginProfile) · adminUrl(Organisation adminOrg, String path, Profile loginProfile) · createAccountConfigSnapshot() · getAutoApplySupportedTypeIds() · applyAccountConfigConfiguration(ConfigDiff config, RemoteServerCredentials creds, Consumer<String> statusCb, AtomicBoolean cancelled, Map<String,List<String>> selectedTypesByAppIdsMap) · listSnapshots() · loadSnapshot(String name) · deleteSnapshot(String fileName) · hideSnapshot(String fileName, Profile hiddenBy) · unhideSnapshot(String fileName) · saveSnapshot(String fileName, AccountConfigSnapshot acs) · enqueueDeploymentItem(String importConfigId, Map<String,List<String>> selectedTypesByAppIdsMap) · diffConfigSnapshots(AccountConfigSnapshot source, AccountConfigSnapshot dest) · applyIgnoredToDiff(ConfigDiff originalDiff) · configDiffToXml(ConfigDiff configDiff) · xmlToConfigDiff(String xml) · accountConfigToJson(AccountConfigSnapshot acs) · jsonToAccountConfigSnapshot(String json) · getDefaultAdminMenu() · getEnvironmentVarsPath() · putEnvVariable(String name, String value) · removeEnvVariable(String name) · getEnvVariables() · putSecret(String name, String value) · removeSecret(String name) · getSecrets() · getSecretNames() · addIgnore(String appId, String type, String portableId) · removeIgnore(String ignoreId) · findIgnoredItems()
newAccountBuilder()
Returns: NewAccountBuilder
Starts a fluent builder for creating a new Kademi account (organisation), optionally with a new administrator profile.
createAccount(NewAccountBuilder b)
Returns: Organisation
Creates a new account as a child organisation of the current admin org, using the settings collected on the given builder. If the builder has no profile, a new administrator profile is created for it and set back onto the builder. Also obtains a licence, initialises the admin domain, installs the builder's recipe app and starts a new project from it asynchronously.
| Parameter | Description |
|---|---|
b | the builder holding the company title, admin domain, recipe and either an existing profile or new-user details |
createStandardAdminGroup()
Returns: Group
Gets or creates the standard Administrators group for the current tenant organisation, granting it the admin role. Idempotent: returns the existing group if one has already been created.
createAccount(String company, Profile profile)
Returns: Organisation
Creates a new account as a child organisation of the current admin org, named after the given company (or the profile's nickname if no company is given), and adds the given profile to its Administrators group. Unlike the builder-based createAccount, this does not obtain a licence, install a recipe or start a project.
| Parameter | Description |
|---|---|
company | display name to derive the new organisation's name from; falls back to the profile's nickname if blank |
profile | the profile to add to the new account's Administrators group, or null to create the account without one |
findAdminDomain(String adminDomain)
Returns: String
Derives a unique, URL-safe admin domain from the given name by lower-casing it, stripping unsafe characters, and appending an incrementing numeric suffix until no existing organisation already uses it.
| Parameter | Description |
|---|---|
adminDomain | candidate name to base the admin domain on, typically a company or nickname |
moveAccountParent(String newParentOrgId)
Returns: void
Moves the current tenant account to be a child of a different parent organisation, identified by its admin domain. Requires the current user to hold the admin role on both the current parent and the destination parent, and the destination parent must have a valid licence.
| Parameter | Description |
|---|---|
newParentOrgId | admin domain of the organisation to become the new parent |
currentAdminUrl(String path, Profile loginProfile)
Returns: String
Builds an absolute admin URL for the current tenant organisation, optionally with an auto-login token for the given profile.
| Parameter | Description |
|---|---|
path | path within the admin site to link to; a leading slash is added if missing |
loginProfile | profile to generate auto-login parameters for, or null for a plain URL; must have admin or admin-viewer access to the organisation |
fullAdminDomain(String adminDomain)
Returns: String
Builds the full external admin domain for the given short admin domain, by appending '.admin.' and the server's primary domain.
| Parameter | Description |
|---|---|
adminDomain | the organisation's short admin domain, as returned by findAdminDomain |
getThisAdminDomain()
Returns: String
Full external admin domain, including the '.admin.' segment and primary domain, for the current tenant organisation.
adminUrl(String adminDomain, String path, Profile loginProfile)
Returns: String
Builds an absolute admin URL for the organisation with the given admin domain, optionally with an auto-login token for the given profile.
| Parameter | Description |
|---|---|
adminDomain | admin domain of the organisation to look up |
path | path within the admin site to link to; a leading slash is added if missing |
loginProfile | profile to generate auto-login parameters for, or null for a plain URL; must have admin or admin-viewer access to the organisation |
adminUrl(Organisation adminOrg, String path, Profile loginProfile)
Returns: String
Builds an absolute admin URL for the given organisation, optionally with an auto-login token for the given profile.
| Parameter | Description |
|---|---|
adminOrg | organisation to build the admin URL for |
path | path within the admin site to link to; a leading slash is added if missing |
loginProfile | profile to generate auto-login parameters for, or null for a plain URL; must have admin or admin-viewer access to the organisation |
createAccountConfigSnapshot()
Returns: AccountConfigSnapshot
Captures the current tenant account's configuration, the settings and other config items of every active app, as a portable AccountConfigSnapshot that can later be compared against another snapshot. Apps whose settings are considered non-portable, such as admin-lib and aws, are excluded, and non-marketplace apps have their content hash recorded so they can be reinstalled directly.
getAutoApplySupportedTypeIds()
Returns: List<String>
Config item type ids, such as 'settings', that at least one currently active app declares support for automatically applying during a configuration deployment.
applyAccountConfigConfiguration(ConfigDiff config, RemoteServerCredentials creds, Consumer<String> statusCb, AtomicBoolean cancelled, Map<String,List<String>> selectedTypesByAppIdsMap)
Returns: Map<String,List<String>>
Applies a previously computed configuration diff to the current tenant account: installing and enabling apps, switching app versions and updating app settings as needed. Runs inside a single transaction and can be cancelled part-way through, in which case the transaction is rolled back.
| Parameter | Description |
|---|---|
config | the diff describing which apps and config item types to apply, produced by diffConfigSnapshots |
creds | credentials used to fetch app content from the remote server when installing or updating an app |
statusCb | callback invoked with human-readable progress messages as each app is processed |
cancelled | flag checked between apps; when set, processing stops and the transaction is rolled back |
selectedTypesByAppIdsMap | the config item types to apply for each app id, restricting processing to only the selected apps and types |
listSnapshots()
Returns: List<ConfigSnapshotInfo>
Lists the account configuration snapshots previously saved for the current tenant, including each one's file size, creation date and, if it has been hidden, who hid it and when.
loadSnapshot(String name)
Returns: AccountConfigSnapshot
Loads a previously saved account configuration snapshot by its file name.
| Parameter | Description |
|---|---|
name | file name of the snapshot to load, as returned by listSnapshots |
deleteSnapshot(String fileName)
Returns: void
Deletes a previously saved account configuration snapshot. Does nothing if no snapshot with that file name exists.
| Parameter | Description |
|---|---|
fileName | file name of the snapshot to delete, as returned by listSnapshots |
hideSnapshot(String fileName, Profile hiddenBy)
Returns: void
Marks a saved account configuration snapshot as hidden, recording who hid it and when. Hiding does not delete the snapshot file.
| Parameter | Description |
|---|---|
fileName | file name of the snapshot to hide |
hiddenBy | the profile hiding the snapshot |
unhideSnapshot(String fileName)
Returns: void
Clears the hidden flag previously set on a saved account configuration snapshot by hideSnapshot.
| Parameter | Description |
|---|---|
fileName | file name of the snapshot to unhide |
saveSnapshot(String fileName, AccountConfigSnapshot acs)
Returns: void
Serialises an account configuration snapshot to XML and saves it to the current tenant's content storage under the given file name.
| Parameter | Description |
|---|---|
fileName | file name to save the snapshot as; must not already exist |
acs | the snapshot to save |
enqueueDeploymentItem(String importConfigId, Map<String,List<String>> selectedTypesByAppIdsMap)
Returns: AsyncJob
Queues a background job that applies a previously imported deployment configuration to the current tenant account.
| Parameter | Description |
|---|---|
importConfigId | the UUID of the imported config file to process |
selectedTypesByAppIdsMap | apps and their config item types to process, keyed by app id |
diffConfigSnapshots(AccountConfigSnapshot source, AccountConfigSnapshot dest)
Returns: ConfigDiff
Compares two account configuration snapshots and builds a ConfigDiff describing every config item that was added, removed or changed between them, skipping items on the account's ignore list. For the admin website's app type, also adds warnings when app versions are inconsistent between the account and website level, or when a website has an unpublished change.
| Parameter | Description |
|---|---|
source | the earlier snapshot to compare from, or null to treat every item in dest as newly added |
dest | the later snapshot to compare to; must not be null |
applyIgnoredToDiff(ConfigDiff originalDiff)
Returns: ConfigDiff
Filters a config diff by removing any deltas that match an entry in the account's ignore list, leaving the original diff untouched.
| Parameter | Description |
|---|---|
originalDiff | the diff to filter; must not be null |
configDiffToXml(ConfigDiff configDiff)
Returns: String
Serialises a config diff to XML using this account manager's XStream configuration.
| Parameter | Description |
|---|---|
configDiff | the diff to serialise, or null |
xmlToConfigDiff(String xml)
Returns: ConfigDiff
Deserialises XML previously produced by configDiffToXml back into a ConfigDiff.
| Parameter | Description |
|---|---|
xml | the XML representation of a config diff |
accountConfigToJson(AccountConfigSnapshot acs)
Returns: String
Serialises an account configuration snapshot to JSON using AccountManagerSerializer.
| Parameter | Description |
|---|---|
acs | the snapshot to serialise |
jsonToAccountConfigSnapshot(String json)
Returns: AccountConfigSnapshot
Deserialises JSON previously produced by accountConfigToJson back into an AccountConfigSnapshot.
| Parameter | Description |
|---|---|
json | the JSON representation of a snapshot, or blank |
getDefaultAdminMenu()
Returns: String
The default admin menu identifier configured for the whole server, used when an organisation has not customised its own admin menu.
getEnvironmentVarsPath()
Returns: String
Relative content-storage path where this tenant's environment variables are persisted.
putEnvVariable(String name, String value)
Returns: void
Sets an environment variable for the current tenant, persisting it to content storage and invalidating the short-lived read cache.
| Parameter | Description |
|---|---|
name | the environment variable name |
value | the value to set |
removeEnvVariable(String name)
Returns: void
Removes an environment variable for the current tenant, persisting the change to content storage and invalidating the short-lived read cache.
| Parameter | Description |
|---|---|
name | the environment variable name to remove |
getEnvVariables()
Returns: Properties
The current tenant's environment variables, loaded from content storage and cached briefly to avoid repeated reads under load.
putSecret(String name, String value)
Returns: void
Sets a secret value for the current tenant, persisting it to content storage and invalidating the short-lived read cache.
| Parameter | Description |
|---|---|
name | the secret name; must start with 'secret.' |
value | the value to set; stored as an empty string if null |
removeSecret(String name)
Returns: void
Removes a secret value for the current tenant, persisting the change to content storage and invalidating the short-lived read cache.
| Parameter | Description |
|---|---|
name | the secret name to remove |
getSecrets()
Returns: Properties
The current tenant's secret values, loaded from content storage and cached briefly to avoid repeated reads under load. Secret property names are always prefixed with 'secret.'.
getSecretNames()
Returns: List<String>
Names of the secret properties stored for the current tenant, without their values.
addIgnore(String appId, String type, String portableId)
Returns: void
Adds a config item to the account's ignore list, so future diffs and deployments skip it. Records the current user and timestamp against the new ignore entry.
| Parameter | Description |
|---|---|
appId | id of the app the ignored item belongs to |
type | config item type of the ignored item, for example a website or app settings type |
portableId | portable id of the config item to ignore |
removeIgnore(String ignoreId)
Returns: void
Removes a single entry from the account's ignore list by its id.
| Parameter | Description |
|---|---|
ignoreId | id of the ignore entry to remove |
findIgnoredItems()
Returns: IgnoredConfigItemList
The current tenant's list of config items excluded from configuration diffs and deployments.