A third party application registered against an account so it can use the Kademi REST API through OAuth2. The row holds the OAuth2 client credentials, the domains an authorisation may redirect back to, and the branding shown on the consent page. Each app is scoped to one admin organisation and its name is unique within it. Deleting an app also deletes every access token and authorisation code issued for it.

Group: Database Entities

Implements: Serializable, Relational


Properties

PropertyReturnsDescription
clientIdStringOAuth2 client id for the application, generated as a UUID when it is created. This is the public identifier the application sends on an authorisation request. Never null.
clientSecretStringOAuth2 client secret, generated as a UUID when the application is created and stored in plain text. Treat it as a credential and never expose it to a browser. Never null.
createdDateDateDate and time the application was registered.
descriptionStringDescription of the application and what it will use the API for, shown to the user on the consent page so they know what they are approving. Holds up to 200000 characters.
idlongDatabase identifier for this registered application.
logoHashStringContent hash of the logo image shown on the OAuth2 consent page, used to fetch the image from the content store.
nameStringPortable, path safe identifier for the application, unique within the account and used in admin URLs. Use getTitle for anything shown to a user.
redirectDomainsStringComma separated list of domains an authorisation is allowed to redirect back to. Use redirectDomains, the no argument method, to read it as a list.
roleNameStringName of a role the signed in user must hold before they are allowed to authorise this application. Null or blank means any signed in user may authorise it.
titleStringFree text display name for the application, shown to users on the OAuth2 consent page. Not unique and not safe to use as an identifier or path segment.

Methods

getId() · setId(long id) · setOrganisation(Organisation organisation) · getCreatedDate() · setCreatedDate(Date createdDate) · getName() · setName(String name) · getTitle() · setTitle(String title) · getClientId() · setClientId(String clientId) · getClientSecret() · setClientSecret(String clientSecret) · getRedirectDomains() · setRedirectDomains(String redirectDomains) · getLogoHash() · setLogoHash(String logoHash) · getDescription() · setDescription(String description) · getRoleName() · setRoleName(String roleName) · redirectDomains()

getId()

Returns: long

Database identifier for this registered application.

setId(long id)

Returns: void

Sets the database identifier. Normally only assigned by the persistence layer.

ParameterDescription
idthe primary key to assign

setOrganisation(Organisation organisation)

Returns: void

Sets the account the application is registered against. Required.

ParameterDescription
organisationthe admin organisation the application belongs to

getCreatedDate()

Returns: Date

Date and time the application was registered.

setCreatedDate(Date createdDate)

Returns: void

Sets the date and time the application was registered.

ParameterDescription
createdDatethe creation date

getName()

Returns: String

Portable, path safe identifier for the application, unique within the account and used in admin URLs. Use getTitle for anything shown to a user.

setName(String name)

Returns: void

Sets the portable identifier for the application. Must be unique within the account and safe to use in a URL path.

ParameterDescription
namethe application's name

getTitle()

Returns: String

Free text display name for the application, shown to users on the OAuth2 consent page. Not unique and not safe to use as an identifier or path segment.

setTitle(String title)

Returns: void

Sets the display name shown to users on the consent page.

ParameterDescription
titlethe application's display title

getClientId()

Returns: String

OAuth2 client id for the application, generated as a UUID when it is created. This is the public identifier the application sends on an authorisation request. Never null.

setClientId(String clientId)

Returns: void

Sets the OAuth2 client id. Changing it stops any application already using the old value from authorising.

ParameterDescription
clientIdthe OAuth2 client id

getClientSecret()

Returns: String

OAuth2 client secret, generated as a UUID when the application is created and stored in plain text. Treat it as a credential and never expose it to a browser. Never null.

setClientSecret(String clientSecret)

Returns: void

Sets the OAuth2 client secret. Changing it revokes the old secret for any application still using it.

ParameterDescription
clientSecretthe OAuth2 client secret

getRedirectDomains()

Returns: String

Comma separated list of domains an authorisation is allowed to redirect back to. Use redirectDomains, the no argument method, to read it as a list.

setRedirectDomains(String redirectDomains)

Returns: void

Sets the raw comma separated list of allowed redirect domains, replacing whatever was there. Use addRedirectDomain to append one without losing the others.

ParameterDescription
redirectDomainsthe comma separated domain list

getLogoHash()

Returns: String

Content hash of the logo image shown on the OAuth2 consent page, used to fetch the image from the content store.

setLogoHash(String logoHash)

Returns: void

Sets the content hash of the logo shown on the consent page.

ParameterDescription
logoHashthe logo file hash

getDescription()

Returns: String

Description of the application and what it will use the API for, shown to the user on the consent page so they know what they are approving. Holds up to 200000 characters.

setDescription(String description)

Returns: void

Sets the description shown to the user on the consent page.

ParameterDescription
descriptionthe application description

getRoleName()

Returns: String

Name of a role the signed in user must hold before they are allowed to authorise this application. Null or blank means any signed in user may authorise it.

setRoleName(String roleName)

Returns: void

Sets the role a user must hold to authorise this application. Set it to null to allow any signed in user.

ParameterDescription
roleNamethe required role name

redirectDomains()

Returns: List<String>

Parses the comma separated redirect domains into a list, trimming each entry.

To get full access to the Kademi Hub existing customers can login here, or new customers can register here.