Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

Introduction

URAC micro-service V3 configuration variables that are needed and can be customized 

1. Password generation configuration

Info
titleLocation

In provision - key configurationcreate a custom registry - urac

You can change the values of the below variables to customize iterations, seeding, and the algorithm used to hash passwords.

NameTypeDescription

Example

hashIterationsintegerHashing iteration value used by SOAJS hasher to encrypt/compare passwords16
seedLengthintegerSeed length value used by SOAJS hasher to encrypt/compare passwords32
12

optionalAlgorithm

string

Password Hashing algorithm name. "aes256" or "des".

You can go to List of Crypto Algorithms to find the name of the algorithm that you can use.

You do not need to set this configuration if you do not want to specify an algorithm

 aes256

More information can be found in the Complete Example

2. Join & Membership

Info
titleLocation

In Add to provision - key configuration

Create custom registry - urac

You can change the values of the below variables to customize if you want the user to validate their email once they join or not.

NameTypeDescriptionExample
validateJoin
boolean
BooleanThis configuration controllers the status of a user after joining. aka ('pendingJoin' : 'active')
 
true
membershipObjectThis configuration allows you to configure different type of membership that can be set while joining to drive different user configuration like groups (make sure the groups is available). Should be an array of groups. 


Code Block
{
	"basic":{
		"groups": ["starter"]
	}
}


3. Mail Configuration

Info
titleLocation

In Add to provision - key configurationIn

custom registryCreate custom registry  - mail & urac

Mail configuration can be found under two configuration objects:

...

More information about Variables used, custom data fields used in "content", and examples of the configuration can be found under Mail Notification Configuration

Examples: In provision

Code Block
languagejs
titleIn provision
"commonFields" : {
  "mail": { // to control the smtp configuration
      "from": 'me@localhost.com',
      "transport": {...}
  },
  "sms":{
	  "from": '16170000000',
      "twilio": {
         "accountSid": "WWWW",
         "authToken": "WWWW"
	  }
  }
},
"urac" : {
  "linkslink": {...}, // this object to control the links in the emails
  "mail": { // this object to control the content of the emails
    "join": {...}, // Join - mail content configuration
    "forgotPassword": {...}, // Forgot password mail - content configuration
    "addUser": {...}, // Add User - mail content configuration
    "changeUserStatus": {...}, // Change User Status - mail content configuration
    "changeEmail": {...} // Change Email - mail content configuration
  },
  "sms": {
	"inviteToJoin": {...}
  }	
}

Examples: In custom registry

You should create to entries under custom registry (one for mail, one for urac, and one for uracsms) as follow:

with the following configuration content:

...

Code Block
languagejs
titleURAC
{
  "linkslink": {...}, // this object to control the links in the emails
		"addUser": "...",
		"changeEmail": "...",
		"forgotPassword": "...",
		"inviteToJoin": "...",
		"join": "..."
	},
  "mail": { // this object to control the content of the emails
    "addUser": {...}, 
    "changeEmail": {...}, 
    "changePin": {...}, 
    "changeUserStatus": {...}, 
    "forgotPassword": {...}, 
    "invitePin": {...}, 
    "join": {...},
    "resetPin": {...}
	"inviteToJoin": {...}
  },
  "sms": {
	"inviteToJoin": {...}
  }		
}


Code Block
languagejs
titlesms
{ // to control the smtp configuration
      "from": '16170000000',
      "twilio": {...}
}


4. Mail token configuration

Info
titleLocation

In Add to provision - key configuration

Create custom registry - urac

The URAC sends verification mail with links containing token with expiration date.

NameTypeDescriptionExample

tokenExpiryTTL

millisecondsThis configuration controllers the expiration period for the email links token.
 

172800000

5. Pin login configuration

Info
titleLocation

In provision - key configuration

In custom registryregistry 

Pin code adds a second layer of authentication to URAC. For example, in the hospitality business you want the manager to login and turn on pin login. This way a user can key in a ping and get access. For more information go to Pin login Configuration.

6. Data configuration

You should add a database configuration to the environment where you deployed URAC. for more information go to Data Configuration.

...

7. Roaming among main tenants

Info
titleLocation

In provision

URAC allows third party login via one of the below methods:

  1. Passport Login: Define application keys for passport integration. Currently supporting Azure, Github, Twitter, Facebook, and Google. Got to the link for more information and an example of the configuration.
  2. OpenAM login: SSO (Single Sign-On).
  3. LDAP (Lightweight Directory Access Protocol) login: Active directory login.

Configuration priority and the default values

This table illustrates the configuration that can be overridden at a different layer of configuration 

Info
titlePriority

Local → Registry → Tenant 

  1. Local Configuration
  2. Custom Registry
  3. Service Configuration (Tenant)

Name

Local Configuration (Default)

config.js

...

Registry Configuration (Per Environment)

req.soajs.registry

Tenant Configuration (Per Tenant Per Environment)

...

hashIterations

...

Create custom registry - urac

You can change the values of the below variable to turn on roaming among main tenants. Either you set masterCode or your set dbCodes.


NameTypeDescription

Example

masterCodeString

consolidate all main tenants' user under one master db and create roaming capabilities among them by invitation only. 

Also this will consolidate all tenants groups under one master db.

"TTTT"
autoRoamingObjectTo automatically allow roaming among main tenants


Code Block
languagejs
{
	"0000_TENANTID_TO_000": {
		"0000_TENANTID_FROM_000": {
			"groups": ["optional", "..."]
		}
	}
}


dbCodesObject

To consolidate designated main tenants' users and create roaming capabilities among them by invitation only. 

for example we have tenant TTT turning on roaming with tCODE1 and tCODE2


Code Block
languagejs
{
	"TTTT": ["tCODE1", "tCODE2"]
	"XXXX": ["tCODE4", "tCODE5"]
}