From 6ca69aef3f14658b0f86eb50f822989de9f687b1 Mon Sep 17 00:00:00 2001 From: Tim Dahlmanns Date: Tue, 23 Jun 2026 12:58:43 +0200 Subject: [PATCH 1/5] refactor: apply cors config to full api --- .../redline/infrastructure/config/SecurityConfig.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java b/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java index 97ad724..964f805 100644 --- a/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java +++ b/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java @@ -76,7 +76,7 @@ CorsConfigurationSource corsConfigurationSource(@Value("${app.cors.allowed-origi config.setAllowedHeaders(List.of("Authorization", "Content-Type", "x-requested-with")); var source = new UrlBasedCorsConfigurationSource(); - source.registerCorsConfiguration("/api/ui/**", config); + source.registerCorsConfiguration("/api/**", config); return source; } From de38071789c0490ec8e7bea998af4822a6402594 Mon Sep 17 00:00:00 2001 From: Tim Dahlmanns Date: Tue, 23 Jun 2026 12:59:05 +0200 Subject: [PATCH 2/5] refactor: cors add methods and headers env config --- .../redline/infrastructure/config/SecurityConfig.java | 11 +++++++---- src/main/resources/application.yml | 4 +++- 2 files changed, 10 insertions(+), 5 deletions(-) diff --git a/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java b/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java index 964f805..5b14d6c 100644 --- a/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java +++ b/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java @@ -68,12 +68,15 @@ public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Excepti @Bean //@Profile("dev") - CorsConfigurationSource corsConfigurationSource(@Value("${app.cors.allowed-origins}") String allowedOrigins) { + CorsConfigurationSource corsConfigurationSource( + @Value("${app.cors.allowed-origins}") List allowedOrigins, + @Value("${app.cors.allowed-methods:GET,POST,PUT,PATCH,DELETE,OPTIONS}") List allowedMethods, + @Value("${app.cors.allowed-headers:Authorization,Content-Type,x-requested-with}") List allowedHeaders) { var config = new CorsConfiguration(); - config.setAllowedOrigins(List.of(allowedOrigins)); - config.setAllowedMethods(List.of("GET", "POST", "PUT", "PATCH", "DELETE", "OPTIONS")); - config.setAllowedHeaders(List.of("Authorization", "Content-Type", "x-requested-with")); + config.setAllowedOrigins(allowedOrigins); + config.setAllowedMethods(allowedMethods); + config.setAllowedHeaders(allowedHeaders); var source = new UrlBasedCorsConfigurationSource(); source.registerCorsConfiguration("/api/**", config); diff --git a/src/main/resources/application.yml b/src/main/resources/application.yml index 4b3c5c2..b432fbb 100644 --- a/src/main/resources/application.yml +++ b/src/main/resources/application.yml @@ -37,7 +37,9 @@ tenant-manager: app: cors: - allowed-origins: ${CORS_ALLOWED_ORIGIN:http://localhost:4200} + allowed-origins: ${CORS_ALLOWED_ORIGINS:http://localhost:4200} + allowed-methods: ${CORS_ALLOWED_METHODS:GET,POST,PUT,PATCH,DELETE,OPTIONS} + allowed-headers: ${CORS_ALLOWED_HEADERS:Authorization,Content-Type,x-requested-with} --- # Development Profile with H2 From 094677c3a19fdcd16f18d37cc8d0fb347d7c5c0b Mon Sep 17 00:00:00 2001 From: Tim Dahlmanns Date: Wed, 24 Jun 2026 09:40:17 +0200 Subject: [PATCH 3/5] delete: duplicated default values --- .../redline/infrastructure/config/SecurityConfig.java | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java b/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java index 5b14d6c..adf30d8 100644 --- a/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java +++ b/src/main/java/com/metaformsystems/redline/infrastructure/config/SecurityConfig.java @@ -70,8 +70,8 @@ public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Excepti //@Profile("dev") CorsConfigurationSource corsConfigurationSource( @Value("${app.cors.allowed-origins}") List allowedOrigins, - @Value("${app.cors.allowed-methods:GET,POST,PUT,PATCH,DELETE,OPTIONS}") List allowedMethods, - @Value("${app.cors.allowed-headers:Authorization,Content-Type,x-requested-with}") List allowedHeaders) { + @Value("${app.cors.allowed-methods}") List allowedMethods, + @Value("${app.cors.allowed-headers}") List allowedHeaders) { var config = new CorsConfiguration(); config.setAllowedOrigins(allowedOrigins); From 258db80e2e89930c45e0dff1118825a693621ad9 Mon Sep 17 00:00:00 2001 From: Tim Dahlmanns Date: Wed, 24 Jun 2026 10:41:31 +0200 Subject: [PATCH 4/5] test: add missing cors config --- src/test/resources/application.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/test/resources/application.yml b/src/test/resources/application.yml index ff72933..5d09d59 100644 --- a/src/test/resources/application.yml +++ b/src/test/resources/application.yml @@ -24,4 +24,6 @@ spring: app: cors: - allowed-origins: "*" \ No newline at end of file + allowed-origins: "*" + allowed-methods: GET,POST,PUT,PATCH,DELETE,OPTIONS + allowed-headers: Authorization,Content-Type,x-requested-with \ No newline at end of file From 84f98dbbafb887d45542892cdb68712316d4adcb Mon Sep 17 00:00:00 2001 From: Tim Dahlmanns Date: Wed, 23 Sep 2026 10:19:04 +0200 Subject: [PATCH 5/5] refactor: bump v5beta api version to v5 --- .../management/ManagementApiClientImpl.java | 40 +++++++++---------- .../DataAccessServiceIntegrationTest.java | 6 +-- .../ManagementApiClientIntegrationTest.java | 4 +- 3 files changed, 25 insertions(+), 25 deletions(-) diff --git a/src/main/java/com/metaformsystems/redline/infrastructure/client/management/ManagementApiClientImpl.java b/src/main/java/com/metaformsystems/redline/infrastructure/client/management/ManagementApiClientImpl.java index 0b3203f..27c1a20 100644 --- a/src/main/java/com/metaformsystems/redline/infrastructure/client/management/ManagementApiClientImpl.java +++ b/src/main/java/com/metaformsystems/redline/infrastructure/client/management/ManagementApiClientImpl.java @@ -74,7 +74,7 @@ public void createAsset(String participantContextId, Asset asset) { var token = getToken(participantContextId); controlPlaneWebClient.post() - .uri("/v5beta/participants/%s/assets".formatted(participantContextId)) + .uri("/v5/participants/%s/assets".formatted(participantContextId)) .header("Authorization", "Bearer %s".formatted(token)) .bodyValue(asset) .retrieve() @@ -85,7 +85,7 @@ public void createAsset(String participantContextId, Asset asset) { @Override public List> queryAssets(String participantContextId, QuerySpec query) { return controlPlaneWebClient.post() - .uri("/v5beta/participants/{participantContextId}/assets/request", encode(participantContextId)) + .uri("/v5/participants/{participantContextId}/assets/request", encode(participantContextId)) .header("Authorization", "Bearer " + getToken(participantContextId)) .bodyValue(query) .retrieve() @@ -97,7 +97,7 @@ public List> queryAssets(String participantContextId, QueryS @Override public void deleteAsset(String participantContextId, String assetId) { controlPlaneWebClient.delete() - .uri("/v5beta/participants/{participantContextId}/assets/{assetId}", encode(participantContextId), assetId) + .uri("/v5/participants/{participantContextId}/assets/{assetId}", encode(participantContextId), assetId) .header("Authorization", "Bearer " + getToken(participantContextId)) .retrieve() .toBodilessEntity() @@ -107,7 +107,7 @@ public void deleteAsset(String participantContextId, String assetId) { @Override public void createPolicy(String participantContextId, NewPolicyDefinition policy) { controlPlaneWebClient.post() - .uri("/v5beta/participants/%s/policydefinitions".formatted(participantContextId)) + .uri("/v5/participants/%s/policydefinitions".formatted(participantContextId)) .header("Authorization", "Bearer %s".formatted(getToken(participantContextId))) .bodyValue(policy) .retrieve() @@ -118,7 +118,7 @@ public void createPolicy(String participantContextId, NewPolicyDefinition policy @Override public List> queryPolicyDefinitions(String participantContextId, QuerySpec query) { return controlPlaneWebClient.post() - .uri("/v5beta/participants/{participantContextId}/policydefinitions/request", encode(participantContextId)) + .uri("/v5/participants/{participantContextId}/policydefinitions/request", encode(participantContextId)) .header("Authorization", "Bearer " + getToken(participantContextId)) .bodyValue(query) .retrieve() @@ -130,7 +130,7 @@ public List> queryPolicyDefinitions(String participantContex @Override public void deletePolicyDefinition(String participantContextId, String policyId) { controlPlaneWebClient.delete() - .uri("/v5beta/participants/{participantContextId}/policydefinitions/{policyId}", encode(participantContextId), policyId) + .uri("/v5/participants/{participantContextId}/policydefinitions/{policyId}", encode(participantContextId), policyId) .header("Authorization", "Bearer " + getToken(participantContextId)) .retrieve() .toBodilessEntity() @@ -139,7 +139,7 @@ public void deletePolicyDefinition(String participantContextId, String policyId) public void createContractDefinition(String participantContextId, NewContractDefinition contractDefinition) { controlPlaneWebClient.post() - .uri("/v5beta/participants/%s/contractdefinitions".formatted(participantContextId)) + .uri("/v5/participants/%s/contractdefinitions".formatted(participantContextId)) .header("Authorization", "Bearer %s".formatted(getToken(participantContextId))) .bodyValue(contractDefinition) .retrieve() @@ -150,7 +150,7 @@ public void createContractDefinition(String participantContextId, NewContractDef @Override public List> queryContractDefinitions(String participantContextId, QuerySpec query) { return controlPlaneWebClient.post() - .uri("/v5beta/participants/{participantContextId}/contractdefinitions/request", participantContextId) + .uri("/v5/participants/{participantContextId}/contractdefinitions/request", participantContextId) .header("Authorization", "Bearer " + getToken(participantContextId)) .bodyValue(query) .retrieve() @@ -162,7 +162,7 @@ public List> queryContractDefinitions(String participantCont @Override public void deleteContractDefinition(String participantContextId, String contractDefinitionId) { controlPlaneWebClient.delete() - .uri("/v5beta/participants/{participantContextId}/contractdefinitions/{id}", participantContextId, contractDefinitionId) + .uri("/v5/participants/{participantContextId}/contractdefinitions/{id}", participantContextId, contractDefinitionId) .header("Authorization", "Bearer " + getToken(participantContextId)) .retrieve() .toBodilessEntity() @@ -179,7 +179,7 @@ public String initiateContractNegotiation(String participantContextId, ContractR throw new RuntimeException(e); } var response = controlPlaneWebClient.post() - .uri("/v5beta/participants/{participantContextId}/contractnegotiations", participantContextId) + .uri("/v5/participants/{participantContextId}/contractnegotiations", participantContextId) .header("Authorization", "Bearer " + getToken(participantContextId)) .bodyValue(negotiationRequest) .retrieve() @@ -193,7 +193,7 @@ public String initiateContractNegotiation(String participantContextId, ContractR @Override public ContractNegotiation getContractNegotiation(String participantContextId, String negotiationId) { return controlPlaneWebClient.get() - .uri("/v5beta/participants/{participantContextId}/contractnegotiations/{id}", participantContextId, negotiationId) + .uri("/v5/participants/{participantContextId}/contractnegotiations/{id}", participantContextId, negotiationId) .header("Authorization", "Bearer " + getToken(participantContextId)) .retrieve() .bodyToMono(new ParameterizedTypeReference() { @@ -204,7 +204,7 @@ public ContractNegotiation getContractNegotiation(String participantContextId, S @Override public List> queryContractNegotiations(String participantContextId, QuerySpec query) { return controlPlaneWebClient.post() - .uri("/v5beta/participants/{participantContextId}/contractnegotiations/request", encode(participantContextId)) + .uri("/v5/participants/{participantContextId}/contractnegotiations/request", encode(participantContextId)) .header("Authorization", "Bearer " + getToken(participantContextId)) .bodyValue(query) .retrieve() @@ -218,7 +218,7 @@ public void createCelExpression(CelExpression celExpression) { var token = tokenProvider.getToken(null, "management-api:write management-api:read"); controlPlaneWebClient.post() - .uri("/v5beta/celexpressions") + .uri("/v5/celexpressions") .header("Authorization", "Bearer %s".formatted(token)) .bodyValue(celExpression) .retrieve() @@ -243,7 +243,7 @@ public Map setupTransfer(String participantContextId, String pol @Override public List listTransferProcesses(String participantContextId) { return controlPlaneWebClient.post() - .uri("/v5beta/participants/{participantContextId}/transferprocesses/request", participantContextId) + .uri("/v5/participants/{participantContextId}/transferprocesses/request", participantContextId) .header("Authorization", "Bearer " + getToken(participantContextId)) .retrieve() .bodyToMono(new ParameterizedTypeReference>() { @@ -254,7 +254,7 @@ public List listTransferProcesses(String participantContextId) @Override public String initiateTransferProcess(String participantContextId, TransferRequest request) { var response = controlPlaneWebClient.post() - .uri("/v5beta/participants/{participantContextId}/transferprocesses", participantContextId) + .uri("/v5/participants/{participantContextId}/transferprocesses", participantContextId) .header("Authorization", "Bearer " + getToken(participantContextId)) .bodyValue(request) .retrieve() @@ -268,7 +268,7 @@ public String initiateTransferProcess(String participantContextId, TransferReque @Override public TransferProcess getTransferProcess(String participantContextId, String transferProcessId) { return controlPlaneWebClient.get() - .uri("/v5beta/participants/{participantContextId}/transferprocesses/{transferProcessId}", participantContextId, transferProcessId) + .uri("/v5/participants/{participantContextId}/transferprocesses/{transferProcessId}", participantContextId, transferProcessId) .header("Authorization", "Bearer " + getToken(participantContextId)) .retrieve() .bodyToMono(TransferProcess.class) @@ -278,7 +278,7 @@ public TransferProcess getTransferProcess(String participantContextId, String tr @Override public Catalog getCatalog(String participantContextId, CatalogRequest request) { return controlPlaneWebClient.post() - .uri("/v5beta/participants/%s/catalog/request".formatted(participantContextId)) + .uri("/v5/participants/%s/catalog/request".formatted(participantContextId)) .header("Authorization", "Bearer " + getToken(participantContextId)) .bodyValue(request) .retrieve() @@ -290,7 +290,7 @@ public Catalog getCatalog(String participantContextId, CatalogRequest request) { @Override public void prepareDataplane(String participantContextId, DataplaneRegistration dataplaneRegistration) { controlPlaneWebClient.put() - .uri("/v5beta/participants/%s/dataplanes".formatted(participantContextId)) + .uri("/v5/participants/%s/dataplanes".formatted(participantContextId)) .header("Authorization", "Bearer %s".formatted(getToken(participantContextId))) .bodyValue(dataplaneRegistration) .retrieve() @@ -301,7 +301,7 @@ public void prepareDataplane(String participantContextId, DataplaneRegistration @Override public List listContracts(String participantContextId) { return controlPlaneWebClient.post() - .uri("/v5beta/participants/{participantContextId}/contractnegotiations/request", participantContextId) + .uri("/v5/participants/{participantContextId}/contractnegotiations/request", participantContextId) .header("Authorization", "Bearer " + getToken(participantContextId)) .contentType(MediaType.APPLICATION_JSON) .retrieve() @@ -313,7 +313,7 @@ public List listContracts(String participantContextId) { @Override public ContractAgreement getAgreement(String participantContextId, String negotiationId) { return controlPlaneWebClient.get() - .uri("/v5beta/participants/{participantContextId}/contractnegotiations/{negotiationId}/agreement", participantContextId, negotiationId) + .uri("/v5/participants/{participantContextId}/contractnegotiations/{negotiationId}/agreement", participantContextId, negotiationId) .header("Authorization", "Bearer " + getToken(participantContextId)) .retrieve() .bodyToMono(ContractAgreement.class) diff --git a/src/test/java/com/metaformsystems/redline/domain/service/DataAccessServiceIntegrationTest.java b/src/test/java/com/metaformsystems/redline/domain/service/DataAccessServiceIntegrationTest.java index 960efe7..a40ae85 100644 --- a/src/test/java/com/metaformsystems/redline/domain/service/DataAccessServiceIntegrationTest.java +++ b/src/test/java/com/metaformsystems/redline/domain/service/DataAccessServiceIntegrationTest.java @@ -276,11 +276,11 @@ void shouldListContracts() throws InterruptedException { assertThat(result.stream().filter(cn -> cn.getId().equals("negotiation-2")).findFirst().orElseThrow().getContractAgreement()).isNull(); var contractsRequest = mockWebServer.takeRequest(); - assertThat(contractsRequest.getPath()).isEqualTo("/cp/v5beta/participants/ctx-4/contractnegotiations/request"); + assertThat(contractsRequest.getPath()).isEqualTo("/cp/v5/participants/ctx-4/contractnegotiations/request"); assertThat(contractsRequest.getMethod()).isEqualTo("POST"); var agreementRequest = mockWebServer.takeRequest(); - assertThat(agreementRequest.getPath()).isEqualTo("/cp/v5beta/participants/ctx-4/contractnegotiations/negotiation-1/agreement"); + assertThat(agreementRequest.getPath()).isEqualTo("/cp/v5/participants/ctx-4/contractnegotiations/negotiation-1/agreement"); assertThat(agreementRequest.getMethod()).isEqualTo("GET"); } @@ -342,7 +342,7 @@ void shouldInitiateContractNegotiation() throws InterruptedException { assertThat(result).isEqualTo("negotiation-123"); var request = mockWebServer.takeRequest(); - assertThat(request.getPath()).isEqualTo("/cp/v5beta/participants/ctx-6/contractnegotiations"); + assertThat(request.getPath()).isEqualTo("/cp/v5/participants/ctx-6/contractnegotiations"); assertThat(request.getMethod()).isEqualTo("POST"); } diff --git a/src/test/java/com/metaformsystems/redline/infrastructure/client/management/ManagementApiClientIntegrationTest.java b/src/test/java/com/metaformsystems/redline/infrastructure/client/management/ManagementApiClientIntegrationTest.java index 061353a..f52474e 100644 --- a/src/test/java/com/metaformsystems/redline/infrastructure/client/management/ManagementApiClientIntegrationTest.java +++ b/src/test/java/com/metaformsystems/redline/infrastructure/client/management/ManagementApiClientIntegrationTest.java @@ -442,7 +442,7 @@ void shouldCreateCelExpression() throws InterruptedException { // Assert var celRequest = mockWebServer.takeRequest(); - assertThat(celRequest.getPath()).isEqualTo("/v5beta/celexpressions"); + assertThat(celRequest.getPath()).isEqualTo("/v5/celexpressions"); assertThat(celRequest.getHeader("Authorization")).isEqualTo("Bearer test-token"); assertThat(celRequest.getBody().readUtf8()).contains("cel-123"); } @@ -465,7 +465,7 @@ void shouldPrepareDataplane() throws InterruptedException { // Assert var dataplaneRequest = mockWebServer.takeRequest(); - assertThat(dataplaneRequest.getPath()).isEqualTo("/v5beta/participants/%s/dataplanes".formatted(participantContextId)); + assertThat(dataplaneRequest.getPath()).isEqualTo("/v5/participants/%s/dataplanes".formatted(participantContextId)); assertThat(dataplaneRequest.getHeader("Authorization")).isEqualTo("Bearer test-token"); }