package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"github.com/conductorone/conductorone-sdk-go/pkg/models/operations"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.SessionPolicy.SearchAppUserSessionPolicies(ctx, operations.C1APISessionPolicyV1SessionPolicyServiceSearchAppUserSessionPoliciesRequest{
AppEntitlementID: "<id>",
AppID: "<id>",
})
if err != nil {
log.Fatal(err)
}
if res.SessionPolicyServiceSearchAppUserSessionPoliciesResponse != nil {
// handle response
}
}curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"pageSize": 123,
"pageToken": "<string>"
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search"
payload = {
"pageSize": 123,
"pageToken": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({pageSize: 123, pageToken: '<string>'})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'pageSize' => 123,
'pageToken' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"list": [
{
"accessTokenTtlSeconds": 123,
"continuousDefaultOutcome": {
"allow": {
"floorLevel": "AUTH_LEVEL_UNSPECIFIED"
},
"challengeRequired": {
"types": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
},
"deny": {
"reasonAdmin": "<string>",
"reasonUser": "<string>"
},
"enrollmentRequired": {
"credentialTypes": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
},
"stepUpRequired": {
"level": "AUTH_LEVEL_UNSPECIFIED",
"maxAgeSeconds": 123,
"types": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
}
},
"continuousRules": [
{
"description": "<string>",
"id": "<string>",
"matchCel": "<string>",
"mode": "POLICY_RULE_MODE_UNSPECIFIED",
"outcome": {
"allow": {
"floorLevel": "AUTH_LEVEL_UNSPECIFIED"
},
"challengeRequired": {
"types": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
},
"deny": {
"reasonAdmin": "<string>",
"reasonUser": "<string>"
},
"enrollmentRequired": {
"credentialTypes": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
},
"stepUpRequired": {
"level": "AUTH_LEVEL_UNSPECIFIED",
"maxAgeSeconds": 123,
"types": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
}
}
}
],
"createdAt": "2023-11-07T05:31:56Z",
"credentialDurations": [
{
"accessTokenTtlSeconds": 123,
"credentialType": "CREDENTIAL_TYPE_UNSPECIFIED",
"maxSessionDurationSeconds": 123
}
],
"deletedAt": "2023-11-07T05:31:56Z",
"displayName": "<string>",
"id": "<string>",
"idleTimeoutSeconds": 123,
"isBuiltin": true,
"maxSessionDurationSeconds": 123,
"persistence": "PERSISTENCE_MODE_UNSPECIFIED",
"priority": 123,
"refreshRotationWindowSeconds": 123,
"refreshTokenTtlSeconds": 123,
"rotateRefreshOnUse": true,
"ssfReceive": {
"enabled": true,
"ssfReceiverStreamIds": [
"<string>"
]
},
"ssfTransmit": {
"enabled": true,
"eventTypes": [
"<string>"
],
"ssfTransmitterStreamIds": [
"<string>"
]
},
"updatedAt": "2023-11-07T05:31:56Z"
}
],
"nextPageToken": "<string>"
}Search App User Session Policies
Search the effective session policies for users holding this application’s SSO sign-in entitlement. Policies are selected per user, not attached to the application; actual sign-in decisions are recorded in the system log.
package main
import(
"context"
"github.com/conductorone/conductorone-sdk-go/pkg/models/shared"
conductoronesdkgo "github.com/conductorone/conductorone-sdk-go"
"github.com/conductorone/conductorone-sdk-go/pkg/models/operations"
"log"
)
func main() {
ctx := context.Background()
s := conductoronesdkgo.New(
conductoronesdkgo.WithSecurity(shared.Security{
BearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
Oauth: "<YOUR_OAUTH_HERE>",
}),
)
res, err := s.SessionPolicy.SearchAppUserSessionPolicies(ctx, operations.C1APISessionPolicyV1SessionPolicyServiceSearchAppUserSessionPoliciesRequest{
AppEntitlementID: "<id>",
AppID: "<id>",
})
if err != nil {
log.Fatal(err)
}
if res.SessionPolicyServiceSearchAppUserSessionPoliciesResponse != nil {
// handle response
}
}curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"pageSize": 123,
"pageToken": "<string>"
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search"
payload = {
"pageSize": 123,
"pageToken": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({pageSize: 123, pageToken: '<string>'})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'pageSize' => 123,
'pageToken' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/apps/{app_id}/entitlements/{app_entitlement_id}/session-policies/search")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"list": [
{
"accessTokenTtlSeconds": 123,
"continuousDefaultOutcome": {
"allow": {
"floorLevel": "AUTH_LEVEL_UNSPECIFIED"
},
"challengeRequired": {
"types": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
},
"deny": {
"reasonAdmin": "<string>",
"reasonUser": "<string>"
},
"enrollmentRequired": {
"credentialTypes": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
},
"stepUpRequired": {
"level": "AUTH_LEVEL_UNSPECIFIED",
"maxAgeSeconds": 123,
"types": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
}
},
"continuousRules": [
{
"description": "<string>",
"id": "<string>",
"matchCel": "<string>",
"mode": "POLICY_RULE_MODE_UNSPECIFIED",
"outcome": {
"allow": {
"floorLevel": "AUTH_LEVEL_UNSPECIFIED"
},
"challengeRequired": {
"types": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
},
"deny": {
"reasonAdmin": "<string>",
"reasonUser": "<string>"
},
"enrollmentRequired": {
"credentialTypes": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
},
"stepUpRequired": {
"level": "AUTH_LEVEL_UNSPECIFIED",
"maxAgeSeconds": 123,
"types": [
"CREDENTIAL_TYPE_UNSPECIFIED"
]
}
}
}
],
"createdAt": "2023-11-07T05:31:56Z",
"credentialDurations": [
{
"accessTokenTtlSeconds": 123,
"credentialType": "CREDENTIAL_TYPE_UNSPECIFIED",
"maxSessionDurationSeconds": 123
}
],
"deletedAt": "2023-11-07T05:31:56Z",
"displayName": "<string>",
"id": "<string>",
"idleTimeoutSeconds": 123,
"isBuiltin": true,
"maxSessionDurationSeconds": 123,
"persistence": "PERSISTENCE_MODE_UNSPECIFIED",
"priority": 123,
"refreshRotationWindowSeconds": 123,
"refreshTokenTtlSeconds": 123,
"rotateRefreshOnUse": true,
"ssfReceive": {
"enabled": true,
"ssfReceiverStreamIds": [
"<string>"
]
},
"ssfTransmit": {
"enabled": true,
"eventTypes": [
"<string>"
],
"ssfTransmitterStreamIds": [
"<string>"
]
},
"updatedAt": "2023-11-07T05:31:56Z"
}
],
"nextPageToken": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Path Parameters
The SSO application's catalog app.
The sign-in entitlement on the app. Must be the entitlement named by the app's SSO application; any other entitlement is rejected.
Body
Search the policies selected for users with accounts holding the application's SSO sign-in entitlement. Accounts not linked to a current user are excluded.
Response
Distinct effective policies, ordered by display name and policy ID. A tenant default appears only if it is selected for at least one user. An empty list means no effective policies were found, including when no current users have accounts holding the sign-in entitlement.
Distinct effective policies, ordered by display name and policy ID. A tenant default appears only if it is selected for at least one user. An empty list means no effective policies were found, including when no current users have accounts holding the sign-in entitlement.
Was this page helpful?