Zum Hauptinhalt springen

Konfiguration

Alle Optionen beider SDKs auf einer Seite. Was Sie nicht setzen, bekommt einen Default — mit Ausnahme der Pflichtfelder Credentials und Umgebung (und in .NET der eigenen DestinationId). Den Einstieg mit Beispielkonfiguration zeigt das Rezept Einrichten.

Datei oder Code — beides geht​

Jede Option auf dieser Seite lässt sich auf zwei Wegen setzen. Die YAML-/JSON-Beispiele unten zeigen den Datei-Weg; der Code-Weg verwendet dieselben Namen.

Datei (YAML)Code (Builder)
EinstiegFitConnectSdk.fromConfigYaml(path)FitConnectSdk.fromConfigBuilder() mit .credentials(), .environment(), .settings()
sdkSettingsBlock in der YAMLSdkSettings.builder()
httpConfigsdkSettings.httpConfigHttpConfig.builder() mit .timeouts(), .proxyConfig(), .retryConfig()
attachmentChunkingConfigsdkSettings.attachmentChunkingConfigAttachmentChunkingConfig.builder()
validationConfigsdkSettings.validationConfigValidationConfig.builder()
virusScannerConfigsdkSettings.virusScannerConfigVirusScannerConfig.daemonOnly(), processOnly(), icapOnly()
environmentTEST, STAGE, PROD oder BlockFitConnectEnvironment.TEST oder FitConnectEnvironment.builder()

Die YAML-Schlüssel heißen wie die Builder-Methoden — mit einer Ausnahme: der Block httpConfig.timeoutConfig wird im Code mit HttpConfig.builder().timeouts(TimeoutConfig) gesetzt. Was Sie im Builder nicht setzen, bekommt denselben Default wie ein fehlender YAML-Schlüssel. Beide Wege lassen sich mischen: Credentials und Umgebung aus der Datei, Settings im Code — oder umgekehrt Werte aus einem Vault in den Builder geben.

Vollständige Beispielkonfiguration​

credentials:
clientId: "your-client-id"
clientSecret: "your-client-secret"

environment: "TEST" # TEST | STAGE | PROD — oder ein Block für eine eigene Umgebung (siehe unten)

sdkSettings:
httpConfig:
timeoutConfig:
readTimeout: 30
writeTimeout: 30
connectionTimeout: 30
callTimeout: 30
proxyConfig:
host: "" # leer = kein Proxy
port: 0
basicAuth:
username: ""
password: ""
retryConfig:
allowRetries: true
retryableStatusCodes: [408, 429, 500, 502, 503, 504]
maxRetryCount: 5
initialDelayInMs: 500

attachmentChunkingConfig:
chunkAllAttachments: false
chunkSizeInMB: 10
attachmentStoragePath: "/tmp/fit-connect-attachments"

validationConfig:
validateMetadata: true
validateData: true
validateAttachments: true
customSchemas: [] # eigene JSON-/XSD-Schemata, siehe Rezept „Custom Schemata“

# virusScannerConfig: … # optionales Modul, siehe Rezept „Virenscanner anbinden“
concurrentAttachmentStreams: 3

Dieselbe Konfiguration programmatisch:

SdkSettings settings = SdkSettings.builder()
.httpConfig(HttpConfig.builder()
.timeouts(TimeoutConfig.builder()
.readTimeout(30).writeTimeout(30).connectionTimeout(30).callTimeout(30).build())
.proxyConfig(ProxyConfig.builder().build()) // kein Proxy
.retryConfig(RetryConfig.builder()
.allowRetries(true)
.retryableStatusCodes(List.of(408, 429, 500, 502, 503, 504))
.maxRetryCount(5).initialDelayInMs(500).build())
.build())
.attachmentChunkingConfig(AttachmentChunkingConfig.builder()
.chunkAllAttachments(false).chunkSizeInMB(10)
.attachmentStoragePath(Path.of("/tmp/fit-connect-attachments")).build())
.validationConfig(ValidationConfig.builder()
.validateMetadata(true).validateData(true).validateAttachments(true)
.customSchemas(List.of()).build())
// .virusScannerConfig(VirusScannerConfig.daemonOnly("clamav", 3310))
.concurrentAttachmentStreams(3)
.build();

FitConnectSdk sdk = FitConnectSdk.fromConfigBuilder()
.credentials("your-client-id", "your-client-secret")
.environment(FitConnectEnvironment.TEST)
.settings(settings)
.build();

Die Schlüsselnamen entsprechen den Feldern von SdkSettings/HttpConfig (timeoutConfig, proxyConfig, retryConfig). Schlüsselmaterial (DestinationKeys, ReplyKeys) ist bewusst nicht Teil dieser Datei und auch kein Builder-Parameter — es wird beim Erzeugen von Organisation/OnlineService übergeben, siehe Schlüssel und Rollover.

Eigene oder angepasste Umgebung​

In der YAML ersetzt ein Block den Namen der Umgebung:

environment:
name: "LOCAL"
authUrl: "https://my-auth/token"
routingUrl: "https://my-routing"
submissionApiUrl: "https://my-api/submission-api"
portalUrl: "https://my-portal"
destinationApiUrl: "https://my-api/destination-api"
allowInsecureKeys: true

Programmatisch:

FitConnectEnvironment env = FitConnectEnvironment.builder()
.name("LOCAL")
.authUrl("https://my-auth/token")
.routingUrl("https://my-routing")
.submissionApiUrl("https://my-api/submission-api")
.portalUrl("https://my-portal")
.destinationApiUrl("https://my-api/destination-api")
.allowInsecureKeys(true)
.build();

FitConnectSdk sdk = FitConnectSdk.fromConfigBuilder()
.credentials("client-id", "client-secret")
.environment(env)
.build();

HTTP-Konfiguration (Timeouts, Proxy, Retries)​

sdkSettings:
httpConfig:
timeoutConfig:
readTimeout: 60
writeTimeout: 60
connectionTimeout: 60
callTimeout: 120 # Gesamtdauer eines Aufrufs inkl. Retries
proxyConfig:
host: "proxy.example.net"
port: 8080
basicAuth:
username: "user"
password: "pass"
retryConfig:
allowRetries: true
maxRetryCount: 5
initialDelayInMs: 500
retryableStatusCodes: [408, 429, 500, 502, 503, 504]

Programmatisch — Proxy-Zugangsdaten kommen so aus einem Vault statt aus der Datei:

HttpConfig http = HttpConfig.builder()
.timeouts(TimeoutConfig.builder()
.readTimeout(60).writeTimeout(60).connectionTimeout(60).callTimeout(120).build())
.proxyConfig(ProxyConfig.builder()
.host("proxy.example.net").port(8080)
.basicAuth(new ProxyAuth(vault.user(), vault.password())).build())
.retryConfig(RetryConfig.builder()
.allowRetries(true).maxRetryCount(5).initialDelayInMs(500)
.retryableStatusCodes(List.of(408, 429, 500, 502, 503, 504)).build())
.build();

SdkSettings settings = SdkSettings.builder().httpConfig(http).build();

Validierungsverhalten steuern​

sdkSettings:
validationConfig:
validateMetadata: true
validateData: true
validateAttachments: true
SdkSettings settings = SdkSettings.builder()
.validationConfig(ValidationConfig.builder()
.validateMetadata(true).validateData(true).validateAttachments(true).build())
.build();

Ein enableAutoReject-Schalter existiert seit 4.0.0-rc.1 nicht mehr: receive(...) liefert immer einen Prüfbericht zurück, den Ihr Fachverfahren selbst auswertet — siehe Konzept: Der Prüfbericht.

Für die Registrierung eigener Fachschemata (JSON Schema / XSD) außerhalb von FIM und XÖV siehe Custom Schemata.

Attachment-Chunking konfigurieren​

Siehe das Rezept Große Anhänge senden und empfangen.

Property-Referenz Java​

Alle Builder hängen an SdkSettings.builder() (.httpConfig(…), .validationConfig(…), .attachmentChunkingConfig(…), .virusScannerConfig(…)); … steht für den jeweils davor genannten Builder.

Property (YAML)BuilderTypBeschreibung
validationConfig.validateMetadataValidationConfig.builder().validateMetadata()boolMetadaten-Schema-Prüfung aktivieren
validationConfig.validateData….validateData()boolFachdaten-Schema-Prüfung aktivieren
validationConfig.validateAttachments….validateAttachments()boolValidatoren für Anhänge ausführen (z. B. Virenprüfung)
validationConfig.customSchemas[].identifier….customSchemas(List.of(new CustomSchema(uri, path)))URIURN/URI, die mit der schemaUri im Metadatensatz übereinstimmt
validationConfig.customSchemas[].pathebd.stringDateisystempfad zur lokalen JSON-Schema- oder XSD-Datei
httpConfig.timeoutConfig.{readTimeout,writeTimeout,connectionTimeout,callTimeout}HttpConfig.builder().timeouts(TimeoutConfig.builder().readTimeout()…)int (Sekunden)Default 30 s je Phase
credentials.clientId / credentials.clientSecretFitConnectSdk.fromConfigBuilder().credentials(id, secret)stringPflicht. OAuth-Credentials
environment.environment(FitConnectEnvironment.TEST) / FitConnectEnvironment.builder()string / objectPflicht. TEST/STAGE/PROD oder Block mit eigenen URLs
httpConfig.retryConfig.allowRetriesRetryConfig.builder().allowRetries()boolDefault true
httpConfig.retryConfig.maxRetryCount / initialDelayInMs….maxRetryCount() / ….initialDelayInMs()intDefault 5 / 500
httpConfig.proxyConfig.*ProxyConfig.builder().host().port().basicAuth(new ProxyAuth(u, p))—Optionaler Proxy mit Basic Auth
httpConfig.retryConfig.retryableStatusCodes….retryableStatusCodes(List.of(…))ListDefault [408, 429, 500, 502, 503, 504]
attachmentChunkingConfig.chunkSizeInMBAttachmentChunkingConfig.builder().chunkSizeInMB()intDefault 10
attachmentChunkingConfig.chunkAllAttachments….chunkAllAttachments()boolDefault false. Alle Anhänge chunken, auch In-Memory
attachmentChunkingConfig.attachmentStoragePath….attachmentStoragePath(Path)stringLokaler Anhangspeicher, Default System-Temp
concurrentAttachmentStreamsSdkSettings.builder().concurrentAttachmentStreams()intParallelität beim Hochladen von Anhängen

Property-Referenz .NET​

PropertyTypBeschreibung
EnvironmentTagstringPflicht. TEST/STAGE/PROD/LOCAL/CI/CUSTOM
CustomEnvironment.*objectBei CUSTOM Pflicht: TokenUrl, SubmissionUrls[], RoutingUrl, SspUrl, DestinationUrl
Client.ClientId / Client.ClientSecretstringPflicht. OAuth-Credentials, eine Paarung für Senden und Empfangen
Client.DestinationIdGuidPflicht. UUID des eigenen Zustellpunkts (fromDestinationId)
Client.DecryptionKeysstring[]Private RSA-JWKs als JSON, geordnet (erster = aktiv). Leer für reine Sender
Client.SignatureKeystringPrivater Signatur-JWK als JSON. Nötig zum Annehmen/Ablehnen/Antworten
Client.VerifyDestinationOnStartupboolDefault true. Zustellpunkt und Typ beim Host-Start prüfen (braucht Netz)
Http.Timeouts.{Read,Write,Connection}int (Sekunden)Default 30 / 30 / 10
Http.Proxy.{Host,Port,Username,Password}—Optionaler Proxy
Http.Retry.AllowRetriesboolDefault false — für Produktion aktivieren
Http.Retry.RetryableStatusCodesint[]Empfehlung [408, 429, 500, 502, 503, 504]
Http.Retry.MaxRetryCountintEmpfehlung 5
Http.Retry.InitialDelayInMsintEmpfehlung 500
Attachments.ChunkSizeInMbintKein eingebauter Default (0, wenn nicht gesetzt) — muss bei aktiviertem Chunking explizit konfiguriert werden
Attachments.ChunkAllAttachmentsboolDefault false
Attachments.BaseDirectorystringDefault Path.GetTempPath()
Validation.{Metadata,Data,Attachments}boolDefault true. Validatoren ein-/ausschalten; Funde landen im Report

Übersicht der Default-Umgebungen​

PRODSTAGETEST
AuthBaseURLhttps://auth-prod.fit-connect.fitko.net/tokenhttps://auth-refz.fit-connect.fitko.net/tokenhttps://auth-testing.fit-connect.fitko.dev/token
RoutingBaseURLhttps://routing-api-prod.fit-connect.fitko.nethttps://routing-api-prod.fit-connect.fitko.net¹https://routing-api-testing.fit-connect.fitko.dev
SubmissionBaseURLshttps://prod.fit-connect.fitko.net/submission-apihttps://stage.fit-connect.fitko.net/submission-apihttps://test.fit-connect.fitko.dev/submission-api
SelfServicePortalBaseURLhttps://portal.auth-prod.fit-connect.fitko.nethttps://portal.auth-refz.fit-connect.fitko.nethttps://portal.auth-testing.fit-connect.fitko.dev
DestinationBaseURLhttps://prod.fit-connect.fitko.net/destination-apihttps://stage.fit-connect.fitko.net/destination-apihttps://test.fit-connect.fitko.dev/destination-api
allowInsecureKeysfalsefalsetrue
¹ STAGE hat keine eigene Routing-API – die PROD-Routing-URL wird als Fallback verwendet.