Skip to main content

Dig in to generated API Template from WSO2 API Manager

As the starting blog-post for 2013,I thought of summarizing about the implementation of key features of WSO2 API Manager as security,throttling,monitoring aspects by explaining a bit of API template.In WSO2 API Manager,once a API creator create the API from publisher app UI and change its status as 'PUBLISHED' ,a template xml for that API will be generated with its input attributes of name,version,context,endpoint,etc.

You can find that generated template from '{AM_Home}/repository/deployment/server/synapse-configs/default/api'.Below is such a generated sample API template.

When you observe that API,you'll notice for each API resource there's a separate in sequence and an out sequence created.And additionally apart from the input data added by the creator,you'll notice for an API ,four handlers have been engaged to each published API.



Each of the above handlers contain the implementation of key providing features of WSO2 API Manager.You can find each of the implementations of these handlers from  here.
An API Handler provides QoS features like security,throttling,monitoring for an API.
If I explained a bit of each of these;

  1. APIAuthenticationHandler -This provides the API Authentication support with OAuth2.0.All the API resource level authentication schemes handling through this handler.
  2. APIMgtUsageHandler- This provides API monitoring support with WSO2 BAM integration.
  3. APIMgtGoogleAnalyticsTrackingHandler-This provides API monitoring support with Google Analytics support.
  4. APIThrottleHandler-This provides API throttling handling support with pre-defined throttling policies.
  5. APIManagerExtentionHandler-This is a extention handler,looking for a in/out sequence with a pre-defined name pattern to be invoked if exits such named sequence.This handler first looks for a sequence named WSO2AM--Ext--[Dir], where [Dir] could be either In or Out, depending on the direction of the message. If such a sequence is found, it is invoked.Additionally below more API specific extension sequence is  also looked up by using the name pattern apiName--[Dir]. If such an API specific sequence is found, that is also invoked. The above searching sequences can be in global level or at the per API level.
Same-way,if you want to add a custom feature to support from API level,you can achieve it by writing a custom handler and engage it to the generated API template.To write such a custom handler ,you can find more information from here.
When an API invocation request comes to API Manager,first the request will process through the engaged handlers of the API element in sequential order.And if the request pass through each security,monitoring, throttling handling layers,it will direct to the relevant API resource.



Comments

Popular posts from this blog

Passing end-user details from client to real backend endpoint via JWT token

In real-world business system,WSO2 API Manager useful on exposing company APIs, in a secured and controlled manner with the features provided by APIManager as; OAuth support [To secure API invocations] Throttling support [To control API invocations] Monitoring support [To track API usage] More technically what happening is when a user sends a particular API request,it will goes to WSO2 APIManager node and from there,the request will route to the real implemented back-end endpoint of the particular API and get back the response and returned it to the API invoked user. There can be a use-case,that this back-end endpoint may expect the details of API invoked user as to pass those details to some internal company usage  as; Additional authentication/authorization Track usage data from an internal system. So how to support above requirement from WSO2 AM. There comes the use of JSON Web Token[JWT] implementation done inside WSO2 AM. JWT is a means of representing claims to...

How to rollback/commit processing messages from WSO2 ESB when enabled JMS transaction

This blog post describes the below use-case where WSO2 ESB 4.6.0 act as the intermediate channel in-between two JMS queues. The Use-case First messages will be de-queue to a proxy service deployed in WSO2 ESB from an queue in ActiveMQ message broker. Then inside ESB,the incoming messages will undergo with some message mediation flow and then the message will be send to another JMS queue deployed in JBoss server. Inside the ESB,following failures could be happen;            a) Failures during message mediation process failure inside ESB [for example if you                use   dbreportmediator/lookup mediator inside mediation flow,some times failures can                happen due  to database connection failures]          b) Message sending failure,due to endpoint is unavailability.[For example,the JBoss  ...

TPP Journey through WSO2 Open Banking

Introduction 2018 is all set to be a game-changing year for European banking. The Revised Payment Services Directive (PSD2) has opened the door to new third party providers [TPPs] to connect with banks and manage finances of bank customers on behalf of them. The PSD2 regulation has mandated banks to expose their core-banking account data and payment services to authorized TPPs to consume. Thus as a bank it’s essential to have a solution which will securely expose their internal banking services to third party providers in a trusted manner. WSO2 Open Banking solution provides all required components to expose bank APIs in a well secured manner in order to become PSD2 compliant. This article explains about the importance of the TPP role in PSD2 domain, the requirements set that banks need to provide for TPPs by PSD2 regulations and how WSO2 Open Banking solution supports these requirements.  From my last blog ,I have given an introduction for PSD2 and WSO2 Open Banking soluti...