1. Application Properties Summary

This section lists the properties available for a server administrator to configure Publication For Capella.

These properties need to be set in the file config/application.properties of the server.

They have sensible default values whenever it is possible.

1.1. Properties Inherited from Underlying Frameworks

1.1.1. General Application Server Properties

Property key Default value Description

server.port

443

The port the server must listen to.

server.servlet.session.timeout

30m

The session timeout (inactivity delay after which a web session is invalidated).

server.ssl.key-store-type

Certificate type, e.g. PKCS12.

server.ssl.key-store

Path to the SSL keystore file, e.g. config/keystore_file.

server.ssl.key-store-password

Password of the SSL Keystore file.

server.ssl.key-alias

Alias of the SSL key in the keystore file.

server.ssl.key-password

Password of the key in the file (generally identical to the file’s password).

spring.datasource.url

jdbc:postgresql://perseus-server-postgres:5432/perseus

The JDBC URL of the Publication For Capella database.

1.1.2. OpenID Connect Properties

The following properties need to be set only if authentication with OpenID Connect is desired.

In this section and the following, {oidc-provider-name} refers to the name of the OpenID Connect provider as it will be displayed in the Login page, if configured.
Table 1. Spring Security Framework - OAuth2 Properties
Property Key Description

spring.security.oauth2.client.provider.{oidc-provider-name}.issuer-uri

The issuer URI of the OpenID Connect server, which can be used to discover other URIs (authorization URI, token URI, User Info URI, and JWK Set URI). For example, when using keycloak, http://keycloak.example.com/realms/Publication. If this property is set, the 4 next properties are not necessary.

spring.security.oauth2.client.provider.{oidc-provider-name}.authorization-uri

The authorization URI of the OpenID Connect server. For example, when using keycloak, http://keycloak.example.com/realms/Publication/protocol/openid-connect/auth.

spring.security.oauth2.client.provider.{oidc-provider-name}.token-uri

The token URI of the OpenID Connect server. For example, when using keycloak, http://keycloak.example.com/realms/Publication/protocol/openid-connect/token

spring.security.oauth2.client.provider.{oidc-provider-name}.user-info-uri

The user information URI of the OpenID Connect server. For example, when using keycloak, http://keycloak.example.com/realms/Publication/protocol/openid-connect/userinfo

spring.security.oauth2.client.provider.{oidc-provider-name}.jwk-set-uri

The JWK set URI of the OpenID Connect server. For example, when using keycloak, http://keycloak.example.com/realms/Publication/protocol/openid-connect/certs

spring.security.oauth2.client.provider.{oidc-provider-name}.user-name-attribute

The attribute to consider as the username within Publication For Capella, for instance preferred_username. The value read in this attribute must be stable over time. Do not use an attribute that would contain the readable person name such as 'Jane Doe', but rather an attribute that would contain a stable and unique login such as 'jdoe'.

spring.security.oauth2.client.registration.{oidc-provider-name}.authorization-grant-type

The authorization grant type to use by Publication For Capella, should be authorization_code.

spring.security.oauth2.client.registration.{oidc-provider-name}.client-id

The Publication For Capella Client-ID, as registered in the OpenID Connect server.

spring.security.oauth2.client.registration.{oidc-provider-name}.client-secret

The Publication For Capella Client secret, as registered in the OpenID Connect server.

spring.security.oauth2.client.registration.{oidc-provider-name}.redirect-uri

The OpenID Connect server’s redirect URI, for example {baseUrl}/login/oauth2/code/{registrationId}.

spring.security.oauth2.client.registration.{oidc-provider-name}.scope

The OpenID Connect scope to use, should be openid.

spring.security.oauth2.resourceserver.jwt.issuer-uri

The JWT issuer URI, for example http://keycloak.example.com/realms/Publication. This is used to secure the API with access tokens when the ID provider uses JWT access tokens. This must not be used together with spring.security.oauth2.resourceserver.opaquetoken.introspection-uri.

spring.security.oauth2.resourceserver.opaquetoken.introspection-uri

The id provider introspection URI to verify opaque access tokens, for example http://ipd.example.com/oauth2/introspect. This is used to secure the API with access tokens when the ID provider uses opaque access tokens. This must not be used together with spring.security.oauth2.resourceserver.jwt.issuer-uri.

spring.security.oauth2.resourceserver.opaquetoken.client-id

The ID of the client that uses these access tokens. This must only be used together with introspection-uri.

spring.security.oauth2.resourceserver.opaquetoken.client-secret

The secret of the client that uses these access tokens. This must only be used together with introspection-uri.

1.1.3. Sirius-Web Properties

Property key Description

sirius.components.cors.allowedOriginPatterns

A list of patterns for servers that can use the Publcation server’s resources in their own web pages. For example, ,https://some-server.example.com:[].

1.1.4. Obeo Enterprise Framework Properties

Property key Description

ocp.license

License key obtained from Obeo.

obeocloudplatform.admin.password

Default password of the admin account. Must be set before the first launch of the Publication server after installation. This property is used only the first time the server is launched, to create the admin user’s password. It is then recommended that the administrator changes his or her password via the web UI.

ocp.oidc.organisation.claimKey

The claim key for user organization.

ocp.oidc.organisation.defaultValue

The default organization where the missing teams will be created.

ocp.oidc.team.claimKey

The claim key for user teams.

ocp.oidc.team.arrayDelimiter

Delimiter used to split multiple team names from the claim.

ocp.oidc.team.createIfAbsent

Whether to automatically create a team if it does not exist.

ocp.oidc.team.defaultValue

Default team assigned when the claim is empty or mapping is missing.

ocp.oidc.team.filter

A regular expression filter indicating whether the team name in the claim should be considered or not.

1.2. Publication For Capella Properties

The following properties are specific to Publication For Capella.

Property key Default value Description

perseus.default.org.name

Default Organization

The name of the default organization.

perseus.jama.poll

true

Enablement of the polling of Jama Connect servers. true to turn on and false to turn off the polling.

perseus.jama.poll.delay.seconds

30

Jama server polling delay, in seconds.

perseus.sync.attachments.enable

true

Enablement of the synchronization of attachments (with Jama Connect servers). true to turn on and false to turn off the polling.

perseus.metaclass.filter.default

Path to the metaclass filter global defaults file.

perseus.versioning.branch-lock-timeout-ms

1000

Timeout for Branch locks, in milliseconds.

perseus.model-lock-timeout-ms

3000

Timeout for Model locks, in milliseconds.

perseus.model-publish-attempts

10

Number of attempts to lock the model for publications.

perseus.ui.extension-reload-delay

PT30M

Delay to reload the UI extension HTML files, in ISO-8601 duration format. Negative durations or non-parsable durations are ignored and fall back to the default.

perseus.ui.extensions[0].id

ID of UI extension number 0 (the 1st extension).

perseus.ui.extensions[0].location

Location of UI extension number 0 (the 1st extension), must be HEADER-RIGHT for now.

perseus.ui.extensions[0].label

Label of UI extension number 0 (the 1st extension), which will be displayed in the desired location. It is recommended to finish this label with a separator and a space, for example: `perseus.ui.extensions[0].label=Get Help - ` with an addition space at the end.

perseus.ui.extensions[0].content

URI of the HTML file to load, like file:///C:/data/extension0.html.

perseus.csp.whitelist

Path to the Content Security Policy whitelist file.

perseus.properties.mappings

Path to the file that contains the mappings of properties

perseus.workbench.panels.left.visible

true

Set the visibility of the left-hand panel.

perseus.workbench.panels.left.views[n].name

explorer/search; n can be 0 or 1.

Set the n-th view (starting at 0) in the left-hand panel (either explorer or search).

perseus.workbench.panels.left.views[n].visible

true/false.

Set the default visibility of the n-th view (starting at 0) in the left-hand panel.

perseus.workbench.panels.right.visible

true

Set the visibility of the right-hand panel.

perseus.workbench.panels.right.views[n].name

details/history; n can be 0 or 1.

Set the n-th view (starting at 0) in the right-hand panel (either details or history).

perseus.workbench.panels.right.views[n].visible

true/false.

Set the default visibility of the n-th view (starting at 0) in the right-hand panel.

perseus.oauth2.registration.id.for.{contributor-client}

keycloak

Registration ID of the OAuth-2.0 Client that provides JWT to the Perseus contributor client. The segment {contributor-client} must be replaced by the client ID declared for the Publication For Capella Contributor Client in the OIDC server. The value is {oidc-provider-name}.

perseus.oauth2.jwt.client.id.claim

azp

Name of the claim to use to obtain the client ID from the JWT provided by the OIDC server for a contributor client authentication. By default, the client ID is read in the azp claim (Authorized Party), but tests have shown that different OIDC server provide that information in different claims, for instance client_id. If the claim is not found, Publication For Capella will attempt to read it from the audience claim.

perseus.oauth2.signing.algorithm.{registration-id}

RS256

Signing Algorithm to use to verify JSON Web Tokens issued by the authentication provider corresponding to {registration-id}. For example, when using keycloak as registration ID, set perseus.oauth2.signing.algorithm.keycloak to HS256 to verify tokens if they’re signed with the HS256 algorithm.
Valid values are: RS256 (the default), RS384, RS512, ES256, ES384, ES512, PS256, PS384, PS512, HS256, HS384, and HS512.

perseus.oauth.connection-request-timeout-ms

3000

Timeout for OAuth connection requests, in milliseconds.

perseus.oauth.connect-timeout-ms

5000

Timeout for OAuth connections, in milliseconds.

perseus.oauth.consumer-parameter-style

AUTHORIZATION_HEADER

Protocol to use to obtain an OAuth-1 access token. Possible values are: AUTHORIZATION_HEADER, BODY, QUERY_STRING. BODY was used until 2025.10 included. Starting with 2025.12.0, the value can be configured, and defaults to AUTHORIZATION_HEADER for compatibility with Polarion 2512.

perseus.oauth.socket-timeout-ms

8000

Timeout for OAuth sockets, in milliseconds.

perseus.oauth.token.validity

The duration for which an OAuth-1.0 token is valid, in ISO-8601 format. For example: P1D for one day, PT1H for one hour, etc.

perseus.oslc.host-name

The public URL of the publication server, as it is accessed by third-party servers and end-users. For example, https://perseus.mycompany.com:9443.

perseus.oslc.rootservices-cache-validity-sec

300 (5 minutes)

Duration for which an entry in the rootservices cache is considered valid.

perseus.oslc.rootservices-cache-size

100

Size of the rootservices cache.

perseus.oslc.links.fetchTimeoutSec

10

Timeout to fetch OSLC links, in seconds.

perseus.oslc.preview.defaultHeight

400px

Default height of OSLC previews, as a CSS String (including unit).

perseus.oslc.preview.defaultWidth

600px

Default width of OSLC previews, as a CSS String (including unit).

perseus.oslc.linking.default

Path to the OSLC linking default config file.

perseus.oslc.credentials.validity

PT8H (8 hours)

The duration for which OSLC credentials are valid, in ISO-8601 format. For example: P1D for one day, PT1H for one hour, etc.

perseus.http.client-headers[X-Atlassian-Token]

no-check

This property must be set to make it possible for Publication For Capella to access the Atlassian (Jira or confluence) OSLC API. This is necessary to be able to connect to recent versions of Jira or Confluence. Adding this property will cause Publication For Capella to systematically add a header X-Atlassian-Token: no-check to all HTTP requests emitted to third-party servers.