Add Java rules to a JRM profile

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

Adds URL-based and group-based Java rules to a Draft JRM profile.

Request URL

https://{serverurl}/bsp/api/v1/bmp/jrm/{jrm_profile_id}/jrm_payloads

Scope

DesktopCentralCloud.BrowserManager.CREATECopied!

Header

Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Request Headers

Content-TypestringMandatory
application/jsonapplication/jsonCopied!
AcceptstringMandatory
application/jsonapplication/jsonCopied!

- Path Parameters

jrm_profile_idstringMandatory

JRM Profile ID from List JRM Profiles response (jrm_profile_id field)

- Request Body

Send Java rules inside the 'jrm_payloads' object. Use 'urls' for website-specific rules (provide webdomain_ids from Web Domain Management) OR 'groups' for group-based rules (provide group ids). Do not mix both in the same payload. Actions: 0=Block Java, 1=Run (allow with optional java_version), 2=Default (browser setting). The 'block_message' field is only available when action=0 (Block) to show a custom message to users.

application/json
JSON Object

Java rules payload. Pick URL or Group from the dropdown

Hide Sub-Attributes
jrm_payloadsOptional

Rule set

Show Sub-Attributes
oneOf

Examples

URL Rules
URL Rules -- Rules for specific website URLs
Group Rules -- Rules for webdomain groups

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request POST \
  --url https://appdomains/bsp/api/v1/bmp/jrm/{jrm_profile_id}/jrm_payloads \
  --header 'Accept: application/json' \
  --header 'Authorization: Zoho-oauthtoken  d92d4xxxxxxxxxxxxx15f52' \
  --header 'Content-Type: application/json' \
  --data '{}'

Sample Request Body - URL Rules

Block Java on URLs with message

Copied!
  {
    "jrm_payloads": {
      "urls": [
        {
          "action": 0,
          "webdomain_ids": [
            "3",
            "1"
          ]
        }
      ],
      "block_message": "Java applet execution is blocked by security policy"
    }
  }
                
Show full

Allow Java on URLs

Copied!
  {
    "jrm_payloads": {
      "urls": [
        {
          "java_version": "1.7.0_04",
          "action": 1,
          "webdomain_ids": [
            "3",
            "1"
          ]
        }
      ]
    }
  }
                
Show full

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request POST \
  --url https://appdomains/bsp/api/v1/bmp/jrm/{jrm_profile_id}/jrm_payloads \
  --header 'Accept: application/json' \
  --header 'Authorization: Zoho-oauthtoken  d92d4xxxxxxxxxxxxx15f52' \
  --header 'Content-Type: application/json' \
  --data '{}'

Sample Request Body - Group Rules

Block Java for group with message

Copied!
  {
    "jrm_payloads": {
      "groups": [
        {
          "ids": [
            "26"
          ],
          "action": 0
        }
      ],
      "block_message": "Java applet execution is blocked by security policy"
    }
  }
                
Show full

Default action for group

Copied!
  {
    "jrm_payloads": {
      "groups": [
        {
          "ids": [
            "28"
          ],
          "action": 2
        }
      ]
    }
  }
                
Show full

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object

Response after adding a new payload

Hide Sub-Attributes
jrm_payloadsJSON Array

The newly created payload with its rules. The 'config_data_item_id' inside 'jrm_details' is needed for future Modify/Delete operations

Show Sub-Attributes
JSON Object

Payload details returned after create or modify

Show Sub-Attributes
payload_typestring

Always '64101' identifies this as a Java Rules Manager payload

block_messagestring

Custom message shown to users when Java is blocked (only applies when action=0). Empty string if not set

jrm_detailsJSON Array

The rule sets with URL/group rules. Use 'config_data_item_id' from here as {jrm_payload_id} for future Modify/Delete calls

Show Sub-Attributes
JSON Object

Individual rule set with URL and group rules

Show Sub-Attributes
config_data_item_idstring

Unique ID for this rule set use as {jrm_payload_id} in Modify Payload (PUT) API

urlsJSON Array

URL-based rules each entry controls Java behavior for a specific website

Show Sub-Attributes
JSON Object

Java rule for a specific website URL

Show Sub-Attributes
idstring

Webdomain ID (references a site configured in Browser Security > Web Domain Management)

urlstring

The website URL/domain name (read-only, set when the webdomain was created)

actionstring

What to do with Java on this site: '0' = Block Java entirely, '1' = Allow Java to run, '2' = Use browser's default Java setting

java_versionstring

When action is '1' (Allow), specifies the required Java version (e.g., '1.7.0_04'). Leave empty to allow any installed version

groupsJSON Array

Group-based rules each entry controls Java behavior for a group of websites

Show Sub-Attributes
JSON Object

Java rule for a webdomain group

Show Sub-Attributes
group_idstring

Webdomain group ID (references a group configured in Browser Security > Web Domain Management)

webdomain_groupstring

Name of the webdomain group (read-only, set when the group was created)

actionstring

What to do with Java for all sites in this group: '0' = Block Java, '1' = Allow Java, '2' = Use browser default

java_versionstring

When action is '1' (Allow), specifies the required Java version. Leave empty to allow any installed version

default_riasboolean

Whether default Rich Internet Application settings are applied

config_labelstring

Configuration label (always 'JAVA_RULES_MANAGER')

- HTTP code 400

Response Body - application/json
JSON Object
Hide Sub-Attributes
errorcodestring

Error identifier (e.g., 'IAM0006' for invalid field value)

errormsgstring

Describes which field or value is invalid

- HTTP code 401

Response Body - application/json
JSON Object
Hide Sub-Attributes
errorCodelong

Unauthorized error code: credentials missing, expired, or invalid

errorMsgstring

Authentication failure reason

- HTTP code 403

Response Body - application/json
JSON Object
Hide Sub-Attributes
errorCodelong

Error code indicating insufficient permissions

errorMsgstring

Message indicating insufficient privileges to access this resource

- HTTP code 404

Response Body - application/json
JSON Object
Hide Sub-Attributes
errormsgstring

Message indicating the requested resource was not found

- HTTP code 429

Response Body - application/json
JSON Object
Hide Sub-Attributes
errorCodelong

Rate limit error code returned when the API call reached threshold

errorMsgstring

Rate limit exceeded message with retry guidance

- HTTP code 500

Response Body - application/json
JSON Object
Hide Sub-Attributes
errormsgstring

Description of the server-side error

Possible Response Codes

200HTTP code
400HTTP code
401HTTP code
403HTTP code
404HTTP code
429HTTP code
500HTTP code

Sample Response: HTTP 200

Created payload

Copied!
  {
    "jrm_payloads": [
      {
        "payload_type": "64101",
        "block_message": "",
        "jrm_details": [
          {
            "config_data_item_id": "971",
            "urls": [
              {
                "java_version": "1.7.0_04",
                "action": "1",
                "id": "3",
                "url": "localhost"
              }
            ],
            "groups": []
          }
        ],
        "default_rias": false,
        "config_label": "JAVA_RULES_MANAGER"
      }
    ]
  }
                
Show full

Sample Response: HTTP 400

Webdomain not found

Copied!
  {
    "errorcode": "IAM0006",
    "errormsg": "Field value of {0} is invalid."
  }
                
Show full

Group not found

Copied!
  {
    "errorcode": "IAM0006",
    "errormsg": "Field value of {0} is invalid."
  }
                
Show full

Sample Response: HTTP 401

Unauthorized

Copied!
  {
    "errorCode": "IAM0001",
    "errorMsg": "Authentication key is invalid. Please regenerate the key and try again."
  }
                
Show full

Sample Response: HTTP 403

Forbidden

Copied!
  {
    "errorCode": "FORBIDDEN",
    "errorMsg": "You do not have permission to access this resource"
  }
                
Show full

Sample Response: HTTP 404

Profile not found

Copied!
  {
    "errormsg": "Profile not found"
  }
                
Show full

Sample Response: HTTP 429

Rate limit exceeded

Copied!
  {
    "errorCode": "RATE_LIMIT_EXCEEDED",
    "errorMsg": "You have exceeded the maximum number of API calls. Please try again later."
  }
                
Show full

Sample Response: HTTP 500

Server error

Copied!
  {
    "errormsg": "Internal Server error, Please try again in a moment."
  }
                
Show full

Duration: 1 minute | Threshold: 60 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.