Compare commits

...

11 Commits

2 changed files with 2248 additions and 0 deletions

File diff suppressed because it is too large Load Diff

View File

@ -0,0 +1,403 @@
openapi: 3.0.3
info:
title: Integration layer APIs for token storage for ABT
description: >-
APIs that give business processes access to the security and authorization state of a token within the scope of HTM. In the backend this is connected to a container which handles the accessToken en refreshToken management for an OVpas as given by GBO.
version: "1.0"
servers:
- url: https://services.acc.api.htm.nl/abt/containertokens/1.0
security:
- oAuthSample: [profile]
tags:
- name: securitytokens
paths:
/securitytokens:
post:
tags:
- securitytokens
summary: Create a new security token entry in the vault
description: Create a new security token entry in the vault, if the customerProfileId has been supplied create in the customerToken DB otherwise in the AnonymousToken DB
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/CreateSecurityTokenBody"
examples:
token details:
value:
{
"xTat": "cf694905-7f76-4799-b0bc-490716921323",
"otpKey": "123456789123456789123456789abcde",
"customerProfileId": 12314
}
responses:
"201":
description: Created
"400":
description: Bad Request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"404":
description: Not found
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
TAT not found:
value:
status: 404
title: Not Found
detail: TAT Account Not Found
"409":
description: Conflict
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
TAT already exists:
value:
status: 409
title: Conflict
detail: Security Token already exists
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Internal Server Error:
value:
status: 500
title: Internal Server Error
detail: An unknown error has occurred
/securitytokens/{xTat}/status:
parameters:
- name: xTat
in: path
schema:
type: string
example: 85dbeacc-b9aa-4d5b-bdec-9319010c597f
required: true
description: The xTat of the OVpastoken for which the status needs to be checked
- name: customerProfileId
in: query
schema:
type: integer
example: 323
required: false
description: The id of the customer Profile for which the request is being done, if customer has identified themselves
get:
tags:
- securitytokens
summary: Request the security and authorization status of an OV pas token
description: Request the security and authorization status of an OV pas token, if the customerProfileId has been supplied look in the customerToken DB otherwise check the AnonymousToken DB.
responses:
"200":
description: OK
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityTokenStatusResponse"
examples:
Not secured and not authorized :
summary: Not secured, not authorized
value:
{
"isAuthorized": false,
"isSecured": false
}
Secured and not authorized :
summary: Secured, not authorized
value:
{
"isAuthorized": false,
"isSecured": true
}
Secured and authorized :
summary: Secured and authorized
value:
{
"isAuthorized": true,
"isSecured": true
}
"400":
description: Bad Request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"404":
description: Not found
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
TAT not found:
value:
status: 404
title: Not Found
detail: TAT Account Not Found
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Internal Server Error:
value:
status: 500
title: Internal Server Error
detail: An unknown error has occurred
/securitytokens/{xTat}:
parameters:
- name: xTat
in: path
schema:
type: string
example: uuid
required: true
description: The xTat of the ovPastoken for which the status needs to be checked
- name: customerProfileId
in: query
schema:
type: integer
example: 323
required: false
description: The id of the customer Profile for which the request is being done, if customer has identified themselves
patch:
tags:
- securitytokens
summary: Validate the supplied OTP and secure and/or authorize the token
description: Validate the supplied OTP and secure and/or authorize the token if the customerProfileId has been supplied look in the customerToken DB otherwise check the AnonymousToken DB.
requestBody:
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityValidateTokenBody"
examples:
token:
value:
{
"otp": "123456"
}
responses:
"200":
description: OK
content:
application/json:
schema:
$ref: "#/components/schemas/SecurityTokenStatusResponse"
examples:
Not secured and not authorized :
summary: Not secured, not authorized
value:
{
"isAuthorized": false,
"isSecured": false
}
Secured and not authorized :
summary: Secured, not authorized
value:
{
"isAuthorized": false,
"isSecured": true
}
Secured and authorized :
summary: Secured and authorized
value:
{
"isAuthorized": true,
"isSecured": true
}
"400":
description: Bad Request
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Missing Parameters:
value:
status: 400
title: Missing Mandatory Parameter
detail: Required parameter {0} is missing.
Invalid Parameters:
value:
status: 400
title: Invalid Parameter
detail: Required parameter {0} is invalid.
"422":
description: Unprocessable Entity
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Validation failed:
value:
status: 422
title: OTP validation failed
detail: The supplied OTP could not be validated
"401":
description: Unauthorized
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Unauthorized:
value:
status: 401
title: Unauthorized
detail: Invalid Access Token
"404":
description: Not found
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
TAT not found:
value:
status: 404
title: Not Found
detail: TAT Account Not Found
"500":
description: Internal server error
content:
application/json:
schema:
$ref: "#/components/schemas/ErrorResponse"
examples:
Internal Server Error:
value:
status: 500
title: Internal Server Error
detail: An unknown error has occurred
components:
securitySchemes:
oAuthSample:
type: oauth2
description: This API uses OAuth 2 with the clientCredentials flow. [More info](https://api.example.com/docs/auth)
flows:
clientCredentials: # <---- OAuth flow( clientCredentials)
tokenUrl: https://identity.{env}.api.htm.nl/oauth2/token
scopes:
profile: "Access user profile"
schemas:
ErrorResponse:
description: Default response when an invalid request has been sent
type: object
properties:
status:
type: integer
description: >-
A status IS An integer that represents the HTTP status code of the
response.
example: 400
title:
type: string
description: A title IS A string that provides a brief summary of the error.
detail:
type: string
description: A detail IS A string that provides more details about the error.
CreateSecurityTokenBody:
description: Body for when the a new security token entry is created
type: object
required:
- xTat
- otpKey
properties:
xTat:
type : string
description: >-
Unique identifier for the GBO transit account
example: 03071794-482a-4168-b60f-84669a9e6a76
otpKey:
type : string
description: >-
Key used to validate the OTP at GBO
example: 123456789123456789123456789abcde
customerProfileId:
type : integer
description: >-
CustomerProfileId of the account requesting security or giving authorization
example: 123456
SecurityTokenStatusResponse:
description: Response for when the status of a token is requested
type: object
properties:
isSecured:
type: boolean
description: >-
Is the OVpas secured according to the GBO
example: false
isAuthorized:
type: boolean
description: >-
Does HTM have the authorization to access the secured the data of the OVpas
example: false
SecurityValidateTokenBody:
description: Body for when the a token entry is validated
type: object
required:
- otp
properties:
otp:
type : string
description: >-
OTP to be used to secure the token and retrieve the JWT at GBO
example: 123456