143 lines
4.7 KiB
YAML
143 lines
4.7 KiB
YAML
openapi: 3.0.1
|
|
info:
|
|
title: Integraion layer APIs for token storage for ABT
|
|
description: >-
|
|
APIs that give business processes access to the security and authorization state of a token within the scope of HTM. In the backend this is connected to a container which handles the accessToken en refreshToken management.
|
|
version: "2.0"
|
|
servers:
|
|
- url: https://services.acc.api.htm.nl/abt/containertokens/1.0
|
|
tags:
|
|
- name: tokens
|
|
paths:
|
|
/tokens/{xtat}/status:
|
|
parameters:
|
|
- name: xtat
|
|
in: path
|
|
schema:
|
|
type: string
|
|
example: uuid
|
|
required: true
|
|
description: The xTAT for the token for which the status needs to be checked
|
|
- name: customerProfileId
|
|
in: query
|
|
schema:
|
|
type: integer
|
|
example: 323
|
|
required: false
|
|
description: The id of the customer Profile for which the request is being done, if customer has identified themselves
|
|
get:
|
|
tags:
|
|
- tokens
|
|
summary: Request the security and authorization status of an OV pas token
|
|
description: Request the security and authorization status of an OV pas token, if the customerProfileId has been supplied look in the customerToken DB otherwise check the AnonymousToken DB.
|
|
responses:
|
|
"200":
|
|
description: OK
|
|
content:
|
|
application/json:
|
|
schema:
|
|
$ref: "#/components/schemas/TokenStatusResponse"
|
|
example:
|
|
isApproved: false
|
|
isSecured: false
|
|
"400":
|
|
description: Bad Request
|
|
content:
|
|
application/json:
|
|
schema:
|
|
$ref: "#/components/schemas/ErrorResponse"
|
|
examples:
|
|
Missing Parameters:
|
|
value:
|
|
status: 400
|
|
title: Missing Mandatory Parameter
|
|
detail: Required parameter {0} is missing.
|
|
Invalid Parameters:
|
|
value:
|
|
status: 400
|
|
title: Invalid Parameter
|
|
detail: Required parameter {0} is invalid.
|
|
"401":
|
|
description: Unauthorized
|
|
content:
|
|
application/json:
|
|
schema:
|
|
$ref: "#/components/schemas/ErrorResponse"
|
|
examples:
|
|
Unauthorized:
|
|
value:
|
|
status: 401
|
|
title: Unauthorized
|
|
detail: Invalid Access Token
|
|
"404":
|
|
description: Not found
|
|
content:
|
|
application/json:
|
|
schema:
|
|
$ref: "#/components/schemas/ErrorResponse"
|
|
examples:
|
|
TAT not found:
|
|
value:
|
|
status: 404
|
|
title: Not Found
|
|
detail: TAT Account Not Found
|
|
"500":
|
|
description: Internal server error
|
|
content:
|
|
application/json:
|
|
schema:
|
|
$ref: "#/components/schemas/ErrorResponse"
|
|
example:
|
|
error: An unknown error has occurred
|
|
components:
|
|
schemas:
|
|
unavailable:
|
|
type: object
|
|
GenerateTatOutput:
|
|
type: object
|
|
properties:
|
|
uid:
|
|
type: string
|
|
description: >-
|
|
An uid IS A unique identifier THAT is associated with the
|
|
user.
|
|
recipient:
|
|
type: string
|
|
description: >-
|
|
A recipient IS A unique identifier THAT is associated with the
|
|
TAT owner.
|
|
key:
|
|
type: string
|
|
description: >-
|
|
A key IS a 32 character string THAT uniquely identifies the
|
|
OTP session.
|
|
ErrorResponse:
|
|
description: Default response when an invalid request has been sent
|
|
type: object
|
|
properties:
|
|
status:
|
|
type: integer
|
|
description: >-
|
|
A status IS An integer that represents the HTTP status code of the
|
|
response.
|
|
example: 400
|
|
title:
|
|
type: string
|
|
description: A title IS A string that provides a brief summary of the error.
|
|
detail:
|
|
type: string
|
|
description: A detail IS A string that provides more details about the error.
|
|
TokenStatusResponse:
|
|
description: Default response when an invalid request has been sent
|
|
type: object
|
|
properties:
|
|
isSecured:
|
|
type: boolean
|
|
description: >-
|
|
Is the OVpas secured according to the GBO
|
|
example: False
|
|
isAuthorized:
|
|
type: boolean
|
|
description: >-
|
|
Does HTM have the authorization to access the secured the data of the OVpas
|
|
example: False |