openapi: 3.2.0
info:
title: User Management Service Session API
version: 1.0.0
description: Endpoints to manage sessions
servers:
- url: /airmdrapi
tags:
- name: Session
description: Endpoints to manage sessions
paths:
/user/authenticate:
post:
tags:
- Session
operationId: authenticateUserAPI
summary: authenticate user
parameters:
- name: User-ID
in: header
description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: Organization-ID
in: header
description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: X-Request-ID
in: header
description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/AuthenticateRequest'
responses:
'200':
description: user authenticated successfully
content:
application/json:
schema:
$ref: '#/components/schemas/AuthenticateUserResponse'
default:
description: unexpected error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/user/login:
post:
tags:
- Session
operationId: loginUserAPI
summary: login user
parameters:
- name: X-Request-ID
in: header
description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/LoginRequest'
responses:
'200':
description: user logged in successfully
content:
application/json:
schema:
$ref: '#/components/schemas/LoginUserResponse'
default:
description: unexpected error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/user/login/url:
post:
tags:
- Session
operationId: getLoginUrlAPI
summary: get login url based on user email
parameters:
- name: X-Request-ID
in: header
description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: Organization-Hosturl
in: header
description: The hosturl associated with the request.
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/GetLoginUrlRequest'
responses:
'200':
description: user logged in successfully
content:
application/json:
schema:
$ref: '#/components/schemas/GetLoginUrlResponse'
default:
description: unexpected error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/user/logout:
get:
tags:
- Session
operationId: logoutUserAPI
summary: logout user
parameters:
- name: User-ID
in: header
description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: Organization-ID
in: header
description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: X-Request-ID
in: header
description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
responses:
'302':
description: user logged out successfully
headers:
Location:
description: URL to redirect the user to after successful logout.
schema:
type: string
default:
description: unexpected error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/session:
get:
tags:
- Session
operationId: getSessionAPI
summary: get session details
parameters:
- name: User-ID
in: header
description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: Organization-ID
in: header
description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: X-Request-ID
in: header
description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
responses:
'200':
description: session details fetched successfully
content:
application/json:
schema:
$ref: '#/components/schemas/LoginUserResponse'
default:
description: unexpected error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
put:
tags:
- Session
operationId: updateSessionAPI
summary: update session
parameters:
- name: User-ID
in: header
description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: Organization-ID
in: header
description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
- name: X-Request-ID
in: header
description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateSessionRequest'
responses:
'200':
description: session updated successfully
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateSessionResponse'
default:
description: unexpected error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
components:
schemas:
LoginUserResponse:
type: object
required:
- data
- message
properties:
message:
type: string
data:
$ref: '#/components/schemas/LoginUserData'
LoginRequest:
type: object
required:
- email
- password
properties:
email:
type: string
password:
type: string
UserRole:
type: string
description: role of the user. A user can view data in accessible organizations but cannot create or modify organizations or user accounts. An admin can view data and manage users in accessible organizations but cannot create or modify organizations. A superadmin can view data, manage users, and manage descendant organizations in their accessible organizations.
enum:
- user
- admin
- superadmin
x-enum-varnames:
- UserRoleUser
- UserRoleAdmin
- UserRoleSuperAdmin
LoginUser:
type: object
required:
- user_id
- first_name
- last_name
- email
- parent_organization
- role
- status
properties:
user_id:
type: string
first_name:
type: string
last_name:
type: string
preferred_name:
type: string
email:
type: string
parent_organization:
$ref: '#/components/schemas/OrganizationMinimal'
created_at:
type: integer
format: int64
created_by:
type: string
status:
$ref: '#/components/schemas/UserStatus'
role:
$ref: '#/components/schemas/UserRole'
features:
type: array
items:
$ref: '#/components/schemas/AirMDRFeature'
permission:
type: array
items:
$ref: '#/components/schemas/Permission'
last_login:
type: integer
format: int64
is_internal:
type: boolean
description: Whether user belongs to airmdr organization or not
AuthenticateRequest:
type: object
required:
- session_token
properties:
session_token:
type: string
metadata:
type: object
AuthenticateUserData:
type: object
required:
- session_id
- user_id
- organization_id
- organization_hosturl
- active_organization_id
- email
properties:
session_id:
type: string
user_id:
type: string
organization_id:
type: string
organization_hosturl:
type: string
active_organization_id:
type: string
email:
type: string
organization_code:
type: string
token_id:
type: string
description: UUID of the API token used to authenticate, when the request is authenticated via an API token. Empty for interactive login sessions.
token_name:
type: string
description: Human-readable name of the API token used to authenticate. Empty for interactive login sessions.
GetLoginUrlResponse:
type: object
required:
- data
- message
properties:
message:
type: string
data:
$ref: '#/components/schemas/LoginUrl'
Permission:
type: object
required:
- permission_id
- name
properties:
permission_id:
type: string
name:
type: string
description:
type: string
Error:
type: object
required:
- message
properties:
message:
type: string
description: user friendly error message
LoginMethod:
type: string
enum:
- password
- sso
x-enum-varnames:
- LoginMethodPassword
- LoginMethodSSO
AuthenticateUserResponse:
type: object
required:
- data
- message
properties:
message:
type: string
data:
$ref: '#/components/schemas/AuthenticateUserData'
UpdateSessionRequest:
type: object
required:
- active_organization_id
properties:
active_organization_id:
type: string
UserStatus:
type: string
description: user account status
enum:
- active
- pending
- disabled
- deleted
- password_reset_required
x-enum-varnames:
- UserStatusActive
- UserStatusPending
- UserStatusDisabled
- UserStatusDeleted
- UserStatusPasswordResetRequired
AirMDRFeature:
type: object
required:
- feature_id
- name
properties:
feature_id:
type: string
description: The id of the feature
name:
type: string
description: The name of the feature
description:
type: string
description: The description of the feature
UpdateSessionResponse:
type: object
required:
- message
properties:
message:
type: string
LoginUserData:
type: object
required:
- session_token
- user
properties:
session_token:
type: string
active_organization_id:
type: string
user:
$ref: '#/components/schemas/LoginUser'
LoginUrl:
type: object
required:
- email
- login_method
properties:
email:
type: string
description: The email of the user
login_method:
$ref: '#/components/schemas/LoginMethod'
description: The method for login, can be password or sso
login_url:
type: string
description: The login url in case the login method is sso
logo_url:
type: string
description: The url of the logo of the user's organization
OrganizationMinimal:
type: object
required:
- organization_id
- name
- code
- sso_enabled
properties:
organization_id:
type: string
description: unique id of the organization
name:
type: string
description: name of the organization
code:
type: string
description: code of the organization
logo_url:
type: string
description: url of the organization's logo
sso_enabled:
type: boolean
description: flag indicating whether sso is enabled for the organization
GetLoginUrlRequest:
type: object
properties:
email:
type: string
redirect_url:
type: string
securitySchemes:
SessionCookie:
type: apiKey
in: cookie
name: Session
x-tagGroups:
- name: Included APIs
tags:
- Organization
- User
- User Group
- Token
- Permission