openapi: 3.2.0 info: title: Admin - User User Password Policy API description: 'The User APIs are use to create, update and retrieve information about User and Profiles. The Bulk User APIs are use to perform operations on users and jobs in bulk. User Services support add, update, delete users in bulk and delete multiple jobs. User Services will support multiple ways to provision Users/Agents 1. Programmatic Interface (Rest APIs) 2. User Interface' contact: name: Avaya API Team url: https://developers.avayacloud.com/onecloud-ccaas email: apiteam@avaya.com license: name: Avaya Software Development Kit (SDK) Software License Terms url: http://support.avaya.com/css/P8/documents/101038288 version: 1.0.2 servers: - url: '{protocol}://{server}:{port}{basePath}' description: Open API variables: protocol: enum: - https default: https server: default: HOST-REGION.api.avayacloud.com port: enum: - '443' default: '443' basePath: default: /api/admin/user/v1 security: - {} - BearerAuth: [] AppKey: [] tags: - name: User Password Policy description: Represents the set of rules to be followed for the user passwords. paths: /accounts/{accountId}/password-policy: get: tags: - User Password Policy summary: Get Password Policy description: '**This API requires the Account Administrator role.** Lists the Passwod Policy rules for an account.' operationId: getPasswordPolicy parameters: - $ref: '#/components/parameters/accountId' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PasswordPolicy' examples: PasswordPolicy: $ref: '#/components/examples/PasswordPolicyRule' '400': $ref: '#/components/responses/ErrorConstraintViolation' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalServer' put: tags: - User Password Policy summary: Update Password Policy description: '**This API requires the Account Administrator role.** Updates the Passwod Policy rules for an account.' operationId: updatePasswordPolicy parameters: - $ref: '#/components/parameters/accountId' requestBody: description: Password policy rule payload content: application/json: schema: $ref: '#/components/schemas/PasswordPolicy' examples: PasswordPolicy: $ref: '#/components/examples/PasswordPolicyRule' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PasswordPolicy' examples: PasswordPolicy: $ref: '#/components/examples/PasswordPolicyRule' '400': $ref: '#/components/responses/ErrorConstraintViolation' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalServer' components: examples: ErrorForbidden: description: Forbidden value: type: https://developers.avayacloud.com/avaya-experience-platform/docs/error-handling#forbidden title: Forbidden status: 403 detail: According to the access control policy the current user and/or accountId does not have permission to access this resource. ErrorNotFound: description: Not Found value: type: https://developers.avayacloud.com/avaya-experience-platform/docs/error-handling#resource-not-found title: Resource Not Found status: 404 detail: Either there is no API method associated with the URL path of the request, or the request refers to one or more resources that were not found. ErrorConstraintViolation: description: Constraint Violation value: type: https://developers.avayacloud.com/avaya-experience-platform/docs/error-handling#constraint-violation title: Constraint Violation status: 400 detail: A problem that indicates a syntactically correct, yet semantically illegal request. The Server can not process this request until the client resolves the semantic errors described in the violations section. violations: - field: accountId message: must match "^[a-zA-Z]{6}$" code: 20006 PasswordPolicyRule: value: accountId: CJRKXW length: 8 specialChars: 1 upperCase: 1 lowerCase: 1 digits: 1 repeatConsecutiveChars: 2 consecutiveChars: 4 passwordHistory: 1 notUsername: true ErrorUnauthorized: description: Unauthorized value: type: https://developers.avayacloud.com/avaya-experience-platform/docs/error-handling#unauthorized title: Unauthorized status: 401 detail: This operation requires authentication. See https://developers.avayacloud.com/avaya-experience-platform/docs/how-to-authenticate-with-ccaas-apis ErrorInternalServerError: description: Server Error value: type: https://developers.avayacloud.com/avaya-experience-platform/docs/error-handling#server-error title: Server Error status: 500 detail: An internal server error was encountered. responses: Unauthorized: description: Unauthorized content: application/problem+json: schema: $ref: '#/components/schemas/Problem' examples: default: $ref: '#/components/examples/ErrorUnauthorized' Forbidden: description: Forbidden content: application/problem+json: schema: $ref: '#/components/schemas/Problem' examples: default: $ref: '#/components/examples/ErrorForbidden' ErrorConstraintViolation: description: Constraint Violation content: application/problem+json: schema: $ref: '#/components/schemas/Problem' examples: default: $ref: '#/components/examples/ErrorConstraintViolation' InternalServer: description: Request processing failed content: application/problem+json: schema: $ref: '#/components/schemas/Problem' examples: default: $ref: '#/components/examples/ErrorInternalServerError' NotFound: description: Not Found content: application/problem+json: schema: $ref: '#/components/schemas/Problem' examples: default: $ref: '#/components/examples/ErrorNotFound' schemas: PasswordPolicy: description: This model represent the password policy rules type: object properties: accountId: type: string description: The unique 6 character internal id that represents the account. readOnly: true example: FSADSJ length: description: Length of the password type: integer format: int32 minimum: 8 default: 14 example: 8 specialChars: description: Number of special characters required in the password type: integer format: int32 minimum: 0 default: 0 example: 1 upperCase: description: Number of uppercase characters required in the password type: integer format: int32 minimum: 0 default: 0 example: 1 lowerCase: description: Number of lowercase characters required in the password type: integer format: int32 minimum: 0 default: 0 example: 1 digits: description: Number of digits required in the password type: integer format: int32 minimum: 0 default: 0 example: 1 maxNoOfConsecutiveChars: description: Number of repeated consecutive characters in the password type: integer format: int32 minimum: 0 default: 2 example: 2 maxNoOfConsecutiveCharSets: description: Number of consecutive characters from the same character classs in the password type: integer format: int32 minimum: 0 default: 4 example: 4 passwordHistory: description: Number of last passwords to be checked in the passwordHistory type: integer format: int32 minimum: 0 maximum: 24 default: 10 example: 1 notUsername: type: boolean default: true example: true description: Password should not be same as username Problem: type: object description: 'Problem Detail as a way to carry machine-readable details of errors in a HTTP response to avoid the need to define new error response formats for HTTP APIs RFC 7807 ' properties: type: type: string format: uri description: 'An absolute URI that identifies the problem type. When dereferenced, it SHOULD provide human-readable documentation for the problem type (e.g., using HTML). ' default: about:blank example: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#constraint-violation title: type: - string - 'null' description: 'A short, summary of the problem type. Written in english and readable for engineers (usually not suited for non technical stakeholders and not localized). ' example: Service Unavailable status: type: - integer - 'null' format: int32 description: 'The HTTP status code generated by the origin server for this occurrence of the problem. ' minimum: 100 example: 503 exclusiveMaximum: 600 detail: type: - string - 'null' description: 'A human readable explanation specific to this occurrence of the problem. ' example: Connection to database timed out instance: type: - string - 'null' format: uri description: 'An absolute URI that identifies the specific occurrence of the problem. It may or may not yield further information if dereferenced. ' violations: type: - array - 'null' description: 'A list of violations that occurred as a result of invalid data provided as part of a request. ' items: type: object properties: field: type: string description: 'The name of the field in the request that caused the violation. This can be the name of a path parameter, query parameter, or a field within the request body. ' example: accountId message: type: string description: 'A human readable explanation specific to this occurrence of the violation. ' example: must match "^[a-zA-Z]{6}$" code: type: integer format: int32 description: 'The violation code generated by the server for this occurrence of the violation. Use this code when implementing any error handling logic instead of the message, as the message can change. ' example: 20006 example: - field: emailAddress message: must not be null code: 20002 - field: accountId message: must match "^[a-zA-Z]{6}$" code: 20006 parameters: accountId: name: accountId description: The unique 6 character internal id that represents the customer account. required: true in: path schema: type: string minLength: 6 maxLength: 6 pattern: ^[a-zA-Z]{6}$ example: ABCDEF securitySchemes: BearerAuth: type: http scheme: bearer description: This API uses Bearer Token Authorization Flow bearerFormat: JWT AppKey: type: apiKey in: header name: appkey description: This API needs an appKey as header x-explorer-enabled: false x-samples-languages: - curl - node - java - javascript - python - go