openapi: 3.0.0 info: title: BigCommerce Abandoned Cart Emails Storefront Security API version: 3.0.0 termsOfService: https://www.bigcommerce.com/terms description: Abandoned Cart Emails V3 API managing Handlebars-based emails. contact: name: BigCommerce url: https://www.bigcommerce.com email: support@bigcommerce.com servers: - url: https://api.bigcommerce.com/stores/{store_hash}/v3 variables: store_hash: default: store_hash description: Permanent ID of the BigCommerce store. description: BigCommerce API Gateway security: - X-Auth-Token: [] tags: - name: Storefront Security paths: /settings/storefront/security: parameters: - $ref: '#/components/parameters/Accept' get: summary: BigCommerce Get Storefront Security Settings operationId: getSettingsStorefrontSecurity description: "Returns security settings.\n\n - Channel ID can be used as a query parameter for getting channel-specific setting. If omitted, you will interact with the global setting only. \n\n - `null` indicates that a particular field has not been overridden on a channel level when channel level settings are requested and values are inherited from global level." parameters: - $ref: '#/components/parameters/ChannelIdParam' responses: '200': description: OK, null indicates that a particular field has not been overridden on a channel level when channel level settings are requested content: application/json: schema: type: object properties: data: $ref: '#/components/schemas/StorefrontSecuritySettings' meta: $ref: '#/components/schemas/MetaOpen' tags: - Storefront Security put: summary: BigCommerce Update Storefront Security Settings operationId: updateSettingsStorefrontSecurity description: "Updates security settings.\n\n - Channel ID can be used as a query parameter for updating channel-specific setting. If omitted, you will interact with the global setting only. \n\n - `null` should be supplied to delete overrides per given channel and to inherit values from global level. Partial updates are not supported and all settings should be supplied with `null` value in order to delete overrides per channel." parameters: - $ref: '#/components/parameters/ContentType' - $ref: '#/components/parameters/ChannelIdParam' requestBody: content: application/json: schema: $ref: '#/components/schemas/StorefrontSecuritySettings' responses: '200': description: OK content: application/json: schema: type: object properties: data: $ref: '#/components/schemas/StorefrontSecuritySettings' meta: $ref: '#/components/schemas/MetaOpen' tags: - Storefront Security components: parameters: Accept: name: Accept in: header required: true description: The [MIME type](https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types) of the response body. schema: type: string default: application/json ContentType: name: Content-Type in: header required: true description: The [MIME type](https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types) of the request body. schema: type: string default: application/json ChannelIdParam: description: Channel ID to use for channel-specific setting. If omitted, you will interact with the global setting only. in: query name: channel_id schema: type: integer schemas: StorefrontSecuritySettings: type: object properties: csp_header: type: object properties: enabled: type: boolean header_value: type: string hsts: type: object properties: enabled: type: boolean include_preload: type: boolean include_subdomains: type: boolean max_age: $ref: '#/components/schemas/HSTSMaxAgeEnumValues' sitewide_https_enabled: type: boolean x_frame_options_header: type: object properties: allowed_url: type: string enabled: type: boolean setting: type: string enum: - deny - same_origin - allow_from_url title: StorefrontSecuritySettings x-internal: false MetaOpen: title: Response meta type: object properties: {} additionalProperties: true description: Response metadata. HSTSMaxAgeEnumValues: type: string enum: - zero_seconds - five_minutes - one_year title: HSTSMaxAgeEnumValues x-tags: - Models securitySchemes: X-Auth-Token: name: X-Auth-Token description: '### OAuth scopes | UI Name | Permission | Parameter | |:--|:--|:-| | Information & Settings | read-only | `store_v2_information_read_only`| | Information & Settings | modify | `store_v2_information` | ### Authentication header | Header | Argument | Description | |:-|:|:| | `X-Auth-Token` | `access_token` | For more about API accounts that generate `access_token`s, see our [Guide to API Accounts](/docs/start/authentication/api-accounts). | ### Further reading For example requests and more information about authenticating BigCommerce APIs, see [Authentication and Example Requests](/docs/start/authentication#x-auth-token-header-example-requests). For more about BigCommerce OAuth scopes, see our [Guide to API Accounts](/docs/start/authentication/api-accounts#oauth-scopes). For a list of API status codes, see [API Status Codes](/docs/start/about/status-codes).' type: apiKey in: header