openapi: 3.0.4 info: title: Bench AccountActivities PersonProfile API description: "

Versioning

\n

\n The API is currently at version 1.0. All API endpoints (other than\n authentication) require you to specify the API version as part of the path.\n

\n\n

URL Paths

\n

\n Authentication requests should be made to /auth/signin,\n as documented below. All other API requests should be made to\n sub-paths of /rp/api/1.0/....\n

\n\n

Authentication

\n

\n API requests are authenticated using an OAuth Bearer token.\n You can get a token by authenticating your user by sending a\n POST request to /auth/signin, with \"username and \"password\"\n parameters form-encoded in the body of the request.\n\n POST /auth/signin HTTP/1.1\n Content-Type: application/x-www-form-urlencoded\n\n username=user@example.com&password=some-secret-password\n

\n

\n The response will be a JSON object including both\n \"access_token\" and \"refresh_token\" property.\n All other requests against the Bench API should include an\n authorization header: Authorization: Bearer xxxYYYzzz,\n where xxxYYYzzz is the value of \"access_token\" in the response.\n

\n For example:\n\n $ curl https://bench.gobridgit.com/auth/signin -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'username=someone@example.com' --data-urlencode 'password=[...snip...]'\n {\n \"access_token\": \"...snip...\",\n \"token_type\": \"Bearer\",\n \"refresh_token\": \"...snip...\"\n \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n }\n\n

\n\n

\n The refresh token can be used to generate new session by request with /auth/token endpoint:\n\n POST /auth/token HTTP/1.1\n Content-Type: application/x-www-form-urlencoded\n\n grant_type=refresh_token&refresh_token=tGzv3JOkF0XG5Qx2TlKWIA\n

\n

\n Note that once the refresh token is used, the previous access and refresh token is no longer valid.\n

\n For example:\n\n $ curl https://bench.gobridgit.com/auth/token -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'grant_type=refresh_token' --data-urlencode 'refresh_token=[...snip...]'\n {\n \"access_token\": \"...snip...\",\n \"token_type\": \"Bearer\",\n \"refresh_token\": \"...snip...\"\n \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n }\n

\n\n

Pagination

\n

\n Several of the API endpoints are paginated. These are denoted by\n including the offset (zero-based offset) and limit query\n parameters. For example, to request the 10 items,\n set the offset=0 to limit=10.\n
\n NOTE: the result set contains items with index of 0-9\n
\n To request the next 10 items (starting at index 10),\n set the offset=10 to limit=10\n

\n

\n Responses to paginated API endpoints return a JSON array of objects.\n If there are results beyond the page you have requested, the server\n will set a query-has-more: true header in the response.\n

\n\n

Request Encoding

\n

\n GET and DELETE requests should have parameters encoded as URL query\n parameters. Boolean values should be encoded as true and\n false, not as 1 and 0.\n

\n\n

Errors

\n

\n Errors are returned for some response codes such as 400 Bad Request in the\n following format:\n\n {\n \"errors\": [\n {\n \"errorType\": \"ValidationError\",\n \"description\": \"The value of Name must be a string with a minimum length of 1 and a maximum length of 8 and not whitespace.\",\n \"field\": \"Name\",\n \"values\": [\n null\n ]\n }\n ],\n \"title\": \"One or more validation errors occurred.\",\n \"status\": 400,\n \"instance\": \"api/v1/accounts/0/persons\",\n \"requestUid\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n

\n" version: '1.0' servers: - url: https://bench.gobridgit.com description: Bridgit Bench production security: - {} tags: - name: PersonProfile paths: /rp/api/v1/accounts/{accountId}/persons/{personId}/profile-picture: put: tags: - PersonProfile summary: Updates a person's profile picture with support for upload and set modes. description: 'Two modes of operation: 1. Upload Mode: When no request body is provided, returns a presigned URL for direct image upload to S3. Use a PUT request to upload your image file to the returned signed URL. 2. Set Mode: When a request body with ImageUrl is provided, sets the profile picture to the specified URL
Permissions
Person: Write
HourlyProfile: Write' operationId: PersonProfile_Put parameters: - name: accountId in: path description: The unique identifier of the account required: true schema: type: integer format: int32 - name: personId in: path description: The unique identifier of the person required: true schema: type: integer format: int64 requestBody: description: 'The profile picture request. Can be null for upload mode or contain an ImageUrl for set mode. When null, generates a presigned upload URL. When provided, sets the profile picture to the specified URL.' content: application/json-patch+json: schema: $ref: '#/components/schemas/ProfilePicture' application/json: schema: $ref: '#/components/schemas/ProfilePicture' text/json: schema: $ref: '#/components/schemas/ProfilePicture' application/*+json: schema: $ref: '#/components/schemas/ProfilePicture' responses: '200': description: Success - Profile picture updated or upload URL generated content: text/plain: schema: $ref: '#/components/schemas/ProfilePicture' application/json: schema: $ref: '#/components/schemas/ProfilePicture' text/json: schema: $ref: '#/components/schemas/ProfilePicture' '400': description: Bad Request - Invalid parameters or request format '401': description: Unauthorized - User is not authenticated '403': description: Forbidden - User lacks required permissions or resource not found '422': description: Unprocessable Entity - Unable to process the profile image (e.g., invalid format, upload failure) delete: tags: - PersonProfile summary: Clear a person's profile picture description: '
Permissions
Person: Write
HourlyProfile: Write' operationId: PersonProfile_Delete parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: personId in: path description: The Person ID required: true schema: type: integer format: int64 responses: '204': description: No Content (success) '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden - User doesn't have permissions on this resource, or the account or person couldn't be found components: schemas: ProfilePicture: type: object properties: ImageUrl: type: string nullable: true example: https://example.com/images/image.png additionalProperties: false securitySchemes: Bearer: type: http description: Standard Authorization header using the Bearer scheme scheme: bearer bearerFormat: JWT