openapi: 3.2.0 info: title: Cesnet Authz Resolver API version: 0.0.0 contact: url: https://perun-aai.org email: perun@cesnet.cz description: 'Operations tagged AuthzResolver across 2 of this provider''s published API definitions: cesnet-perun-rpc-openapi.yml, cesnet-perun-rpc-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed security: - BasicAuth: [] - BearerAuth: [] tags: - name: AuthzResolver description: AuthzResolver RPC API in Perun externalDocs: url: https://perun-aai.org/documentation/technical-documentation/rpc-api/rpc-javadoc-AuthzResolver.html paths: /json/authzResolver/getPrincipalRoleNames: get: tags: - AuthzResolver operationId: getPrincipalRoleNames summary: Returns list of caller's role names. responses: '200': $ref: '#/components/responses/ListOfStringsResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getPerunPrincipal: get: tags: - AuthzResolver operationId: getPerunPrincipal summary: Gets current user description: Returns object representing the currently authenticated user. responses: '200': description: successfully returned authenticated user content: application/json: schema: $ref: '#/components/schemas/PerunPrincipal' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getRichAdmins: get: tags: - AuthzResolver operationId: getAuthzRichAdmins summary: Gets all valid rich admins description: Get all valid richUser administrators (for group-based rights, status must be VALID for both Vo and group) for complementary object and role with specified attributes. parameters: - $ref: '#/components/parameters/role' - $ref: '#/components/parameters/complementaryObjectId' - $ref: '#/components/parameters/complementaryObjectName' - name: specificAttributes description: list of specified attributes which are needed in object richUser schema: type: array items: type: string in: query required: true - name: allUserAttributes description: When true, do not specify attributes through list and return them all in objects richUser. Ignoring list of specific attributes schema: type: boolean default: false in: query required: false - name: onlyDirectAdmins description: When true, return only direct users of the complementary object for role with specific attributes schema: type: boolean default: true in: query required: false responses: '200': $ref: '#/components/responses/ListOfRichUsersResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getAdmins: get: tags: - AuthzResolver operationId: getAuthzAdmins summary: Gets all valid admins description: Get all valid user administrators (for group-based rights, status must be VALID for both Vo and group) for complementary object and role. parameters: - $ref: '#/components/parameters/role' - $ref: '#/components/parameters/complementaryObjectId' - $ref: '#/components/parameters/complementaryObjectName' - name: onlyDirectAdmins description: When true, return only direct users of the complementary object for role schema: type: boolean default: true in: query required: false responses: '200': $ref: '#/components/responses/ListOfUsersResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/someAdminExists: get: tags: - AuthzResolver operationId: someAdminExists summary: Checks if some valid admin exists description: Checks if valid user administrators (for group-based rights, status must be VALID for both Vo and group) for complementary object and role exists. parameters: - $ref: '#/components/parameters/role' - $ref: '#/components/parameters/complementaryObjectId' - $ref: '#/components/parameters/complementaryObjectName' - name: onlyDirectAdmins description: When true, check only direct users of the complementary object for role schema: type: boolean default: true in: query required: false responses: '200': $ref: '#/components/responses/BooleanResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getAdminGroups: get: tags: - AuthzResolver operationId: getAuthzAdminGroups summary: Get all groups of managers (authorizedGroups) for complementaryObject and role parameters: - $ref: '#/components/parameters/role' - $ref: '#/components/parameters/complementaryObjectId' - $ref: '#/components/parameters/complementaryObjectName' responses: '200': $ref: '#/components/responses/ListOfGroupsResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/setRole/u: post: tags: - AuthzResolver operationId: setRoleForUser summary: Set role for user responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: setRoleForUser description: input to setRoleForUser type: object required: - role - user properties: role: type: string user: type: integer servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/unsetRole/u: post: tags: - AuthzResolver operationId: unsetRoleForUser summary: Unset role for user responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: unsetRoleForUser description: input to unsetRoleForUser type: object required: - role - user properties: role: type: string user: type: integer servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/setRole/u-co: post: tags: - AuthzResolver operationId: setRoleWithUserComplementaryObject summary: Set role for user and complementaryObject responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: setRoleWithUserComplementaryObject description: 'input to setRoleWithUserComplementaryObject (supported objects: Group | RichGroup | Vo | Resource | Facility)' type: object required: - role - users properties: role: type: string users: type: array description: List of user ids items: type: integer complementaryObject: $ref: '#/components/schemas/PerunBean' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/setRole/u-cos: post: tags: - AuthzResolver operationId: setRoleWithUserComplementaryObjects summary: Set role for user and complementaryObjects responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: setRoleWithUserComplementaryObjects description: input to setRoleWithUserComplementaryObjects type: object required: - role - user properties: role: type: string user: type: integer description: user id complementaryObjects: type: array description: 'List of complementary objects (supported objects: Group | RichGroup | Vo | Resource | Facility)' items: $ref: '#/components/schemas/PerunBean' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/unsetRole/u-co: post: tags: - AuthzResolver operationId: unsetRoleWithUserComplementaryObject summary: Unset role for user and complementaryObject responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: unsetRoleWithUserComplementaryObject description: 'input to unsetRoleWithUserComplementaryObject (supported objects: Group | RichGroup | Vo | Resource | Facility)' type: object required: - role - users properties: role: type: string users: type: array description: List of user ids items: type: integer complementaryObject: $ref: '#/components/schemas/PerunBean' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/unsetRole/u-cos: post: tags: - AuthzResolver operationId: unsetRoleWithUserComplementaryObjects summary: Unset role for user and complementaryObjects responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: unsetRoleWithUserComplementaryObjects description: input to unsetRoleWithUserComplementaryObjects type: object required: - role - user properties: role: type: string user: type: integer description: user id complementaryObjects: type: array description: 'List of complementary objects (supported objects: Group | RichGroup | Vo | Resource | Facility)' items: $ref: '#/components/schemas/PerunBean' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/setRole/g: post: tags: - AuthzResolver operationId: setRoleForGroup summary: Set role for authorizedGroup responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: setRoleForGroup description: input to setRoleForGroup type: object required: - role - authorizedGroup properties: role: type: string authorizedGroup: type: integer servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/unsetRole/g: post: tags: - AuthzResolver operationId: unsetRoleForGroup summary: Unset role for authorizedGroup responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: unsetRoleForGroup description: input to unsetRoleForGroup type: object required: - role - authorizedGroup properties: role: type: string authorizedGroup: type: integer servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/setRole/g-co: post: tags: - AuthzResolver operationId: setRoleWithGroupComplementaryObject summary: Set role for authorizedGroup and complementaryObject responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: setRoleWithGroupComplementaryObject description: 'input to unsetRoleWithUserComplementaryObject (supported objects: Group | RichGroup | Vo | Resource | Facility)' type: object required: - role - authorizedGroups properties: role: type: string authorizedGroups: type: array description: List of authorizedGroups ids items: type: integer complementaryObject: $ref: '#/components/schemas/PerunBean' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/setRole/g-cos: post: tags: - AuthzResolver operationId: setRoleWithGroupComplementaryObjects summary: Set role for authorizedGroup and complementaryObjects responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: setRoleWithGroupComplementaryObjects description: input to setRoleWithUserComplementaryObjects type: object required: - role - authorizedGroup properties: role: type: string authorizedGroup: type: integer complementaryObjects: type: array description: 'List of complementary objects (supported objects: Group | RichGroup | Vo | Resource | Facility)' items: $ref: '#/components/schemas/PerunBean' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/unsetRole/g-co: post: tags: - AuthzResolver operationId: unsetRoleWithGroupComplementaryObject summary: Unset role for authorizedGroup and complementaryObject responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: unsetRoleWithGroupComplementaryObject description: 'input to unsetRoleWithUserComplementaryObject (supported objects: Group | RichGroup | Vo | Resource | Facility)' type: object required: - role - authorizedGroups properties: role: type: string authorizedGroups: type: array description: List of authorizedGroups ids items: type: integer complementaryObject: $ref: '#/components/schemas/PerunBean' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/unsetRole/g-cos: post: tags: - AuthzResolver operationId: unsetRoleWithGroupComplementaryObjects summary: Unset role for authorizedGroup and complementaryObjects responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' requestBody: required: true content: application/json: schema: title: unsetRoleWithGroupComplementaryObjects description: input to unsetRoleWithUserComplementaryObjects type: object required: - role - authorizedGroup properties: role: type: string authorizedGroup: type: integer complementaryObjects: type: array description: 'List of complementary objects (supported objects: Group | RichGroup | Vo | Resource | Facility)' items: $ref: '#/components/schemas/PerunBean' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getUserRoles: get: tags: - AuthzResolver operationId: getUserRoles summary: Returns all roles accessible to the principal as an AuthzRoles object for a… parameters: - $ref: '#/components/parameters/userId' responses: '200': $ref: '#/components/responses/AuthzRolesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getRegistrarUserRoles: get: tags: - AuthzResolver operationId: getRegistrarUserRoles summary: Returns all new Registrar roles for the user derived from roles in Perun parameters: - $ref: '#/components/parameters/userId' responses: '200': $ref: '#/components/responses/MapStringSetOfIdmObjectResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getUserDirectRoles: get: tags: - AuthzResolver operationId: getUserDirectRoles summary: Returns all roles accessible to the principal except for those obtained from… parameters: - $ref: '#/components/parameters/userId' responses: '200': $ref: '#/components/responses/AuthzRolesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getUserRolesObtainedFromAuthorizedGroupMemberships: get: tags: - AuthzResolver operationId: getUserRolesObtainedFromAuthorizedGroupMemberships summary: Returns roles resulting from membership in authorized groups as an AuthzRoles… parameters: - $ref: '#/components/parameters/userId' responses: '200': $ref: '#/components/responses/AuthzRolesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getRoleComplementaryObjectsWithAuthorizedGroups: get: tags: - AuthzResolver operationId: getRoleComplementaryObjectsWithAuthorizedGroups summary: Returns map of role names with map of corresponding complementary objects… parameters: - $ref: '#/components/parameters/userId' responses: '200': $ref: '#/components/responses/ComplementaryObjectsWithAuthzGroupsResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getUserRoleNames: get: tags: - AuthzResolver operationId: getUserRoleNames summary: Returns list of user's role names. parameters: - $ref: '#/components/parameters/userId' responses: '200': $ref: '#/components/responses/ListOfStringsResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getGroupRoleNames: get: tags: - AuthzResolver operationId: getGroupRoleNames summary: Returns list of group's role names. parameters: - $ref: '#/components/parameters/groupId' responses: '200': $ref: '#/components/responses/ListOfStringsResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /urlinjsonout/authzResolver/getGroupRoles: get: tags: - AuthzResolver operationId: getGroupRoles summary: Returns all roles as an AuthzRoles object for a given group parameters: - name: groupId description: id of Group schema: type: integer in: query required: true responses: '200': $ref: '#/components/responses/AuthzRolesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /urlinjsonout/authzResolver/isVoAdmin: get: tags: - AuthzResolver operationId: isVoAdmin summary: Returns 1 if User has VO manager role (VOADMIN) or for specific VO defined by id parameters: - name: vo description: id of Vo schema: type: integer in: query required: false responses: '200': $ref: '#/components/responses/IntegerResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /urlinjsonout/authzResolver/isGroupAdmin: get: tags: - AuthzResolver operationId: isGroupAdmin summary: Returns 1 if User has Group manager role (GROUPADMIN) or for specific Group… parameters: - $ref: '#/components/parameters/optionalGroupId' responses: '200': $ref: '#/components/responses/IntegerResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /urlinjsonout/authzResolver/isFacilityAdmin: get: tags: - AuthzResolver operationId: isFacilityAdmin summary: Returns 1 if User has Facility manager role (FACILITYADMIN) or for specific… parameters: - $ref: '#/components/parameters/optionalFacilityId' responses: '200': $ref: '#/components/responses/IntegerResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/isPerunAdmin: get: tags: - AuthzResolver operationId: isPerunAdmin summary: Returns 1 if User has Perun admin role (perunadmin) responses: '200': $ref: '#/components/responses/IntegerResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/isGroupLastAdminInFacilities: get: tags: - AuthzResolver operationId: isGroupLastAdminInFacilities summary: Checks whether groups is the last admin the facilities and returns those in… parameters: - $ref: '#/components/parameters/groupId' - $ref: '#/components/parameters/facilityIds' responses: '200': $ref: '#/components/responses/ListOfFacilitiesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/isGroupLastAdminInVos: get: tags: - AuthzResolver operationId: isGroupLastAdminInVos summary: Checks whether groups is the last admin the vos and returns those in which it is parameters: - $ref: '#/components/parameters/groupId' - $ref: '#/components/parameters/voIds' responses: '200': $ref: '#/components/responses/ListOfVosResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/isUserLastAdminInFacilities: get: tags: - AuthzResolver operationId: isUserLastAdminInFacilities summary: Checks whether user is the last admin the facilities and returns those in which… parameters: - $ref: '#/components/parameters/userId' - $ref: '#/components/parameters/facilityIds' responses: '200': $ref: '#/components/responses/ListOfFacilitiesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/isUserLastAdminInVos: get: tags: - AuthzResolver operationId: isUserLastAdminInVos summary: Checks whether user is the last admin the vos and returns those in which it is parameters: - $ref: '#/components/parameters/userId' - $ref: '#/components/parameters/voIds' responses: '200': $ref: '#/components/responses/ListOfVosResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getLoggedUser: get: tags: - AuthzResolver operationId: getLoggedUser summary: Returns User which is associated with credentials used to log-in to Perun responses: '200': $ref: '#/components/responses/UserResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/keepAlive: get: tags: - AuthzResolver operationId: keepAlive summary: Returns "OK" string. Helper method for GUI check if connection is alive responses: '200': $ref: '#/components/responses/StringResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getAllPolicies: get: tags: - AuthzResolver operationId: getAllPolicies summary: Return all loaded perun policies responses: '200': $ref: '#/components/responses/ListOfPerunPoliciesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getAllRolesManagementRules: get: tags: - AuthzResolver operationId: getAllRolesManagementRules summary: Return all loaded roles management rules responses: '200': $ref: '#/components/responses/ListOfRolesManagementRulesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/loadAuthorizationComponents: get: tags: - AuthzResolver operationId: loadAuthorizationComponents summary: Load perun roles and policies from the configuration file perun-roles.yml. responses: '200': $ref: '#/components/responses/VoidResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getVosWhereUserIsInRoles: get: tags: - AuthzResolver operationId: getVosWhereUserIsInRoles summary: Get all Vos where the given user (principal if user not sent) has set one of… parameters: - $ref: '#/components/parameters/optionalUserId' - $ref: '#/components/parameters/ListOfRoles' responses: '200': $ref: '#/components/responses/ListOfVosResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getFacilitiesWhereUserIsInRoles: get: tags: - AuthzResolver operationId: getFacilitiesWhereUserIsInRoles summary: Get all Facilities where the given user (principal if user not sent) has set… parameters: - $ref: '#/components/parameters/optionalUserId' - $ref: '#/components/parameters/ListOfRoles' responses: '200': $ref: '#/components/responses/ListOfFacilitiesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getResourcesWhereUserIsInRoles: get: tags: - AuthzResolver operationId: getResourcesWhereUserIsInRoles summary: Get all Resources where the given user (principal if user not sent) has set one… parameters: - $ref: '#/components/parameters/optionalUserId' - $ref: '#/components/parameters/ListOfRoles' responses: '200': $ref: '#/components/responses/ListOfResourcesResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getGroupsWhereUserIsInRoles: get: tags: - AuthzResolver operationId: getGroupsWhereUserIsInRoles summary: Get all Groups where the given user (principal if user not sent) has set one of… parameters: - $ref: '#/components/parameters/optionalUserId' - $ref: '#/components/parameters/ListOfRoles' responses: '200': $ref: '#/components/responses/ListOfGroupsResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed /json/authzResolver/getMembersWhereUserIsInRoles: get: tags: - AuthzResolver operationId: getMembersWhereUserIsInRoles summary: Get all Members where the given user (principal if user not sent) has set one… parameters: - $ref: '#/components/parameters/optionalUserId' - $ref: '#/components/parameters/ListOfRoles' responses: '200': $ref: '#/components/responses/ListOfMembersResponse' default: $ref: '#/components/responses/ExceptionResponse' servers: - url: https://{server}/{authentication}/rpc description: Perun RPC server variables: server: default: api-dev.perun-aai.org description: DNS name of a Perun server authentication: default: ba description: 'way of authentication: ba - HTTP Basic Auth krb - Kerberos non - no authentication cert - X509 client certificate oauth - OAuth 2.0 bearer access token fed - SAML federation ' enum: - ba - krb - non - cert - oauth - fed components: responses: ListOfRolesManagementRulesResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/RoleManagementRules' ListOfFacilitiesResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/Facility' MapStringSetOfIdmObjectResponse: description: returns Map> content: application/json: schema: type: object additionalProperties: type: array items: $ref: '#/components/schemas/IdmObject' uniqueItems: true ListOfResourcesResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/Resource' ListOfPerunPoliciesResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/PerunPolicy' StringResponse: description: returns String content: application/json: schema: type: string VoidResponse: description: returns nothing ListOfGroupsResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/Group' AuthzRolesResponse: description: AuthzRoles of user content: application/json: schema: $ref: '#/components/schemas/AuthzRoles' ExceptionResponse: description: exception occurred content: application/json: schema: $ref: '#/components/schemas/PerunException' ComplementaryObjectsWithAuthzGroupsResponse: description: Complementary objects combined with authorized groups (connected by role) content: application/json: schema: type: object additionalProperties: type: object additionalProperties: type: object additionalProperties: type: array items: $ref: '#/components/schemas/Group' UserResponse: description: returns User content: application/json: schema: $ref: '#/components/schemas/User' ListOfMembersResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/Member' ListOfUsersResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/User' IntegerResponse: description: returns Integer content: application/json: schema: type: integer BooleanResponse: description: returns Boolean content: application/json: schema: type: boolean ListOfVosResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/Vo' ListOfRichUsersResponse: description: returns List content: application/json: schema: type: array items: $ref: '#/components/schemas/RichUser' ListOfStringsResponse: description: returns List content: application/json: schema: type: array items: type: string parameters: facilityIds: name: facilities[] description: list of Facility ids List in: query required: true schema: type: array items: type: integer optionalUserId: name: user description: id of User schema: type: integer in: query required: false userId: name: user description: id of User schema: type: integer in: query required: true role: name: role description: User role schema: type: string in: query required: true groupId: name: group description: id of Group schema: type: integer in: query required: true complementaryObjectName: name: complementaryObjectName description: 'Property beanName of complementaryObject, meaning object type (supported object types: Group | RichGroup | Vo | Resource | Facility)' schema: type: string in: query required: true complementaryObjectId: name: complementaryObjectId description: Property id of complementaryObject to get managers for schema: type: integer in: query required: true optionalGroupId: name: group description: id of Group schema: type: integer in: query required: false optionalFacilityId: name: facility description: id of Facility schema: type: integer in: query required: false voIds: name: vos[] description: list of Vo ids List in: query required: true schema: type: array items: type: integer ListOfRoles: name: roles[] description: list of role names List in: query required: true schema: type: array items: type: string schemas: AttributeDefinition: allOf: - $ref: '#/components/schemas/Auditable' properties: friendlyName: type: string namespace: type: string description: type: - string - 'null' type: type: string displayName: type: string writable: type: boolean unique: type: boolean friendlyNameParameter: type: string readOnly: true baseFriendlyName: type: string readOnly: true entity: type: string readOnly: true PerunBean: description: identifiable entity in Perun, common ancestor of all entity classes type: object properties: id: type: integer beanName: type: string required: - id - beanName discriminator: propertyName: beanName PerunPolicy: type: object properties: policyName: type: string includePolicies: type: array items: type: string perunRoles: type: array items: type: object additionalProperties: type: string required: - policyName - includePolicies - perunRoles Facility: allOf: - $ref: '#/components/schemas/Auditable' properties: name: type: string description: type: - string - 'null' uuid: type: string format: uuid Vo: allOf: - $ref: '#/components/schemas/Auditable' properties: name: type: string shortName: type: string uuid: type: string format: uuid RoleManagementRules: type: object properties: roleName: type: string primaryObject: type: - string - 'null' privilegedRolesToManage: type: array items: type: object additionalProperties: type: - string - 'null' privilegedRolesToRead: type: array items: type: object additionalProperties: type: - string - 'null' entitiesToManage: type: object additionalProperties: type: string assignedObjects: type: object additionalProperties: type: string assignableToAttributes: type: boolean skipMFA: type: boolean displayName: type: string required: - roleName - primaryObject - privilegedRolesToManage - privilegedRolesToRead - entitiesToManage - assignedObjects - assignableToAttributes - skipMFA - displayName Resource: allOf: - $ref: '#/components/schemas/Auditable' properties: name: type: string description: type: string voId: type: integer facilityId: type: integer uuid: type: string format: uuid RichUser: description: user data packed together with all user attributes and UserExtSources allOf: - $ref: '#/components/schemas/User' properties: userExtSources: type: - array - 'null' items: $ref: '#/components/schemas/UserExtSource' userAttributes: type: - array - 'null' items: $ref: '#/components/schemas/Attribute' required: - userExtSources - userAttributes UserExtSource: description: represents specific user authentication or identification in external source of data allOf: - $ref: '#/components/schemas/Auditable' properties: login: type: string userId: type: integer loa: type: integer persistent: type: boolean lastAccess: type: string format: timestamp description: SQL timestamp example: '2012-01-01 00:00:00.100000' extSource: $ref: '#/components/schemas/ExtSource' required: - login - extSource IdmObject: type: object properties: idmObjectType: type: string objectId: type: string required: - idmObjectType - objectId AuthzRoles: type: object additionalProperties: type: object additionalProperties: type: array items: type: integer Group: allOf: - $ref: '#/components/schemas/Auditable' type: - object - 'null' properties: name: type: string shortName: type: string description: type: - string - 'null' voId: type: integer parentGroupId: type: - integer - 'null' uuid: type: string format: uuid PerunException: description: exception thrown from inside of Perun type: object properties: errorId: type: string name: type: string message: type: string ExtSource: description: represents external source of data for users such as an IdP or an HR database allOf: - $ref: '#/components/schemas/Auditable' properties: name: type: string type: type: string Auditable: description: represents audit information allOf: - $ref: '#/components/schemas/PerunBean' properties: createdAt: type: - string - 'null' createdBy: type: - string - 'null' modifiedAt: type: - string - 'null' modifiedBy: type: - string - 'null' createdByUid: type: - integer - 'null' modifiedByUid: type: - integer - 'null' User: description: represents user as a physical person allOf: - $ref: '#/components/schemas/Auditable' properties: firstName: type: - string - 'null' lastName: type: - string - 'null' middleName: type: - string - 'null' titleBefore: type: - string - 'null' titleAfter: type: - string - 'null' serviceUser: type: boolean sponsoredUser: type: boolean uuid: type: string format: uuid specificUser: type: boolean majorSpecificType: type: string Member: description: represents Member of a Virtual Organization allOf: - $ref: '#/components/schemas/Auditable' properties: userId: type: integer voId: type: integer status: type: string membershipType: type: string dualMembership: type: boolean sourceGroupId: type: - integer - 'null' sponsored: type: boolean groupStatus: type: string groupStatuses: type: object additionalProperties: type: string PerunPrincipal: type: object required: - userId - user properties: actor: type: string extSourceName: type: string extSourceType: type: string extSourceLoa: type: integer user: $ref: '#/components/schemas/User' authzInitialized: type: boolean additionalInformations: type: object additionalProperties: type: string userId: type: integer roles: type: object additionalProperties: type: object additionalProperties: type: array items: type: integer Attribute: allOf: - $ref: '#/components/schemas/AttributeDefinition' properties: valueCreatedAt: type: - string - 'null' valueCreatedBy: type: - string - 'null' valueModifiedAt: type: - string - 'null' valueModifiedBy: type: - string - 'null' value: {} securitySchemes: BasicAuth: description: HTTP Basic authentication with username and password type: http scheme: basic BearerAuth: description: 'OAuth2 Resource Server authentication using access token in ''Authorization: Bearer'' HTTP header' type: http scheme: bearer x-refined-from: - cesnet-perun-rpc-openapi.yml - cesnet-perun-rpc-openapi.yml