openapi: 3.2.0 info: title: Dependency Track Permission API version: 1.0.0 contact: name: The Dependency-Track Authors url: https://github.com/DependencyTrack/dependency-track license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html description: 'Operations tagged permission across 2 of this provider''s published API definitions: dependency-track-openapi-v1.yaml, dependency-track-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: /api tags: - name: Permission paths: /v1/permission: get: description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_READ operationId: getAllPermissions responses: '200': content: application/json: schema: type: string enum: - BOM_UPLOAD - VIEW_PORTFOLIO - PORTFOLIO_ACCESS_CONTROL_BYPASS - PORTFOLIO_MANAGEMENT - PORTFOLIO_MANAGEMENT_CREATE - PORTFOLIO_MANAGEMENT_READ - PORTFOLIO_MANAGEMENT_UPDATE - PORTFOLIO_MANAGEMENT_DELETE - VIEW_VULNERABILITY - VULNERABILITY_ANALYSIS - VULNERABILITY_ANALYSIS_CREATE - VULNERABILITY_ANALYSIS_READ - VULNERABILITY_ANALYSIS_UPDATE - VIEW_POLICY_VIOLATION - VULNERABILITY_MANAGEMENT - VULNERABILITY_MANAGEMENT_CREATE - VULNERABILITY_MANAGEMENT_READ - VULNERABILITY_MANAGEMENT_UPDATE - VULNERABILITY_MANAGEMENT_DELETE - POLICY_VIOLATION_ANALYSIS - ACCESS_MANAGEMENT - ACCESS_MANAGEMENT_CREATE - ACCESS_MANAGEMENT_READ - ACCESS_MANAGEMENT_UPDATE - ACCESS_MANAGEMENT_DELETE - SECRET_MANAGEMENT - SECRET_MANAGEMENT_CREATE - SECRET_MANAGEMENT_UPDATE - SECRET_MANAGEMENT_DELETE - SYSTEM_CONFIGURATION - SYSTEM_CONFIGURATION_CREATE - SYSTEM_CONFIGURATION_READ - SYSTEM_CONFIGURATION_UPDATE - SYSTEM_CONFIGURATION_DELETE - PROJECT_CREATION_UPLOAD - POLICY_MANAGEMENT - POLICY_MANAGEMENT_CREATE - POLICY_MANAGEMENT_READ - POLICY_MANAGEMENT_UPDATE - POLICY_MANAGEMENT_DELETE - TAG_MANAGEMENT - TAG_MANAGEMENT_DELETE description: A list of all permissions '401': description: Unauthorized security: - ApiKeyAuth: [] - BearerAuth: [] summary: Returns a list of all permissions tags: - Permission servers: - url: /api /v1/permission/team: put: description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_UPDATE operationId: setTeamPermissions requestBody: content: application/json: schema: $ref: '#/components/schemas/TeamPermissionsSetRequest' description: Team UUID and requested permissions responses: '200': content: application/json: schema: $ref: '#/components/schemas/Team' description: The updated team '304': description: The team already has the specified permission(s) '400': description: Bad request '401': description: Unauthorized '404': description: The team could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Replaces a team's permissions with the specified list tags: - Permission servers: - url: /api /v1/permission/user: put: description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_UPDATE operationId: setUserPermissions requestBody: content: application/json: schema: $ref: '#/components/schemas/UserPermissionsSetRequest' description: A username and valid list permission responses: '200': content: application/json: schema: $ref: '#/components/schemas/User' description: The updated user '304': description: The user is already has the specified permission(s) '400': description: Bad request '401': description: Unauthorized '404': description: The user could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Replaces a users's permissions with the specified list tags: - Permission servers: - url: /api /v1/permission/{permission}/team/{uuid}: delete: description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_DELETE operationId: removePermissionFromTeam parameters: - description: A valid team uuid in: path name: uuid required: true schema: type: string format: uuid - description: A valid permission in: path name: permission required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/Team' description: The updated team '304': description: The team already has the specified permission assigned '401': description: Unauthorized '404': description: The team could not be found security: - ApiKeyAuth: [] - BearerAuth: [] tags: - Permission summary: Remove permission from team x-summary-source: derived post: description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_UPDATE operationId: addPermissionToTeam parameters: - description: A valid team uuid in: path name: uuid required: true schema: type: string format: uuid - description: A valid permission in: path name: permission required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/Team' description: The updated team '304': description: The team already has the specified permission assigned '401': description: Unauthorized '404': description: The team could not be found security: - ApiKeyAuth: [] - BearerAuth: [] tags: - Permission summary: Add permission to team x-summary-source: derived servers: - url: /api /v1/permission/{permission}/user/{username}: delete: description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_DELETE operationId: removePermissionFromUser parameters: - description: A valid username in: path name: username required: true schema: type: string - description: A valid permission in: path name: permission required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/User' description: The updated user '304': description: The user already has the specified permission assigned '401': description: Unauthorized '404': description: The user could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Removes the permission from the user tags: - Permission post: description: Requires permission ACCESS_MANAGEMENT or ACCESS_MANAGEMENT_UPDATE operationId: addPermissionToUser parameters: - description: A valid username in: path name: username required: true schema: type: string - description: A valid permission in: path name: permission required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/User' description: The updated user '304': description: The user already has the specified permission assigned '401': description: Unauthorized '404': description: The user could not be found security: - ApiKeyAuth: [] - BearerAuth: [] summary: Adds the permission to the specified username tags: - Permission servers: - url: /api components: schemas: ManagedUser: type: object properties: confirmPassword: type: string email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' forcePasswordChange: type: boolean fullname: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' lastPasswordChange: type: integer format: int64 description: UNIX epoch timestamp in milliseconds newPassword: type: string nonExpiryPassword: type: boolean permissions: type: array items: $ref: '#/components/schemas/Permission' suspended: type: boolean teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - lastPasswordChange - username TeamPermissionsSetRequest: type: object properties: permissions: type: array items: type: string enum: - BOM_UPLOAD - VIEW_PORTFOLIO - PORTFOLIO_ACCESS_CONTROL_BYPASS - PORTFOLIO_MANAGEMENT - PORTFOLIO_MANAGEMENT_CREATE - PORTFOLIO_MANAGEMENT_READ - PORTFOLIO_MANAGEMENT_UPDATE - PORTFOLIO_MANAGEMENT_DELETE - VIEW_VULNERABILITY - VULNERABILITY_ANALYSIS - VULNERABILITY_ANALYSIS_CREATE - VULNERABILITY_ANALYSIS_READ - VULNERABILITY_ANALYSIS_UPDATE - VIEW_POLICY_VIOLATION - VULNERABILITY_MANAGEMENT - VULNERABILITY_MANAGEMENT_CREATE - VULNERABILITY_MANAGEMENT_READ - VULNERABILITY_MANAGEMENT_UPDATE - VULNERABILITY_MANAGEMENT_DELETE - POLICY_VIOLATION_ANALYSIS - ACCESS_MANAGEMENT - ACCESS_MANAGEMENT_CREATE - ACCESS_MANAGEMENT_READ - ACCESS_MANAGEMENT_UPDATE - ACCESS_MANAGEMENT_DELETE - SECRET_MANAGEMENT - SECRET_MANAGEMENT_CREATE - SECRET_MANAGEMENT_UPDATE - SECRET_MANAGEMENT_DELETE - SYSTEM_CONFIGURATION - SYSTEM_CONFIGURATION_CREATE - SYSTEM_CONFIGURATION_READ - SYSTEM_CONFIGURATION_UPDATE - SYSTEM_CONFIGURATION_DELETE - PROJECT_CREATION_UPLOAD - POLICY_MANAGEMENT - POLICY_MANAGEMENT_CREATE - POLICY_MANAGEMENT_READ - POLICY_MANAGEMENT_UPDATE - POLICY_MANAGEMENT_DELETE - TAG_MANAGEMENT - TAG_MANAGEMENT_DELETE uniqueItems: true team: type: string minLength: 1 required: - permissions - team MappedOidcGroup: type: object properties: group: $ref: '#/components/schemas/OidcGroup' uuid: type: string format: uuid required: - uuid UserPermissionsSetRequest: type: object properties: permissions: type: array items: type: string enum: - BOM_UPLOAD - VIEW_PORTFOLIO - PORTFOLIO_ACCESS_CONTROL_BYPASS - PORTFOLIO_MANAGEMENT - PORTFOLIO_MANAGEMENT_CREATE - PORTFOLIO_MANAGEMENT_READ - PORTFOLIO_MANAGEMENT_UPDATE - PORTFOLIO_MANAGEMENT_DELETE - VIEW_VULNERABILITY - VULNERABILITY_ANALYSIS - VULNERABILITY_ANALYSIS_CREATE - VULNERABILITY_ANALYSIS_READ - VULNERABILITY_ANALYSIS_UPDATE - VIEW_POLICY_VIOLATION - VULNERABILITY_MANAGEMENT - VULNERABILITY_MANAGEMENT_CREATE - VULNERABILITY_MANAGEMENT_READ - VULNERABILITY_MANAGEMENT_UPDATE - VULNERABILITY_MANAGEMENT_DELETE - POLICY_VIOLATION_ANALYSIS - ACCESS_MANAGEMENT - ACCESS_MANAGEMENT_CREATE - ACCESS_MANAGEMENT_READ - ACCESS_MANAGEMENT_UPDATE - ACCESS_MANAGEMENT_DELETE - SECRET_MANAGEMENT - SECRET_MANAGEMENT_CREATE - SECRET_MANAGEMENT_UPDATE - SECRET_MANAGEMENT_DELETE - SYSTEM_CONFIGURATION - SYSTEM_CONFIGURATION_CREATE - SYSTEM_CONFIGURATION_READ - SYSTEM_CONFIGURATION_UPDATE - SYSTEM_CONFIGURATION_DELETE - PROJECT_CREATION_UPLOAD - POLICY_MANAGEMENT - POLICY_MANAGEMENT_CREATE - POLICY_MANAGEMENT_READ - POLICY_MANAGEMENT_UPDATE - POLICY_MANAGEMENT_DELETE - TAG_MANAGEMENT - TAG_MANAGEMENT_DELETE uniqueItems: true username: type: string minLength: 1 pattern: ^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$ required: - permissions - username ServiceAccount: type: object properties: email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' suspended: type: boolean teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username OidcGroup: type: object properties: name: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' uuid: type: string format: uuid required: - name - uuid MappedLdapGroup: type: object properties: dn: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' uuid: type: string format: uuid required: - dn - uuid Permission: type: object properties: description: type: string ldapUsers: type: array items: $ref: '#/components/schemas/LdapUser' managedUsers: type: array items: $ref: '#/components/schemas/ManagedUser' name: type: string maxLength: 255 minLength: 1 pattern: ^[a-zA-Z_0-9]*$ oidcUsers: type: array items: $ref: '#/components/schemas/OidcUser' required: - name Team: type: object properties: apiKeys: type: array items: $ref: '#/components/schemas/ApiKey' ldapUsers: type: array items: $ref: '#/components/schemas/LdapUser' managedUsers: type: array items: $ref: '#/components/schemas/ManagedUser' mappedLdapGroups: type: array items: $ref: '#/components/schemas/MappedLdapGroup' mappedOidcGroups: type: array items: $ref: '#/components/schemas/MappedOidcGroup' name: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' oidcUsers: type: array items: $ref: '#/components/schemas/OidcUser' permissions: type: array items: $ref: '#/components/schemas/Permission' serviceAccounts: type: array items: $ref: '#/components/schemas/ServiceAccount' uuid: type: string format: uuid required: - name - uuid LdapUser: type: object properties: dn: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username OidcUser: type: object properties: email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' subjectIdentifier: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username User: type: object properties: email: type: string maxLength: 255 minLength: 0 pattern: '[\P{Cc}]+' permissions: type: array items: $ref: '#/components/schemas/Permission' teams: type: array items: $ref: '#/components/schemas/Team' username: type: string maxLength: 255 minLength: 1 pattern: '[\P{Cc}]+' required: - username ApiKey: type: object properties: comment: type: string maxLength: 255 minLength: 0 created: type: integer format: int64 description: UNIX epoch timestamp in milliseconds expiresAt: type: integer format: int64 description: UNIX epoch timestamp in milliseconds key: type: string lastUsed: type: integer format: int64 description: UNIX epoch timestamp in milliseconds legacy: type: boolean maskedKey: type: string publicId: type: string maxLength: 8 minLength: 5 securitySchemes: ApiKeyAuth: description: Authentication via API key. in: header name: X-Api-Key type: apiKey BearerAuth: bearerFormat: Opaque description: 'Authentication via opaque server-issued session token. Tokens are obtained from `POST /api/v1/user/login` or `POST /api/v1/user/oidc/login`.' scheme: bearer type: http x-refined-from: - dependency-track-openapi-v1.yaml - dependency-track-openapi.yml