openapi: 3.2.0 info: title: Sakura Internet OIDC認証 API version: 2.1.0 contact: name: SAKURA internet Inc. license: name: Copyright(C) SAKURA internet Inc. all rights reserved. description: 'Operations tagged OIDC認証 across 2 of this provider''s published API definitions: apigw-api.yaml, sakura-internet-apigw-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://secure.sakura.ad.jp/cloud/api/apigw/1.0/ tags: - name: OIDC認証 paths: /oidc: post: tags: - OIDC認証 summary: OIDC認証登録API description: OIDC認証の設定値を登録します。 operationId: addOidc requestBody: content: application/json: schema: $ref: '#/components/schemas/Oidc' required: true responses: '201': description: 成功時のレスポンス content: application/json: schema: type: object required: - apigw properties: apigw: type: object properties: oidc: $ref: '#/components/schemas/Oidc' '400': $ref: '#/components/responses/BadRequestResponse' '401': $ref: '#/components/responses/UnauthorizedResponse' '404': $ref: '#/components/responses/NotFoundResponse' '409': $ref: '#/components/responses/ConflictResponse' '422': $ref: '#/components/responses/UnprocessableEntityResponse' '500': $ref: '#/components/responses/ServerErrorResponse' get: tags: - OIDC認証 summary: OIDC認証一覧照会API description: 登録した OIDC認証 の一覧を取得します。 operationId: getOidc responses: '200': description: 成功時のレスポンス content: application/json: schema: required: - apigw properties: apigw: properties: oidcs: type: array items: $ref: '#/components/schemas/Oidc' '400': $ref: '#/components/responses/BadRequestResponse' '401': $ref: '#/components/responses/UnauthorizedResponse' '404': $ref: '#/components/responses/NotFoundResponse' '500': $ref: '#/components/responses/ServerErrorResponse' servers: - url: https://secure.sakura.ad.jp/cloud/api/apigw/1.0/ /oidc/{oidcId}: get: tags: - OIDC認証 summary: OIDC認証詳細照会API description: 登録した OIDC認証 の詳細を取得します。 operationId: getOidcById parameters: - $ref: '#/components/parameters/OidcID' responses: '200': description: 成功時のレスポンス content: application/json: schema: required: - apigw properties: apigw: properties: oidc: $ref: '#/components/schemas/OidcDetail' '400': $ref: '#/components/responses/BadRequestResponse' '401': $ref: '#/components/responses/UnauthorizedResponse' '404': $ref: '#/components/responses/NotFoundResponse' '500': $ref: '#/components/responses/ServerErrorResponse' put: tags: - OIDC認証 summary: OIDC認証更新API description: 登録した OIDC認証 を更新します。 operationId: updateOidc parameters: - $ref: '#/components/parameters/OidcID' requestBody: content: application/json: schema: $ref: '#/components/schemas/Oidc' required: true responses: '204': description: 成功時の返却値はありません。 '400': $ref: '#/components/responses/BadRequestResponse' '401': $ref: '#/components/responses/UnauthorizedResponse' '404': $ref: '#/components/responses/NotFoundResponse' '409': $ref: '#/components/responses/ConflictResponse' '500': $ref: '#/components/responses/ServerErrorResponse' delete: tags: - OIDC認証 summary: OIDC認証削除API description: 登録した OIDC認証 を削除します。 operationId: deleteOidc parameters: - $ref: '#/components/parameters/OidcID' responses: '204': description: 成功時の返却値はありません。 '400': $ref: '#/components/responses/BadRequestResponse' '401': $ref: '#/components/responses/UnauthorizedResponse' '404': $ref: '#/components/responses/NotFoundResponse' '409': $ref: '#/components/responses/ConflictResponse' '500': $ref: '#/components/responses/ServerErrorResponse' servers: - url: https://secure.sakura.ad.jp/cloud/api/apigw/1.0/ components: responses: ServerErrorResponse: description: サーバーエラー content: application/json: schema: $ref: '#/components/schemas/ErrorSchema' ConflictResponse: description: リソースが競合している content: application/json: schema: $ref: '#/components/schemas/ErrorSchema' UnprocessableEntityResponse: description: Request自体は正しいが、処理できない content: application/json: schema: $ref: '#/components/schemas/ErrorSchema' BadRequestResponse: description: Requestエラー content: application/json: schema: $ref: '#/components/schemas/ErrorSchema' NotFoundResponse: description: リソースが存在しない content: application/json: schema: $ref: '#/components/schemas/ErrorSchema' UnauthorizedResponse: description: 認証エラー content: application/json: schema: $ref: '#/components/schemas/ErrorSchema' schemas: Name: type: string description: Unicode文字、数字、ハイフン、アンダースコア、ピリオドのみ許可 minLength: 1 maxLength: 255 example: name pattern: ^[\p{L}\p{N}._\-]+$ AuthenticationMethods: type: array description: OIDC認証フロー items: type: string enum: - authorizationCodeFlow - accessToken example: accessToken Oidc: description: Oidc認証情報 type: object allOf: - $ref: '#/components/schemas/Model' - properties: name: $ref: '#/components/schemas/Name' description: 認証名
認証名は半角英数字およびアンダースコアのみを許可 example: name authenticationMethods: $ref: '#/components/schemas/AuthenticationMethods' issuer: type: string description: IdPに紐づくエンドポイント example: http://example.com clientId: type: string description: IdPに紐づくクライアントID example: abc123xyz456def789ghi012jkl345mno678pqr x-oapi-codegen-extra-tags: mask: 'true' clientSecret: type: string description: IdPに紐づくクライアントシークレット example: s3cr3tK3y!@12345vWxz67890uYz@Qp x-oapi-codegen-extra-tags: mask: 'true' scopes: type: array description: IdPに要求するスコープ items: type: string example: openid hideCredentials: type: boolean description: 認証情報のサービス(アップストリームサーバ)への転送を有効にするかどうか default: false tokenAudiences: type: array description: トークンaudクレーム検証値 items: type: string example: value1 useSession: type: boolean description: 認証情報をセッションとしてAPIゲートウェイへの保存を有効にするかどうか default: false refreshTokenParamName: type: string description: この項目は現在、指定することができない
リフレッシュトークンパラメータ名
指定がない場合は"refresh_token"が設定される
※authenticationMethodsに"refreshToken"が含まれる場合に使用される example: refreshToken deprecated: true required: - name - authenticationMethods - issuer - clientId - clientSecret OidcDetail: description: OIDC詳細情報 type: object allOf: - $ref: '#/components/schemas/Oidc' - properties: services: type: array description: OIDC認証を使用するServiceの要約情報 items: $ref: '#/components/schemas/ServiceSummary' Model: type: object properties: id: type: string format: uuid readOnly: true example: b69f7bfe-1d8f-48bb-8b85-b47359366e48 description: Entityを識別するためのID createdAt: type: string format: date-time readOnly: true description: 作成日時 updatedAt: type: string format: date-time readOnly: true description: 更新日時 description: 各Entity共通のモデル ServiceSummary: description: Service要約情報 type: object allOf: - properties: id: type: string format: uuid readOnly: true description: Entityを識別するためのID example: b69f7bfe-1d8f-48bb-8b85-b47359366e48 name: $ref: '#/components/schemas/Name' description: Service名
Service名は半角英数字およびアンダースコアのみを許可 example: serviceName ErrorSchema: type: object properties: message: type: string description: 各エラーに対応したメッセージが返却される example: Bad Request parameters: OidcID: in: path name: oidcId description: OidcID schema: type: string format: uuid example: 7c8d78bc-e4a3-4600-b70a-f5fe802dc1ba required: true example: 7c8d78bc-e4a3-4600-b70a-f5fe802dc1ba x-refined-from: - apigw-api.yaml - sakura-internet-apigw-openapi.yml