Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Table of Contents

...

  1. Verify the validity of access token
    1. Return 401 in case validation fails
  2. Check scopes in order to perform this action (scope = 'employee_role:write')
    1. Return 403 in case invalid scope(s)

Validate legal entity

Check that legal entity is active (status = ACTIVE, SUSPENDED)

  1. Extract client_id from token (token.client_id == legal_entity_id)
  2. Check legal entity status (status = ACTIVE, SUSPENDED)

Validate employee role

  1. Check that employee role with such ID exists in the system (is_active = true)
    1. In case of error - return 404
  2. Check that employee role belongs to the same legal entity as the user
    1. In case of error - return 403

...

ParameterSourceDescription
end_dateTimestamp: now()Get current date-time
statusConst: INACTIVE
updated_atTimestamp: now()Get current date-time
updated_byToken: user_id