ЕСОЗ - публічна документація
[DRAFT] Refresh client secret [API-009-001-006-0340]
Сторінка знаходиться в процесі розробки. Інформація на ній може бути застарілою.
https://e-health-ua.atlassian.net/wiki/spaces/EN/pages/17591304241 (remove the link block before publishing the document)
- 1 Properties of a REST API method document
- 2 Purpose
- 3 Logic
- 4 Configuration parameters
- 5 Dictionaries
- 6 Input parameters
- 7 Request structure
- 8 Headers
- 9 Request data validation
- 9.1 Authorize
- 10 Processing
- 11 Response structure examples
- 12 HTTP status codes
- 13 Post-processing processes
- 14 Technical modules where the method is used
Properties of a REST API method document
Document type | Метод REST API |
---|---|
Document title | [DRAFT] Refresh client secret [API-009-001-006-0340] |
Guideline ID | GUI-0011 |
Author | @ |
Document version | 1 |
Document status | DRAFT |
Date of creation | ХХ.ХХ.ХХХХ (дата фінальної версії документа – RC або PROD) |
Date of update | ХХ.ХХ.ХХХХ (дата зміни версії) |
Method API ID | API-009-001-006-0340 |
Microservices (namespace) | Mithril |
Component | Mithril |
Component ID | COM-009-001 |
Link на API-специфікацію | |
Resource | {{host}}/api/clients/{{id}}/connections/{{connection_id}}/actions/refresh_secret |
Scope | connection:refresh_secret |
Protocol type | REST |
Request type | PATCH |
Sync/Async | Sync |
Public/Private | Public |
Purpose
This method is used to refresh client secret for specified client connection Only legal entity owner can request new client secret for his own legal entity
Logic
This service manages connections restricted by Client ID and context
Extract client_type from token
Validate specified Client ID according to context:
MSP, MIS, PHARMACY - receives only its own client
in case of error generate 403 response ('forbidden')
Generate new secret for specified Connection ID and update it in mithril.connections for specified Connection ID
Configuration parameters
N/A
Dictionaries
N/A
Input parameters
Input parameter | Mandatory | Type | Description | Example | |
---|---|---|---|---|---|
1 | id |
| String | Required | 1380df72-275a-11e7-93ae-92361f002671 |
2 | connection_id |
| String | Required | e5372365-d47a-467f-81d0-f35117864352 |
Request structure
See on API-specification
Headers
Request data validation
Authorize
erify the validity of access token
in case of error return 401 ('Access denied')
Check user scope connection:refresh_secret in order to perform this action
in case of error generate 403 response ('Invalid scopes')
Processing
N/A
Response structure examples
See on API-specification
HTTP status codes
Response code | HTTP Status code | Message | Internal name | Description | |
---|---|---|---|---|---|
1 | Базові | ||||
2 |
| 200 | Response |
|
|
3 |
| 401 | Access denied |
|
|
4 |
| 403 | Invalid scopes |
|
|
5 |
| 403 | Forbidden |
|
|
6 | Специфічні | ||||
7 |
|
|
|
|
|
Post-processing processes
N/A
Technical modules where the method is used
ЕСОЗ - публічна документація