Indian Institute of Technology Kanpur orders API

Manage acquisition orders

OpenAPI Specification

iit-kanpur-orders-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  contact:
    name: Koha Development Team
    url: https://koha-community.org/
  description: "## Background\n\nThe API supports two sets of endpoints, one targetted at library staff and the other at at library users.\n\nThose endpoints under the `/public` path are aimed at delivering functionality tailored to library users and offer\na more restricted set of functions, overrides and data in thier responses for data privacy and library policy\nreasons. Many of these endpoints do not require authentication for fetching public data, though an authenticated\nsession will expose additional options and allow users to see more data where it is part of their own record.\n\nAll other endpoints are targetted at the staff interface level and allow for additional functionality and a more\nunrestricted view of data.  These endpoints, however, have a level of redaction built in for resources that the\napi consumer should not have access to.  For example, user data for users who do not belong to the same library\nor library group of your api user will be reduced to just minimum neccesary for a valid response. Object keys will\nbe consistent for all responses, but their values may be removed depending on access.\n\n## Authentication\n\nThe API supports the following authentication mechanisms\n\n* HTTP Basic authentication\n* OAuth2 (client credentials grant)\n* Cookie-based\n\nBoth _Basic authentication_ and the _OAuth2_ flow, need to be enabled\nby system preferences.\n\n## Authorization\n\nThe API uses existing user profiles to restrict access to resources based on user permissions and the library the\nAPI user is assigned to.  This may result, at times, in resources being returned in a redacted form with all keys\npresent but sensative values nulled.\n\nWe do not yet support OAuth Scopes or the Authorization Code grant flow.\n\n## Errors\n\nThe API uses standard HTTP status codes to indicate the success or failure\nof the API call. The body of the response will be JSON in the following format:\n\n```\n{\n  \"error\": \"Current settings prevent the passed due date to be applied\",\n  \"error_code\": \"invalid_due_date\"\n}\n```\n\nNote: Some routes might offer additional attributes in their error responses but that\"s\nsubject to change and thus not documented.\n\n## Filtering responses\n\nThe API allows for some advanced response filtering using a JSON based query syntax. The\nquery can be added to the requests:\n\n* as a query parameter `q=`\n* in the request body\n\nFor simple field equality matches we can use `{ \"fieldname\": \"value\" }` where the fieldname\nmatches one of the fields as described in the particular endpoints response object.\n\nWe can refine that with more complex matching clauses by nesting a the clause into the\nobject; `{ \"fieldname\": { \"clause\": \"value\" } }`.\n\nAvailable matching clauses include `=`, `!=`, `<`, `>`, `<=`, `>=` and `-not`. We also support `-like`\nand `-not_like` string comparisons with `%` used to denote wildcards, thus you can pass\n`{ \"fieldname\": { \"-like\": \"value%\" } }` to do a 'starts with' string match for example.\n\nWe can filter on multiple fields by adding them to the JSON respresentation. Adding at `HASH`\nlevel will result in an \"AND\" query, whilst combinding them in an `ARRAY` will result in an\n\"OR\" query: `{ \"field1\": \"value2\", \"field2\": \"value2\" }` will filter the response to only those\nresults with both field1 containing value2 AND field2 containing value2 for example.\n\nThere is a collection of special operators also available to you, including:\n\n* `-in` - Expects an array of values to perform an OR match against\n* `-not_in` - Expects an array of values to perform a NOR match against\n* `-between` - Expects two values which the value of the field is expected to fall between\n* `-not_between` - Expects two values which the value of the field is expected to fall outside of\n* `-ident` - Expects a second field name to match the two field values against\n* `-regexp` - Expects a perl compatible regular expression for which the value should match\n\nLogic and nesting is also supported and you may use `-and` and `-or` to change the logic of an ARRAY\nor HASH as described above.\n\nAdditionally, if you are requesting related data be embedded into the response one can query\non the related data using dot notation in the field names.\n\n### Examples\n\nThe following request would return any patron with firstname \"Henry\" and lastname \"Acevedo\";\n\n`curl -u koha:koha --request GET \"http://127.0.0.1:8081/api/v1/patrons/\" --data-raw '{ \"surname\": \"Acevedo\", \"firstname\": \"Henry\" }'`\n\nThe following request would return any patron whose lastname begins with \"Ace\";\n\n`curl -u koha:koha --request GET \"http://127.0.0.1:8081/api/v1/patrons/\" --data-raw '{ \"surname\": { \"-like\": \"Ace%\" }'`\n\nThe following request would return any patron whose lastname is \"Acevedo\" OR \"Bernardo\"\n\n`curl -u koha:koha --request GET \"http://127.0.0.1:8081/api/v1/patrons/\" --data-raw '{ \"surname\": [ \"Acevedo\", \"Bernardo\" ] }'`\n\nThe following request embeds the related patron extended attributes data and filters on it.\n\n`curl -u koha:koha =--request GET 'http://127.0.0.1:8081/api/v1/patrons/' --header 'x-koha-embed: extended_attributes' --data-raw '{ \"extended_attributes.code\": \"internet\", \"extended_attributes.attribute\": \"1\" }'`\n\n## Special headers\n\n### x-koha-embed\n\nThis optional header allows the api consumer to request additional related data\nto be returned in the api response.  It also allows for cross referencing in the\nqueries as described above. It accepts a comma delimited list of relation names.\n\nRelations may on occasion also support dot delimited nesting to allow traversal.\n\n### x-koha-library\n\nThis optional header should be passed to give your api request a library\ncontext; If it is not included in the request, then the request context\nwill default to using your api comsumer\"s assigned home library.\n"
  license:
    name: GPL v3,
    url: http://www.gnu.org/licenses/gpl.txt
  title: Koha REST 2fa orders API
  version: '1'
servers:
- url: https://libserv.iitk.ac.in/api/v1
  description: PKK Library Koha REST API (production)
tags:
- description: 'Manage acquisition orders

    '
  name: orders
  x-displayName: Orders
paths:
  /acquisitions/orders:
    get:
      tags:
      - orders
      summary: List orders
      operationId: listOrders
      parameters:
      - name: biblio_id
        in: query
        required: false
        description: Identifier for a linked bibliographic record
        schema:
          type: integer
      - name: basket_id
        in: query
        required: false
        description: Identifier for a linked acquisition basket
        schema:
          type: integer
      - name: fund_id
        in: query
        required: false
        description: Identifier for the fund the order goes against
        schema:
          type: integer
      - name: status
        in: query
        required: false
        description: Current status for the order. Can be 'new', 'ordered', 'partial', 'complete' or 'cancelled'
        schema:
          type: string
      - name: only_active
        in: query
        required: false
        description: If only active orders should be listed
        schema:
          type: boolean
      - name: _match
        in: query
        required: false
        description: Matching criteria
        schema:
          type: string
          enum:
          - contains
          - exact
          - starts_with
          - ends_with
      - name: _order_by
        in: query
        required: false
        description: Sorting criteria
        schema:
          type: array
          items:
            type: string
      - name: _page
        in: query
        required: false
        description: Page number, for paginated object listing
        schema:
          type: integer
      - name: _per_page
        in: query
        required: false
        description: Page size, for paginated object listing
        schema:
          type: integer
      - name: q
        in: query
        required: false
        description: Query filter sent as a request parameter
        style: form
        explode: true
        schema:
          type: array
          items:
            type: string
      - name: x-koha-request-id
        in: header
        required: false
        description: Request id header
        schema:
          type: integer
      - name: x-koha-embed
        in: header
        required: false
        description: Embed list sent as a request header
        schema:
          type: array
          items:
            enum:
            - basket
            - basket.basket_group
            - basket.creator
            - biblio
            - biblio.active_orders+count
            - biblio.holds+count
            - biblio.items+count
            - biblio.suggestions.suggester
            - creator
            - fund
            - fund.budget
            - current_item_level_holds+count
            - invoice
            - items
            - items+strings
            - subscription
            type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
        description: Query filter sent through request"s body
      responses:
        '200':
          description: A list of orders
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/order_yaml'
                type: array
        '400':
          description: "Bad request. Possible `error_code` attribute values:\n\n  * `invalid_query`\n"
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '403':
          description: Access forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '404':
          description: Order not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '500':
          description: 'Internal server error. Possible `error_code` attribute values:


            * `internal_server_error`

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '501':
          description: Default response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DefaultResponse'
        '503':
          description: Under maintenance
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
    post:
      tags:
      - orders
      summary: Add order
      operationId: addOrder
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/order_yaml'
        description: A JSON object representing an order
      responses:
        '201':
          description: Order added
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/order_yaml'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '403':
          description: Access forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '404':
          description: Default response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DefaultResponse'
        '409':
          description: Conflict in creating the resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '500':
          description: 'Internal server error. Possible `error_code` attribute values:


            * `internal_server_error`

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '501':
          description: Default response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DefaultResponse'
        '503':
          description: Under maintenance
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
  /acquisitions/orders/{order_id}:
    delete:
      tags:
      - orders
      summary: Delete order
      operationId: deleteOrder
      parameters:
      - name: order_id
        in: path
        required: true
        description: Internal order identifier
        schema:
          type: integer
      responses:
        '204':
          description: Order deleted
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '403':
          description: Access forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '404':
          description: Order not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '500':
          description: 'Internal server error. Possible `error_code` attribute values:


            * `internal_server_error`

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '501':
          description: Default response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DefaultResponse'
        '503':
          description: Under maintenance
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
    get:
      tags:
      - orders
      summary: Get order
      operationId: getOrder
      parameters:
      - name: order_id
        in: path
        required: true
        description: Internal order identifier
        schema:
          type: integer
      - name: x-koha-embed
        in: header
        required: false
        description: Embed list sent as a request header
        schema:
          type: array
          items:
            enum:
            - basket
            - basket.basket_group
            - basket.creator
            - biblio
            - biblio.active_orders+count
            - biblio.holds+count
            - biblio.items+count
            - biblio.suggestions.suggester
            - fund
            - current_item_level_holds+count
            - invoice
            - items
            - subscription
            type: string
      responses:
        '200':
          description: An order
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/order_yaml'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '403':
          description: Access forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '404':
          description: Order not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '500':
          description: 'Internal server error. Possible `error_code` attribute values:


            * `internal_server_error`

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '501':
          description: Default response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DefaultResponse'
        '503':
          description: Under maintenance
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
    put:
      tags:
      - orders
      summary: Update order
      operationId: updateOrder
      parameters:
      - name: order_id
        in: path
        required: true
        description: Internal order identifier
        schema:
          type: integer
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/order_yaml'
        description: A JSON object representing an order
      responses:
        '200':
          description: An order
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/order_yaml'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '403':
          description: Access forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '404':
          description: Order not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '500':
          description: 'Internal server error. Possible `error_code` attribute values:


            * `internal_server_error`

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
        '501':
          description: Default response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DefaultResponse'
        '503':
          description: Under maintenance
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error_yaml'
components:
  schemas:
    error_yaml:
      additionalProperties: true
      properties:
        error:
          description: Error message
          type: string
        error_code:
          description: Error code
          type: string
      type: object
    DefaultResponse:
      properties:
        errors:
          items:
            properties:
              message:
                type: string
              path:
                type: string
            required:
            - message
            type: object
          type: array
      required:
      - errors
      type: object
    order_yaml:
      additionalProperties: false
      properties:
        basket:
          type:
          - object
          - 'null'
        basket_id:
          description: Basket this order is linked to
          type:
          - integer
          - 'null'
        biblio:
          type:
          - object
          - 'null'
        biblio_id:
          description: Identifier for the linked bibliographic record
          type:
          - integer
          - 'null'
        cancellation_date:
          description: Date the line item was deleted
          format: date
          type:
          - string
          - 'null'
        cancellation_reason:
          description: Reason of cancellation
          type:
          - string
          - 'null'
        claims_count:
          description: Generated claim letters count
          type: integer
        created_by:
          description: Interal patron identifier of the order line creator
          type:
          - integer
          - 'null'
        creator:
          description: Patron that created the order
          type:
          - object
          - 'null'
        currency:
          description: Currency used for the purchase
          type:
          - string
          - 'null'
        current_item_level_holds_count:
          description: Current holds count for associated items
          type: integer
        date_received:
          description: Date the order was received
          format: date
          type:
          - string
          - 'null'
        deleted_biblio_id:
          description: Identifier for the linked deleted bibliographic record
          type:
          - integer
          - 'null'
        discount_rate:
          description: Discount rate
          type:
          - number
          - 'null'
        ecost:
          description: Effective cost
          type:
          - number
          - 'null'
        ecost_tax_excluded:
          description: Effective cost (tax excluded)
          type:
          - number
          - 'null'
        ecost_tax_included:
          description: Effective cost (tax included)
          type:
          - number
          - 'null'
        entry_date:
          description: Date the bib was added to the basket
          format: date
          type:
          - string
          - 'null'
        estimated_delivery_date:
          description: Estimated delivery date
          format: date
          type:
          - string
          - 'null'
        fund:
          type:
          - object
          - 'null'
        fund_id:
          description: Internal identifier for the fund this order goes against
          type: integer
        internal_note:
          description: Notes related to this order line, made for staff
          type:
          - string
          - 'null'
        invoice:
          type:
          - object
          - 'null'
        invoice_currency:
          description: Currency of the actual cost used when receiving
          type:
          - string
          - 'null'
        invoice_id:
          description: Id of the order invoice
          type:
          - integer
          - 'null'
        invoice_unit_price:
          description: The actual cost in the foreign currency used in the invoice
          type:
          - number
          - 'null'
        items:
          type: array
        last_claim_date:
          description: Last date a claim letter was generated
          format: date
          type:
          - string
          - 'null'
        list_price:
          description: Vendor price for the line item
          type:
          - number
          - 'null'
        order_id:
          description: Internally assigned order identifier
          type: integer
        parent_order_id:
          description: Order ID of parent order line if exists
          type:
          - integer
          - 'null'
        quantity:
          description: Ordered quantity
          type:
          - integer
          - 'null'
        quantity_received:
          description: Quantity received so far
          type: integer
        replacement_price:
          description: Replacement cost for this item
          type:
          - number
          - 'null'
        rrp:
          description: Retail cost for this item
          type:
          - number
          - 'null'
        rrp_tax_excluded:
          description: Replacement cost for this item (tax excluded)
          type:
          - number
          - 'null'
        rrp_tax_included:
          description: Replacement cost for this item (tax included)
          type:
          - number
          - 'null'
        shipping_cost:
          description: Shipping cost
          type:
          - number
          - 'null'
        statistics_1:
          description: Statistical field
          type:
          - string
          - 'null'
        statistics_1_authcat:
          description: Statistical category for this order
          type:
          - string
          - 'null'
        statistics_2:
          description: Statistical field (2)
          type:
          - string
          - 'null'
        statistics_2_authcat:
          description: Statistical category for this order (2)
          type:
          - string
          - 'null'
        status:
          description: The current order status
          enum:
          - new
          - ordered
          - partial
          - complete
          - cancelled
          type: string
        subscription:
          type:
          - object
          - 'null'
        subscription_id:
          description: Subscription ID linking the order to a subscription
          type:
          - integer
          - 'null'
        tax_rate_on_ordering:
          description: Tax rate on ordering (%)
          type:
          - number
          - 'null'
        tax_rate_on_receiving:
          description: Tax rate on receiving (%)
          type:
          - number
          - 'null'
        tax_value_on_ordering:
          description: Tax value on ordering
          type:
          - number
          - 'null'
        tax_value_on_receiving:
          description: Tax value on receiving
          type:
          - number
          - 'null'
        timestamp:
          description: Date and time this order line was last modified
          format: date-time
          type: string
        uncertain_price:
          description: If this price was uncertain
          type: boolean
        unit_price:
          description: The actual cost entered when receiving this line item
          type:
          - number
          - 'null'
        unit_price_tax_excluded:
          description: Unit price excluding tax (on receiving)
          type:
          - number
          - 'null'
        unit_price_tax_included:
          description: Unit price including tax (on receiving)
          type:
          - number
          - 'null'
        vendor_note:
          description: Notes related to this order line, made for vendor
          type:
          - string
          - 'null'
      type: object