Newstore roles API

Roles

OpenAPI Specification

newstore-roles-api-openapi.yml Raw ↑
swagger: '2.0'
info:
  version: '1.0'
  title: NewStore address roles API
  description: NewStore public APIs
  contact:
    email: support@newstore.com
    name: NewStore API Support
    url: https://developer.newstore.com
host: dodici-demo.p.newstore.net
basePath: /
schemes:
- https
consumes:
- application/json
produces:
- application/json
security: []
tags:
- name: roles
  description: Roles
paths:
  /iam/permissions:
    get:
      description: Lists all the user permissions available for the retailer.
      summary: listPermissions
      tags:
      - roles
      operationId: listPermissions
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      parameters: []
      responses:
        default:
          description: Default response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: Returns all permissions.
          schema:
            $ref: '#/definitions/GetPermissionsResponse'
          headers: {}
        '401':
          description: Unauthorized.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal server error.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:roles:read
  /iam/roles:
    get:
      description: Lists all available user roles for the retailer. Search if the query parameter is used.
      summary: listRoles
      tags:
      - roles
      operationId: listRoles
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      parameters:
      - name: q
        in: query
        required: false
        type: string
        description: Query the resulting list by name.
      responses:
        default:
          description: Default response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: Returns all roles.
          schema:
            $ref: '#/definitions/GetRolesResponse'
          headers: {}
        '400':
          description: Bad Request, invalid query parameters.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '401':
          description: Unauthorized.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal server error.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:roles:read
    post:
      description: Creates a new role.
      summary: createRole
      tags:
      - roles
      operationId: createRole
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      consumes:
      - application/json
      parameters:
      - name: Content-Type
        in: header
        required: false
        enum:
        - application/json
        type: string
        description: ''
      - name: body
        in: body
        required: true
        description: ''
        schema:
          $ref: '#/definitions/PostRolesRequest'
      responses:
        default:
          description: Default response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '201':
          description: The role is created.
          schema:
            $ref: '#/definitions/Role'
          headers: {}
        '400':
          description: Bad Request, invalid request body.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '401':
          description: Unauthorized.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '409':
          description: The provided name is already in use.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '412':
          description: One or more permissions used were not found.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal server error.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:roles:write
  /iam/roles/{id}:
    delete:
      description: 'Deletes the user role with the specified ID.


        Once deleted, the user role is unassigned from all associated user accounts.

        '
      summary: destroyRole
      tags:
      - roles
      operationId: destroyRole
      deprecated: false
      produces:
      - application/problem+json
      parameters:
      - name: id
        in: path
        required: true
        type: string
        description: role id
      responses:
        default:
          description: Default response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '204':
          description: The deletion request was sucessful.
          headers: {}
        '401':
          description: Unauthorized.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '404':
          description: Role was not found.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '423':
          description: Cannot delete a read-only role.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal server error.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:roles:write
    get:
      description: Retrieves the user role with the specified ID.
      summary: showRole
      tags:
      - roles
      operationId: showRole
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      parameters:
      - name: id
        in: path
        required: true
        type: string
        description: role id
      responses:
        default:
          description: Default response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: ''
          schema:
            $ref: '#/definitions/Role'
          headers: {}
        '401':
          description: Unauthorized.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '404':
          description: Role not found.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal server error.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:roles:read
    put:
      description: Updates the user role with the specified ID.
      summary: replaceRole
      tags:
      - roles
      operationId: replaceRole
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      consumes:
      - application/json
      parameters:
      - name: id
        in: path
        required: true
        type: string
        description: role id
      - name: Content-Type
        in: header
        required: false
        enum:
        - application/json
        type: string
        description: ''
      - name: body
        in: body
        required: true
        description: ''
        schema:
          $ref: '#/definitions/PutRolesByIdRequest'
      responses:
        default:
          description: Default response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: The updated role.
          schema:
            $ref: '#/definitions/Role'
          headers: {}
        '400':
          description: Bad Request, invalid request body.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '401':
          description: Unauthorized.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '404':
          description: Role was not found.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '412':
          description: One or more user roles used were not found.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '423':
          description: Cannot update a read-only role.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal server error.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:roles:write
  /iam/roles/{id}/users:
    get:
      description: Retrieves all user accounts that have been assigned the specified user role.
      summary: listUsersByRole
      tags:
      - roles
      operationId: listUsersByRole
      deprecated: false
      produces:
      - application/problem+json
      - application/json
      parameters:
      - name: id
        in: path
        required: true
        type: string
        description: role id
      - name: offset
        in: query
        required: false
        default: 0
        type: integer
        format: int32
        minimum: 0.0
        maximum: 1000000.0
        exclusiveMaximum: false
        exclusiveMinimum: false
        description: The offset to be used for the resulting user account list.
      - name: count
        in: query
        required: false
        default: 25
        type: integer
        format: int32
        maximum: 50.0
        exclusiveMaximum: false
        description: The number of requested user accounts.
      responses:
        default:
          description: Default response
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '200':
          description: Returns all users by role.
          schema:
            $ref: '#/definitions/GetUsersByRoleResponse'
          headers: {}
        '400':
          description: Bad Request, invalid query parameters.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '401':
          description: Unauthorized.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '403':
          description: Forbidden.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '404':
          description: Role not found.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '429':
          description: Too Many Requests
          schema:
            $ref: '#/definitions/Problem'
          headers:
            Retry-After:
              type: string
        '500':
          description: Internal Server Error.
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '502':
          description: Bad Gateway
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
        '503':
          description: Service Unavailable
          schema:
            $ref: '#/definitions/Problem'
          headers: {}
      security:
      - oauth:
        - iam:roles:read
definitions:
  GetPermissionsResponse:
    title: GetPermissionsResponse
    description: Returns a list of available permissions the system provides.
    type: object
    properties:
      elements:
        type: array
        items:
          $ref: '#/definitions/Permission'
  Problem:
    title: Problem
    type: object
    properties:
      detail:
        description: A human readable explanation specific to this occurrence of the problem that is helpful to locate the problem and give advice on how to proceed. Written in English and readable for engineers, usually not suited for non technical stakeholders and not localized.
        example: some description for the error situation
        type: string
      error_code:
        type: string
      instance:
        description: A URI reference that identifies the specific occurrence of the problem, e.g. by adding a fragment identifier or sub-path to the problem type. May be used to locate the root of this problem in the source code.
        example: /some/uri-reference#specific-occurrence-context
        type: string
      message:
        type: string
      messages:
        type: array
        items:
          type: string
      request_id:
        type: string
      status:
        description: The HTTP status code generated by the origin server for this occurrence of the problem.
        type: integer
        minimum: 100.0
        maximum: 600.0
        exclusiveMaximum: true
        format: int32
      title:
        description: A short summary of the problem type. Written in English and readable for engineers, usually not suited for non technical stakeholders and not localized.
        example: some title for the error situation
        type: string
      type:
        description: A URI reference that uniquely identifies the problem type only in the context of the provided API. Opposed to the specification in RFC-7807, it is neither recommended to be dereferenceable and point to a human-readable documentation nor globally unique for the problem type.
        example: /some/uri-reference
        type: string
        default: about:blank
  Application:
    title: Application
    description: Abbreviation of the application this permission belongs to.
    type: string
    enum:
    - nom
    - aa
    - mcp
  Permission:
    title: Permission
    description: List of all available system permissions.
    type: object
    properties:
      application:
        type: object
        allOf:
        - $ref: '#/definitions/Application'
        - description: Abbreviation of the application this permission belongs to.
      children:
        description: Nested list of child permissions.
        type: array
        items:
          $ref: '#/definitions/Permission'
        minItems: 1
      name:
        description: Name of the permission.
        type: string
    required:
    - application
    - name
  User:
    title: User
    type: object
    properties:
      associate_id:
        description: External identifier for the NewStore plattform. Formerly known as "newstore_id".
        type: string
      created_at:
        type: string
        format: date-time
      email:
        description: Email address of the user.
        type: string
      external_directory:
        description: User is managed by an external directory.
        type: boolean
      first_name:
        description: First name of the user.
        type: string
      id:
        description: Identifier of the user.
        type: string
      is_active:
        description: Whether the user can login or not.
        type: boolean
      last_login_at:
        description: Shows last login time of the user. If user never logged in the property is not presence.
        type: string
        format: date-time
      last_name:
        description: Last name of the user.
        type: string
      phone:
        description: Telephone number of the user.
        type: string
      roles:
        description: List of roles the user is assigned to.
        type: array
        items:
          $ref: '#/definitions/RoleItem'
      updated_at:
        type: string
        format: date-time
  PostRolesRequest:
    title: PostRolesRequest
    description: Needed for granting permissions per group not individually.
    type: object
    properties:
      name:
        description: Name of the role. To be valid, it can't include slashes ('/').
        type: string
        pattern: ^[^/]+$
      permissions:
        description: List of permissions.
        type: array
        items:
          $ref: '#/definitions/Permission'
        minItems: 1
    required:
    - name
    - permissions
  PutRolesByIdRequest:
    title: PutRolesByIdRequest
    description: Needed for granting permissions per group not individually.
    type: object
    properties:
      name:
        description: Name of the role. To be valid, it can't include slashes ('/').
        type: string
        pattern: ^[^/]+$
      permissions:
        description: List of permissions.
        type: array
        items:
          $ref: '#/definitions/Permission'
        minItems: 1
    required:
    - name
    - permissions
  Role:
    title: Role
    description: Needed for granting permissions per group not individually.
    type: object
    properties:
      created_at:
        type: string
        format: date-time
      id:
        description: Identifier of the role.
        type: string
      is_readonly:
        description: The role is read-only and not editable.
        type: boolean
      name:
        description: Name of the role.
        type: string
      permissions:
        description: List of permissions which are assigned to the role.
        type: array
        items:
          $ref: '#/definitions/Permission'
      updated_at:
        type: string
        format: date-time
    required:
    - id
    - name
  GetUsersByRoleResponse:
    title: GetUsersByRoleResponse
    description: Gets all users by role
    type: object
    properties:
      elements:
        type: array
        items:
          $ref: '#/definitions/User'
  RoleItem:
    title: RoleItem
    description: Needed for granting permissions per group not individually.
    type: object
    properties:
      id:
        description: Identifier of the role.
        type: string
      is_readonly:
        description: The role is read-only and not editable.
        type: boolean
      name:
        description: Name of the role.
        type: string
      updated_at:
        type: string
        format: date-time
    required:
    - id
    - name
  GetRolesResponse:
    title: GetRolesResponse
    description: Returns a list of roles.
    type: object
    properties:
      elements:
        type: array
        items:
          $ref: '#/definitions/RoleItem'
securityDefinitions:
  oauth:
    type: oauth2
    flow: application
    tokenUrl: https://id.p.newstore.net/auth/realms/dodici-demo/protocol/openid-connect/token
    scopes:
      catalog:import-schemas:read: Grants privileges to read import schema
      catalog:import-schemas:write: Grants privileges to write import schema
      catalog:pricebook-export:read: Grants privileges to export pricebook data
      catalog:product-export:read: Grants privileges to export product data
      checkout:carts:read: Grants privileges to read cart data
      checkout:carts:write: Grants privileges to write cart data
      clienteling:profile:read: Grants privileges to read clienteling profiles
      customer:profile:read: Grants privileges to read API customer data
      customer:profile:write: Grants privileges to modify API customer data
      newstore:configuration:read: Grants privileges to read configuration
      newstore:configuration:write: Grants privileges to write configuration
      fiscalization:orders:read: View orders with fiscal transactions and signatures
      fiscalization:orders:write: Create orders with fiscal transactions and signatures
      shipments:read: Read Shipping Options and Audits
      iam:providers:read: ' Grants read privileges to provider resources'
      iam:providers:write: ' Grants write privileges to provider resources'
      iam:roles:read: ' Grants privileges to read roles data'
      iam:roles:write: ' Grants privileges to write roles data'
      iam:users:read: ' Grants privileges to read user data'
      iam:users:write: ' Grants privileges to write user data'
      inventory:reservations:read: Allows access to retrieve reservations
      inventory:reservations:write: Allows access to create and update reservations
      promotions:config:read: Grants privileges to read configuration
      promotions:config:write: Grants privileges to write into configuration
      promotions:reason-codes:read: Grants privileges to list reason codes
      promotions:reason-codes:write: Grants privileges to create and update reason codes
      audit-events:read: Grants read access to the tenant's audit events.
      taxes:preview-transactions:write: Preview tax transactions
      taxes:transactions:read: Read tax transactions