OpenProject Principals API

Principals are the superclass of users, groups and placeholder users. This endpoint returns all principals within a joined collection but can be filtered to e.g. only return groups or users.

OpenAPI Specification

openproject-principals-api-openapi.yml Raw ↑
openapi: 3.1.2
info:
  description: "You're looking at the current **stable** documentation of the OpenProject APIv3. If you're interested in the current\ndevelopment version, please go to [github.com/opf](https://github.com/opf/openproject/tree/dev/docs/api/apiv3).\n\n## Introduction\n\nThe documentation for the APIv3 is written according to the [OpenAPI 3.1 Specification](https://swagger.io/specification/).\nYou can either view the static version of this documentation on the [website](https://www.openproject.org/docs/api/introduction/)\nor the interactive version, rendered with [OpenAPI Explorer](https://github.com/Rhosys/openapi-explorer/blob/main/README.md),\nin your OpenProject installation under `/api/docs`.\nIn the latter you can try out the various API endpoints directly interacting with our OpenProject data.\nMoreover you can access the specification source itself under `/api/v3/spec.json` and `/api/v3/spec.yml`\n(e.g. [here](https://community.openproject.org/api/v3/spec.yml)).\n\nThe APIv3 is a hypermedia REST API, a shorthand for \"Hypermedia As The Engine Of Application State\" (HATEOAS).\nThis means that each endpoint of this API will have links to other resources or actions defined in the resulting body.\n\nThese related resources and actions for any given resource will be context sensitive. For example, only actions that the\nauthenticated user can take are being rendered. This can be used to dynamically identify actions that the user might take for any\ngiven response.\n\nAs an example, if you fetch a work package through the [Work Package endpoint](https://www.openproject.org/docs/api/endpoints/work-packages/), the `update` link will only\nbe present when the user you authenticated has been granted a permission to update the work package in the assigned project.\n\n## HAL+JSON\n\nHAL is a simple format that gives a consistent and easy way to hyperlink between resources in your API.\nRead more in the following specification: [https://tools.ietf.org/html/draft-kelly-json-hal-08](https://tools.ietf.org/html/draft-kelly-json-hal-08)\n\n**OpenProject API implementation of HAL+JSON format** enriches JSON and introduces a few meta properties:\n\n- `_type` - specifies the type of the resource (e.g.: WorkPackage, Project)\n- `_links` - contains all related resource and action links available for the resource\n- `_embedded` - contains all embedded objects\n\nHAL does not guarantee that embedded resources are embedded in their full representation, they might as well be\npartially represented (e.g. some properties can be left out).\nHowever in this API you have the guarantee that whenever a resource is **embedded**, it is embedded in its **full representation**.\n\n## API response structure\n\nAll API responses contain a single HAL+JSON object, even collections of objects are technically represented by\na single HAL+JSON object that itself contains its members. More details on collections can be found\nin the [Collections Section](https://www.openproject.org/docs/api/collections/).\n\n## Authentication\n\nThe API supports the following authentication schemes:\n\n* Session-based authentication\n* API tokens\n    * passed as Bearer token\n    * passed via Basic auth\n* OAuth 2.0\n    * using built-in authorization server\n    * using an external authorization server (RFC 9068)\n\nDepending on the settings of the OpenProject instance many resources can be accessed without being authenticated.\nIn case the instance requires authentication on all requests the client will receive an **HTTP 401** status code\nin response to any request.\n\nOtherwise unauthenticated clients have all the permissions of the anonymous user.\n\n### Session-based authentication\n\nThis means you have to login to OpenProject via the Web-Interface to be authenticated in the API.\nThis method is well-suited for clients acting within the browser, like the Angular-Client built into OpenProject.\n\nIn this case, you always need to pass the HTTP header `X-Requested-With \"XMLHttpRequest\"` for authentication.\n\n### API token as bearer token\n\nUsers can authenticate towards the API v3 using an API token as a bearer token.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42\n```\n\nUsers can generate API tokens on their account page.\n\n### API token through Basic Auth\n\nAPI tokens can also be used with basic auth, using the user name `apikey` (NOT your login) and the API token as the password.\n\nFor example:\n\n```shell\nAPI_KEY=opapi-2519132cdf62dcf5a66fd96394672079f9e9cad1\ncurl -u apikey:$API_KEY https://community.openproject.org/api/v3/users/42\n```\n\n### OAuth 2.0 authentication\n\nOpenProject allows authentication and authorization with OAuth2 with *Authorization code flow*, as well as *Client credentials* operation modes.\n\nTo get started, you first need to register an application in the OpenProject OAuth administration section of your installation.\nThis will save an entry for your application with a client unique identifier (`client_id`) and an accompanying secret key (`client_secret`).\n\nYou can then use one the following guides to perform the supported OAuth 2.0 flows:\n\n- [Authorization code flow](https://oauth.net/2/grant-types/authorization-code)\n\n- [Authorization code flow with PKCE](https://doorkeeper.gitbook.io/guides/ruby-on-rails/pkce-flow), recommended for clients unable to keep the client_secret confidential\n\n- [Client credentials](https://oauth.net/2/grant-types/client-credentials/) - Requires an application to be bound to an impersonating user for non-public access\n\n### OAuth 2.0 using an external authorization server\n\nThere is a possibility to use JSON Web Tokens (JWT) generated by an OIDC provider configured in OpenProject as a bearer token to do authenticated requests against the API.\nThe following requirements must be met:\n\n- OIDC provider must be configured in OpenProject with **jwks_uri**\n- JWT must be signed using RSA algorithm\n- JWT **iss** claim must be equal to OIDC provider **issuer**\n- JWT **aud** claim must contain the OpenProject **client ID** used at the OIDC provider\n- JWT **scope** claim must include a valid scope to access the desired API (e.g. `api_v3` for APIv3)\n- JWT must be actual (neither expired or too early to be used)\n- JWT must be passed in Authorization header like: `Authorization: Bearer {jwt}`\n- User from **sub** claim must be linked to OpenProject before (e.g. by logging in), otherwise it will be not authenticated\n\nIn more general terms, OpenProject should be compliant to [RFC 9068](https://www.rfc-editor.org/rfc/rfc9068) when validating access tokens.\n\n### Why not username and password?\n\nThe simplest way to do basic auth would be to use a user's username and password naturally.\nHowever, OpenProject already has supported API keys in the past for the API v2, though not through basic auth.\n\nUsing **username and password** directly would have some advantages:\n\n* It is intuitive for the user who then just has to provide those just as they would when logging into OpenProject.\n\n* No extra logic for token management necessary.\n\nOn the other hand using **API keys** has some advantages too, which is why we went for that:\n\n* If compromised while saved on an insecure client the user only has to regenerate the API key instead of changing their password, too.\n\n* They are naturally long and random which makes them invulnerable to dictionary attacks and harder to crack in general.\n\nMost importantly users may not actually have a password to begin with. Specifically when they have registered\nthrough an OpenID Connect provider.\n\n## Cross-Origin Resource Sharing (CORS)\n\nBy default, the OpenProject API is _not_ responding with any CORS headers.\nIf you want to allow cross-domain AJAX calls against your OpenProject instance, you need to enable CORS headers being returned.\n\nPlease see [our API settings documentation](https://www.openproject.org/docs/system-admin-guide/api-and-webhooks/) on\nhow to selectively enable CORS.\n\n## Allowed HTTP methods\n\n- `GET` - Get a single resource or collection of resources\n\n- `POST` - Create a new resource or perform\n\n- `PATCH` - Update a resource\n\n- `DELETE` - Delete a resource\n\n## Compression\n\nResponses are compressed if requested by the client. Currently [gzip](https://www.gzip.org/) and [deflate](https://tools.ietf.org/html/rfc1951)\nare supported. The client signals the desired compression by setting the [`Accept-Encoding` header](https://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.3).\nIf no `Accept-Encoding` header is send, `Accept-Encoding: identity` is assumed which will result in the API responding uncompressed."
  title: OpenProject API V3 (Stable) Actions & Capabilities Principals API
  version: '3'
servers:
- url: https://qa.openproject-edge.com
  description: Edge QA instance
- url: https://qa.openproject-stage.com
  description: Staging instance
- url: https://community.openproject.org
  description: Community instance
security:
- BasicAuth: []
tags:
- description: 'Principals are the superclass of users, groups and placeholder users. This endpoint returns all principals

    within a joined collection but can be filtered to e.g. only return groups or users.'
  name: Principals
paths:
  /api/v3/placeholder_users:
    get:
      summary: List placehoder users
      operationId: list_placeholder_users
      tags:
      - Principals
      description: 'List all placeholder users. This can only be accessed if the requesting user has the global permission

        `manage_placeholder_user` or `manage_members` in any project.'
      parameters:
      - name: filters
        description: 'JSON specifying filter conditions.

          Accepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/) endpoint.

          Currently supported filters are:


          - name: filters placeholder users by the name.

          - group: filters placeholder by the group it is contained in.

          - status: filters placeholder by the status it has.'
        in: query
        required: false
        schema:
          type: string
        example: '[{ "name": { "operator": "~", "values": ["Darth"] } }]'
      - name: select
        description: Comma separated list of properties to include.
        in: query
        required: false
        schema:
          type: string
        example: total,elements/name,elements/self,self
      responses:
        '200':
          description: OK
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/PrincipalCollectionModel'
        '400':
          description: Returned if the client sends invalid request parameters e.g. filters
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:InvalidQuery
                message: Filters Invalid filter does not exist.
    post:
      summary: Create placeholder user
      operationId: create_placeholder_user
      tags:
      - Principals
      description: 'Creates a new placeholder user. Only administrators and users with `manage_placeholder_user` global permission are

        allowed to do so. When calling this endpoint the client provides a single object, containing at least the

        properties and links that are required, in the body.'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PlaceholderUserCreateModel'
      responses:
        '201':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/PlaceholderUserModel'
          description: Created
        '400':
          $ref: '#/components/responses/InvalidRequestBody'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not allowed to create new placeholder users.
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** Administrator'
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
        '422':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _embedded:
                  details:
                    attribute: name
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
                message: Name has already been taken.
          description: 'Returned if:


            * a constraint for a property was violated (`PropertyConstraintViolation`)'
  /api/v3/placeholder_users/{id}:
    delete:
      summary: Delete placeholder user
      operationId: delete_placeholder_user
      description: Set the specified placeholder user to deleted status.
      tags:
      - Principals
      parameters:
      - description: Placeholder user id
        example: 1
        in: path
        name: id
        required: true
        schema:
          type: integer
      responses:
        '202':
          description: 'Returned if the group was marked for deletion.


            Note that the response body is empty as of now. In future versions of the API a body

            *might* be returned, indicating the progress of deletion.'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not allowed to delete the account of this user.
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** `manage_placeholder_users`'
        '404':
          description: Returned if the placeholder user does not exist.
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The specified placeholder user does not exist.
    get:
      summary: View placeholder user
      operationId: view_placeholder_user
      description: Return the placeholder user resource.
      tags:
      - Principals
      parameters:
      - description: The placeholder user id
        example: 1
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/PlaceholderUserModel'
              examples:
                placeholder user response:
                  $ref: '#/components/examples/PlaceholderUserResponse'
          description: OK
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The specified placeholder user does not exist or you do not have permission to view them.
          description: 'Returned if the user does not exist or if the API user does not have permission to view them.


            **Required permission**: `manage_placeholder_users`'
    patch:
      summary: Update placeholder user
      operationId: update_placeholder_user
      tags:
      - Principals
      description: 'Updates the placeholder user''s writable attributes.

        When calling this endpoint the client provides a single object, containing at least the properties and links

        that are required, in the body.'
      parameters:
      - description: Placeholder user id
        example: 1
        in: path
        name: id
        required: true
        schema:
          type: integer
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PlaceholderUserCreateModel'
      responses:
        '200':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/PlaceholderUserModel'
          description: OK
        '400':
          $ref: '#/components/responses/InvalidRequestBody'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not allowed to update the account of this user.
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission**: `manage_placeholder_users`'
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The specified placeholder user does not exist.
          description: Returned if the placeholder user does not exist.
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
        '422':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _embedded:
                  details:
                    attribute: name
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
                message: Name has already been taken.
          description: 'Returned if:


            - the client tries to modify a read-only property (`PropertyIsReadOnly`)

            - a constraint for a property was violated (`PropertyConstraintViolation`)'
  /api/v3/principals:
    get:
      summary: List principals
      operationId: list_principals
      tags:
      - Principals
      description: 'List all principals. The client can choose to filter the principals similar to how work packages are filtered. In

        addition to the provided filters, the server will reduce the result set to only contain principals who are members

        in projects the client is allowed to see.'
      parameters:
      - name: filters
        description: 'JSON specifying filter conditions.

          Accepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/) endpoint.

          Currently supported filters are:


          - type: filters principals by their type (*User*, *Group*, *PlaceholderUser*).

          - member: filters principals by the projects they are members in.

          - name: filters principals by the user or group name.

          - any_name_attribute: filters principals by the user or group first- and last name, email or login.

          - status: filters principals by their status number (active = *1*, registered = *2*, locked = *3*, invited = *4*)'
        in: query
        required: false
        schema:
          type: string
        example: '[{ "type": { "operator": "=", "values": ["User"] } }]'
      - name: select
        description: Comma separated list of properties to include.
        in: query
        required: false
        schema:
          type: string
        example: total,elements/name,elements/self,self
      responses:
        '200':
          description: OK
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/PrincipalCollectionModel'
        '400':
          description: Returned if the client sends invalid request parameters e.g. filters
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:InvalidQuery
                message: Filters Invalid filter does not exist.
  /api/v3/users:
    get:
      summary: List Users
      operationId: list_Users
      description: 'Lists users. Only administrators or users with the following global permission can access this resource:

        - `manage_user`'
      tags:
      - Principals
      parameters:
      - description: Page number inside the requested collection.
        example: '25'
        in: query
        name: offset
        required: false
        schema:
          default: 1
          type: integer
      - description: Number of elements to display per page.
        example: '25'
        in: query
        name: pageSize
        required: false
        schema:
          type: integer
      - description: 'JSON specifying filter conditions.

          Accepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/)

          endpoint. Currently supported filters are:


          + status: Status the user has


          + group: Name of the group in which to-be-listed users are members.


          + name: Filter users in whose first or last names, or email addresses the given string occurs.


          + login: User''s login'
        example: '[{ "status": { "operator": "=", "values": ["invited"] } }, { "group": { "operator": "=", "values": ["1"] } }, { "name": { "operator": "=", "values": ["h.wurst@openproject.com"] } }]'
        in: query
        name: filters
        required: false
        schema:
          type: string
      - description: 'JSON specifying sort criteria.

          Accepts the same format as returned by the [queries](https://www.openproject.org/docs/api/endpoints/queries/) endpoint.'
        example: '[["status", "asc"]]'
        in: query
        name: sortBy
        required: false
        schema:
          type: string
      - description: Comma separated list of properties to include.
        example: total,elements/name,elements/self,self
        in: query
        name: select
        required: false
        schema:
          type: string
      responses:
        '200':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/UserCollectionModel'
          description: OK
        '400':
          $ref: '#/components/responses/InvalidRequestBody'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not allowed to list users.
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** Administrator or any of: ''manage_members'', ''manage_user'', ''share_work_packages''.'
    post:
      summary: Create User
      operationId: create_user
      tags:
      - Principals
      description: 'Creates a new user. Only administrators and users with manage_user global permission are allowed to do so.

        When calling this endpoint the client provides a single object, containing at least the properties and links that are required, in the body.


        Valid values for `status`:


        1) "active" - In this case a password has to be provided in addition to the other attributes.


        2) "invited" - In this case nothing but the email address is required. The rest is optional. An invitation will be sent to the user.'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserCreateModel'
      responses:
        '201':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/UserModel'
          description: Created
        '400':
          $ref: '#/components/responses/InvalidRequestBody'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not allowed to create new users.
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** Administrator'
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
        '422':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _embedded:
                  details:
                    attribute: email
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
                message: The email address is already taken.
          description: 'Returned if:


            * a constraint for a property was violated (`PropertyConstraintViolation`)'
  /api/v3/users/{id}:
    delete:
      summary: Delete user
      operationId: delete_user
      description: Permanently deletes the specified user account.
      tags:
      - Principals
      parameters:
      - description: User id. Use `me` to reference current user, if any.
        example: 1
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '202':
          description: 'Returned if the account was deleted successfully.


            Note that the response body is empty as of now. In future versions of the API a body

            *might* be returned, indicating the progress of deletion.'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not allowed to delete the account of this user.
          description: 'Returned if the client does not have sufficient permissions or if deletion of users was disabled in the instance wide settings.


            **Required permission:** Administrators only (exception: users might be able to delete their own accounts)'
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The specified user does not exist.
          description: Returned if the user does not exist.
    get:
      summary: View user
      operationId: view_user
      description: ''
      tags:
      - Principals
      parameters:
      - description: User id. Use `me` to reference current user, if any.
        example: 1
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/UserModel'
              examples:
                user response:
                  $ref: '#/components/examples/UserResponse'
          description: OK
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The specified user does not exist or you do not have permission to view them.
          description: 'Returned if the user does not exist or if the API user does not have permission to view them.


            **Required permission** The user needs to be locked in if the installation is configured to prevent anonymous access'
    patch:
      summary: Update user
      operationId: update_user
      tags:
      - Principals
      description: 'Updates the user''s writable attributes.

        When calling this endpoint the client provides a single object, containing at least the properties and links that are required, in the body.


        Password updates for self-service account changes require both `password` and `currentPassword`.'
      parameters:
      - description: User id. Use `me` to reference current user, if any.
        example: 1
        in: path
        name: id
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserCreateModel'
      responses:
        '200':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/UserModel'
          description: OK
        '400':
          $ref: '#/components/responses/InvalidRequestBody'
        '403':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:MissingPermission
                message: You are not allowed to update the account of this user.
          description: 'Returned if the client does not have sufficient permissions.


            **Required permission:** Administrators, manage_user global permission'
        '404':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _type: Error
                errorIdentifier: urn:openproject-org:api:v3:errors:NotFound
                message: The specified user does not exist or you do not have permission to view them.
          description: 'Returned if the user does not exist or if the API user does not have the necessary permissions to update it.


            **Required permission:** Administrators only (exception: users may update their own accounts)'
        '406':
          $ref: '#/components/responses/MissingContentType'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
        '422':
          content:
            application/hal+json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                email constraint violation:
                  value:
                    _embedded:
                      details:
                        attribute: email
                    _type: Error
                    errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
                    message: The email address is already taken.
                invalid current password:
                  value:
                    _embedded:
                      details:
                        attribute: currentPassword
                    _type: Error
                    errorIdentifier: urn:openproject-org:api:v3:errors:PropertyConstraintViolation
                    message: Current password is invalid.
          description: 'Returned if:


            * the client tries to modify a read-only property (`PropertyIsReadOnly`)


            * a constraint for a property was violated (`PropertyConstraintViolation`)'
components:
  schemas:
    CollectionModel:
 

# --- truncated at 32 KB (52 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/openproject/refs/heads/main/openapi/openproject-principals-api-openapi.yml