Canvas · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Canvas LMS REST Content Security Policy Settings API

9 actions 9 updates phrasing extends openapi/canvas-content-security-policy-settings-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Canvas's API. It is a proposal applied on top of the contract, not a document Canvas publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 9

$.info
$.paths['/v1/courses/{course_id}/csp_settings'].get
$.paths['/v1/courses/{course_id}/csp_settings'].put
$.paths['/v1/accounts/{account_id}/csp_settings'].get
$.paths['/v1/accounts/{account_id}/csp_settings'].put
$.paths['/v1/accounts/{account_id}/csp_settings/lock'].put
$.paths['/v1/accounts/{account_id}/csp_settings/domains'].post
$.paths['/v1/accounts/{account_id}/csp_settings/domains'].delete
$.paths['/v1/accounts/{account_id}/csp_settings/domains/batch_create'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Canvas LMS REST Content Security Policy Settings API
  version: 1.0.0
extends: openapi/canvas-content-security-policy-settings-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 8
- target: $.paths['/v1/courses/{course_id}/csp_settings'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a course's content security policy settings
      effect: read
      questions:
      - Is the content security policy enabled for my course?
      - Does a course inherit its CSP setting from its parent account?
      instructions:
      - text: Get the CSP settings for course {course_id}.
        slots:
          course_id: path.course_id
      - text: Show whether content security policy is on for course {course_id}.
        slots:
          course_id: path.course_id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/v1/courses/{course_id}/csp_settings'].put
  update:
    x-apievangelist-phrasing:
      intent: Turn a course's CSP on, off or back to inherited
      effect: write
      questions:
      - How do I turn off the content security policy for one course?
      - Can a course go back to using its account's CSP setting?
      instructions:
      - text: Set the CSP status of course {course_id} to {status}.
        slots:
          course_id: path.course_id
          status: requestBody.status
      - text: Make course {course_id} inherit the content security policy from its account.
        slots:
          course_id: path.course_id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/v1/accounts/{account_id}/csp_settings'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an account's content security policy settings
      effect: read
      questions:
      - What CSP settings and allowed domains does my account have?
      - Are an account's content security policy settings locked for sub-accounts?
      instructions:
      - text: Get the CSP settings for account {account_id}.
        slots:
          account_id: path.account_id
      - text: Show account {account_id}'s content security policy and its allowed domains.
        slots:
          account_id: path.account_id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/v1/accounts/{account_id}/csp_settings'].put
  update:
    x-apievangelist-phrasing:
      intent: Turn an account's CSP on, off or back to inherited
      effect: write
      questions:
      - How do I enable the content security policy for an account and its sub-accounts?
      - Can a sub-account clear its explicit CSP setting and inherit from the parent?
      instructions:
      - text: Set the CSP status of account {account_id} to {status}.
        slots:
          account_id: path.account_id
          status: requestBody.status
      - text: Explicitly enable content security policy on account {account_id}.
        slots:
          account_id: path.account_id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/v1/accounts/{account_id}/csp_settings/lock'].put
  update:
    x-apievangelist-phrasing:
      intent: Lock CSP settings for sub-accounts and courses
      effect: write
      questions:
      - Can I stop sub-accounts and courses from changing the CSP setting I chose?
      - Why can't I lock CSP settings when my account inherits them?
      instructions:
      - text: Set CSP settings lock on account {account_id} to {settings_locked}.
        slots:
          account_id: path.account_id
          settings_locked: requestBody.settings_locked
      - text: Lock account {account_id}'s content security policy so sub-accounts and courses cannot override it.
        slots:
          account_id: path.account_id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/v1/accounts/{account_id}/csp_settings/domains'].post
  update:
    x-apievangelist-phrasing:
      intent: Allow a domain in an account's CSP
      effect: write
      questions:
      - How do I whitelist a domain so it can load under the account content security policy?
      - Will an allowed domain take effect if CSP isn't explicitly enabled?
      instructions:
      - text: Add {domain} to the allowed CSP domains for account {account_id}.
        slots:
          domain: requestBody.domain
          account_id: path.account_id
      - text: Allow content from {domain} in account {account_id}.
        slots:
          domain: requestBody.domain
          account_id: path.account_id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/v1/accounts/{account_id}/csp_settings/domains'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove an allowed domain from an account's CSP
      effect: destructive
      questions:
      - How do I take a domain off my account's CSP allow list?
      - Can I revoke a previously allowed CSP domain?
      instructions:
      - text: Remove {domain} from the allowed CSP domains of account {account_id}.
        slots:
          domain: query.domain
          account_id: path.account_id
      - text: Stop allowing {domain} under account {account_id}'s content security policy.
        slots:
          domain: query.domain
          account_id: path.account_id
      method: generated
      generated: '2026-10-01'
- target: $.paths['/v1/accounts/{account_id}/csp_settings/domains/batch_create'].post
  update:
    x-apievangelist-phrasing:
      intent: Allow several domains in an account's CSP at once
      effect: write
      questions:
      - Can I add a whole list of domains to the CSP allow list in one request?
      - Is there a batch way to whitelist several domains for an account?
      instructions:
      - text: Add domains {domains} to account {account_id}'s CSP allow list in one batch.
        slots:
          domains: requestBody.domains
          account_id: path.account_id
      - text: 'Batch allow these domains for account {account_id}: {domains}.'
        slots:
          account_id: path.account_id
          domains: requestBody.domains
      method: generated
      generated: '2026-10-01'