Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions code/API_definitions/esim-remote-management.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@


<!-- CAMARA:MANDATORY:authorization-and-authentication:BEGIN -->

# Authorization and authentication

The "Camara Security and Interoperability Profile" provides details of how an API consumer requests an access token. Please refer to Identity and Consent Management (https://github.com/camaraproject/IdentityAndConsentManagement/) for the released version of the profile.
Expand All @@ -30,6 +31,7 @@
In cases where personal data is processed by the API and users can exercise their rights through mechanisms such as opt-in and/or opt-out, the use of three-legged access tokens is mandatory. This ensures that the API remains in compliance with privacy regulations, upholding the principles of transparency and user-centric privacy-by-design.
<!-- CAMARA:MANDATORY:authorization-and-authentication:END -->
<!-- CAMARA:MANDATORY:identifying-device-from-access-token:BEGIN -->

# Identifying the device from the access token

This API requires the API consumer to identify a device as the subject of the API as follows:
Expand All @@ -41,11 +43,12 @@
## Error handling:

- If the subject cannot be identified from the access token and the optional `device` object is not included in the request, then the server will return an error with the `422 MISSING_IDENTIFIER` error code.

Check notice on line 46 in code/API_definitions/esim-remote-management.yaml

View workflow job for this annotation

GitHub Actions / validation / Validate

info.description mandatory template content drift

[P-027] info.description template 'additional-error-responses' has drifted from canonical at paragraph 3. canonical: Please refer to the `CAMARA_common.yaml` of the Commonalities Release associated to this API version for a complete list of error responses. The applicable C... found: Please refer to the `CAMARA_common.yaml` of the Commonalities Release associated to this API version for a complete list of error responses. The applicable C... Re-copy the BEGIN..END block from 'code/common/info-description-templates.yaml'. | Suggestion: Re-copy the BEGIN..END block from code/common/info-description-templates.yaml to replace the drifted content; the message identifies the first differing paragraph.
- If the subject can be identified from the access token and the optional `device` object is also included in the request, then the server will return an error with the `422 UNNECESSARY_IDENTIFIER` error code. This will be the case even if the same device is identified by these two methods, as the server is unable to make this comparison.
<!-- CAMARA:MANDATORY:identifying-device-from-access-token:END -->

<!-- CAMARA:MANDATORY:additional-error-responses:BEGIN -->

# Additional CAMARA error responses

The list of error codes in this API specification is not exhaustive. Therefore the API specification MAY not document some non-mandatory error statuses as indicated in `CAMARA API Design Guide`.
Expand All @@ -56,6 +59,7 @@
<!-- CAMARA:MANDATORY:additional-error-responses:END -->

<!-- CAMARA:MANDATORY:request-body-strictness:BEGIN -->

# Request body strictness

This API rejects requests with JSON request bodies that contain properties not declared in this specification, at any nesting level. Unknown properties result in a `400 INVALID_ARGUMENT` response.
Expand Down
Loading