Class: Zyphr::AuthApplicationApi
- Inherits:
-
Object
- Object
- Zyphr::AuthApplicationApi
- Defined in:
- lib/zyphr/api/auth_application_api.rb
Instance Attribute Summary collapse
-
#api_client ⇒ Object
Returns the value of attribute api_client.
Instance Method Summary collapse
-
#export_end_user_data(id, user_id, opts = {}) ⇒ nil
Export all data held about an end user Returns a machine-readable JSON bundle of everything stored about one end user, for answering a GDPR Art.
-
#export_end_user_data_with_http_info(id, user_id, opts = {}) ⇒ Array<(nil, Integer, Hash)>
Export all data held about an end user Returns a machine-readable JSON bundle of everything stored about one end user, for answering a GDPR Art.
-
#get_self_application(opts = {}) ⇒ ApplicationSelfResponse
Get the authenticating application Return non-sensitive metadata about the application whose credentials authenticated this request.
-
#get_self_application_with_http_info(opts = {}) ⇒ Array<(ApplicationSelfResponse, Integer, Hash)>
Get the authenticating application Return non-sensitive metadata about the application whose credentials authenticated this request.
-
#initialize(api_client = ApiClient.default) ⇒ AuthApplicationApi
constructor
A new instance of AuthApplicationApi.
-
#set_self_application_test_recipients(set_self_application_test_recipients_request, opts = {}) ⇒ ApplicationSelfResponse
Set the authenticating application's auth-email test allowlist Set
test_recipients— the per-application auth-email allowlist — on the application whose credentials authenticated this request. -
#set_self_application_test_recipients_with_http_info(set_self_application_test_recipients_request, opts = {}) ⇒ Array<(ApplicationSelfResponse, Integer, Hash)>
Set the authenticating application's auth-email test allowlist Set `test_recipients` — the per-application auth-email allowlist — on the application whose credentials authenticated this request.
Constructor Details
#initialize(api_client = ApiClient.default) ⇒ AuthApplicationApi
Returns a new instance of AuthApplicationApi.
19 20 21 |
# File 'lib/zyphr/api/auth_application_api.rb', line 19 def initialize(api_client = ApiClient.default) @api_client = api_client end |
Instance Attribute Details
#api_client ⇒ Object
Returns the value of attribute api_client.
17 18 19 |
# File 'lib/zyphr/api/auth_application_api.rb', line 17 def api_client @api_client end |
Instance Method Details
#export_end_user_data(id, user_id, opts = {}) ⇒ nil
Export all data held about an end user
Returns a machine-readable JSON bundle of everything stored about one end user, for answering a GDPR Art. 15 (access) or Art. 20 (portability) request. Zyphr is a processor: we do not answer data subjects directly. This endpoint gives you, the controller, the data needed to respond to your own end user. Credentials are deliberately excluded and are listed in export_metadata.excluded: password hashes, session refresh-token hashes, MFA secrets, OAuth access/refresh tokens and WebAuthn public keys. These are authentication artifacts rather than personal data about the subject, and including them would turn this endpoint into a credential-exfiltration path. Message history is capped at the 1,000 most recent messages; export_metadata.message_history_truncated reports whether the cap was hit.
28 29 30 31 |
# File 'lib/zyphr/api/auth_application_api.rb', line 28 def export_end_user_data(id, user_id, opts = {}) export_end_user_data_with_http_info(id, user_id, opts) nil end |
#export_end_user_data_with_http_info(id, user_id, opts = {}) ⇒ Array<(nil, Integer, Hash)>
Export all data held about an end user Returns a machine-readable JSON bundle of everything stored about one end user, for answering a GDPR Art. 15 (access) or Art. 20 (portability) request. Zyphr is a processor: we do not answer data subjects directly. This endpoint gives you, the controller, the data needed to respond to your own end user. Credentials are deliberately excluded and are listed in `export_metadata.excluded`: password hashes, session refresh-token hashes, MFA secrets, OAuth access/refresh tokens and WebAuthn public keys. These are authentication artifacts rather than personal data about the subject, and including them would turn this endpoint into a credential-exfiltration path. Message history is capped at the 1,000 most recent messages; `export_metadata.message_history_truncated` reports whether the cap was hit.
39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 |
# File 'lib/zyphr/api/auth_application_api.rb', line 39 def export_end_user_data_with_http_info(id, user_id, opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AuthApplicationApi.export_end_user_data ...' end # verify the required parameter 'id' is set if @api_client.config.client_side_validation && id.nil? fail ArgumentError, "Missing the required parameter 'id' when calling AuthApplicationApi.export_end_user_data" end # verify the required parameter 'user_id' is set if @api_client.config.client_side_validation && user_id.nil? fail ArgumentError, "Missing the required parameter 'user_id' when calling AuthApplicationApi.export_end_user_data" end # resource path local_var_path = '/v1/applications/{id}/users/{userId}/export'.sub('{' + 'id' + '}', CGI.escape(id.to_s)).sub('{' + 'userId' + '}', CGI.escape(user_id.to_s)) # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] # return_type return_type = opts[:debug_return_type] # auth_names auth_names = opts[:debug_auth_names] || [] = opts.merge( :operation => :"AuthApplicationApi.export_end_user_data", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:GET, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AuthApplicationApi#export_end_user_data\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |
#get_self_application(opts = {}) ⇒ ApplicationSelfResponse
Get the authenticating application Return non-sensitive metadata about the application whose credentials authenticated this request. Lets an integrator read their own application_id (the sole tenant discriminator embedded in every end-user token) directly from the API, rather than only from the dashboard UI or by decoding a token. Returns only id, name, the calling environment's mode, and the JWT signing algorithm — never secrets, signing keys, or account-internal fields.
93 94 95 96 |
# File 'lib/zyphr/api/auth_application_api.rb', line 93 def get_self_application(opts = {}) data, _status_code, _headers = get_self_application_with_http_info(opts) data end |
#get_self_application_with_http_info(opts = {}) ⇒ Array<(ApplicationSelfResponse, Integer, Hash)>
Get the authenticating application Return non-sensitive metadata about the application whose credentials authenticated this request. Lets an integrator read their own application_id (the sole tenant discriminator embedded in every end-user token) directly from the API, rather than only from the dashboard UI or by decoding a token. Returns only id, name, the calling environment's mode, and the JWT signing algorithm — never secrets, signing keys, or account-internal fields.
102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 |
# File 'lib/zyphr/api/auth_application_api.rb', line 102 def get_self_application_with_http_info(opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AuthApplicationApi.get_self_application ...' end # resource path local_var_path = '/auth/application' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json']) unless header_params['Accept'] # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] # return_type return_type = opts[:debug_return_type] || 'ApplicationSelfResponse' # auth_names auth_names = opts[:debug_auth_names] || ['ApplicationSecret', 'ApplicationPublicKey'] = opts.merge( :operation => :"AuthApplicationApi.get_self_application", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:GET, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AuthApplicationApi#get_self_application\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |
#set_self_application_test_recipients(set_self_application_test_recipients_request, opts = {}) ⇒ ApplicationSelfResponse
Set the authenticating application's auth-email test allowlist
Set test_recipients — the per-application auth-email allowlist — on the application whose credentials authenticated this request. When non-empty, this allowlist gates ALL auth emails (only listed addresses receive them); an EMPTY array clears it and disables the gate. Lets an integrator manage the allowlist from their own infrastructure config instead of the dashboard. Application-SECRET scoped (server-side write): requires X-Application-Key AND X-Application-Secret. Mutates ONLY the authenticating application — it never takes an application id from the request, so there is no cross-tenant write path. The response mirrors GET /auth/application exactly (never returns secrets).
151 152 153 154 |
# File 'lib/zyphr/api/auth_application_api.rb', line 151 def set_self_application_test_recipients(set_self_application_test_recipients_request, opts = {}) data, _status_code, _headers = set_self_application_test_recipients_with_http_info(set_self_application_test_recipients_request, opts) data end |
#set_self_application_test_recipients_with_http_info(set_self_application_test_recipients_request, opts = {}) ⇒ Array<(ApplicationSelfResponse, Integer, Hash)>
Set the authenticating application's auth-email test allowlist Set `test_recipients` — the per-application auth-email allowlist — on the application whose credentials authenticated this request. When non-empty, this allowlist gates ALL auth emails (only listed addresses receive them); an EMPTY array clears it and disables the gate. Lets an integrator manage the allowlist from their own infrastructure config instead of the dashboard. Application-SECRET scoped (server-side write): requires X-Application-Key AND X-Application-Secret. Mutates ONLY the authenticating application — it never takes an application id from the request, so there is no cross-tenant write path. The response mirrors GET /auth/application exactly (never returns secrets).
161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 |
# File 'lib/zyphr/api/auth_application_api.rb', line 161 def set_self_application_test_recipients_with_http_info(set_self_application_test_recipients_request, opts = {}) if @api_client.config.debugging @api_client.config.logger.debug 'Calling API: AuthApplicationApi.set_self_application_test_recipients ...' end # verify the required parameter 'set_self_application_test_recipients_request' is set if @api_client.config.client_side_validation && set_self_application_test_recipients_request.nil? fail ArgumentError, "Missing the required parameter 'set_self_application_test_recipients_request' when calling AuthApplicationApi.set_self_application_test_recipients" end # resource path local_var_path = '/auth/application' # query parameters query_params = opts[:query_params] || {} # header parameters header_params = opts[:header_params] || {} # HTTP header 'Accept' (if needed) header_params['Accept'] = @api_client.select_header_accept(['application/json']) unless header_params['Accept'] # HTTP header 'Content-Type' content_type = @api_client.select_header_content_type(['application/json']) if !content_type.nil? header_params['Content-Type'] = content_type end # form parameters form_params = opts[:form_params] || {} # http body (model) post_body = opts[:debug_body] || @api_client.object_to_http_body(set_self_application_test_recipients_request) # return_type return_type = opts[:debug_return_type] || 'ApplicationSelfResponse' # auth_names auth_names = opts[:debug_auth_names] || ['ApplicationSecret', 'ApplicationPublicKey'] = opts.merge( :operation => :"AuthApplicationApi.set_self_application_test_recipients", :header_params => header_params, :query_params => query_params, :form_params => form_params, :body => post_body, :auth_names => auth_names, :return_type => return_type ) data, status_code, headers = @api_client.call_api(:PATCH, local_var_path, ) if @api_client.config.debugging @api_client.config.logger.debug "API called: AuthApplicationApi#set_self_application_test_recipients\nData: #{data.inspect}\nStatus code: #{status_code}\nHeaders: #{headers}" end return data, status_code, headers end |