2023-05-17 21:13:08 -04:00
|
|
|
User API
|
|
|
|
========
|
2023-05-20 21:47:15 -04:00
|
|
|
|
|
|
|
The User API allows managing users and their permissions.
|
|
|
|
|
|
|
|
Sachet implements the following endpoints for this API::
|
|
|
|
|
|
|
|
GET /users/<username>
|
|
|
|
PATCH /users/<username>
|
|
|
|
PUT /users/<username>
|
|
|
|
|
|
|
|
.. _user_schema:
|
|
|
|
|
|
|
|
User Schema
|
|
|
|
-----------
|
|
|
|
|
|
|
|
In JSON, a User object has the following properties:
|
|
|
|
|
|
|
|
.. code-block:: json
|
|
|
|
|
|
|
|
{
|
|
|
|
"username": "<username>",
|
|
|
|
"password": "<password>",
|
|
|
|
"permissions": ["PERMISSION1", "PERMISSION2"],
|
|
|
|
"register_date": "2023-05-08T18:57:27.982479"
|
|
|
|
}
|
|
|
|
|
|
|
|
.. list-table::
|
|
|
|
:header-rows: 1
|
|
|
|
:widths: 25 25 25 50
|
|
|
|
|
|
|
|
* - Property
|
|
|
|
- Type
|
|
|
|
- Limits
|
|
|
|
- Description
|
|
|
|
* - ``username``
|
|
|
|
- String
|
|
|
|
-
|
|
|
|
- User's name. This also acts as an ID.
|
|
|
|
* - ``password``
|
|
|
|
- String
|
|
|
|
- Write-only
|
|
|
|
- Password in plain text.
|
|
|
|
* - ``permissions``
|
|
|
|
- List of String
|
|
|
|
-
|
|
|
|
- List of permissions (see :ref:`permissions_table`).
|
|
|
|
* - ``register_date``
|
|
|
|
- DateTime
|
|
|
|
- Read-only
|
|
|
|
- Time the user registered at.
|
|
|
|
|
|
|
|
Endpoints
|
|
|
|
---------
|
|
|
|
|
|
|
|
GET
|
|
|
|
^^^
|
|
|
|
Requesting ``GET /users/<username>`` returns a JSON object conforming to the :ref:`User schema<user_schema>`.
|
|
|
|
This contains the information about the specified username.
|
|
|
|
|
|
|
|
An example response:
|
|
|
|
|
|
|
|
.. code-block:: json
|
|
|
|
|
|
|
|
{
|
|
|
|
"permissions": [
|
|
|
|
"CREATE",
|
|
|
|
"DELETE",
|
|
|
|
"LIST",
|
|
|
|
"READ"
|
|
|
|
],
|
|
|
|
"register_date": "2023-05-08T18:57:27.982479",
|
|
|
|
"username": "user"
|
|
|
|
}
|
|
|
|
|
|
|
|
A user can only read information about themselves, unless they have the :ref:`administrator permission<permissions_table>`.
|
|
|
|
|
|
|
|
PATCH
|
|
|
|
^^^^^
|
|
|
|
|
|
|
|
Requesting ``PATCH /users/<username>`` allows modifying some or all fields of a user.
|
|
|
|
The request body is JSON conforming to the :ref:`User schema<user_schema>`.
|
|
|
|
Properties may be left out: they won't be modified.
|
|
|
|
|
|
|
|
For example, to modify a user's permissions:
|
|
|
|
|
|
|
|
.. code-block:: json
|
|
|
|
|
|
|
|
{
|
|
|
|
"permissions": [
|
|
|
|
"CREATE"
|
|
|
|
]
|
|
|
|
}
|
|
|
|
|
|
|
|
Only :ref:`administrators<permissions_table>` can request this method.
|
|
|
|
|
|
|
|
PUT
|
|
|
|
^^^
|
|
|
|
|
|
|
|
Requesting ``PUT /users/<username>`` completely replaces a user's information.
|
|
|
|
The request body is JSON conforming to the :ref:`User schema<user_schema>`.
|
|
|
|
No property may be left out.
|
|
|
|
|
|
|
|
For example:
|
|
|
|
|
|
|
|
.. code-block:: json
|
|
|
|
|
|
|
|
{
|
|
|
|
"permissions": [
|
|
|
|
"CREATE"
|
|
|
|
],
|
|
|
|
"password": "123",
|
|
|
|
"username": "user"
|
|
|
|
}
|
|
|
|
|
|
|
|
Only :ref:`administrators<permissions_table>` can request this method.
|
|
|
|
|
|
|
|
User List API
|
|
|
|
-------------
|
|
|
|
|
|
|
|
There is also a User List API::
|
|
|
|
|
|
|
|
GET /users
|
|
|
|
POST /users
|
|
|
|
|
|
|
|
This API is only accessible to administrators (see :ref:`permissions_table`).
|
|
|
|
|
|
|
|
GET
|
|
|
|
^^^
|
|
|
|
|
|
|
|
``GET /users`` is a :ref:`paginated endpoint<pagination>` that returns a list of users.
|
|
|
|
|
|
|
|
POST
|
|
|
|
^^^^
|
|
|
|
|
2023-05-21 12:56:44 -04:00
|
|
|
``POST /users`` creates a new user.
|
2023-05-20 21:47:15 -04:00
|
|
|
The request body must conform to the :ref:`User schema<user_schema>`.
|