GrantForgeDocs

    技术文档

    REST API 参考

    全部 REST 接口及其访问要求,由 OpenAPI 契约生成。

    本页由仓库中的 OpenAPI 契约(core/grantforge-web/src/api/openapi.json)在构建文档时生成,与服务端保持一致。运行中的服务还在 /v3/api-docs 提供同一份契约。

    • 公开:无需登录。
    • 登录即可:任何已登录的账号。
    • 其余接口列出所需的权限码,权限码在资源目录中登记为 API 资源。

    控制台接口使用会话与 CSRF 令牌,见 安全设计;业务应用使用的开放 API 见 开放 API。

    初始化与注册

    方法 路径 访问要求
    GET /api/v1/bootstrap 公开
    POST /api/v1/register 公开
    POST /api/v1/setup 公开

    登录与会话

    方法 路径 访问要求
    POST /api/v1/auth/login 公开
    POST /api/v1/auth/logout 公开
    POST /api/v1/auth/mfa 公开
    POST /api/v1/auth/step-up 登录即可

    联合登录

    方法 路径 访问要求
    GET /api/v1/auth/federated/{code} 公开

    两步验证

    方法 路径 访问要求
    GET /api/v1/me/mfa 登录即可
    POST /api/v1/me/mfa/confirm 登录即可
    POST /api/v1/me/mfa/disable 登录即可
    POST /api/v1/me/mfa/enroll 登录即可
    POST /api/v1/me/mfa/recovery-codes 登录即可

    当前用户

    方法 路径 访问要求
    GET /api/v1/me 登录即可
    PUT /api/v1/me 登录即可
    GET /api/v1/me/authorization 登录即可
    GET /api/v1/me/login-history 登录即可
    POST /api/v1/me/password 登录即可

    在线会话

    方法 路径 访问要求
    GET /api/v1/me/sessions 登录即可
    DELETE /api/v1/me/sessions/{id} 登录即可
    GET /api/v1/sessions system.session.read
    DELETE /api/v1/sessions/{id} system.session.revoke

    用户

    方法 路径 访问要求
    GET /api/v1/users system.user.read
    POST /api/v1/users system.user.create
    DELETE /api/v1/users/{id} system.user.delete
    GET /api/v1/users/{id} system.user.read
    PUT /api/v1/users/{id} system.user.update
    POST /api/v1/users/{id}/disable system.user.status
    POST /api/v1/users/{id}/enable system.user.status
    POST /api/v1/users/{id}/lock system.user.status
    POST /api/v1/users/{id}/mfa/reset system.user.mfa-reset
    POST /api/v1/users/{id}/password system.user.reset-password
    POST /api/v1/users/{id}/unlock system.user.status

    组织架构

    方法 路径 访问要求
    GET /api/v1/org-units system.org.read
    POST /api/v1/org-units system.org.create
    DELETE /api/v1/org-units/{id} system.org.delete
    PUT /api/v1/org-units/{id} system.org.update
    POST /api/v1/org-units/{id}/move system.org.move

    用户组

    方法 路径 访问要求
    GET /api/v1/groups system.group.read
    POST /api/v1/groups system.group.create
    DELETE /api/v1/groups/{id} system.group.delete
    PUT /api/v1/groups/{id} system.group.update
    GET /api/v1/groups/{id}/members system.group.read
    POST /api/v1/groups/{id}/members system.group.members
    POST /api/v1/groups/{id}/members/remove system.group.members

    岗位

    方法 路径 访问要求
    GET /api/v1/positions system.position.read
    POST /api/v1/positions system.position.create
    DELETE /api/v1/positions/{id} system.position.delete
    PUT /api/v1/positions/{id} system.position.update
    GET /api/v1/positions/{id}/holders system.position.read
    GET /api/v1/positions/options system.position.read

    导入导出

    方法 路径 访问要求
    GET /api/v1/org-units/export system.org.export
    POST /api/v1/org-units/import system.org.import
    GET /api/v1/users/export system.user.export
    POST /api/v1/users/import system.user.import

    身份源

    方法 路径 访问要求
    GET /api/v1/identity-sources system.identity-source.read
    POST /api/v1/identity-sources system.identity-source.create
    DELETE /api/v1/identity-sources/{id} system.identity-source.delete
    GET /api/v1/identity-sources/{id} system.identity-source.read
    PUT /api/v1/identity-sources/{id} system.identity-source.update
    POST /api/v1/identity-sources/{id}/sync system.identity-source.sync
    POST /api/v1/identity-sources/{id}/test system.identity-source.update

    租户

    方法 路径 访问要求
    GET /api/v1/tenants platform.tenant.read
    POST /api/v1/tenants platform.tenant.create
    GET /api/v1/tenants/{id} platform.tenant.read
    PUT /api/v1/tenants/{id} platform.tenant.update
    POST /api/v1/tenants/{id}/activate platform.tenant.status
    POST /api/v1/tenants/{id}/suspend platform.tenant.status

    角色

    方法 路径 访问要求
    GET /api/v1/roles system.role.read
    POST /api/v1/roles system.role.create
    DELETE /api/v1/roles/{id} system.role.delete
    GET /api/v1/roles/{id} system.role.read
    PUT /api/v1/roles/{id} system.role.update
    POST /api/v1/roles/{id}/copy system.role.create
    POST /api/v1/roles/{id}/disable system.role.status
    POST /api/v1/roles/{id}/enable system.role.status

    角色授权

    方法 路径 访问要求
    GET /api/v1/roles/{id}/grants system.role.read
    PUT /api/v1/roles/{id}/grants system.role.grant
    POST /api/v1/roles/{id}/grants/impact system.role.grant
    POST /api/v1/roles/{id}/grants/preview system.role.grant

    角色继承

    方法 路径 访问要求
    GET /api/v1/role-links system.role.read
    GET /api/v1/roles/{id}/inheritance system.role.read
    PUT /api/v1/roles/{id}/parents system.role.inherit

    角色分配

    方法 路径 访问要求
    DELETE /api/v1/role-assignments/{id} system.role.assign
    PUT /api/v1/role-assignments/{id} system.role.assign
    GET /api/v1/roles/{id}/assignments system.role.read
    POST /api/v1/roles/{id}/assignments system.role.assign
    GET /api/v1/users/{id}/roles system.user.read

    影响分析

    方法 路径 访问要求
    GET /api/v1/resource-dependencies/{id}/impact platform.resource.update
    POST /api/v1/resources/{id}/dependencies/impact platform.resource.update
    GET /api/v1/resources/{id}/impact platform.resource.update

    数据权限

    方法 路径 访问要求
    GET /api/v1/data-entities system.role.read
    DELETE /api/v1/data-policies/{id} system.role.data
    PUT /api/v1/data-policies/{id} system.role.data
    GET /api/v1/roles/{id}/data-policies system.role.read
    POST /api/v1/roles/{id}/data-policies system.role.data
    POST /api/v1/roles/{id}/data-policies/preview system.role.data

    字段权限

    方法 路径 访问要求
    GET /api/v1/roles/{id}/field-policies system.role.read
    PUT /api/v1/roles/{id}/field-policies system.role.data

    权限解释与模拟

    方法 路径 访问要求
    POST /api/v1/authz/check system.authz.check
    POST /api/v1/authz/effective system.authz.check
    POST /api/v1/authz/explain system.authz.explain
    POST /api/v1/authz/simulate system.authz.simulate

    职责分离

    方法 路径 访问要求
    GET /api/v1/sod-conflicts system.sod.read
    GET /api/v1/sod-constraints system.sod.read
    POST /api/v1/sod-constraints system.sod.create
    DELETE /api/v1/sod-constraints/{id} system.sod.delete
    PUT /api/v1/sod-constraints/{id} system.sod.update

    权限申请

    方法 路径 访问要求
    GET /api/v1/access-requests system.access-request.read
    POST /api/v1/access-requests/{id}/approve system.access-request.approve
    POST /api/v1/access-requests/{id}/reject system.access-request.approve
    POST /api/v1/access-requests/{id}/revoke system.access-request.approve
    GET /api/v1/me/access-requests 登录即可
    POST /api/v1/me/access-requests 登录即可
    POST /api/v1/me/access-requests/{id}/cancel 登录即可
    GET /api/v1/me/requestable-roles 登录即可
    GET /api/v1/requestable-roles system.access-request.read
    PUT /api/v1/requestable-roles system.access-request.configure

    权限复核

    方法 路径 访问要求
    POST /api/v1/access-review-rounds/{id}/cancel system.access-review.manage
    POST /api/v1/access-review-rounds/{id}/complete system.access-review.manage
    POST /api/v1/access-review-rounds/{id}/decisions system.access-review.decide
    GET /api/v1/access-review-rounds/{id}/items system.access-review.read
    GET /api/v1/access-reviews system.access-review.read
    POST /api/v1/access-reviews system.access-review.manage
    DELETE /api/v1/access-reviews/{id} system.access-review.manage
    PUT /api/v1/access-reviews/{id} system.access-review.manage
    GET /api/v1/access-reviews/{id}/rounds system.access-review.read
    POST /api/v1/access-reviews/{id}/start system.access-review.manage

    审计日志

    方法 路径 访问要求
    GET /api/v1/audit-events system.audit.read
    GET /api/v1/audit-events/export system.audit.export

    应用

    方法 路径 访问要求
    GET /api/v1/applications platform.catalog.read
    POST /api/v1/applications platform.application.create
    DELETE /api/v1/applications/{id} platform.application.delete
    PUT /api/v1/applications/{id} platform.application.update
    GET /api/v1/applications/{id}/resources platform.catalog.read
    POST /api/v1/applications/{id}/resources platform.resource.create

    资源

    方法 路径 访问要求
    DELETE /api/v1/resources/{id} platform.resource.delete
    PUT /api/v1/resources/{id} platform.resource.update
    POST /api/v1/resources/{id}/move platform.resource.move

    资源依赖

    方法 路径 访问要求
    GET /api/v1/applications/{id}/dependencies platform.catalog.read
    DELETE /api/v1/resource-dependencies/{id} platform.resource.update
    PUT /api/v1/resource-dependencies/{id} platform.resource.update
    GET /api/v1/resources/{id}/dependencies platform.catalog.read
    POST /api/v1/resources/{id}/dependencies platform.resource.update

    字段出现的接口

    方法 路径 访问要求
    GET /api/v1/resources/{id}/field-usages platform.catalog.read

    API 目录

    方法 路径 访问要求
    GET /api/v1/api-endpoints platform.catalog.read
    POST /api/v1/api-endpoints/review platform.api.review

    目录体检

    方法 路径 访问要求
    GET /api/v1/applications/{id}/health platform.catalog.health

    OAuth 客户端

    方法 路径 访问要求
    GET /api/v1/applications/{id}/clients platform.client.read
    POST /api/v1/applications/{id}/clients platform.client.create
    DELETE /api/v1/clients/{id} platform.client.delete
    PUT /api/v1/clients/{id} platform.client.update
    POST /api/v1/clients/{id}/rotate-secret platform.client.rotate

    授权服务器

    方法 路径 访问要求
    GET /api/v1/oauth platform.oauth.read
    POST /api/v1/oauth/signing-keys/rotate platform.oauth.rotate

    开放 API:权限

    方法 路径 访问要求
    GET /api/v1/open/me/authorization 登录即可
    GET /api/v1/open/me/permissions 登录即可

    开放 API:数据

    方法 路径 访问要求
    PUT /api/v1/open/catalog/data-entities 登录即可
    GET /api/v1/open/me/data-access 登录即可

    插件

    方法 路径 访问要求
    GET /api/v1/plugins platform.plugin.read
    POST /api/v1/plugins/{id}/disable platform.plugin.update
    POST /api/v1/plugins/{id}/enable platform.plugin.update
    POST /api/v1/plugins/rescan platform.plugin.update

    数据服务

    方法 路径 访问要求
    GET /api/v1/service-types data.service.read
    GET /api/v1/services data.service.read
    POST /api/v1/services data.service.create
    DELETE /api/v1/services/{id} data.service.delete
    GET /api/v1/services/{id} data.service.read
    PUT /api/v1/services/{id} data.service.update
    POST /api/v1/services/{id}/lookup data.service.read
    POST /api/v1/services/test data.service.test

    策略

    方法 路径 访问要求
    DELETE /api/v1/policies/{id} data.policy.delete
    GET /api/v1/policies/{id} data.policy.read
    PUT /api/v1/policies/{id} data.policy.update
    GET /api/v1/policy-subjects data.policy.read
    GET /api/v1/services/{id}/policies data.policy.read
    POST /api/v1/services/{id}/policies data.policy.create

    代理管理

    方法 路径 访问要求
    POST /api/v1/agent-tokens/{id}/revoke data.agent.manage
    GET /api/v1/policy-signing-key data.agent.read
    GET /api/v1/services/{id}/agent-tokens data.agent.read
    POST /api/v1/services/{id}/agent-tokens data.agent.manage
    GET /api/v1/services/{id}/agents data.agent.read
    DELETE /api/v1/services/{id}/agents/{agentId} data.agent.manage

    代理接口

    方法 路径 访问要求
    POST /api/v1/agent/access-events 登录即可
    POST /api/v1/agent/heartbeat 登录即可
    GET /api/v1/agent/policies 登录即可
    GET /api/v1/agent/signing-key 登录即可

    访问审计

    方法 路径 访问要求
    GET /api/v1/services/{id}/access-events data.audit.read

    在 GitHub 上编辑此页