{
 "openapi": "3.1.0",
 "info": {
  "title": "Rikskampen X Theme 5 API - audit",
  "version": "0.1.0",
  "description": "Theme 5 API contract proposal (API01, decision D11): the audit trail and the caller's permissions."
 },
 "tags": [
  {
   "name": "audit"
  }
 ],
 "paths": {
  "/api/theme5/clients/{clientId}/audit": {
   "get": {
    "operationId": "listAuditEntries",
    "tags": [
     "audit"
    ],
    "summary": "List the client's audit entries",
    "description": "Append-only audit trail of every change to this client's Theme 5 data; before and after hold the previous and new values as JSON text (null when absent).",
    "security": [
     {
      "coachAuth": []
     }
    ],
    "parameters": [
     {
      "$ref": "common.openapi.json#/components/parameters/ClientId"
     }
    ],
    "responses": {
     "200": {
      "description": "Success.",
      "content": {
       "application/json": {
        "schema": {
         "type": "object",
         "additionalProperties": false,
         "required": [
          "entries"
         ],
         "properties": {
          "entries": {
           "type": "array",
           "items": {
            "type": "object",
            "additionalProperties": false,
            "required": [
             "auditId",
             "at",
             "actorId",
             "actorRole",
             "action",
             "before",
             "after"
            ],
            "properties": {
             "auditId": {
              "type": "string"
             },
             "at": {
              "type": "string",
              "format": "date-time"
             },
             "actorId": {
              "type": "string"
             },
             "actorRole": {
              "type": "string",
              "enum": [
               "coach",
               "admin",
               "system"
              ]
             },
             "action": {
              "type": "string"
             },
             "before": {
              "type": [
               "string",
               "null"
              ]
             },
             "after": {
              "type": [
               "string",
               "null"
              ]
             }
            }
           }
          }
         }
        }
       }
      }
     },
     "400": {
      "$ref": "common.openapi.json#/components/responses/BadRequest"
     },
     "401": {
      "$ref": "common.openapi.json#/components/responses/Unauthorized"
     },
     "403": {
      "$ref": "common.openapi.json#/components/responses/Forbidden"
     },
     "404": {
      "$ref": "common.openapi.json#/components/responses/NotFound"
     }
    },
    "x-theme5-rules": [
     "R-AUDIT-APPEND-ONLY",
     "R-COACH-ASSIGNED"
    ]
   }
  },
  "/api/theme5/me/permissions": {
   "get": {
    "operationId": "getMyPermissions",
    "tags": [
     "audit"
    ],
    "summary": "Get the caller's permissions",
    "description": "Who the caller is and which clients they may act on; the server enforces the same rule on every request.",
    "security": [
     {
      "coachAuth": []
     }
    ],
    "responses": {
     "200": {
      "description": "Success.",
      "content": {
       "application/json": {
        "schema": {
         "type": "object",
         "additionalProperties": false,
         "required": [
          "actorId",
          "role",
          "clientIds"
         ],
         "properties": {
          "actorId": {
           "type": "string"
          },
          "role": {
           "type": "string",
           "enum": [
            "coach",
            "admin"
           ]
          },
          "clientIds": {
           "type": "array",
           "uniqueItems": true,
           "items": {
            "type": "string"
           }
          }
         }
        }
       }
      }
     },
     "401": {
      "$ref": "common.openapi.json#/components/responses/Unauthorized"
     }
    },
    "x-theme5-rules": [
     "R-COACH-ASSIGNED"
    ]
   }
  }
 },
 "components": {
  "securitySchemes": {
   "coachAuth": {
    "$ref": "common.openapi.json#/components/securitySchemes/coachAuth"
   }
  }
 }
}
