seahaven-ap/packages/api/openapi/openapi.yaml
Adam Moussa bbfa6e4a3c
feat(api): switch live auth to host cookie BFF
Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.
2026-09-22 12:39:00 -04:00

45 lines
1.3 KiB
YAML

openapi: 3.1.0
info:
title: Sea Haven AP API
version: 1.0.0
description: "Accounts payable HTTP API for Sea Haven Industries. Liveness, cookie session, and authenticated session smoke under local and AWS runtimes."
license:
name: Proprietary
servers:
- url: http://127.0.0.1:8787
description: Local API process used by Vite proxy and unit tests.
tags:
- name: Health
description: Liveness and readiness checks for the API process.
- name: Session
description: Cookie session via Cognito hosted UI, plus caller identity after upsert.
paths:
/api/health:
$ref: ./paths/health.yaml
/api/ready:
$ref: ./paths/ready.yaml
/api/auth/login:
$ref: ./paths/auth-login.yaml
/api/auth/callback:
$ref: ./paths/auth-callback.yaml
/api/auth/refresh:
$ref: ./paths/auth-refresh.yaml
/api/auth/logout:
$ref: ./paths/auth-logout.yaml
/api/me:
$ref: ./paths/me.yaml
components:
securitySchemes:
cookieAuth:
$ref: ./components/security.yaml#/cookieAuth
schemas:
Error:
$ref: ./components/schemas.yaml#/Error
HealthResponse:
$ref: ./components/schemas.yaml#/HealthResponse
ReadyResponse:
$ref: ./components/schemas.yaml#/ReadyResponse
MeResponse:
$ref: ./components/schemas.yaml#/MeResponse
security:
- cookieAuth: []