seahaven-ap/packages/api/openapi/paths/auth-refresh.yaml
Adam Moussa bbfa6e4a3c
feat(api): switch live auth to host cookie BFF
Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.
2026-09-22 12:39:00 -04:00

32 lines
974 B
YAML

post:
tags:
- Session
summary: Refresh the session cookies
description: Rotates HttpOnly token cookies when the refresh token is still valid.
operationId: post-api-auth-refresh
security: []
responses:
"204":
description: Session refreshed.
"401":
description: Missing or invalid refresh token.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
example:
error:
code: UNAUTHENTICATED
message: Missing refresh token.
correlationId: 11111111-1111-4111-8111-111111111111
"403":
description: CSRF origin check failed.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
example:
error:
code: FORBIDDEN
message: Origin is not allowed.
correlationId: 11111111-1111-4111-8111-111111111111