Appearance
@aletheia-dev/api-client
0.7.0
Minor Changes
- 6ef571a: Uploads are presigned PUTs, which every S3-compatible store serves, Cloudflare R2 among them.
DocumentUploadTicket.uploadis{ method: 'PUT', url, headers, expiresAt }: the URL is signed for the declaredContent-TypeandsizeBytes, andfieldsandmaxBytesare gone.uploadToStoragesends the file as the request body with the ticket's headers, andUploadXhrgainssetRequestHeader.
Patch Changes
- 250c4b6: The package ships without source maps. Its homepage is its page on the documentation site, issues go to the support page or
aletheia-dev@ajrd.net, and the changelog no longer links commits. - Updated dependencies [c7b166c]
- Updated dependencies [6ef571a]
- Updated dependencies [250c4b6]
- @aletheia-dev/core@0.7.0
0.6.0
Minor Changes
d6ddf8b:
apps,appInvocationsandappCallbackscover the app routes: the catalogue, module uploads (uploadsends the bytes asapplication/wasm), publishing and its approvals, installs, secrets, test calls, usage, health and the record of app calls and vendor sessions.26474ac:
plugins,pluginInvocationsandpluginCallbacksare removed with the plugin routes, and so arePluginSummary,ConfigurePluginBody,PluginHealthParams,PluginInvocationQuery, the plugin client types and the plugin schemas re-exported from@aletheia-dev/core.apps,appInvocationsandappCallbackscover the apps that replace them.d40d16f:
SubmissionEventInput(step_viewedwith astepId,upload_failedwith afieldKeyand a lowercasereasoncode) andMAX_SUBMISSION_EVENTS: what the collection terminal reports toPOST /collection-submissions/:id/events.FlowFunnelandFlowFunnelQuery: a flow's drop-off fromGET /stats/flows/:key/funnel(opened,submitted, per stepreachedandstoppedHere, anduploadFailures), which the API client reads withstats.flowFunnel(key, { days }).78c68ac: An app whose asynchronous action starts a session the applicant takes part in (a liveness check, documents the vendor collects) declares
handles.handoff(anAppHandoffSdksuch assumsub) and hands the session to the applicant's browser as anAppHandoff(sdk, a short-livedtokenand itsexpiresAt), ornullonce the vendor has everything. The collection terminal shows the vendor's SDK with it after the submit.HandoffUnavailableError(409handoff_unavailable) says nothing waits for the applicant at a vendor, andSubmissionStatus.handoffis true while the run waits for such a check.
Patch Changes
- Updated dependencies [7821afa, c9d9f77, 8984323, 19af0f9, 0b5f8ad, 26474ac, 729209c, e2bef29, d40d16f, 259e0b5, c05e741, e290fd4, 75b54c5, 1551100, 78c68ac]:
- @aletheia-dev/core@0.6.0
0.5.0
Minor Changes
4bbc905: Approvals: a requester (or an admin) withdraws an open request with
POST <prefix>/{key}/versions/{version}/withdraw, which closes it aswithdrawn(a newApprovalDecision) and returns the version to draft; anyone else gets 403not_requester(NotRequesterError). Requests carry an append-only discussion (GET/POST /approvals/{id}/comments,ApprovalComment).GET /approvalsfilters onstatus(openordecided),kind,mineandstale, pages, and returns atotal(ApprovalListQuery);GET /approvals/{id}returns the request with its version, published version, diff, latest backtest, dependencies, usage, eligible approvers and discussion (ApprovalDetail).POST /backtestsalso takes a workflow version (StartWorkflowBacktestInput,{ workflowKey, version? }): each recorded evaluation of its runs is replayed through the rule step of the same id, and the summary adds the replayed outcomes indecisions;BacktestcarriesworkflowKeyandworkflowVersion, withruleKeyandruleVersionnow optional. The client replacesgovernance.approvals.listOpenwithlistand addsapprovals.get,commentsandcomment,governance.withdrawandisNotRequester.40ee302: Audit: every row written during an API request records
meta(RequestMeta: request id, route, IP, user agent;TenantContext.request), included in exports as ametacolumn.GET /audit-events/{id}answers anAuditEventDetail: the event, itsneighborsunder the list filters it takes and therelatedcase, decision, run and subject.GET /audit-events/countpreviews an export (AuditExportPreview). The export takesfilenameand trailsX-Export-Rows. Saved views per user:GET,POST /audit-views,DELETE /audit-views/{id}(AuditView,AuditViewInput,AuditViewFilters). Scheduled exports:GET,POST /audit-export-schedules,GET,PUT,DELETE /audit-export-schedules/{id},GET /audit-export-schedules/{id}/runsandPOST /audit-export-runs/{id}/download(AuditExportSchedule,AuditExportScheduleInput,ScheduledExportFilter,CronExpression,AuditExportRun,AuditExportRunStatus,AuditExportDownload);AttentionItemgainsexport_failed. The client'saudit.gettakes the list filter and answers the detail,audit.countis new,audit.exportandaudit.exportUrltake a file name, andauditViewsandauditExportsare new.e236779: Requests for information.
POST /cases/:id/request-infosends the applicant the form the case's run collected again, pre-filled, with the reviewer's message; the case waits with its SLA paused (infoRequestedAt) and the run repeats its checks on the answers before handing the case back. An unanswered request expires with the case rejected (info_not_provided). Submissions gain thewithdrawnandexpiredstatuses andcaseId,requestMessageandexpiresAt; operators can re-issue a link (POST /collection-submissions/:id/link) or withdraw a submission (POST /collection-submissions/:id/withdraw), andGET /collection-submissions/:id/statusnames the form the run waits for next. The client addscases.requestInfo,collectionSubmissions.reissueLinkandcollectionSubmissions.withdraw.6d17f78: Cases:
GET /casesfilters onqueue(the routing label a run gives its case through thecreate_casestep'squeueFrom;priorityFromsets the priority the same way),reasonCode,countryandwaiting, searches the subject and the case id, applies a queue withqueueIdand names the assignee withexpand=assignee.GET /cases/{id}/evidencereturns the rule hits, documents, vendor checks (with a readableresultLabel), events and decisions in one response,GET /case-typesthe types in use, andGET/PUT /reason-codesa reason-code catalogue that decisions are then checked against (ReasonCode,CaseEvidence,CaseType). Every tenant has the system queues; queues carrysystemKey,visibility(everyone,admins,personal) andclaimNext, are reordered withPUT /case-queues/orderand previewed withPOST /case-queues/preview, andPOST /cases/claim-next {}draws from the claim-next queues. The client addscases.evidence,typesandreasonCodes, andcaseQueues.reorderandpreview.84e50a4: Definitions:
PATCH <prefix>/{key}/versions/{version}saves a draft version in place (the bodyPUTtakes, with an optional changenote; 409 once it is no longer a draft), and every definition entity andDefinitionVersionSummarycarriesnoteandupdatedBy(VersionNote,VersionNoteInput).POST /rule-definitions/validateandPOST /rule-sets/validateanswer aValidationReportwith warnings such aslist_staleandunpublished_rule. Dry runs takeversions(up to 5) and answer{ key, results: [{ version, status, type, result, explanation }], dataPaths }(DryRunInput,DryRunResponse); analysts withbacktests:runmay run them. A workflowDefinitionDiffaddssteps(DiffStep).GET /definitions/usagelists what names each rule, rule set and collection flow (DefinitionUsage,UsageLink).POST /workflow-definitions/context-pathslists the run-context paths a step can read (ContextPath).POST /collection-flows/{key}/versions/{version}/previewreturns a 15-minute preview link (FlowPreviewLink) that the collection terminal opens withGET /collection-flow-preview(FlowPreview).GET /definitions/packslists the starter packs (PolicyPackSummary) andPOST /definitions/import?pack=imports one. The client addsupdateDraftto every definition domain,ruleDefinitions.validate,ruleSets.validate,workflowDefinitions.contextPaths,collectionFlows.preview,definitions.usage,policyPacks.startersandimportStarter;dryRuntakesversions.6ba6815: Outbound webhooks:
GET,POST /webhook-endpoints,GET,PUT,DELETE /webhook-endpoints/{id}(the signing secret is returned once),POST /webhook-endpoints/{id}/test(a signedping),POST /webhook-endpoints/{id}/rotate-secret(the previous secret signs too for 24 hours),GET /webhook-deliverieswith endpoint, status, event, run and time filters,POST /webhook-deliveries/{id}/retryand the catalogueGET /webhook-events(WebhookEventType,WEBHOOK_EVENTS,webhookEventOf,WebhookPayload,WebhookEndpoint,WebhookEndpointInput,CreatedWebhookEndpoint,RotatedWebhookSecret,WebhookTestResult,WebhookDelivery,WebhookDeliveryStatus,WebhookDeliveryFilter,WEBHOOK_MAX_ATTEMPTS,WEBHOOK_RETRY_DELAYS_MS,WEBHOOK_SECRET_OVERLAP_MS). Notifications:GET /notificationsandPOST /notifications/read(Notification,NotificationKind,NotificationList,NotificationQuery,MarkNotificationsRead,NotificationsMarked).RunRelatedgainsdeliveries;AttentionItemgainswebhook_exhausted. New environment variableWEBHOOK_ALLOW_PRIVATE_NETWORKS. The client addswebhooksandnotifications.0019b2e: New permissions for the console routes to come:
runs:write,ops:read,webhooks:read,webhooks:writeandusers:manage(admins) andnotifications:read(admins and analysts). Named errorsqueue_name_taken(QueueNameTakenError),case_not_assigned(CaseNotAssignedError: deciding someone else's case; an unassigned case is claimed by the decision) andrate_limited(429 withRetry-After, per caller,API_RATE_LIMIT_PER_MINUTE). The client addsisQueueNameTaken,isCaseNotAssignedandisRateLimited.ff4da19: Plugins: a manifest may give
category,vendor,docsUrl(https) andpricingNote, whichGET /plugins/availablereturns withactionDetails, each action's timeout, retry policy, idempotency, webhook timeout and input and output JSON Schemas (PluginSummary,PluginActionSummary).GET /plugins/healthaddscircuits, the plugins whose circuit breaker the workers report open or half-open (PluginCircuit,PluginCircuitState); Home'splugin_failingattention item carriescircuit.POST /plugins/{name}/testcalls one synchronous action once with the tenant configuration (TestPluginInput,PluginTestResult).POST /plugins/{name}/secrets/{secret}stores a secret value sealed withSECRET_STORE_KEYand answers itsstore:reference (SetPluginSecretInput,PluginSecretRef);DELETErevokes it. Service users:GET,POST /service-users,PATCH /service-users/{id},POST /service-users/{id}/keys(the token is returned once) andDELETE /service-users/{id}/keys/{keyId}manage the tenant's machine users in Zitadel withZITADEL_MANAGEMENT_PAT(ServiceUser,ServiceUserKey,CreateServiceUserInput,UpdateServiceUserInput,CreateServiceUserKeyInput,IssuedServiceUserKey). New errors:secret_store_unavailableandservice_users_unavailable(503). The client addsplugins.test,plugins.setSecret,plugins.revokeSecretandserviceUsers; itsPluginSummaryis core's.f1b6377: Runs record what started them (
trigger:api,consoleorreplay) and the caller'scorrelationId, set onPOST /workflow-runs, filtered withtriggerand matched exactly bysearch. The worker traces every step visit:GET /workflow-runs/{id}/stepsreturns each visit's status, timings, summary, input and output and the rows it wrote (RunStep), andGET /workflow-runs/{id}/relatedthe run's cases, decision, replay links and, forops:read, a trace link (RunRelated,TRACE_URL_TEMPLATE). Admins cancel an active run (POST /workflow-runs/{id}/cancel, which closes its open cases and withdraws its forms) and replay a finished one from a step it reached (POST /workflow-runs/{id}/replay). New errorsrun_finished,run_activeandstep_not_reached(RunFinishedError,RunActiveError,StepNotReachedError); the client addsworkflowRuns.steps,related,cancelandreplayandisRunFinished,isRunActiveandisStepNotReached.dec5e57: Search, Home, health and document thumbnails.
GET /searchfinds subjects, cases, runs and definitions as far as the caller may read (SearchQuery,SearchResults,SearchGroup,SearchItem,SearchItemKind,SearchScope).GET /setup/checklistcomputes the setup steps (SetupChecklist,SetupItem,SetupItemId) andGET /activitytells recent decisions, breaches, publishes and approvals as sentences (ActivityFeed,ActivityItem,ActivityQuery).GET /health/summaryreports the dependencies, failing plugins and given-up webhooks (HealthSummary,HealthState,DependencyStatus). The scan renders a grayscale thumbnail of clean images and of a PDF's first page (Document.thumbnailKey), served byGET /documents/{id}/thumbnail(DocumentThumbnail). The client addshome.search,home.setupChecklist,home.activity,health.summaryanddocuments.thumbnail.bcce30e: Statistics:
GET /stats/overviewanswers Home's figures (StatsOverview: open, unassigned, breached and due cases, the last 24 hours of runs withautoDecidedPct, and theAttentionItems the caller may act on);GET /stats/definitions?kind=the activity per rule, workflow or collection flow over 1 to 90 days (DefinitionStats:RuleStats,WorkflowStats,FlowStats);GET /stats/slaSLA attainment, breaches and median time to decide, per workflow (SlaStats);GET /stats/rules/{key}/hitsa rule's recorded hits per UTC day and, withcompareVersion, that version's backtest beside them (RuleHits). A rule backtest's summary addsdaily(BacktestDay).GET /cases,/subjects,/audit-events,/workflow-runsand/plugin-invocationsstop counting at 100,000 and flag it withtotalIsEstimate.GET /workflow-runs/summarytakes every filter of the list and addsautoDecidedPct.GET /decisionspages (limit,offset,from,to) and returnstotal.GET /subjects/{id}/timelinepages bycursorand answersTimelinePage({ items, nextCursor }) in place ofoffset.GET /plugin-callbacksfilters bypluginNameand returnstotal. The client addsstats(overview,definitions,sla,ruleHits),pluginCallbacks.list,decisions.listPageandPage.totalIsEstimate;subjects.timelinereturns the page with its cursor, andworkflowRuns.summarytakes the list's filters. Core addspercentOf.774356c: Subjects can be changed with
PATCH /subjects/{id}(UpdateSubjectInput:dataas a JSON merge patch,tags,status), audited assubject.updatedwith the changed paths; core addsapplyMergePatch,diffMergePatchandchangedPaths.GET /subjects/{id}returnslastSeenAt(SubjectDetail),GET /subjects/{id}/linksthe subjects sharing a device, card, IP address, email, address or referral (SubjectLink), andGET /subjects/{id}/flagsthe derived signals (SubjectFlag).GET /subjectsfilters oncountryandlastDecision, andGET /subjects/exportreturns the filtered list as CSV. The client addssubjects.update,links,flagsandexportCsv.98d2fec: Tenant settings gain
cases.warnAtPct(the share of the SLA left when a new case turnsdue_soon, kept on the case asslaWarnPct),collection.defaultLinkTtlSeconds(the lifetime of links for flows that set none;CollectionFlowBody.linkTtlSecondsis optional andlinkLifetimeresolves it), andconsole.showRunContextToandconsole.maskForAnalysts, which decide what people see of run context and personal data (maskPersonalDatatakes the kinds to mask;PERSONAL_DATA_KINDS).TenantProfile.regionreportsDEPLOYMENT_REGION. Statistics count days in the tenant'sconsole.timeZone(RuleHits.timeZone;dayIn,midnightIn,daysIn).f4cfd62: Tenant settings gain namespaces:
cases.businessHours(BusinessHours, used byaddBusinessTimeto compute due times) andcases.onBreach(BreachActions),approvals.requiredFor(checked byapprovalRequired),collection.flowUrl(CollectionSettings) andconsole(ConsoleSettings);tenant.settings.updatedrecords thechangedpaths.Tenantgainsstatus,suspendedAt,suspendedReasonandlinksValidAfter. New routes:GET /tenants/me(TenantProfile),POST /tenants/me/suspend(SuspendTenantInput),POST /tenants/me/resumeandPOST /tenants/me/revoke-links(RevokedLinks), each behind a recent sign-in sent asX-Aletheia-Reauth;GET /roles(RoleDescription);GETandPUT /me/preferences(UserPreferences); and the team under/team(TeamUser,InviteUserInput,ChangeRoleInput). ErrorsTenantSuspendedError(tenant_suspended) andReauthRequiredError(reauth_required) are new. The client addstenants.profile,suspend,resume,revokeLinks,roles,preferences,updatePreferencesandtenants.team, theisTenantSuspendedandisReauthRequiredguards, and per-requestheaders.
Patch Changes
- Updated dependencies [4bbc905, 40ee302, e236779, 6d17f78, 84e50a4, 6ba6815, 0019b2e, ff4da19, f1b6377, dec5e57, bcce30e, 774356c, 98d2fec, f4cfd62]:
- @aletheia-dev/core@0.5.0
0.4.0
Minor Changes
- 3282c50:
GET /collection-submissionslists submissions newest first, filtered bysubjectId,workflowRunIdandstatus, with the total.CollectionSubmissionFilterdescribes the filters, and the client'scollectionSubmissions.listandlistPagecall it.
Patch Changes
- Updated dependencies [3282c50]:
- @aletheia-dev/core@0.4.0
0.3.0
Minor Changes
eb2c640: Page-returning list variants:
cases.listPage,subjects.listPageandaudit.listPageresolve to{ items, total }(Page<T>), wheretotalcounts every match ignoringlimitandoffset.cases.listPagetakesexpand: ['subject']andsubjects.listPagetakesexpand: ['openCases', 'lastDecision']. The array-returninglistmethods are unchanged.New case methods:
cases.countscounts several named filters in one request,cases.claimNextatomically assigns the caller the next free case of a queue or filter (a 404 with the codenothing_to_claimwhen there is none; seeisNothingToClaim), andcases.bulkassigns, claims or closes up to 100 cases.caseFilterBodyturns a list query into a filter body.cases.assign,cases.claimandcases.closenow read the{ case }envelope the API answers with; they failed to parse real responses before. A case'scontextcomes back redacted for callers withoutruns:contextand masked for callers withoutsubjects:pii, like the run context it was copied from.eb2c640:
ApiErrorcarriesrequestId: the id in the API's error body (error.requestId), falling back to thex-request-idresponse header.ApiError.fromResponsetakes the response headers as an optional fourth argument and the constructor an optional fifth; existing calls are unchanged.audit.exportnow needs theaudit:exportpermission, and subject data, events, run context and plugin payloads come back masked or redacted for callers withoutsubjects:piiorruns:context.eb2c640: Runs across the tenant:
workflowRuns.listPageresolves to{ items, total }with the filterssubjectId,statusandoutcome(repeated),definitionKey,from,toandsearch, andexpand: ['subject']; each item carriesdurationMsandoutcome.workflowRuns.summaryreads the counts per status and the p95 duration of the runs started in a window.workflowRuns.listBySubjectstill returns an array of runs.audit.getreads one audit event by id.pluginInvocations.listPagepages the invocations with the newpluginName,status,fromandtofilters (also accepted bypluginInvocations.list, which still returns an array),pluginInvocations.getreads one invocation, andplugins.healthreads the per-plugin calls, failures, timeouts, p95 and last call and failure times of a window (5 to 1440 minutes, 60 by default). Invocation payloads come back redacted for callers withoutruns:context.
Patch Changes
- Updated dependencies [ffa9107, eb2c640, 7c5c045, eb2c640, eb2c640]:
- @aletheia-dev/core@0.3.0
0.2.0
Minor Changes
- 2d95c87: New
policyPacksdomain:import(pack, { publish? })posts aPolicyPacktoPOST /definitions/importandexport(keys, { name?, version?, description? })reads one back fromGET /definitions/export.PolicyPackand the import result schema are re-exported.
Patch Changes
- Updated dependencies [1b1c13f]:
- @aletheia-dev/core@0.2.0
0.1.0
Minor Changes
- a783a44: First published release.
@aletheia-dev/api-clientand@aletheia-dev/collection-flow-uiare published for teams that embed collection flows or build their own back office;@aletheia-dev/coreand@aletheia-dev/collection-floware published as their dependencies and carry no stability promise before 1.0.
Patch Changes
- Updated dependencies [a783a44]:
- @aletheia-dev/core@0.1.0