blob: 8f6a9933b65031e246bf2cee1cf137b3bf30d9ff [file] [log] [blame]
Pamela Dragoshb4a8ef22020-04-21 15:30:35 -04001.. This work is licensed under a Creative Commons Attribution 4.0 International License.
2
3.. _decision-api-label:
4
5Decision API
Pamela Dragoshf65c8ff2020-04-29 08:23:12 -04006############
Pamela Dragoshb4a8ef22020-04-21 15:30:35 -04007
Pamela Dragoshf65c8ff2020-04-29 08:23:12 -04008The Decision API is used by ONAP components that enforce policies and need a decision on which policy to enforce for a
9specific situation. The Decision API mimics closely the XACML request standard in that it supports a subject, action
10and resource.
Pamela Dragoshb4a8ef22020-04-21 15:30:35 -040011
liamfallona91dcf92021-09-29 13:44:34 +010012When the PAP activates an xacml-pdp, the decision API becomes available. Conversely, when the PAP deactivates an xacml-pdp, the
13decision API is disabled. The decision API is enabled/disabled by the PDP-STATE-CHANGE messages from PAP. If a request is made
14to the decision API while it is deactivated, a "404 - Not Found" error will be returned.
15
Pamela Dragoshb4a8ef22020-04-21 15:30:35 -040016.. csv-table::
17 :header: "Field", "Required", "XACML equivalent", "Description"
18
19 "ONAPName", "True", "subject", "The name of the ONAP project making the call"
20 "ONAPComponent", "True", "subject", "The name of the ONAP sub component making the call"
21 "ONAPInstance", "False", "subject", "An optional instance ID for that sub component"
22 "action", "True", "action", "The action being performed"
23 "resource", "True", "resource", "An object specific to the action that contains properties describing the resource"
24
25It is worth noting that we use basic authorization for API access with username and password set to *healthcheck* and *zb!XztG34* respectively.
26Also, the new APIs support both *http* and *https*.
27
28For every API call, the client is encouraged to insert an uuid-type requestID as parameter. It is helpful for tracking each http transaction
29and facilitates debugging. Most importantly, it complies with Logging requirements v1.2. If the client does not provide the requestID in the API call,
30one will be randomly generated and attached to the response header *x-onap-requestid*.
31
32In accordance with `ONAP API Common Versioning Strategy Guidelines <https://wiki.onap.org/display/DW/ONAP+API+Common+Versioning+Strategy+%28CVS%29+Guidelines>`_,
33in the response of each API call, several custom headers are added::
34
35 x-latestversion: 1.0.0
36 x-minorversion: 0
37 x-patchversion: 0
38 x-onap-requestid: e1763e61-9eef-4911-b952-1be1edd9812b
39
40x-latestversion is used only to communicate an API's latest version.
41
42x-minorversion is used to request or communicate a MINOR version back from the client to the server, and from the server back to the client.
43
44x-patchversion is used only to communicate a PATCH version in a response for troubleshooting purposes only, and will be provided to the client on request.
45
46x-onap-requestid is used to track REST transactions for logging purpose, as described above.
47
Pamela Dragosh1d101d22020-07-09 13:46:16 -040048:download:`Download the Decision API Swagger <swagger.json>`
49
Pamela Dragoshb4a8ef22020-04-21 15:30:35 -040050.. swaggerv2doc:: swagger.json
51
52
53End of Document