navidrome/api/openapi/components/schemas/TokenRequest.yaml
Deluan 294c1a9a6a feat(api): add API v1 login, setup, token, grant and password endpoints
Adds the seven auth operations to the spec (createAccessToken, listGrants,
revokeGrant and logout in core; login, setupFirstAdmin and changePassword in
the password module), the bearerAuth/grantAuth schemes, and vacuum rules
requiring explicit security and a known x-scope. The strict handlers sit on
core/apiauth and are covered end to end against a real SQLite database.

The first operations with parameters make the generated code import
github.com/oapi-codegen/runtime. An oapi-codegen overlay renames the shared
offset/limit parameter types, since a generated Offset clashes with Ginkgo's
dot-imported Offset in this package's tests; the published spec is unchanged.
2026-09-28 20:06:27 -04:00

9 lines
266 B
YAML

type: object
description: Optional narrowing of a new access token.
properties:
scopes:
type: array
maxItems: 32
description: "Subset of the grant's scopes. Omit for all of them; an empty list asks for none."
items:
$ref: ./ScopeRequest.yaml