Download OpenAPI specification:Download
Entrosity Matrix portal REST API: per-tenant control of computer-room
internet access through FortiGate firewall policies, via an on-premises
connector (rooms on/off, "disable until", address objects of the
rooms' address groups, teacher room grants, history). This file is the source of
truth for the backend server interfaces (oapi-codegen), request
validation, and the frontend types (openapi-typescript). Run make gen
after editing.
Authentication: Authorization: Bearer <product token>: users sign in
on Entrosity Hub, which issues five-minute product tokens for Matrix
(POST /api/platform/v1/auth/product-token {"product":"matrix"}, with the
Hub's session cookie). Users, tenants (the Hub's organizations) and
roles are managed on the Hub; Matrix keeps a copy.
Every route's access rule (public, authenticated, global admin, tenant
permission) is declared in internal/http/portal/access.go and enforced
before the handler runs.
Returns a token valid for 60 seconds that opens
GET /tenants/{tenantID}/stream?sse_token= for the given tenant and
the caller's session. Access to the tenant is checked when the
stream opens. Keeps the access token out of URLs.
| tenant_id required | string <uuid> |
{- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0"
}{- "token": "string",
- "expires_in": 0
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "string",
- "display_name": "string",
- "status": "active",
- "is_global_admin": true,
- "memberships": [
- {
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "tenant_name": "string",
- "tenant_status": "active",
- "role": "tenant_admin"
}
], - "created_at": "2019-08-24T14:15:22Z"
}{- "tenants_total": 0,
- "tenants_active": 0,
- "global_admins": 0,
- "tenant_users": 0,
- "firewalls_total": 0,
- "firewalls_online": 0,
- "rooms_total": 0,
- "rooms_disabled": 0,
- "connectors_total": 0,
- "connectors_online": 0,
- "tenants": [
- {
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "name": "string",
- "status": "string",
- "firewalls_total": 0,
- "firewalls_online": 0,
- "rooms_total": 0,
- "connectors_total": 0,
- "connectors_online": 0
}
]
}Every stored Matrix connector installer (the newest ten), newest first, each with a link that needs no sign-in until download_expires_at; current marks the release connectors are updated to (MATRIX_CONNECTOR_UPDATE_CHANNEL). adoption counts the enrolled connectors by version. Empty when releases are off.
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "version": "string",
- "channel": "stable",
- "sha256": "string",
- "size_bytes": 0,
- "notes": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "current": true,
- "file_name": "string",
- "download_url": "string",
- "download_expires_at": "2019-08-24T14:15:22Z"
}
], - "adoption": [
- {
- "version": "string",
- "count": 0
}
], - "update_channel": "stable",
- "releases_enabled": true,
- "public_key": "string"
}| page | integer [ 1 .. 100000 ] Default: 1 |
| page_size | integer [ 1 .. 200 ] Default: 50 |
| q | string <= 200 characters |
| status | string (TenantStatus) Enum: "active" "suspended" |
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "slug": "string",
- "status": "active",
- "settings": {
- "default_timezone": "string",
- "retention": {
- "job_days": 7,
- "audit_days": 30
}
}, - "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}
], - "page": 0,
- "page_size": 0,
- "total": 0
}{- "users": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "string",
- "display_name": "string",
- "role": "global_admin",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "status": "active",
- "created_at": "2019-08-24T14:15:22Z"
}
]
}| page | integer [ 1 .. 100000 ] Default: 1 |
| page_size | integer [ 1 .. 200 ] Default: 50 |
| tenant_id | string <uuid> |
| actor_user_id | string <uuid> |
| action | string <= 100 characters |
| resource_type | string <= 100 characters |
| from | string <date-time> |
| to | string <date-time> |
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "ts": "2019-08-24T14:15:22Z",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "actor_user_id": "d6ed4497-4325-4995-9f49-e288b7192e46",
- "actor_email": "string",
- "action": "string",
- "resource_type": "string",
- "resource_id": "string",
- "before": { },
- "after": { },
- "ip": "string",
- "request_id": "string"
}
], - "page": 0,
- "page_size": 0,
- "total": 0
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "slug": "string",
- "status": "active",
- "settings": {
- "default_timezone": "string",
- "retention": {
- "job_days": 7,
- "audit_days": 30
}
}, - "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
object (TenantSettings) | |||||
| |||||
{- "settings": {
- "default_timezone": "string",
- "retention": {
- "job_days": 7,
- "audit_days": 30
}
}
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "slug": "string",
- "status": "active",
- "settings": {
- "default_timezone": "string",
- "retention": {
- "job_days": 7,
- "audit_days": 30
}
}, - "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
{- "connectors_total": 0,
- "connectors_online": 0,
- "firewalls_total": 0,
- "firewalls_online": 0,
- "rooms_total": 0,
- "rooms_disabled": 0,
- "schedules_open": 0,
- "sites_total": 0,
- "changes_today": 0,
- "changes_failed_today": 0
}| tenantID required | string <uuid> |
{- "users": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "string",
- "display_name": "string",
- "role": "global_admin",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "status": "active",
- "created_at": "2019-08-24T14:15:22Z"
}
]
}{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "name": "string",
- "description": "string",
- "timezone": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}
]
}| tenantID required | string <uuid> |
| name required | string [ 1 .. 200 ] characters |
| description | string <= 2000 characters |
| timezone | string [ 1 .. 64 ] characters |
{- "name": "string",
- "description": "string",
- "timezone": "string"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "name": "string",
- "description": "string",
- "timezone": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
| siteID required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "name": "string",
- "description": "string",
- "timezone": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
| siteID required | string <uuid> |
| name | string [ 1 .. 200 ] characters |
| description | string <= 2000 characters |
| timezone | string [ 1 .. 64 ] characters |
{- "name": "string",
- "description": "string",
- "timezone": "string"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "name": "string",
- "description": "string",
- "timezone": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
| siteID required | string <uuid> |
{- "type": "about:blank",
- "title": "string",
- "status": 0,
- "detail": "string",
- "code": "string",
- "instance": "string",
- "request_id": "string",
- "fields": {
- "property1": "string",
- "property2": "string"
}
}| tenantID required | string <uuid> |
| page | integer [ 1 .. 100000 ] Default: 1 |
| page_size | integer [ 1 .. 200 ] Default: 50 |
| actor_user_id | string <uuid> |
| action | string <= 100 characters |
| resource_type | string <= 100 characters |
| from | string <date-time> |
| to | string <date-time> |
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "ts": "2019-08-24T14:15:22Z",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "actor_user_id": "d6ed4497-4325-4995-9f49-e288b7192e46",
- "actor_email": "string",
- "action": "string",
- "resource_type": "string",
- "resource_id": "string",
- "before": { },
- "after": { },
- "ip": "string",
- "request_id": "string"
}
], - "page": 0,
- "page_size": 0,
- "total": 0
}| tenantID required | string <uuid> |
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "label": "string",
- "max_uses": 0,
- "uses": 0,
- "expires_at": "2019-08-24T14:15:22Z",
- "revoked_at": "2019-08-24T14:15:22Z",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_by_email": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "status": "active"
}
]
}| tenantID required | string <uuid> |
| label | string <= 200 characters |
| site_id | string <uuid> |
| expires_at | string <date-time> |
| max_uses | integer [ 1 .. 100000 ] |
{- "label": "string",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "expires_at": "2019-08-24T14:15:22Z",
- "max_uses": 1
}{- "token": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "label": "string",
- "max_uses": 0,
- "uses": 0,
- "expires_at": "2019-08-24T14:15:22Z",
- "revoked_at": "2019-08-24T14:15:22Z",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_by_email": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "status": "active"
}, - "secret": "string",
- "install_command": "string",
- "cli_command": "string",
- "download_url": "string"
}| tenantID required | string <uuid> |
| tokenID required | string <uuid> |
{- "type": "about:blank",
- "title": "string",
- "status": 0,
- "detail": "string",
- "code": "string",
- "instance": "string",
- "request_id": "string",
- "fields": {
- "property1": "string",
- "property2": "string"
}
}Global admins confirm with their own password: they send
step_up_token, which Entrosity Hub issues for the password
(POST /api/platform/v1/auth/step-up, product matrix).
| tenantID required | string <uuid> |
| tokenID required | string <uuid> |
| step_up_token required | string [ 1 .. 4096 ] characters |
{- "step_up_token": "string"
}{- "type": "about:blank",
- "title": "string",
- "status": 0,
- "detail": "string",
- "code": "string",
- "instance": "string",
- "request_id": "string",
- "fields": {
- "property1": "string",
- "property2": "string"
}
}The release connectors are updated to (MATRIX_CONNECTOR_UPDATE_CHANNEL). download_url needs no sign-in and works until download_expires_at. 404 when no release has been published.
| tenantID required | string <uuid> |
{- "version": "0.1.0",
- "channel": "stable",
- "sha256": "string",
- "size_bytes": 0,
- "notes": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "download_url": "string",
- "download_expires_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "name": "string",
- "hostname": "string",
- "domain": "string",
- "version": "string",
- "capabilities": [
- "string"
], - "status": "online",
- "last_seen_at": "2019-08-24T14:15:22Z",
- "firewall_count": 0,
- "created_at": "2019-08-24T14:15:22Z"
}
]
}| tenantID required | string <uuid> |
| connectorID required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "name": "string",
- "hostname": "string",
- "domain": "string",
- "version": "string",
- "capabilities": [
- "string"
], - "status": "online",
- "last_seen_at": "2019-08-24T14:15:22Z",
- "firewall_count": 0,
- "created_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
| connectorID required | string <uuid> |
| name | string <= 200 characters |
| site_id | string <uuid> |
| clear_site | boolean Remove the connector from its site. |
{- "name": "string",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "clear_site": true
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "name": "string",
- "hostname": "string",
- "domain": "string",
- "version": "string",
- "capabilities": [
- "string"
], - "status": "online",
- "last_seen_at": "2019-08-24T14:15:22Z",
- "firewall_count": 0,
- "created_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
| connectorID required | string <uuid> |
{- "type": "about:blank",
- "title": "string",
- "status": 0,
- "detail": "string",
- "code": "string",
- "instance": "string",
- "request_id": "string",
- "fields": {
- "property1": "string",
- "property2": "string"
}
}404 for teachers when the job concerns a room (or firewall) not granted to them.
| tenantID required | string <uuid> |
| jobID required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "policy_id": 0,
- "room_code": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "type": "string",
- "status": "created",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "sent_at": "2019-08-24T14:15:22Z",
- "finished_at": "2019-08-24T14:15:22Z",
- "progress_pct": 0,
- "progress_message": "string",
- "error_code": "string",
- "error": "string",
- "result": { }
}| tenantID required | string <uuid> |
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "name": "string",
- "driver": "fortigate",
- "host": "string",
- "port": 0,
- "vdom": "string",
- "src_intf": "string",
- "dst_intf": "string",
- "policy_pattern": "string",
- "building_labels": {
- "property1": "string",
- "property2": "string"
}, - "hostname_suffix": ".coding.local",
- "marker_prefix": "string",
- "verify_tls": true,
- "ca_pem": "string",
- "expected_version": "string",
- "report_interval_s": 0,
- "writes_enabled": true,
- "address_writes_enabled": true,
- "site_writes_enabled": true,
- "sites_supported": true,
- "enabled": true,
- "has_token": true,
- "credentials_version": 0,
- "status": "pending",
- "status_error": "string",
- "error_code": "string",
- "fortios_version": "string",
- "guard_state": "string",
- "last_report_at": "2019-08-24T14:15:22Z",
- "stale": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}
]
}The configuration is sent to the connector (matrix.firewall.apply).
writes_enabled and address_writes_enabled default to false. The
token is write-only (also PUT .../token). 422 with fields when
the configuration is invalid (e.g. policy_pattern without a
(?P<room>…) group).
| tenantID required | string <uuid> |
| name required | string [ 1 .. 200 ] characters |
| connector_id required | string <uuid> |
| site_id | string <uuid> |
| driver required | string (FirewallDriver) Enum: "fortigate" "simulator" simulator is an in-memory FortiGate built into the connector, for trials and tests. |
| host required | string [ 1 .. 253 ] characters |
| port | integer [ 1 .. 65535 ] Default: 443 |
| vdom | string [ 1 .. 79 ] characters Default: "root" |
| src_intf required | string [ 1 .. 79 ] characters |
| dst_intf required | string [ 1 .. 79 ] characters |
| policy_pattern required | string [ 1 .. 500 ] characters |
object <= 200 properties | |
| hostname_suffix required | string [ 2 .. 200 ] characters |
| marker_prefix | string [ 1 .. 64 ] characters |
| verify_tls | boolean Default: true |
| ca_pem | string <= 65536 characters |
| expected_version | string <= 20 characters |
| report_interval_s | integer [ 15 .. 300 ] Default: 30 |
| writes_enabled | boolean Default: false |
| address_writes_enabled | boolean Default: false |
| site_writes_enabled | boolean Default: false |
| enabled | boolean Default: true |
| token | string [ 1 .. 512 ] characters |
{- "name": "string",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "driver": "fortigate",
- "host": "string",
- "port": 443,
- "vdom": "root",
- "src_intf": "string",
- "dst_intf": "string",
- "policy_pattern": "string",
- "building_labels": {
- "property1": "string",
- "property2": "string"
}, - "hostname_suffix": "string",
- "marker_prefix": "string",
- "verify_tls": true,
- "ca_pem": "string",
- "expected_version": "string",
- "report_interval_s": 30,
- "writes_enabled": false,
- "address_writes_enabled": false,
- "site_writes_enabled": false,
- "enabled": true,
- "token": "string"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "name": "string",
- "driver": "fortigate",
- "host": "string",
- "port": 0,
- "vdom": "string",
- "src_intf": "string",
- "dst_intf": "string",
- "policy_pattern": "string",
- "building_labels": {
- "property1": "string",
- "property2": "string"
}, - "hostname_suffix": ".coding.local",
- "marker_prefix": "string",
- "verify_tls": true,
- "ca_pem": "string",
- "expected_version": "string",
- "report_interval_s": 0,
- "writes_enabled": true,
- "address_writes_enabled": true,
- "site_writes_enabled": true,
- "sites_supported": true,
- "enabled": true,
- "has_token": true,
- "credentials_version": 0,
- "status": "pending",
- "status_error": "string",
- "error_code": "string",
- "fortios_version": "string",
- "guard_state": "string",
- "last_report_at": "2019-08-24T14:15:22Z",
- "stale": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "name": "string",
- "driver": "fortigate",
- "host": "string",
- "port": 0,
- "vdom": "string",
- "src_intf": "string",
- "dst_intf": "string",
- "policy_pattern": "string",
- "building_labels": {
- "property1": "string",
- "property2": "string"
}, - "hostname_suffix": ".coding.local",
- "marker_prefix": "string",
- "verify_tls": true,
- "ca_pem": "string",
- "expected_version": "string",
- "report_interval_s": 0,
- "writes_enabled": true,
- "address_writes_enabled": true,
- "site_writes_enabled": true,
- "sites_supported": true,
- "enabled": true,
- "has_token": true,
- "credentials_version": 0,
- "status": "pending",
- "status_error": "string",
- "error_code": "string",
- "fortios_version": "string",
- "guard_state": "string",
- "last_report_at": "2019-08-24T14:15:22Z",
- "stale": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}Moving the firewall to another connector removes it from the old
one. Every change is re-applied (matrix.firewall.apply); a
disabled firewall is removed from its connector.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| name | string [ 1 .. 200 ] characters |
| connector_id | string <uuid> |
| site_id | string <uuid> |
| clear_site | boolean |
| driver | string (FirewallDriver) Enum: "fortigate" "simulator" simulator is an in-memory FortiGate built into the connector, for trials and tests. |
| host | string [ 1 .. 253 ] characters |
| port | integer [ 1 .. 65535 ] |
| vdom | string [ 1 .. 79 ] characters |
| src_intf | string [ 1 .. 79 ] characters |
| dst_intf | string [ 1 .. 79 ] characters |
| policy_pattern | string [ 1 .. 500 ] characters |
object <= 200 properties | |
| hostname_suffix | string [ 2 .. 200 ] characters |
| marker_prefix | string [ 1 .. 64 ] characters |
| verify_tls | boolean |
| ca_pem | string <= 65536 characters |
| expected_version | string <= 20 characters |
| report_interval_s | integer [ 15 .. 300 ] |
| writes_enabled | boolean |
| address_writes_enabled | boolean |
| site_writes_enabled | boolean |
| enabled | boolean |
{- "name": "string",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "clear_site": true,
- "driver": "fortigate",
- "host": "string",
- "port": 1,
- "vdom": "string",
- "src_intf": "string",
- "dst_intf": "string",
- "policy_pattern": "string",
- "building_labels": {
- "property1": "string",
- "property2": "string"
}, - "hostname_suffix": "string",
- "marker_prefix": "string",
- "verify_tls": true,
- "ca_pem": "string",
- "expected_version": "string",
- "report_interval_s": 15,
- "writes_enabled": true,
- "address_writes_enabled": true,
- "site_writes_enabled": true,
- "enabled": true
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "name": "string",
- "driver": "fortigate",
- "host": "string",
- "port": 0,
- "vdom": "string",
- "src_intf": "string",
- "dst_intf": "string",
- "policy_pattern": "string",
- "building_labels": {
- "property1": "string",
- "property2": "string"
}, - "hostname_suffix": ".coding.local",
- "marker_prefix": "string",
- "verify_tls": true,
- "ca_pem": "string",
- "expected_version": "string",
- "report_interval_s": 0,
- "writes_enabled": true,
- "address_writes_enabled": true,
- "site_writes_enabled": true,
- "sites_supported": true,
- "enabled": true,
- "has_token": true,
- "credentials_version": 0,
- "status": "pending",
- "status_error": "string",
- "error_code": "string",
- "fortios_version": "string",
- "guard_state": "string",
- "last_report_at": "2019-08-24T14:15:22Z",
- "stale": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
{- "type": "about:blank",
- "title": "string",
- "status": 0,
- "detail": "string",
- "code": "string",
- "instance": "string",
- "request_id": "string",
- "fields": {
- "property1": "string",
- "property2": "string"
}
}Stored encrypted, never returned; bumps credentials_version and re-applies the firewall.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| token required | string [ 1 .. 512 ] characters |
{- "token": "string"
}{- "type": "about:blank",
- "title": "string",
- "status": 0,
- "detail": "string",
- "code": "string",
- "instance": "string",
- "request_id": "string",
- "fields": {
- "property1": "string",
- "property2": "string"
}
}Creates a matrix.firewall.check job; its result (GET /jobs/{jobID}
or job.update) is a CheckResult. 409 connector_offline.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "policy_id": 0,
- "room_code": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "type": "string",
- "status": "created",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "sent_at": "2019-08-24T14:15:22Z",
- "finished_at": "2019-08-24T14:15:22Z",
- "progress_pct": 0,
- "progress_message": "string",
- "error_code": "string",
- "error": "string",
- "result": { }
}| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| scope required | string Enum: "rooms" "addresses" "all" |
{- "scope": "rooms"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "policy_id": 0,
- "room_code": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "type": "string",
- "status": "created",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "sent_at": "2019-08-24T14:15:22Z",
- "finished_at": "2019-08-24T14:15:22Z",
- "progress_pct": 0,
- "progress_message": "string",
- "error_code": "string",
- "error": "string",
- "result": { }
}Teachers see only the rooms granted to them and the firewalls they
hold a room on (firewalls keeps such a firewall even before its
rooms are reported, for its stale and connection state); a
teacher without grants gets empty lists. Tenant admins, global
admins and viewers see every room.
| tenantID required | string <uuid> |
| firewall_id | string <uuid> |
{- "firewalls": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "stale": true,
- "updated_at": "2019-08-24T14:15:22Z",
- "error": "string",
- "error_code": "string",
- "simulated": true,
- "guard_state": "string",
- "writes_enabled": true,
- "address_writes_enabled": true,
- "site_writes_enabled": true,
- "sites_supported": true,
- "shared_allowed_sites": 0,
- "status": "pending",
- "connector_online": true,
- "enabled": true
}
], - "rooms": [
- {
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "code": "SB1-102",
- "building": "string",
- "building_label": "string",
- "policy_id": 0,
- "policy_name": "string",
- "status": "enable",
- "present": true,
- "can_manage": true,
- "busy_job_id": "205b04f8-8435-4c58-a3d4-520c8ad3279e",
- "allowed_sites": 0,
- "schedule": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "reenable_at": "2019-08-24T14:15:22Z"
}, - "last_change": {
- "result": "pending",
- "at": "2019-08-24T14:15:22Z"
}
}
]
}Records the change (change) and sends a matrix.policy.set job.
reenable_at (disable only, 5 minutes to 7 days ahead) switches
the room on again then; enabling cancels a pending re-enable.
Errors: 403 forbidden; 404 unknown_room (for teachers also every
room not granted to them, which they do not see); 409 busy,
snapshot_stale, connector_offline, writes_disabled, unknown_room
(the firewall does not report the room); 429 rate_limited.
Refused attempts are recorded too.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| room required | string [ 1 .. 64 ] characters |
| status required | string (PolicyStatus) Enum: "enable" "disable" |
| reenable_at | string <date-time> Disable only: switch on again then (5 minutes to 7 days ahead). |
{- "status": "enable",
- "reenable_at": "2019-08-24T14:15:22Z"
}{- "change": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "kind": "policy",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "actor_email": "string",
- "ip": "string",
- "room": "string",
- "policy_id": 0,
- "policy_name": "string",
- "previous": "string",
- "desired": "string",
- "result": "pending",
- "detail": "string",
- "object_name": "string",
- "group_name": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "job_id": "453bd7d7-5355-4d6d-a38e-d9e7eb218c3f",
- "bulk_id": "2cabd00a-c72a-41d3-b208-4522c30a8fd2",
- "schedule_id": "8929bb67-0da1-406c-99d2-5447376a4f58",
- "source": "string",
- "metadata": { },
- "created_at": "2019-08-24T14:15:22Z"
}, - "job": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "policy_id": 0,
- "room_code": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "type": "string",
- "status": "created",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "sent_at": "2019-08-24T14:15:22Z",
- "finished_at": "2019-08-24T14:15:22Z",
- "progress_pct": 0,
- "progress_message": "string",
- "error_code": "string",
- "error": "string",
- "result": { }
}
}Teachers must hold a grant for every listed room, otherwise nothing
is sent (404 unknown_room: rooms not granted to them do not exist
for them); a building means its rooms granted to them. Each room
counts against the rate
limits. A room with a change already running is skipped
(items[].error = busy).
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| status required | string (PolicyStatus) Enum: "enable" "disable" |
| rooms | Array of strings [ 1 .. 2000 ] items [ items [ 1 .. 64 ] characters ] |
| building | string [ 1 .. 64 ] characters Every present room of the building (when rooms is not given). |
| reenable_at | string <date-time> |
{- "status": "enable",
- "rooms": [
- "string"
], - "building": "string",
- "reenable_at": "2019-08-24T14:15:22Z"
}{- "bulk": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "desired": "enable",
- "building": "string",
- "rooms": [
- "string"
], - "reenable_at": "2019-08-24T14:15:22Z",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "items": [
- {
- "room": "string",
- "change_id": "53a22efb-209d-4639-a6e7-7072a755c213",
- "job_id": "453bd7d7-5355-4d6d-a38e-d9e7eb218c3f",
- "result": "pending",
- "error": "string"
}
]
}
}404 for teachers when any of its rooms is not granted to them.
| tenantID required | string <uuid> |
| bulkID required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "desired": "enable",
- "building": "string",
- "rooms": [
- "string"
], - "reenable_at": "2019-08-24T14:15:22Z",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "items": [
- {
- "room": "string",
- "change_id": "53a22efb-209d-4639-a6e7-7072a755c213",
- "job_id": "453bd7d7-5355-4d6d-a38e-d9e7eb218c3f",
- "result": "pending",
- "error": "string"
}
]
}Teachers get only the schedules of the rooms granted to them.
| tenantID required | string <uuid> |
| status | string (ScheduleStatus) Enum: "pending" "firing" "done" "cancelled" "failed" |
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "room_code": "string",
- "policy_id": 0,
- "reenable_at": "2019-08-24T14:15:22Z",
- "status": "pending",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_by_email": "string",
- "disable_job_id": "cdb01658-22b2-4b65-a10e-06515d33a85d",
- "enable_job_id": "9ae42c9e-6bce-4b61-a6f2-f5b3f470aa2b",
- "bulk_id": "2cabd00a-c72a-41d3-b208-4522c30a8fd2",
- "detail": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}
]
}409 schedule_not_pending when it is already firing or finished; 404 unknown_room for a teacher when the room is not granted to them (recorded as refused).
| tenantID required | string <uuid> |
| scheduleID required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "room_code": "string",
- "policy_id": 0,
- "reenable_at": "2019-08-24T14:15:22Z",
- "status": "pending",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_by_email": "string",
- "disable_job_id": "cdb01658-22b2-4b65-a10e-06515d33a85d",
- "enable_job_id": "9ae42c9e-6bce-4b61-a6f2-f5b3f470aa2b",
- "bulk_id": "2cabd00a-c72a-41d3-b208-4522c30a8fd2",
- "detail": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}Teachers get only the groups of the rooms granted to them, and 404 for a firewall they hold no room on.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
{- "groups": [
- {
- "policy_id": 0,
- "name": "string",
- "room": "string",
- "building": "string",
- "count": 0,
- "version": "string",
- "editable": true,
- "reason": "string"
}
], - "stale": true,
- "updated_at": "2019-08-24T14:15:22Z",
- "error": "string"
}policy_id and group are required (422 when missing). 404 for a teacher when the group's room is not granted to them.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| policy_id | integer <int64> [ 1 .. 4294967295 ] |
| group | string [ 1 .. 255 ] characters |
{- "group": {
- "policy_id": 0,
- "name": "string",
- "room": "string",
- "building": "string",
- "count": 0,
- "version": "string",
- "editable": true,
- "reason": "string",
- "members": [
- {
- "name": "string",
- "ip": "string",
- "type": "string",
- "editable": true,
- "reason": "string"
}
]
}, - "operations": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "kind": "update",
- "policy_id": 0,
- "room": "string",
- "group_name": "string",
- "object_name": "string",
- "desired_ip": "string",
- "previous_ip": "string",
- "group_version": "string",
- "stage": "prepared",
- "address_uuid": "string",
- "result": "pending",
- "last_job_id": "ff50ec87-6f42-4569-b426-b1e2ecfdfc0f",
- "retryable": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}
], - "stale": true,
- "updated_at": "2019-08-24T14:15:22Z"
}Tenant admins only. request_id makes the request idempotent (the
same request returns the same operation). 409 conflict when the
group changed since group_version, busy while another address
change of the firewall runs.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| policy_id required | integer <int64> [ 1 .. 4294967295 ] |
| group required | string [ 1 .. 255 ] characters |
| name required | string [ 1 .. 255 ] characters |
| ip required | string <= 15 characters |
| expected_ip required | string <= 15 characters |
| group_version required | string^[0-9a-f]{64}$ |
| request_id required | string <uuid> |
{- "policy_id": 1,
- "group": "string",
- "name": "string",
- "ip": "string",
- "expected_ip": "string",
- "group_version": "string",
- "request_id": "266ea41d-adf5-480b-af50-15b940c2b846"
}{- "operation": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "kind": "update",
- "policy_id": 0,
- "room": "string",
- "group_name": "string",
- "object_name": "string",
- "desired_ip": "string",
- "previous_ip": "string",
- "group_version": "string",
- "stage": "prepared",
- "address_uuid": "string",
- "result": "pending",
- "last_job_id": "ff50ec87-6f42-4569-b426-b1e2ecfdfc0f",
- "retryable": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}, - "job": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "policy_id": 0,
- "room_code": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "type": "string",
- "status": "created",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "sent_at": "2019-08-24T14:15:22Z",
- "finished_at": "2019-08-24T14:15:22Z",
- "progress_pct": 0,
- "progress_message": "string",
- "error_code": "string",
- "error": "string",
- "result": { }
}, - "change": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "kind": "policy",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "actor_email": "string",
- "ip": "string",
- "room": "string",
- "policy_id": 0,
- "policy_name": "string",
- "previous": "string",
- "desired": "string",
- "result": "pending",
- "detail": "string",
- "object_name": "string",
- "group_name": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "job_id": "453bd7d7-5355-4d6d-a38e-d9e7eb218c3f",
- "bulk_id": "2cabd00a-c72a-41d3-b208-4522c30a8fd2",
- "schedule_id": "8929bb67-0da1-406c-99d2-5447376a4f58",
- "source": "string",
- "metadata": { },
- "created_at": "2019-08-24T14:15:22Z"
}
}| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| policy_id required | integer <int64> [ 1 .. 4294967295 ] |
| group required | string [ 1 .. 255 ] characters |
| name required | string [ 1 .. 255 ] characters |
| ip required | string <= 15 characters |
| group_version required | string^[0-9a-f]{64}$ |
| request_id required | string <uuid> |
{- "policy_id": 1,
- "group": "string",
- "name": "string",
- "ip": "string",
- "group_version": "string",
- "request_id": "266ea41d-adf5-480b-af50-15b940c2b846"
}{- "operation": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "kind": "update",
- "policy_id": 0,
- "room": "string",
- "group_name": "string",
- "object_name": "string",
- "desired_ip": "string",
- "previous_ip": "string",
- "group_version": "string",
- "stage": "prepared",
- "address_uuid": "string",
- "result": "pending",
- "last_job_id": "ff50ec87-6f42-4569-b426-b1e2ecfdfc0f",
- "retryable": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}, - "job": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "policy_id": 0,
- "room_code": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "type": "string",
- "status": "created",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "sent_at": "2019-08-24T14:15:22Z",
- "finished_at": "2019-08-24T14:15:22Z",
- "progress_pct": 0,
- "progress_message": "string",
- "error_code": "string",
- "error": "string",
- "result": { }
}, - "change": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "kind": "policy",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "actor_email": "string",
- "ip": "string",
- "room": "string",
- "policy_id": 0,
- "policy_name": "string",
- "previous": "string",
- "desired": "string",
- "result": "pending",
- "detail": "string",
- "object_name": "string",
- "group_name": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "job_id": "453bd7d7-5355-4d6d-a38e-d9e7eb218c3f",
- "bulk_id": "2cabd00a-c72a-41d3-b208-4522c30a8fd2",
- "schedule_id": "8929bb67-0da1-406c-99d2-5447376a4f58",
- "source": "string",
- "metadata": { },
- "created_at": "2019-08-24T14:15:22Z"
}
}| tenantID required | string <uuid> |
| operationID required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "kind": "update",
- "policy_id": 0,
- "room": "string",
- "group_name": "string",
- "object_name": "string",
- "desired_ip": "string",
- "previous_ip": "string",
- "group_version": "string",
- "stage": "prepared",
- "address_uuid": "string",
- "result": "pending",
- "last_job_id": "ff50ec87-6f42-4569-b426-b1e2ecfdfc0f",
- "retryable": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}409 not_retryable when it never started writing (prepared) or is done.
| tenantID required | string <uuid> |
| operationID required | string <uuid> |
| group_version required | string^[0-9a-f]{64}$ |
{- "group_version": "string"
}{- "operation": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "kind": "update",
- "policy_id": 0,
- "room": "string",
- "group_name": "string",
- "object_name": "string",
- "desired_ip": "string",
- "previous_ip": "string",
- "group_version": "string",
- "stage": "prepared",
- "address_uuid": "string",
- "result": "pending",
- "last_job_id": "ff50ec87-6f42-4569-b426-b1e2ecfdfc0f",
- "retryable": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}, - "job": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "policy_id": 0,
- "room_code": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "type": "string",
- "status": "created",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "sent_at": "2019-08-24T14:15:22Z",
- "finished_at": "2019-08-24T14:15:22Z",
- "progress_pct": 0,
- "progress_message": "string",
- "error_code": "string",
- "error": "string",
- "result": { }
}, - "change": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "kind": "policy",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "actor_email": "string",
- "ip": "string",
- "room": "string",
- "policy_id": 0,
- "policy_name": "string",
- "previous": "string",
- "desired": "string",
- "result": "pending",
- "detail": "string",
- "object_name": "string",
- "group_name": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "job_id": "453bd7d7-5355-4d6d-a38e-d9e7eb218c3f",
- "bulk_id": "2cabd00a-c72a-41d3-b208-4522c30a8fd2",
- "schedule_id": "8929bb67-0da1-406c-99d2-5447376a4f58",
- "source": "string",
- "metadata": { },
- "created_at": "2019-08-24T14:15:22Z"
}
}Domains the rooms' computers can still reach while a room's
internet is off, as last reported by the connector. rooms holds a
list for every present room (exists: false when its address group
is not set up). can_edit says whether the caller may change a list
(tenant admins: every list; teachers: the lists of rooms granted to
them). Readable by everyone who can read rooms; teachers get the
shared list (read only) and the lists of the rooms granted to them,
and 404 for a firewall they hold no room on.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
{- "firewall": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "stale": true,
- "updated_at": "2019-08-24T14:15:22Z",
- "error": "string",
- "status": "pending",
- "connector_online": true,
- "enabled": true,
- "guard_state": "string",
- "site_writes_enabled": true,
- "sites_supported": true
}, - "shared": {
- "list": "string",
- "room": "string",
- "building": "string",
- "group": "string",
- "exists": true,
- "policy": {
- "policy_id": 0,
- "name": "string",
- "status": "enable",
- "covers": true
}, - "setup": "ok",
- "version": "string",
- "editable": true,
- "reason": "string",
- "domains": [
- {
- "domain": "string",
- "object": "string",
- "owned": true,
- "editable": true,
- "reason": "string"
}
], - "can_edit": true,
- "busy_job_id": "205b04f8-8435-4c58-a3d4-520c8ad3279e",
- "last_change": {
- "result": "pending",
- "at": "2019-08-24T14:15:22Z"
}
}, - "rooms": [
- {
- "list": "string",
- "room": "string",
- "building": "string",
- "group": "string",
- "exists": true,
- "policy": {
- "policy_id": 0,
- "name": "string",
- "status": "enable",
- "covers": true
}, - "setup": "ok",
- "version": "string",
- "editable": true,
- "reason": "string",
- "domains": [
- {
- "domain": "string",
- "object": "string",
- "owned": true,
- "editable": true,
- "reason": "string"
}
], - "can_edit": true,
- "busy_job_id": "205b04f8-8435-4c58-a3d4-520c8ad3279e",
- "last_change": {
- "result": "pending",
- "at": "2019-08-24T14:15:22Z"
}
}
], - "can_setup": true
}Text to paste into the FortiGate CLI: the address groups (member
"none") and ACCEPT policies (edit 0, the firewall's source →
destination, srcaddr = the room address groups) of the shared list
and the per-room lists named in rooms, only where they are
missing. Matrix never creates policies itself.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| rooms | string <= 20000 characters Comma-separated room codes whose per-room lists should be set up too. |
{- "cli": "string",
- "lists": [
- "string"
], - "warnings": [
- "string"
]
}domains is the full desired set of Matrix-managed domains
(canonicalized: lower-case, sorted, duplicates removed; at most
200). Records the change (change, kind sites) and sends a
matrix.sites.set job. The shared list: tenant admins only;
a per-room list: tenant admins and teachers the room is granted to.
Errors: 403 forbidden / group_read_only (Matrix
may not change the group on the FortiGate); 409 busy, conflict (the
list changed since list_version), snapshot_stale,
connector_offline, connector_outdated (the connector does not
support allowed sites yet), writes_disabled (allowed-sites editing
is off for the firewall), sites_not_set_up, unknown_room; 404
unknown_room for a teacher when the room is not granted to them; 422
invalid_domain; 429 rate_limited. Refused attempts are recorded too.
| tenantID required | string <uuid> |
| firewallID required | string <uuid> |
| list required | string [ 1 .. 64 ] characters
|
| domains required | Array of strings <= 200 items [ items [ 1 .. 253 ] characters ] |
| list_version required | string^[0-9a-f]{64}$ |
{- "domains": [
- "string"
], - "list_version": "string"
}{- "change": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "kind": "policy",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "actor_email": "string",
- "ip": "string",
- "room": "string",
- "policy_id": 0,
- "policy_name": "string",
- "previous": "string",
- "desired": "string",
- "result": "pending",
- "detail": "string",
- "object_name": "string",
- "group_name": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "job_id": "453bd7d7-5355-4d6d-a38e-d9e7eb218c3f",
- "bulk_id": "2cabd00a-c72a-41d3-b208-4522c30a8fd2",
- "schedule_id": "8929bb67-0da1-406c-99d2-5447376a4f58",
- "source": "string",
- "metadata": { },
- "created_at": "2019-08-24T14:15:22Z"
}, - "job": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "connector_id": "9389ba6f-3696-4571-84d4-34d588c4b109",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "policy_id": 0,
- "room_code": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "type": "string",
- "status": "created",
- "created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
- "created_at": "2019-08-24T14:15:22Z",
- "sent_at": "2019-08-24T14:15:22Z",
- "finished_at": "2019-08-24T14:15:22Z",
- "progress_pct": 0,
- "progress_message": "string",
- "error_code": "string",
- "error": "string",
- "result": { }
}
}| tenantID required | string <uuid> |
| user_id | string <uuid> |
{- "items": [
- {
- "user_id": "a169451c-8525-4352-b8ca-070dd449a1a5",
- "user_email": "string",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "room_code": "string",
- "granted_by": "a8e4a498-f971-4203-a849-4967743579d4",
- "created_at": "2019-08-24T14:15:22Z"
}
]
}Recorded as a grants change. Rooms to add must be known rooms of
the firewall; removing is always possible. 422 not_teacher when
the user is not a teacher of the tenant.
| tenantID required | string <uuid> |
| userID required | string <uuid> |
| firewall_id required | string <uuid> |
| rooms required | Array of strings <= 2000 items [ items [ 1 .. 64 ] characters ] |
{- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "rooms": [
- "string"
]
}{- "items": [
- {
- "user_id": "a169451c-8525-4352-b8ca-070dd449a1a5",
- "user_email": "string",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "room_code": "string",
- "granted_by": "a8e4a498-f971-4203-a849-4967743579d4",
- "created_at": "2019-08-24T14:15:22Z"
}
]
}Teachers get only the changes of the rooms granted to them (including their own refused attempts on those rooms); changes without a room (firewall, grant, shared-list changes) are left out.
| tenantID required | string <uuid> |
| from | string <date-time> |
| to | string <date-time> |
| user_id | string <uuid> |
| room | string <= 64 characters Part of a room code (case-insensitive). |
| kind | string (ChangeKind) Enum: "policy" "address_update" "address_create" "grants" "schedule" "bulk" "sites" "services" What a change did. |
| firewall_id | string <uuid> |
| cursor | string <= 200 characters next_cursor of the previous page. |
| limit | integer [ 1 .. 200 ] Default: 50 |
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "firewall_id": "5b8ae62a-9fb0-43bd-91d3-a9c16b3ec753",
- "kind": "policy",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "actor_email": "string",
- "ip": "string",
- "room": "string",
- "policy_id": 0,
- "policy_name": "string",
- "previous": "string",
- "desired": "string",
- "result": "pending",
- "detail": "string",
- "object_name": "string",
- "group_name": "string",
- "operation_id": "cb4ede3c-a5d1-45e3-a9d2-fe83accbce52",
- "job_id": "453bd7d7-5355-4d6d-a38e-d9e7eb218c3f",
- "bulk_id": "2cabd00a-c72a-41d3-b208-4522c30a8fd2",
- "schedule_id": "8929bb67-0da1-406c-99d2-5447376a4f58",
- "source": "string",
- "metadata": { },
- "created_at": "2019-08-24T14:15:22Z"
}
], - "next_cursor": "string"
}text/event-stream of the tenant's live updates: matrix.rooms
({firewall_id}: reload the rooms), matrix.addresses
({firewall_id}: reload the address groups), matrix.sites
({firewall_id}: reload the allowed sites), matrix.change
(a change event finished), connector.status and job.update. Authenticate with a bearer token or, for EventSource,
?sse_token= from POST /auth/sse-token. Teachers get only the
events of the rooms granted to them (matrix.change: changes of
those rooms; job.update: their jobs) and of the firewalls they
hold a room on.
| tenantID required | string <uuid> |
| sse_token | string <= 4096 characters |
{- "type": "about:blank",
- "title": "string",
- "status": 0,
- "detail": "string",
- "code": "string",
- "instance": "string",
- "request_id": "string",
- "fields": {
- "property1": "string",
- "property2": "string"
}
}