REST-Endpunkte
Neben GraphQL gibt es ein paar einfache HTTP-Endpunkte: die Anmeldung im Browser, Health-Checks und PDF-Berichte. Alles andere läuft über GraphQL.
https://vulnara-gw.rso.devSign-in
GET/auth/oauth2
Start browser sign-in
Redirects the browser to the Vulnara sign-in page. After sign-in the browser comes back to the callback below.
Antworten
| Name | Beschreibung |
|---|---|
| 302 | Redirect to the sign-in page. |
curl "https://vulnara-gw.rso.dev/auth/oauth2"GET/auth/oauth2/callback
Finish browser sign-in
The sign-in page redirects here. The gateway exchanges the code for tokens and hands them to the web app. You do not call this yourself.
Parameter
| Name | Typ | Beschreibung |
|---|---|---|
| codePflicht | query | |
| statePflicht | query |
Antworten
| Name | Beschreibung |
|---|---|
| 302 | Redirect to the web app, signed in, or to the sign-in failure page. |
curl "https://vulnara-gw.rso.dev/auth/oauth2/callback"POST/auth/oauth2/refresh
Refresh an access token
Swap a refresh token for a new access token and refresh token.
Antworten
| Name | Beschreibung |
|---|---|
| 200 | New tokens. |
| 400 | The refresh token is missing, expired or revoked. Sign in again. |
curl -X POST "https://vulnara-gw.rso.dev/auth/oauth2/refresh" \
-H "Content-Type: application/json" \
-d '{"refreshToken":"<refresh token>"}'Health
GET/health/live
Liveness
Answers while the gateway process is running.
Antworten
| Name | Beschreibung |
|---|---|
| 200 | Running. |
curl "https://vulnara-gw.rso.dev/health/live"GET/health/ready
Readiness
Answers 200 when the gateway can serve requests.
Antworten
| Name | Beschreibung |
|---|---|
| 200 | Ready. |
| 503 | Not ready yet. |
curl "https://vulnara-gw.rso.dev/health/ready"Reports
GET/reports/summary
Security summary report
A PDF summary of the security posture of the whole workspace.
Parameter
| Name | Typ | Beschreibung |
|---|---|---|
| X-Tenant | header | Workspace id. Optional when you belong to one workspace only. |
Antworten
| Name | Beschreibung |
|---|---|
| 200 | The report as a PDF download. |
| 401 | Missing or invalid bearer token. |
| 403 | You are not a member of the requested workspace. |
| 404 | The item does not exist in this workspace. |
| 502 | The report could not be generated. Try again. |
curl "https://vulnara-gw.rso.dev/reports/summary" \
-H "Authorization: Bearer $VULNARA_TOKEN" \
-H "X-Tenant: $VULNARA_TENANT" \
-o report.pdfGET/reports/scan/{id}
Scan report
A PDF report for one scan result.
Parameter
| Name | Typ | Beschreibung |
|---|---|---|
| idPflicht | path | Id of the scan result. |
| X-Tenant | header | Workspace id. Optional when you belong to one workspace only. |
Antworten
| Name | Beschreibung |
|---|---|
| 200 | The report as a PDF download. |
| 401 | Missing or invalid bearer token. |
| 403 | You are not a member of the requested workspace. |
| 404 | The item does not exist in this workspace. |
| 502 | The report could not be generated. Try again. |
curl "https://vulnara-gw.rso.dev/reports/scan/<id>" \
-H "Authorization: Bearer $VULNARA_TOKEN" \
-H "X-Tenant: $VULNARA_TENANT" \
-o report.pdfGET/reports/workspace/{id}
Git workspace report
A PDF report for one GitHub or GitLab organisation or user.
Parameter
| Name | Typ | Beschreibung |
|---|---|---|
| idPflicht | path | Id of the git workspace. |
| X-Tenant | header | Workspace id. Optional when you belong to one workspace only. |
Antworten
| Name | Beschreibung |
|---|---|
| 200 | The report as a PDF download. |
| 401 | Missing or invalid bearer token. |
| 403 | You are not a member of the requested workspace. |
| 404 | The item does not exist in this workspace. |
| 502 | The report could not be generated. Try again. |
curl "https://vulnara-gw.rso.dev/reports/workspace/<id>" \
-H "Authorization: Bearer $VULNARA_TOKEN" \
-H "X-Tenant: $VULNARA_TENANT" \
-o report.pdfGET/reports/repository/{id}
Repository report
A PDF report for one repository.
Parameter
| Name | Typ | Beschreibung |
|---|---|---|
| idPflicht | path | Id of the repository. |
| X-Tenant | header | Workspace id. Optional when you belong to one workspace only. |
Antworten
| Name | Beschreibung |
|---|---|
| 200 | The report as a PDF download. |
| 401 | Missing or invalid bearer token. |
| 403 | You are not a member of the requested workspace. |
| 404 | The item does not exist in this workspace. |
| 502 | The report could not be generated. Try again. |
curl "https://vulnara-gw.rso.dev/reports/repository/<id>" \
-H "Authorization: Bearer $VULNARA_TOKEN" \
-H "X-Tenant: $VULNARA_TENANT" \
-o report.pdf