From 976a74b81bab62c2cd4d7725cdfb3586013696e7 Mon Sep 17 00:00:00 2001 From: Herbert Damker <52109189+hdamker@users.noreply.github.com> Date: Wed, 23 Sep 2026 20:35:48 +0200 Subject: [PATCH 01/14] fix: bump x-camara-commonalities to 0.9.0 and re-sync error-response template --- code/API_definitions/location-retrieval.yaml | 5 +++-- code/API_definitions/location-verification.yaml | 5 +++-- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/code/API_definitions/location-retrieval.yaml b/code/API_definitions/location-retrieval.yaml index 80131db5..e8c6cd07 100644 --- a/code/API_definitions/location-retrieval.yaml +++ b/code/API_definitions/location-retrieval.yaml @@ -102,11 +102,12 @@ info: - Check with the API provider whether a unique "secondary" phone number is already associated with each device and use the secondary phone number to identify the intended device if available. + # Additional CAMARA error responses The list of error codes in this API specification is not exhaustive. Therefore the API specification MAY not document some non-mandatory error statuses as indicated in `CAMARA API Design Guide`. - Please refer to the `CAMARA_common.yaml` of the Commonalities Release associated to this API version for a complete list of error responses. The applicable Commonalities Release can be identified in the `API Readiness Checklist` document associated to this API version. + Please refer to the `CAMARA_common.yaml` of the Commonalities Release associated to this API version for a complete list of error responses. The applicable Commonalities Release can be identified from the `x-camara-commonalities` field, the changelog and the metadata of the released API version. As a specific rule, error `501 - NOT_IMPLEMENTED` can be only a possible error response if it is explicitly documented in the API. @@ -124,7 +125,7 @@ info: license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html - x-camara-commonalities: 0.8.0 + x-camara-commonalities: 0.9.0 externalDocs: description: Product documentation at CAMARA url: https://github.com/camaraproject/DeviceLocation diff --git a/code/API_definitions/location-verification.yaml b/code/API_definitions/location-verification.yaml index 9c1d54be..757e2d2d 100644 --- a/code/API_definitions/location-verification.yaml +++ b/code/API_definitions/location-verification.yaml @@ -86,11 +86,12 @@ info: - Check with the API provider whether a unique "secondary" phone number is already associated with each device and use the secondary phone number to identify the intended device if available. + # Additional CAMARA error responses The list of error codes in this API specification is not exhaustive. Therefore the API specification MAY not document some non-mandatory error statuses as indicated in `CAMARA API Design Guide`. - Please refer to the `CAMARA_common.yaml` of the Commonalities Release associated to this API version for a complete list of error responses. The applicable Commonalities Release can be identified in the `API Readiness Checklist` document associated to this API version. + Please refer to the `CAMARA_common.yaml` of the Commonalities Release associated to this API version for a complete list of error responses. The applicable Commonalities Release can be identified from the `x-camara-commonalities` field, the changelog and the metadata of the released API version. As a specific rule, error `501 - NOT_IMPLEMENTED` can be only a possible error response if it is explicitly documented in the API. @@ -108,7 +109,7 @@ info: license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html - x-camara-commonalities: 0.8.0 + x-camara-commonalities: 0.9.0 externalDocs: description: Product documentation at CAMARA url: https://github.com/camaraproject/DeviceLocation From 363b43af23101ff461fed32b6fc00aa85a17a877 Mon Sep 17 00:00:00 2001 From: Herbert Damker <52109189+hdamker@users.noreply.github.com> Date: Wed, 23 Sep 2026 20:36:53 +0200 Subject: [PATCH 02/14] fix: migrate location-retrieval/verification to Commonalities r4.4 catalogue responses --- code/API_definitions/location-retrieval.yaml | 94 +++---------------- .../location-verification.yaml | 90 +++--------------- 2 files changed, 22 insertions(+), 162 deletions(-) diff --git a/code/API_definitions/location-retrieval.yaml b/code/API_definitions/location-retrieval.yaml index e8c6cd07..aa98f642 100644 --- a/code/API_definitions/location-retrieval.yaml +++ b/code/API_definitions/location-retrieval.yaml @@ -210,13 +210,13 @@ paths: LOCATION_CIRCLE_WITH_DEVICE: $ref: "#/components/examples/LOCATION_CIRCLE_WITH_DEVICE" '400': - $ref: '../common/CAMARA_common.yaml#/components/responses/Generic400' + $ref: '../common/CAMARA_common.yaml#/components/responses/BadRequestWithRange400' '401': - $ref: '../common/CAMARA_common.yaml#/components/responses/Generic401' + $ref: '../common/CAMARA_common.yaml#/components/responses/Unauthenticated401' '403': - $ref: '#/components/responses/Generic403' + $ref: '../common/CAMARA_common.yaml#/components/responses/PermissionDenied403' '404': - $ref: '#/components/responses/RetrieveLocationNotFound404' + $ref: '../common/CAMARA_common.yaml#/components/responses/IdentifierNotFound404' '422': $ref: '#/components/responses/RetrieveLocationUnprocessableEntity422' security: @@ -301,58 +301,6 @@ components: example: "2023-09-07T10:40:52Z" responses: - Generic403: - description: Forbidden - headers: - x-correlator: - $ref: '../common/CAMARA_common.yaml#/components/headers/x-correlator' - content: - application/json: - schema: - allOf: - - $ref: '../common/CAMARA_common.yaml#/components/schemas/ErrorInfo' - - type: object - properties: - status: - enum: - - 403 - code: - enum: - - PERMISSION_DENIED - examples: - GENERIC_403_PERMISSION_DENIED: - summary: Permission denied - description: Permission denied. OAuth2 token access does not have the required scope or when the user fails operational security - value: - status: 403 - code: PERMISSION_DENIED - message: Client does not have sufficient permissions to perform this action. - RetrieveLocationNotFound404: - description: Not found - headers: - x-correlator: - $ref: '../common/CAMARA_common.yaml#/components/headers/x-correlator' - content: - application/json: - schema: - allOf: - - $ref: '../common/CAMARA_common.yaml#/components/schemas/ErrorInfo' - - type: object - properties: - status: - enum: - - 404 - code: - enum: - - IDENTIFIER_NOT_FOUND - examples: - GENERIC_404_IDENTIFIER_NOT_FOUND: - summary: Identifier not found - description: Some identifier cannot be matched to a device - value: - status: 404 - code: IDENTIFIER_NOT_FOUND - message: Device identifier not found. RetrieveLocationUnprocessableEntity422: description: Unprocessable Content headers: @@ -379,33 +327,13 @@ components: - LOCATION_RETRIEVAL.UNABLE_TO_LOCATE examples: GENERIC_422_SERVICE_NOT_APPLICABLE: - summary: Service not applicable - description: Service not applicable for the provided identifier - value: - status: 422 - code: SERVICE_NOT_APPLICABLE - message: The service is not available for the provided identifier. - GENERIC_422_MISSING_IDENTIFIER: - summary: Missing identifier - description: An identifier is not included in the request and the device or phone number identification cannot be derived from the 3-legged access token - value: - status: 422 - code: MISSING_IDENTIFIER - message: The device cannot be identified. - GENERIC_422_UNSUPPORTED_IDENTIFIER: - summary: Unsupported identifier - description: None of the provided identifiers is supported by the implementation - value: - status: 422 - code: UNSUPPORTED_IDENTIFIER - message: The identifier provided is not supported. - GENERIC_422_UNNECESSARY_IDENTIFIER: - summary: Unnecessary identifier - description: An explicit identifier is provided when a device or phone number has already been identified from the access token - value: - status: 422 - code: UNNECESSARY_IDENTIFIER - message: The device is already identified by the access token. + $ref: '../common/CAMARA_common.yaml#/components/examples/GENERIC_422_SERVICE_NOT_APPLICABLE' + GENERIC_422_MISSING_IDENTIFIER_DEVICE: + $ref: '../common/CAMARA_common.yaml#/components/examples/GENERIC_422_MISSING_IDENTIFIER_DEVICE' + GENERIC_422_UNSUPPORTED_IDENTIFIER_DEVICE: + $ref: '../common/CAMARA_common.yaml#/components/examples/GENERIC_422_UNSUPPORTED_IDENTIFIER_DEVICE' + GENERIC_422_UNNECESSARY_IDENTIFIER_DEVICE: + $ref: '../common/CAMARA_common.yaml#/components/examples/GENERIC_422_UNNECESSARY_IDENTIFIER_DEVICE' LOCATION_RETRIEVAL_422_UNABLE_TO_FULFILL_MAX_AGE: summary: Unable to fulfill maxAge description: The system is not able to provide the fresh location required by the client diff --git a/code/API_definitions/location-verification.yaml b/code/API_definitions/location-verification.yaml index 757e2d2d..1bfe0014 100644 --- a/code/API_definitions/location-verification.yaml +++ b/code/API_definitions/location-verification.yaml @@ -233,13 +233,13 @@ paths: matchRate: 74 lastLocationTime: "2023-09-07T10:40:52Z" "400": - $ref: "../common/CAMARA_common.yaml#/components/responses/Generic400" + $ref: "../common/CAMARA_common.yaml#/components/responses/BadRequestWithRange400" "401": - $ref: "../common/CAMARA_common.yaml#/components/responses/Generic401" + $ref: "../common/CAMARA_common.yaml#/components/responses/Unauthenticated401" "403": - $ref: "#/components/responses/Generic403" + $ref: "../common/CAMARA_common.yaml#/components/responses/PermissionDenied403" "404": - $ref: "#/components/responses/VerifyLocationNotFound404" + $ref: "../common/CAMARA_common.yaml#/components/responses/IdentifierNotFound404" "422": $ref: "#/components/responses/VerifyLocationUnprocessableEntity422" security: @@ -361,58 +361,6 @@ components: example: "2023-09-07T10:40:52Z" responses: - Generic403: - description: Forbidden - headers: - x-correlator: - $ref: "../common/CAMARA_common.yaml#/components/headers/x-correlator" - content: - application/json: - schema: - allOf: - - $ref: "../common/CAMARA_common.yaml#/components/schemas/ErrorInfo" - - type: object - properties: - status: - enum: - - 403 - code: - enum: - - PERMISSION_DENIED - examples: - GENERIC_403_PERMISSION_DENIED: - description: Permission denied. OAuth2 token access does not have the required scope or when the user fails operational security - value: - status: 403 - code: PERMISSION_DENIED - message: Client does not have sufficient permissions to perform this action. - - VerifyLocationNotFound404: - description: Not found - headers: - x-correlator: - $ref: "../common/CAMARA_common.yaml#/components/headers/x-correlator" - content: - application/json: - schema: - allOf: - - $ref: "../common/CAMARA_common.yaml#/components/schemas/ErrorInfo" - - type: object - properties: - status: - enum: - - 404 - code: - enum: - - IDENTIFIER_NOT_FOUND - examples: - GENERIC_404_IDENTIFIER_NOT_FOUND: - description: Some identifier cannot be matched to a device - value: - status: 404 - code: IDENTIFIER_NOT_FOUND - message: Device identifier not found. - VerifyLocationUnprocessableEntity422: description: Unprocessable Content headers: @@ -440,29 +388,13 @@ components: - LOCATION_VERIFICATION.UNABLE_TO_LOCATE examples: GENERIC_422_SERVICE_NOT_APPLICABLE: - description: Service not applicable for the provided identifier - value: - status: 422 - code: SERVICE_NOT_APPLICABLE - message: The service is not available for the provided identifier. - GENERIC_422_MISSING_IDENTIFIER: - description: An identifier is not included in the request and the device or phone number identification cannot be derived from the 3-legged access token - value: - status: 422 - code: MISSING_IDENTIFIER - message: The device cannot be identified. - GENERIC_422_UNSUPPORTED_IDENTIFIER: - description: None of the provided identifiers is supported by the implementation - value: - status: 422 - code: UNSUPPORTED_IDENTIFIER - message: The identifier provided is not supported. - GENERIC_422_UNNECESSARY_IDENTIFIER: - description: An explicit identifier is provided when a device or phone number has already been identified from the access token - value: - status: 422 - code: UNNECESSARY_IDENTIFIER - message: The device is already identified by the access token. + $ref: "../common/CAMARA_common.yaml#/components/examples/GENERIC_422_SERVICE_NOT_APPLICABLE" + GENERIC_422_MISSING_IDENTIFIER_DEVICE: + $ref: "../common/CAMARA_common.yaml#/components/examples/GENERIC_422_MISSING_IDENTIFIER_DEVICE" + GENERIC_422_UNSUPPORTED_IDENTIFIER_DEVICE: + $ref: "../common/CAMARA_common.yaml#/components/examples/GENERIC_422_UNSUPPORTED_IDENTIFIER_DEVICE" + GENERIC_422_UNNECESSARY_IDENTIFIER_DEVICE: + $ref: "../common/CAMARA_common.yaml#/components/examples/GENERIC_422_UNNECESSARY_IDENTIFIER_DEVICE" LOCATION_VERIFICATION_422_AREA_NOT_COVERED: summary: The area cannot be covered description: The system is not able cover the requested area From ac346fd8288812564e9d01f9b07657cba19174cc Mon Sep 17 00:00:00 2001 From: Herbert Damker <52109189+hdamker@users.noreply.github.com> Date: Wed, 23 Sep 2026 20:37:09 +0200 Subject: [PATCH 03/14] fix(location-retrieval): remove unused schema aliases --- code/API_definitions/location-retrieval.yaml | 24 -------------------- 1 file changed, 24 deletions(-) diff --git a/code/API_definitions/location-retrieval.yaml b/code/API_definitions/location-retrieval.yaml index aa98f642..fa4b9f7c 100644 --- a/code/API_definitions/location-retrieval.yaml +++ b/code/API_definitions/location-retrieval.yaml @@ -249,36 +249,12 @@ components: maximum: 2147483647 description: Maximum surface in square meters which is accepted by the client for the location retrieval. Absence of maxSurface means "any surface size". example: 1000000 - Device: - $ref: '../common/CAMARA_common.yaml#/components/schemas/Device' - DeviceResponse: $ref: '../common/CAMARA_common.yaml#/components/schemas/DeviceResponse' Area: $ref: '../common/CAMARA_common.yaml#/components/schemas/Area' - AreaType: - $ref: '../common/CAMARA_common.yaml#/components/schemas/AreaType' - - Circle: - $ref: '../common/CAMARA_common.yaml#/components/schemas/Circle' - - Polygon: - $ref: '../common/CAMARA_common.yaml#/components/schemas/Polygon' - - PointList: - $ref: '../common/CAMARA_common.yaml#/components/schemas/PointList' - - Point: - $ref: '../common/CAMARA_common.yaml#/components/schemas/Point' - - Latitude: - $ref: '../common/CAMARA_common.yaml#/components/schemas/Latitude' - - Longitude: - $ref: '../common/CAMARA_common.yaml#/components/schemas/Longitude' - Location: type: object description: Device location From 1bfbc29e6131f69af6a74fc9d5e4d5991db3426a Mon Sep 17 00:00:00 2001 From: Herbert Damker <52109189+hdamker@users.noreply.github.com> Date: Wed, 23 Sep 2026 20:37:28 +0200 Subject: [PATCH 04/14] fix: normalize OAS pointer prefixes in location-retrieval/verification feature files --- .../location-retrieval.feature | 18 +++++----- .../location-verification.feature | 36 +++++++++---------- 2 files changed, 27 insertions(+), 27 deletions(-) diff --git a/code/Test_definitions/location-retrieval.feature b/code/Test_definitions/location-retrieval.feature index d49276e2..f54ba3c7 100644 --- a/code/Test_definitions/location-retrieval.feature +++ b/code/Test_definitions/location-retrieval.feature @@ -98,11 +98,11 @@ Feature: CAMARA Device location retrieval API, vwip - Operation retrieveLocation And the response property "$.message" contains a user friendly text Examples: - | device_identifier | oas_spec_schema | - | $.device.phoneNumber | /components/schemas/PhoneNumber | - | $.device.ipv4Address | /components/schemas/DeviceIpv4Addr | - | $.device.ipv6Address | /components/schemas/DeviceIpv6Address | - | $.device.networkAccessIdentifier | /components/schemas/NetworkAccessIdentifier | + | device_identifier | oas_spec_schema | + | $.device.phoneNumber | #/components/schemas/PhoneNumber | + | $.device.ipv4Address | #/components/schemas/DeviceIpv4Addr | + | $.device.ipv6Address | #/components/schemas/DeviceIpv6Address | + | $.device.networkAccessIdentifier | #/components/schemas/NetworkAccessIdentifier | @location_retrieval_C01.03_device_not_found Scenario: Some identifier cannot be matched to a device @@ -190,13 +190,13 @@ Feature: CAMARA Device location retrieval API, vwip - Operation retrieveLocation And the response property "$.message" contains a user friendly text Examples: - | input_property | oas_spec_schema | - | $.maxAge | /components/schemas/RetrievalLocationRequest/properties/maxAge | - | $.maxSurface | /components/schemas/RetrievalLocationRequest/properties/maxSurface | + | input_property | oas_spec_schema | + | $.maxAge | #/components/schemas/RetrievalLocationRequest/properties/maxAge | + | $.maxSurface | #/components/schemas/RetrievalLocationRequest/properties/maxSurface | @location_retrieval_400.3_invalid_x-correlator Scenario: Invalid x-correlator value - Given the header "x-correlator" does not comply with the OAS schema at "/components/schemas/XCorrelator" + Given the header "x-correlator" does not comply with the OAS schema at "#/components/schemas/XCorrelator" When the request "retrieveLocation" is sent Then the response status code is 400 And the response property "$.status" is 400 diff --git a/code/Test_definitions/location-verification.feature b/code/Test_definitions/location-verification.feature index 731874ae..99cd3144 100644 --- a/code/Test_definitions/location-verification.feature +++ b/code/Test_definitions/location-verification.feature @@ -33,7 +33,7 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio And the response header "Content-Type" is "application/json" And the response header "x-correlator" has same value as the request header "x-correlator" # The response has to comply with the generic response schema which is part of the spec - And the response body complies with the OAS schema at "/components/schemas/VerifyLocationResponse" + And the response body complies with the OAS schema at "#/components/schemas/VerifyLocationResponse" # Additionally any success response has to comply with some constraints not documented in the schema And the response property "$.matchRate" exists only if "$.verificationResult" is "PARTIAL" @@ -48,7 +48,7 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio Then the response status code is 200 And the response header "Content-Type" is "application/json" And the response header "x-correlator" has same value as the request header "x-correlator" - And the response body complies with the OAS schema at "/components/schemas/VerifyLocationResponse" + And the response body complies with the OAS schema at "#/components/schemas/VerifyLocationResponse" And the response property "$.verificationResult" is one of: ["TRUE", "PARTIAL"] And the response property "$.lastLocationTime" exists And the response property "$.matchRate" exists only if "$.verificationResult" is "PARTIAL" @@ -62,7 +62,7 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio Then the response status code is 200 And the response header "Content-Type" is "application/json" And the response header "x-correlator" has same value as the request header "x-correlator" - And the response body complies with the OAS schema at "/components/schemas/VerifyLocationResponse" + And the response body complies with the OAS schema at "#/components/schemas/VerifyLocationResponse" And the response property "$.verificationResult" is one of: ["TRUE", "PARTIAL"] And the response property "$.matchRate" exists only if "$.verificationResult" is "PARTIAL" And the response property "$.lastLocationTime" value is not older than the value of "$.maxAge" in the request @@ -75,7 +75,7 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio Then the response status code is 200 And the response header "Content-Type" is "application/json" And the response header "x-correlator" has same value as the request header "x-correlator" - And the response body complies with the OAS schema at "/components/schemas/VerifyLocationResponse" + And the response body complies with the OAS schema at "#/components/schemas/VerifyLocationResponse" And the response property "$.verificationResult" is "FALSE" And the response property "$.lastLocationTime" exists And the response property "$.matchRate" does not exist @@ -91,9 +91,9 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio Then the response status code is 200 And the response header "Content-Type" is "application/json" And the response header "x-correlator" has same value as the request header "x-correlator" - And the response body complies with the OAS schema at "/components/schemas/VerifyLocationResponse" + And the response body complies with the OAS schema at "#/components/schemas/VerifyLocationResponse" And the response property "$.device" exists - And the response property "$.device" complies with the OAS schema at "/components/schemas/DeviceResponse" + And the response property "$.device" complies with the OAS schema at "#/components/schemas/DeviceResponse" # Error scenarios for management of input parameter device @@ -118,11 +118,11 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio And the response property "$.message" contains a user friendly text Examples: - | device_identifier | oas_spec_schema | - | $.device.phoneNumber | /components/schemas/PhoneNumber | - | $.device.ipv4Address | /components/schemas/DeviceIpv4Addr | - | $.device.ipv6Address | /components/schemas/DeviceIpv6Address | - | $.device.networkAccessIdentifier | /components/schemas/NetworkAccessIdentifier | + | device_identifier | oas_spec_schema | + | $.device.phoneNumber | #/components/schemas/PhoneNumber | + | $.device.ipv4Address | #/components/schemas/DeviceIpv4Addr | + | $.device.ipv6Address | #/components/schemas/DeviceIpv6Address | + | $.device.networkAccessIdentifier | #/components/schemas/NetworkAccessIdentifier | # This scenario may happen e.g. with 2-legged access tokens, which do not identify a single device. @location_verification_C01.03_device_not_found @@ -208,12 +208,12 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio And the response property "$.message" contains a user friendly text Examples: - | input_property | oas_spec_schema | - | $.area.areaType | /components/schemas/AreaType | - | $.area.center.latitude | /components/schemas/Latitude | - | $.area.center.longitude | /components/schemas/Longitude | - | $.area.radius | /components/schemas/Circle/allOf/1/properties/radius | - | $.maxAge | /components/schemas/MaxAge | + | input_property | oas_spec_schema | + | $.area.areaType | #/components/schemas/AreaType | + | $.area.center.latitude | #/components/schemas/Latitude | + | $.area.center.longitude | #/components/schemas/Longitude | + | $.area.radius | #/components/schemas/Circle/allOf/1/properties/radius | + | $.maxAge | #/components/schemas/MaxAge | @location_verification_400.4_required_input_properties_missing Scenario Outline: Required input properties are missing @@ -235,7 +235,7 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio @location_verification_400.5_invalid_x-correlator Scenario: Invalid x-correlator value - Given the header "x-correlator" does not comply with the OAS schema at "/components/schemas/XCorrelator" + Given the header "x-correlator" does not comply with the OAS schema at "#/components/schemas/XCorrelator" When the request "verifyLocation" is sent Then the response status code is 400 And the response property "$.status" is 400 From 4c9dfd956b99c1522301417212599d0378e20da0 Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:12:06 +0200 Subject: [PATCH 05/14] Update code/Test_definitions/location-retrieval.feature Co-authored-by: Jose Luis Urien --- code/Test_definitions/location-retrieval.feature | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code/Test_definitions/location-retrieval.feature b/code/Test_definitions/location-retrieval.feature index f54ba3c7..fdd6ba96 100644 --- a/code/Test_definitions/location-retrieval.feature +++ b/code/Test_definitions/location-retrieval.feature @@ -100,7 +100,7 @@ Feature: CAMARA Device location retrieval API, vwip - Operation retrieveLocation Examples: | device_identifier | oas_spec_schema | | $.device.phoneNumber | #/components/schemas/PhoneNumber | - | $.device.ipv4Address | #/components/schemas/DeviceIpv4Addr | + | $.device.ipv4Address | #/components/schemas/DeviceIpv4Address | | $.device.ipv6Address | #/components/schemas/DeviceIpv6Address | | $.device.networkAccessIdentifier | #/components/schemas/NetworkAccessIdentifier | From 7c32c85c58dead687412b45afecbfccd621d9bea Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:12:59 +0200 Subject: [PATCH 06/14] Update code/Test_definitions/location-retrieval.feature Co-authored-by: Jose Luis Urien --- code/Test_definitions/location-retrieval.feature | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code/Test_definitions/location-retrieval.feature b/code/Test_definitions/location-retrieval.feature index fdd6ba96..337ed807 100644 --- a/code/Test_definitions/location-retrieval.feature +++ b/code/Test_definitions/location-retrieval.feature @@ -182,7 +182,7 @@ Feature: CAMARA Device location retrieval API, vwip - Operation retrieveLocation @location_retrieval_400.2_other_input_properties_schema_not_compliant Scenario Outline: Input property values do not comply with the schema - Given the request body property "" does not comply with the OAS schema at + Given the request body property "" does not comply with the OAS schema at "" When the request "retrieveLocation" is sent Then the response status code is 400 And the response property "$.status" is 400 From 4c57d3902e6566752a8b5da5389dc51277ed3e9f Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:13:10 +0200 Subject: [PATCH 07/14] Update code/Test_definitions/location-verification.feature Co-authored-by: Jose Luis Urien --- code/Test_definitions/location-verification.feature | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code/Test_definitions/location-verification.feature b/code/Test_definitions/location-verification.feature index 99cd3144..a1b327f6 100644 --- a/code/Test_definitions/location-verification.feature +++ b/code/Test_definitions/location-verification.feature @@ -200,7 +200,7 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio @location_verification_400.3_other_input_properties_schema_not_compliant # Test other input properties in addition to device Scenario Outline: Input property values do not comply with the schema - Given the request body property "" does not comply with the OAS schema at + Given the request body property "" does not comply with the OAS schema at "" When the request "verifyLocation" is sent Then the response status code is 400 And the response property "$.status" is 400 From ed64e29b120994042f32a8475c7fa9478ccf3135 Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:13:24 +0200 Subject: [PATCH 08/14] Update code/API_definitions/location-verification.yaml Co-authored-by: Jose Luis Urien --- code/API_definitions/location-verification.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/code/API_definitions/location-verification.yaml b/code/API_definitions/location-verification.yaml index 1bfe0014..84bc49f2 100644 --- a/code/API_definitions/location-verification.yaml +++ b/code/API_definitions/location-verification.yaml @@ -97,6 +97,7 @@ info: + # Request body strictness This API rejects requests with JSON request bodies that contain properties not declared in this specification, at any nesting level. Unknown properties result in a `400 INVALID_ARGUMENT` response. From 5a54a080856698de144488e9dc85b8907f54c369 Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:13:37 +0200 Subject: [PATCH 09/14] Update code/API_definitions/location-verification.yaml Co-authored-by: Jose Luis Urien --- code/API_definitions/location-verification.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/code/API_definitions/location-verification.yaml b/code/API_definitions/location-verification.yaml index 84bc49f2..b5204fd8 100644 --- a/code/API_definitions/location-verification.yaml +++ b/code/API_definitions/location-verification.yaml @@ -56,6 +56,7 @@ info: + # Identifying the device from the access token This API requires the API consumer to identify a device as the subject of the API as follows: From 905a3abb0bd88a073e60917e3905e2c6c3d323c7 Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:13:46 +0200 Subject: [PATCH 10/14] Update code/API_definitions/location-verification.yaml Co-authored-by: Jose Luis Urien --- code/API_definitions/location-verification.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/code/API_definitions/location-verification.yaml b/code/API_definitions/location-verification.yaml index b5204fd8..0cb7cffb 100644 --- a/code/API_definitions/location-verification.yaml +++ b/code/API_definitions/location-verification.yaml @@ -46,6 +46,7 @@ info: - Verify whether the device location is within a requested area, currently a circle with center specified by the latitude and longitude, and radius specified by the accuracy. The operation returns a verification result and, optionally, a match rate estimation for the location verification in percent. + # Authorization and authentication The "Camara Security and Interoperability Profile" provides details of how an API consumer requests an access token. Please refer to Identity and Consent Management (https://github.com/camaraproject/IdentityAndConsentManagement/) for the released version of the profile. From 00681eb8f3129988f4177633a3e67048eaf779ab Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:14:11 +0200 Subject: [PATCH 11/14] Update code/Test_definitions/location-verification.feature Co-authored-by: Jose Luis Urien --- code/Test_definitions/location-verification.feature | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code/Test_definitions/location-verification.feature b/code/Test_definitions/location-verification.feature index a1b327f6..08d81304 100644 --- a/code/Test_definitions/location-verification.feature +++ b/code/Test_definitions/location-verification.feature @@ -120,7 +120,7 @@ Feature: CAMARA Device location verification API, vwip - Operation verifyLocatio Examples: | device_identifier | oas_spec_schema | | $.device.phoneNumber | #/components/schemas/PhoneNumber | - | $.device.ipv4Address | #/components/schemas/DeviceIpv4Addr | + | $.device.ipv4Address | #/components/schemas/DeviceIpv4Address | | $.device.ipv6Address | #/components/schemas/DeviceIpv6Address | | $.device.networkAccessIdentifier | #/components/schemas/NetworkAccessIdentifier | From e85620c7c4740b91df1a17c7cbb9f883e8995a19 Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:14:22 +0200 Subject: [PATCH 12/14] Update code/API_definitions/location-retrieval.yaml Co-authored-by: Jose Luis Urien --- code/API_definitions/location-retrieval.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/code/API_definitions/location-retrieval.yaml b/code/API_definitions/location-retrieval.yaml index fa4b9f7c..91bdbd15 100644 --- a/code/API_definitions/location-retrieval.yaml +++ b/code/API_definitions/location-retrieval.yaml @@ -113,6 +113,7 @@ info: + # Request body strictness This API rejects requests with JSON request bodies that contain properties not declared in this specification, at any nesting level. Unknown properties result in a `400 INVALID_ARGUMENT` response. From 6361459b9e4fa2122f54fc83b9c47bf6442b1b03 Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:14:31 +0200 Subject: [PATCH 13/14] Update code/API_definitions/location-retrieval.yaml Co-authored-by: Jose Luis Urien --- code/API_definitions/location-retrieval.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/code/API_definitions/location-retrieval.yaml b/code/API_definitions/location-retrieval.yaml index 91bdbd15..37e196f6 100644 --- a/code/API_definitions/location-retrieval.yaml +++ b/code/API_definitions/location-retrieval.yaml @@ -72,6 +72,7 @@ info: + # Identifying the device from the access token This API requires the API consumer to identify a device as the subject of the API as follows: From ba65c9309d9ea02047a129fd334b623f39535210 Mon Sep 17 00:00:00 2001 From: Herbert Damker Date: Mon, 5 Oct 2026 21:14:42 +0200 Subject: [PATCH 14/14] Update code/API_definitions/location-retrieval.yaml Co-authored-by: Jose Luis Urien --- code/API_definitions/location-retrieval.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/code/API_definitions/location-retrieval.yaml b/code/API_definitions/location-retrieval.yaml index 37e196f6..74b15af3 100644 --- a/code/API_definitions/location-retrieval.yaml +++ b/code/API_definitions/location-retrieval.yaml @@ -62,6 +62,7 @@ info: * a timestamp with the location information freshness. + # Authorization and authentication The "Camara Security and Interoperability Profile" provides details of how an API consumer requests an access token. Please refer to Identity and Consent Management (https://github.com/camaraproject/IdentityAndConsentManagement/) for the released version of the profile.