Check that the stored audit was not changed
HttpRequest request = HttpRequest.newBuilder() .uri(URI.create("http://localhost:8080/v1/audit-log/integrity")) .header("Authorization", "Bearer <token>") .method("GET", HttpRequest.BodyPublishers.noBody()) .build();HttpResponse<String> response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString());System.out.println(response.body());const url = 'http://localhost:8080/v1/audit-log/integrity';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url http://localhost:8080/v1/audit-log/integrity \ --header 'Authorization: Bearer <token>'Checks the caller’s tenant’s stored ACCESS and IDENTITY entries against their hash chains and names, per chain, the first place the chain no longer holds (CHANGED, UNLINKED, MISSING or HEAD). Removing the oldest entries is what retention does and is not a break. Embedded keeps its audit in memory only and answers durable false with no chains. Requires audit:read. Reads every stored entry of the tenant.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Header Parameters
Section titled “Header Parameters”Tenant selection. A principal of one tenant may omit it, and if sent it must name that tenant. A principal that may act in several tenants sends it on every request.
Query Parameters
Section titled “Query Parameters”Also answer each chain’s stored hash at this position
Responses
Section titled “ Responses ”One report per chain
object
object
object
Example
{ "chains": [ { "category": "ACCESS", "broken": { "problem": "CHANGED" } } ]}Invalid request
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:invalid-argument", "title": "Bad Request", "status": 400, "detail": "The request is malformed", "instance": "/v1/audit-log/integrity"}Authentication required
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:unauthorized", "title": "Unauthorized", "status": 401, "detail": "A valid bearer credential is required", "instance": "/v1/audit-log/integrity"}Headers
Section titled “Headers”The caller lacks the required permission.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:forbidden", "title": "Forbidden", "status": 403, "detail": "The principal lacks the action this route requires", "instance": "/v1/audit-log/integrity"}Tenant-scoped resource not found
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:not-found", "title": "Not Found", "status": 404, "detail": "The requested resource does not exist", "instance": "/v1/audit-log/integrity"}Idempotency conflict
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:conflict", "title": "Conflict", "status": 409, "detail": "The idempotency key is already associated with another request", "instance": "/v1/audit-log/integrity"}Authenticated request exceeds its configured bound
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:payload-too-large", "title": "Payload Too Large", "status": 413, "detail": "The request exceeds the configured size limit", "instance": "/v1/audit-log/integrity"}Tenant quota exhausted
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:quota-exhausted", "title": "Quota Exhausted", "status": 429, "detail": "The tenant active-instance quota is exhausted", "instance": "/v1/audit-log/integrity"}Non-leaking internal failure
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:internal", "title": "Internal Server Error", "status": 500, "detail": "The request could not be completed", "instance": "/v1/audit-log/integrity"}The operation is on the reviewed allow-list of what this deployment mode cannot serve.
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:mode-not-supported", "title": "Mode Not Supported", "status": 501, "detail": "GET /v1/audit-log/integrity is not supported in embedded mode", "instance": "/v1/audit-log/integrity", "mode": "embedded"}Backpressure or dependency unavailable
object
The request path.
Present only on mode-not-supported. It names the engine’s mode.
Example
{ "type": "urn:bpm:error:unavailable", "title": "Service Unavailable", "status": 503, "detail": "The required engine service is not ready", "instance": "/v1/audit-log/integrity"}