Discussion about RESTful Admin API Group Name: SEC & ARC Source: FUJITSU Meeting Date: Agenda Item: Device Configuration
Introduction In TP 18, the need to have dedicated API for administrative operation regarding security. When Field Device Configuration is triggered by external entity, some information to be deployed on platform through admin API. For consistency with other APIs, designing admin API as RESTful API is preferred. 2
Summary of Proposals Admin User – Admin User is human to be authenticated by platform – Admin User can add/delete AE Account/Access Code Entity Account – AE-ID/CSE-ID and its credential for authentication – Access Policy for Entity Access Code – Proof of access right to specific resource – Issued by Admin User 3 Following resources should be exposed as oneM2M resource
resource entityID credential name credential credentialType codeValue scope permission credentialType adminScope 4 allowedResourcesRead allowedResourcesModify