Skip to content

Spec coverage

Every endpoint, header, query parameter and lifecycle rule of the ONE Record API specification, with its status in this package. Status values: implemented, partial (with a note), planned, not planned (with a reason). Each implemented row links to the test that proves it.

Spec sources: 2025-07 edition (API 2.2.0) and 2026-07 edition (API 2.3.0). Pinned commits are recorded in src/Vocabulary/Generated/Manifest.php.

Compliance collection

Besides the PHPUnit tests linked below, tests/Compliance/ holds a newman collection generated from the specification's example bodies with assertions taken from its MUST tables (status codes, Location, Type, Content-Type version echo, Content-Language, revision headers, RFC 1123 dates, api:Error bodies, the action-request lifecycle end to end). CI runs it against bin/serve once for API 2.2.0 and once for 2.3.0; locally, ddev compliance. The request set mirrors IATA's own Postman collection, which carries no assertions of its own.

Endpoints

Endpoint API Status Notes / test
GET / server information 2.2, 2.3 implemented ServerInformationAndNegotiationTest
POST /logistics-objects 2.2, 2.3 implemented Internal-only per spec; exposed only when the access policy allows. CreateObjectAndNotificationsTest
GET /logistics-objects/{id} 2.2, 2.3 implemented incl. ?at= historical reads and ?embedded=true. LogisticsObjectReadTest
HEAD /logistics-objects/{id} 2.2, 2.3 implemented LogisticsObjectReadTest
PATCH /logistics-objects/{id} (Change → ChangeRequest) 2.2, 2.3 implemented 201 + Location + Type; the holder's own changes are applied at once. ChangeRequestsTest
POST /logistics-objects/{id} (Verification → VerificationRequest) 2.2, 2.3 implemented SubscriptionsDelegationsAndVerificationTest
GET /logistics-objects/{id}/audit-trail 2.2, 2.3 implemented updated-from, updated-to, status. LogisticsObjectReadTest, ChangeRequestsTest
POST /logistics-objects/{id}/logistics-events 2.2, 2.3 implemented LogisticsEventsTest
GET /logistics-objects/{id}/logistics-events 2.2, 2.3 implemented event-code, created-after/-before, occurred-after/-before, sort, limit, skip; api:Collection body. LogisticsEventsTest
HEAD /logistics-objects/{id}/logistics-events 2.2, 2.3 implemented LogisticsEventsTest
GET /logistics-objects/{id}/logistics-events/{eventId} 2.2, 2.3 implemented LogisticsEventsTest
POST /logistics-events (bulk, 207 Multi-Status) 2.3 implemented Optional in the spec; off by default (ServerConfig::$bulkLogisticsEvents); 404 at 2.2. SubscriptionsDelegationsAndVerificationTest
POST /notifications 2.2, 2.3 implemented 204; raises NotificationReceived. CreateObjectAndNotificationsTest
GET /subscriptions?topicType&topic 2.2, 2.3 implemented Answered from the host's own subscription interests; several as api:Collection (question 17). SubscriptionsDelegationsAndVerificationTest
POST /subscriptions (Subscription → SubscriptionRequest) 2.2, 2.3 implemented SubscriptionsDelegationsAndVerificationTest
POST /access-delegations (AccessDelegation → AccessDelegationRequest) 2.2, 2.3 implemented isRequestedFor read as list or single value; api:expiresAt honoured. SubscriptionsDelegationsAndVerificationTest
GET /action-requests/{id} 2.2, 2.3 implemented Status-since and history at 2.3 only. ChangeRequestsTest
HEAD /action-requests/{id} 2.2, 2.3 implemented ChangeRequestsTest
PATCH /action-requests/{id}?status= 2.2, 2.3 implemented Internal-only per spec; exposed only when the access policy allows. ChangeRequestsTest
DELETE /action-requests/{id} (revoke) 2.2, 2.3 implemented 422 on a state that cannot be revoked at 2.3; 400 at 2.2. ChangeRequestsTest
POST /oauth/token (client credentials) n/a implemented Not part of the ONE Record API; an optional helper component (Auth\TokenEndpoint). TokenEndpointAndAuthenticatorTest

Client

Client\OneRecordClient covers the same endpoints from the consuming side, negotiating the API version from the partner's server information. Proven by OneRecordClientTest against scripted answers and by ClientAgainstServerTest against this package's own server at both versions.

Client capability Status Notes
Server information discovery, cached (PSR-16) implemented
API version negotiation (highest common), forced version implemented 2.3-only properties read as optional
Read / HEAD logistics objects, ?at=, ?embedded= implemented Revision metadata on the response object, stripped from the body
Create object, change request, verification request implemented
Audit trail with filters, parsed action requests implemented
Post event, list / filter events, read event implemented
Bulk events with per-object fallback implemented Falls back on 404/405 or at 2.2.0
Subscribe, query offered subscriptions, access delegation implemented Single Subscription or Collection answers
Action requests: read, decide, revoke implemented
Send notification implemented
OAuth 2.0 client credentials token provider (PSR-18 + PSR-16) implemented client_secret_post and client_secret_basic, refresh before expiry
Typed errors with the partner's api:Error implemented No automatic retries, by design

Cross-cutting

Rule Status Notes
Accept version negotiation and Content-Type echo implemented ServerInformationAndNegotiationTest
Content-Language on every response implemented Languages from ServerConfig::$languages
Type header with the most specific class implemented On every response, errors included (api:Error)
Revision, Latest-Revision, Last-Modified (RFC 1123) implemented LogisticsObjectReadTest
api:hasRevision / api:hasLatestRevision in logistics-object bodies implemented
api:Error body with api:ErrorDetail on every 4xx/5xx; 2.3 standard titles implemented api:hasSeverity written at 2.3 only
Access control per logistics object with the four permissions, default deny (403) implemented A policy may answer 404 instead (Decision::Hide); grants from accepted access delegations honoured
Stable embedded-object ids (internal:<uuid5>) implemented Minted when an object is first stored; blank nodes in changes minted on application
Change application: atomic, deletes before adds, revision check, no events edits, subject validation implemented A failed application leaves the request REQUEST_FAILED with errors
Action-request state machines (change/subscription/delegation and verification) implemented Other pending changes on the replaced revision rejected with 409
Notification fan-out: by identifier or type, event-type filter, notifyRequestStatusChange, sendLogisticsObjectBody implemented Queued in the NotificationOutbox; the host sends
Request size limit, UTF-8 bodies, no 301 redirects implemented 413 above ServerConfig::$maxBodyBytes
text/turtle content type not planned JSON-LD is the mandatory serialisation; Turtle may follow after 1.0.0