/api/v1
The current Eternaltwin API. Every path below is relative to /api/v1.
- / — server metadata (the API home document).
- app — the desktop application's release feed.
- apps — registered applications.
- archive — archived Dinoparc, Hammerfest and Twinoid data.
- auth — the authentication context, sign-in and sign-out.
- captcha — the proof-of-work captcha used by the registration and sign-in forms.
- clock — the server clock (and, in development, time travel).
- config — the pieces of the server configuration a client needs.
- forum — sections, threads, posts and moderation.
- job — background jobs and tasks. Administrators only.
- oauth_clients — seeding of system OAuth clients. Internal: requires the
Etwin-Internal-Authheader. - oauth_consent — data behind the OAuth consent screen. Internal to the website, no stability guarantee.
- outbound_email — the outbound mail queue. Administrators only.
- users — user accounts, their links and their sanctions.
Routes served by the same process but outside /api — the
backend-for-frontend, the OAuth browser flow and the OpenTelemetry collectors —
are listed in Internal endpoints.
Cross-origin requests
The router installs a CORS layer that allows http://localhost:4200 (the
Angular development server) with credentials, for the methods GET, HEAD,
POST, PUT, PATCH, DELETE and OPTIONS, and the headers
Content-Type, Authorization and Accept. Other origins are not allowed by
the backend itself; a deployment puts the website and the API behind the same
origin instead.