Proteside Docs
Referência de endpointsScripts

Autorizar um script (justificativa PCI 6.4.3 obrigatória)

POST
/scripts/{id}/authorize

Define status = authorized, authorization_method = api, authorized_by = api:<prefix>, registra uma revisão e desativa qualquer regra de bloqueio que corresponda ao script. expires_days define expires_at / review_due_at.

Autorização

bearerAuth
headerAutorizaçãoBearer <token>

Token de API criado em Configurações → API. Os escopos ficam vinculados ao token; cada operação lista o escopo exigido em x-scope.

Parâmetros de caminho

id*string
Formatouuid

Parâmetros de consulta

org_id?string

Somente parceiros (orgs:manage): atua sobre esta organização filha. Também pode ser enviado como org_id em corpos JSON.

Formatouuid

Parâmetros de cabeçalho

Idempotency-Key?string

Reproduz a resposta original por 24 h

Tamanho1 <= length <= 255

Corpo da requisição

application/json
  1. body
justification*string
Tamanho10 <= length <= 2000
expires_days?integer
Intervalo1 <= value <= 3650

Corpo da resposta

Script autorizado

application/json
  1. response
id?string
Formatouuid
store_id?string
Formatouuid
src?string
type?|
Valor em"first_party""known_third""unknown"null
category?string|null
status?string
Valor em"trusted""needs_review""suspicious""malicious""authorized""blocked"
integrity_status?|
Valor em"match""mismatch""pending""monitored""blocked"null
current_hash?string|null
authorized_hash?string|null
hash_source?string|null
sri_hash?string|null
integrity_attr?boolean|null
size_bytes?integer|null
vendor_id?string|null
gtm_container?string|null
authorization_method?|
Valor em"manual""auto""policy""ai_assisted""import""api""expiry""integrity""system"null
authorized_by?string|null
justification?string|null
policy_id?|
Formatouuid
policy_version?integer|null
reviewed_at?|
Formatodate-time
expires_at?|
Formatodate-time
review_due_at?|
Formatodate-time
first_seen_at?string
Formatodate-time
last_seen_at?string
Formatodate-time
last_verified_at?|
Formatodate-time
last_hash_change_at?|
Formatodate-time
block_rules_deactivated?boolean
curl -X POST "https://example.com/scripts/497f6eca-6276-4993-bfeb-53cbbbba6f08/authorize" \  -H "Content-Type: application/json" \  -d '{    "justification": "Google Tag Manager container owned by the marketing team; no access to payment fields.",    "expires_days": 90  }'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "store_id": "7fe87115-950c-4ae8-bd7e-970406bc9ac0",  "src": "string",  "type": "first_party",  "category": "string",  "status": "trusted",  "integrity_status": "match",  "current_hash": "string",  "authorized_hash": "string",  "hash_source": "string",  "sri_hash": "string",  "integrity_attr": true,  "size_bytes": 0,  "vendor_id": "string",  "gtm_container": "string",  "authorization_method": "manual",  "authorized_by": "string",  "justification": "string",  "policy_id": "ee9b03e0-6495-427a-85a5-34444d24ae04",  "policy_version": 0,  "reviewed_at": "2019-08-24T14:15:22Z",  "expires_at": "2019-08-24T14:15:22Z",  "review_due_at": "2019-08-24T14:15:22Z",  "first_seen_at": "2019-08-24T14:15:22Z",  "last_seen_at": "2019-08-24T14:15:22Z",  "last_verified_at": "2019-08-24T14:15:22Z",  "last_hash_change_at": "2019-08-24T14:15:22Z",  "block_rules_deactivated": true}