CentralCSP
APIInventory Rules

Create an inventory rule

Adds a rule so scripts from a known vendor are justified without being reviewed one by one. Reconciliation runs straight away and applies the rule to scripts already in the inventory that are still unreviewed. A website is limited to 200 rules.

Requires the manager role on the website and the compliance plan feature.

POST
/v1/workspaces/{workspaceId}/websites/{websiteId}/compliance/rules

Authorization

AuthorizationBearer <token>

An OpenID Connect access token issued by Keycloak, acting as the signed-in user.

In: header

Path Parameters

workspaceId*string
websiteId*string

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

name*string

Display name for the rule.

Length1 <= length <= 255
urlPattern*string

Pattern to match script URLs against.

Length1 <= length <= 1024
patternType?|

How urlPattern is read. glob uses * wildcards and is the default. regex is a regular expression, kept for existing integrations. Patterns are matched safely, and one with too many unbounded repetitions is rejected.

justification*string

Applied to every script the pattern matches.

Length1 <= length <= 4096
tagIds?array<string>

Tags to apply to every script this rule matches.

Itemsitems <= 50
enabled?boolean

Defaults to true.

sortOrder?|

Rules are tried from the lowest value up, and the first match wins. Put the most specific rules first.

Range0 <= value

Response Body

application/json

curl -X POST "https://api-next.centralcsp.com/v1/workspaces/string/websites/string/compliance/rules" \  -H "Content-Type: application/json" \  -d '{    "name": "Stripe",    "urlPattern": "https://*.stripe.com/*",    "justification": "Stripe payment scripts, approved vendor."  }'
{  "id": "string",  "workspaceId": "string",  "websiteId": "string",  "name": "Stripe",  "urlPattern": "https://*.stripe.com/*",  "patternType": "glob",  "justification": "string",  "tagIds": [    "string"  ],  "enabled": true,  "sortOrder": 0,  "createdAt": "2019-08-24T14:15:22Z",  "updatedAt": "2019-08-24T14:15:22Z"}