Admin Access
Root-only management of who may do what in the admin API: list the resources and levels, grant a level to a role, and override it for one member.
List the admin resources and levels
/api/admin/access/catalogThe resources a grant can name and the four levels, with descriptions.
Authentication: Admin session token (Authorization: Bearer <token>)
Responses
| Status | Description | Body |
|---|---|---|
200 | Resources and levels. | |
401 | Missing or invalid admin session. | |
403 | Root admin access required. |
Open in Swagger (opens in a new tab)
Get a member's overrides
/api/admin/access/members/{memberId}Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
memberId | path | string | yes |
Responses
| Status | Description | Body |
|---|---|---|
200 | The overrides of the member. | |
401 | Missing or invalid admin session. | |
403 | Root admin access required. | |
404 | Member not found. |
Open in Swagger (opens in a new tab)
Replace a member's overrides
/api/admin/access/members/{memberId}An override replaces what the roles grant for that resource, for this member only. none denies.
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
memberId | path | string | yes |
Request body (JSON, required): SetGrantsDto schema.
Responses
| Status | Description | Body |
|---|---|---|
200 | The overrides now held by the member. | |
400 | Unknown resource or level, or a root member. | |
401 | Missing or invalid admin session. | |
403 | Root admin access required. | |
404 | Member not found. |
Open in Swagger (opens in a new tab)
Explain a member's effective access
/api/admin/access/members/{memberId}/effectiveThe member's name, the resolved level per resource and where it comes from: root, an override, or the role that supplied it.
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
memberId | path | string | yes |
Responses
| Status | Description | Body |
|---|---|---|
200 | Effective access with sources. | |
401 | Missing or invalid admin session. | |
403 | Root admin access required. | |
404 | Member not found. |
Open in Swagger (opens in a new tab)
Remove one override
/api/admin/access/members/{memberId}/{resource}The member falls back to what their roles grant for that resource.
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
memberId | path | string | yes | |
resource | path | string | yes |
Responses
| Status | Description | Body |
|---|---|---|
204 | Override removed. | |
400 | Unknown resource. | |
401 | Missing or invalid admin session. | |
403 | Root admin access required. | |
404 | Member or override not found. |
Open in Swagger (opens in a new tab)
List the members that have overrides
/api/admin/access/overridesEvery member with at least one override and their overrides, ordered by name. Not paginated: the list is bounded by the club's size. root marks a member whose overrides are inactive because they currently hold a root role.
Authentication: Admin session token (Authorization: Bearer <token>)
Responses
| Status | Description | Body |
|---|---|---|
200 | Members with their overrides. | |
401 | Missing or invalid admin session. | |
403 | Root admin access required. |
Open in Swagger (opens in a new tab)
List main-server roles with their grants
/api/admin/access/rolesRoot roles are flagged and cannot be given grants.
Authentication: Admin session token (Authorization: Bearer <token>)
Responses
| Status | Description | Body |
|---|---|---|
200 | Roles with their grants. | |
401 | Missing or invalid admin session. | |
403 | Root admin access required. |
Open in Swagger (opens in a new tab)
Replace a role's grants
/api/admin/access/roles/{roleId}Replaces every grant of the role. Resources left out, or set to none, have no grant.
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
roleId | path | string | yes |
Request body (JSON, required): SetGrantsDto schema.
Responses
| Status | Description | Body |
|---|---|---|
200 | The grants now held by the role. | |
400 | Unknown resource or level, or a root role. | |
401 | Missing or invalid admin session. | |
403 | Root admin access required. | |
404 | Role not found in the main server. |
Open in Swagger (opens in a new tab)
Schemas
SetGrantsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
grants | map of "none" or "read" or "write" or "manage" | yes | Level per resource. Resources not listed get no grant. For a role, none removes the grant. For a member, none denies access that the roles would give. |
Source: apps/api/openapi.json.