Skip to main content

Admin Access

Root-only management of who may do what in the admin API: list the resources and levels, grant a level to a role, and override it for one member.

List the admin resources and levels

GET/api/admin/access/catalog

The resources a grant can name and the four levels, with descriptions.

Authentication: Admin session token (Authorization: Bearer <token>)

Responses

StatusDescriptionBody
200Resources and levels.
401Missing or invalid admin session.
403Root admin access required.

Open in Swagger (opens in a new tab)

Get a member's overrides

GET/api/admin/access/members/{memberId}

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
memberIdpathstringyes

Responses

StatusDescriptionBody
200The overrides of the member.
401Missing or invalid admin session.
403Root admin access required.
404Member not found.

Open in Swagger (opens in a new tab)

Replace a member's overrides

PUT/api/admin/access/members/{memberId}

An override replaces what the roles grant for that resource, for this member only. none denies.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
memberIdpathstringyes

Request body (JSON, required): SetGrantsDto schema.

Responses

StatusDescriptionBody
200The overrides now held by the member.
400Unknown resource or level, or a root member.
401Missing or invalid admin session.
403Root admin access required.
404Member not found.

Open in Swagger (opens in a new tab)

Explain a member's effective access

GET/api/admin/access/members/{memberId}/effective

The member's name, the resolved level per resource and where it comes from: root, an override, or the role that supplied it.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
memberIdpathstringyes

Responses

StatusDescriptionBody
200Effective access with sources.
401Missing or invalid admin session.
403Root admin access required.
404Member not found.

Open in Swagger (opens in a new tab)

Remove one override

DELETE/api/admin/access/members/{memberId}/{resource}

The member falls back to what their roles grant for that resource.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
memberIdpathstringyes
resourcepathstringyes

Responses

StatusDescriptionBody
204Override removed.
400Unknown resource.
401Missing or invalid admin session.
403Root admin access required.
404Member or override not found.

Open in Swagger (opens in a new tab)

List the members that have overrides

GET/api/admin/access/overrides

Every member with at least one override and their overrides, ordered by name. Not paginated: the list is bounded by the club's size. root marks a member whose overrides are inactive because they currently hold a root role.

Authentication: Admin session token (Authorization: Bearer <token>)

Responses

StatusDescriptionBody
200Members with their overrides.
401Missing or invalid admin session.
403Root admin access required.

Open in Swagger (opens in a new tab)

List main-server roles with their grants

GET/api/admin/access/roles

Root roles are flagged and cannot be given grants.

Authentication: Admin session token (Authorization: Bearer <token>)

Responses

StatusDescriptionBody
200Roles with their grants.
401Missing or invalid admin session.
403Root admin access required.

Open in Swagger (opens in a new tab)

Replace a role's grants

PUT/api/admin/access/roles/{roleId}

Replaces every grant of the role. Resources left out, or set to none, have no grant.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
roleIdpathstringyes

Request body (JSON, required): SetGrantsDto schema.

Responses

StatusDescriptionBody
200The grants now held by the role.
400Unknown resource or level, or a root role.
401Missing or invalid admin session.
403Root admin access required.
404Role not found in the main server.

Open in Swagger (opens in a new tab)

Schemas

SetGrantsDto schema

FieldTypeRequiredDescription
grantsmap of "none" or "read" or "write" or "manage"yesLevel per resource. Resources not listed get no grant. For a role, none removes the grant. For a member, none denies access that the roles would give.

Source: apps/api/openapi.json.