Export Endpoint to Seed YAML
Generates a YAML seed snippet for the current permissions of one endpoint. IN PRACTICE THIS OPERATION CANNOT SUCCEED FOR ANY REGISTERED ENDPOINT, and the reason is the route pattern rather than the handler. {endpoint} is a single chi path segment, but every value it has to carry is a path of its own — /v1/customers and the like. Percent-encoding the slashes does not help: chi v5 routes on r.URL.RawPath whenever it is set, and neither the handler nor any middleware calls url.PathUnescape, so ExportEndpointToSeed receives the literal "%2Fv1%2Fcustomers", the endpoint = ? AND method = ? lookup misses, and the caller gets 404 rbac_m.endpoint_not_found. Sending the slashes undecoded adds path segments and does not match the route at all. Use POST /v1/rbac/endpoint-role/export, which takes the endpoint in a JSON body, until the route is fixed.
Authorization
BearerAuth In: header
Path Parameters
The endpoint path, as a single path segment. See the operation description: no registered endpoint can be expressed here, because the captured value is never percent-decoded.
Response Body
text/yaml
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/rbac/endpoint-role/export/GET//v1/customers"" - endpoint: /v1/customers\n method: GET\n roles:\n - User\n - StandardUser\n description: \"GET /v1/customers\"\n"{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2019-08-24T14:15:22Z"
}Generates one YAML seed snippet covering the listed endpoints. The response is the YAML itself, not JSON: the module name is repeated in the X-Module-Name header and in the Content-Disposition filename, which the Configurator uses when saving the download. Partial failure is not an error. An entry that names no active endpoint — or whose role lookup fails — is dropped and the export succeeds with 200 covering the rest; the only signal is a `# Note: N endpoints could not be exported` comment line in the YAML, and which ones failed appears in the server log only. The request fails with 404 only when NONE of the listed endpoints resolves.
Removes a role's access to a specific API endpoint. Administrator role cannot be removed.