Remove Role from Endpoint
Removes a role's access to a specific API endpoint. Administrator role cannot be removed.
Authorization
BearerAuth In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/rbac/endpoint-role/remove" \ -H "Content-Type: application/json" \ -d '{ "endpoint": "/v1/accounts/%", "method": "GET", "role": "StandardUser" }'{
"message": "Role removed successfully",
"endpoint": "/v1/customers",
"method": "GET",
"role": "StandardUser"
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2019-08-24T14:15:22Z"
}Generates a YAML seed snippet for the current permissions of one endpoint. IN PRACTICE THIS OPERATION CANNOT SUCCEED FOR ANY REGISTERED ENDPOINT, and the reason is the route pattern rather than the handler. {endpoint} is a single chi path segment, but every value it has to carry is a path of its own — /v1/customers and the like. Percent-encoding the slashes does not help: chi v5 routes on r.URL.RawPath whenever it is set, and neither the handler nor any middleware calls url.PathUnescape, so ExportEndpointToSeed receives the literal "%2Fv1%2Fcustomers", the endpoint = ? AND method = ? lookup misses, and the caller gets 404 rbac_m.endpoint_not_found. Sending the slashes undecoded adds path segments and does not match the route at all. Use POST /v1/rbac/endpoint-role/export, which takes the endpoint in a JSON body, until the route is fixed.
Counts currently registered endpoints. Full sync requires server restart.