OperatorAPI opme:list: Difference between revisions
Operator API reference (generated from func=help) |
Operator API reference: multi-line response shape |
||
| Line 15: | Line 15: | ||
== Response == | == Response == | ||
Success is <code>{"ok":true,"data":{...}}</code>; on refusal <code>{"ok":false,"code":"...","message":"..."}</code>. This function's data shape: < | Success is <code>{"ok":true,"data":{...}}</code>; on refusal <code>{"ok":false,"code":"...","message":"..."}</code>. This function's data shape (<code>n</code> = number, <code>s</code> = string, <code>?</code> = present only when set): | ||
<pre> | |||
{ | |||
"ok":true, | |||
"data":{ | |||
"rows":[ | |||
{ | |||
"id":n, | |||
"app":s, | |||
"name":s, | |||
"detalle":s, | |||
"mowner":s, | |||
"groups":s | |||
} | |||
], | |||
"page":n, | |||
"pagesize":n, | |||
"fields":[ | |||
s | |||
], | |||
"available":[ | |||
s | |||
], | |||
"order":s, | |||
"dir":s, | |||
"filterby":s?, | |||
"filter":s? | |||
} | |||
} | |||
</pre> | |||
== Errors == | == Errors == | ||
Latest revision as of 08:28, 19 August 2026
newadmapi (Operator API) function. Available to: Operator.
Description
Which groups reach each menu option. Edit-only by root, operator audience only. `name`, `detalle`, `imagen` and `url` are READABLE BUT NOT WRITABLE: the legacy renders them into an inline JavaScript block unescaped, so a write path here would let an operator run script in another administrator's browser. Narrower than the legacy, deliberately, and NOT a fix - the sink remains open. Paginated. Sorting and searching are restricted to the declared fields; anything else is rejected and named. Read audience is provisional pending operator confirmation.
Call
GET|POST https://YOUR_HOST:9089/newadm?func=opme:list
Send your API key with every request (header X-API-Key: YOUR_KEY, or Authorization: Bearer YOUR_KEY, or the ukey query parameter).
Parameters
None beyond the API key and func=opme:list.
Example
https://host:port/newadm?func=opme:list
Response
Success is {"ok":true,"data":{...}}; on refusal {"ok":false,"code":"...","message":"..."}. This function's data shape (n = number, s = string, ? = present only when set):
{
"ok":true,
"data":{
"rows":[
{
"id":n,
"app":s,
"name":s,
"detalle":s,
"mowner":s,
"groups":s
}
],
"page":n,
"pagesize":n,
"fields":[
s
],
"available":[
s
],
"order":s,
"dir":s,
"filterby":s?,
"filter":s?
}
}
Errors
Refusals carry a machine-readable code (branch on the code, never the message). See OperatorAPI#Error codes.
Back to OperatorAPI