OperatorAPI opme:list
newadmapi (Operator API) function. Available to: Operator.
Description
Which groups reach each menu option. Edit-only by root, operator audience only. `name`, `detalle`, `imagen` and `url` are READABLE BUT NOT WRITABLE: the legacy renders them into an inline JavaScript block unescaped, so a write path here would let an operator run script in another administrator's browser. Narrower than the legacy, deliberately, and NOT a fix - the sink remains open. Paginated. Sorting and searching are restricted to the declared fields; anything else is rejected and named. Read audience is provisional pending operator confirmation.
Call
GET|POST https://YOUR_HOST:9089/newadm?func=opme:list
Send your API key with every request (header X-API-Key: YOUR_KEY, or Authorization: Bearer YOUR_KEY, or the ukey query parameter).
Parameters
None beyond the API key and func=opme:list.
Example
https://host:port/newadm?func=opme:list
Response
Success is {"ok":true,"data":{...}}; on refusal {"ok":false,"code":"...","message":"..."}. This function's data shape: {"ok":true,"data":{"rows":[{"id":n,"app":s,"name":s,"detalle":s,"mowner":s,"groups":s}],"page":n,"pagesize":n,"fields":[s],"available":[s],"order":s,"dir":s,"filterby":s?,"filter":s?}}.
Errors
Refusals carry a machine-readable code (branch on the code, never the message). See OperatorAPI#Error codes.
Back to OperatorAPI