Replace a folder's access rules
const url = 'https://api.ebitex.io/content/management/v1/folders/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/access-rules';const options = { method: 'PUT', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"rules":[{"roleDefinitionId":"2489E9AD-2EE2-8E00-8EC9-32D5F69181C0","action":"example"}]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PUT \ --url https://api.ebitex.io/content/management/v1/folders/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/access-rules \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "rules": [ { "roleDefinitionId": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "action": "example" } ] }'Replaces every rule declared on this folder with { rules: [ { roleDefinitionId, action } ] }. An empty list removes them all, so the folder inherits from its parent again.
edit, delete and publish each imply view: a role given any of them is also given view, and the response shows the stored set with those rows added. Restricting view hides the folder and everything under it from every role not listed, except roles holding content.access.manage, which bypass all branch rules.
Needs the key’s role to hold content.access.manage.
Key: a management key with content.management.authoring.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”Request Bodyrequired
Section titled “Request Bodyrequired”object
object
Examplegenerated
{ "rules": [ { "roleDefinitionId": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "action": "example" } ]}Responses
Section titled “ Responses ”The rules as stored, implied view rows included.
validation_failed: an action other than view, edit, delete or publish.
missing_api_key or invalid_api_key: no key was sent, or it is unknown, revoked or expired.
payment_required: the organization’s subscription needs attention.
permission_denied: the key’s role lacks content.access.manage.
scope_denied: the key lacks this route’s scope. tier_required: the Content Management API needs the Pro plan or above. ip_denied: the caller’s address is outside the key’s allowed ranges. app_not_available: Content is not enabled for the organization.
No folder has this id.
Rate limit or quota exceeded; Retry-After says how long to wait. too_many_failed_authentications: too many bad keys from this address.