Skip to content
YAADMIN
Download

APPLICATION REFERENCE

Roles & permissions API

4 verified roles & permissions routes: authentication, fields, responses, errors and approval boundaries.

VerifiedSource snapshot · 2026-10-02

Application boundary#

These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.

Verified routes#

4 routes

GET/roles

Roles page.

Authentication
session + administrator role
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
role=None
Headers
none beyond shared session/CSRF
Response structure
HTML template response (handler names the template)
Important errors
404
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler roles_page. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/security/roles

Create role.

Authentication
session + administrator role
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
RoleCreatePayload [name, description]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, role}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
namestr = Field(min_length=1, max_length=120)
descriptionstr | None = Field(default=None, max_length=1000)

Verified route registration · handler api_create_role. Some definitions may be partially redacted; no missing fields are inferred.

PUT/api/security/roles/{role_id}

Update role.

Authentication
session + administrator role
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
RoleUpdatePayload [description]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, role}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
descriptionstr | None = Field(default=None, max_length=1000)

Verified route registration · handler api_update_role. Some definitions may be partially redacted; no missing fields are inferred.

PUT/api/security/roles/{role_id}/permissions/{permission_id}

Update role permission.

Authentication
session + administrator role
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
RolePermissionPayload [effect]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, effect}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
effectPermissionEffect | None = None

Verified route registration · handler api_update_role_permission. Some definitions may be partially redacted; no missing fields are inferred.

Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.

Search documentation

Search stays in your browser.