Update a role

Change what a role allows, or the note describing it. Send only what you want to change; a role's name cannot be changed once it exists. Sending `permissions` replaces the whole list, so include everything the role should keep. You cannot give a role more than you hold yourself. Changing only the description is always allowed, even for a role that outranks you. Everyone holding this role is affected. New authorization checks use the change within about 30 seconds, after the gateway's short permission cache expires. Requires the `organizations.roles.update` permission.

PATCH
/organizations/{organizationId}/roles/{roleId}
AuthorizationBearer <token>

The access token returned after a successful sign-in, sent as Authorization: Bearer <access_token>.

It identifies the person and the organization they are working in, and it lasts about fifteen minutes. When it runs out, use their refresh token at POST /auth/refresh-token instead of asking them to sign in again.

In: header

Path Parameters

organizationId*string

Identifier of the organization. Each endpoint states whether it must be the caller's active organization or may be used without authentication.

roleId*string

Identifier of the role.

Request Body

application/json

The parts of the role to change.

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X PATCH "https://api.dual.network/organizations/665f1c2d4b1a2c3d4e5f6aa0/roles/665f1c2d4b1a2c3d4e5f6ab0" \  -H "Content-Type: application/json" \  -d '{    "permissions": [      {        "resource": "objects",        "crud": {          "read": true,          "create": false,          "update": false,          "delete": false        }      },      {        "resource": "objects.state-changes",        "crud": {          "read": true,          "create": false,          "update": false,          "delete": false        }      },      {        "resource": "ebus.actions",        "crud": {          "read": true,          "create": true,          "update": false,          "delete": false        }      }    ]  }'
{}
{
  "code": 3,
  "message": "Key: 'limit' Error:Field validation for 'limit' failed on the 'lte' tag"
}

{
  "code": 16,
  "message": "no auth provided"
}

{
  "code": 7,
  "message": "cannot grant permissions beyond your own"
}
{
  "code": 5,
  "message": "object not found"
}
{
  "code": 13,
  "message": "internal error"
}