Permissions#
KIO user permissions and the built-in permission catalog.Concepts#
Permission: a name and a unique slug. Endpoints check the slug, e.g. users-users-read.
Catalog: the built-in catalog maps modules to submodules to actions. Each <Module> <Submodule> <action> triple becomes one permission whose slug is the triple lowercased and hyphenated.
Seeding: the generate-permissions endpoints insert the catalog into the database. They are not idempotent: run them only on an empty collection, because duplicate slugs raise unhandled errors that terminate the API process.
Endpoints#
Every KIO user permission, sorted by name.Creates a permission; the slug is derived from the name.DELETE /v1/permissions/{id}GET /v1/config/generate-permissionsSeeds the KIO user permissions from the catalog.GET /v1/config/generate-permissions-businessSeeds the business user permissions from the catalog.Source#
Router: routes/v1/users.js
Controllers: controllers/users/users-permissions.js, controllers/business/business-roles-permissions.js
Models: models/user_permission.js, models/business_user_permission.js
Modified at 2026-10-05 20:21:01