1. Update a Space Role

Update a Space Role

This endpoint allows you to update a space role by the numeric ID.

https://mapi.storyblok.com/v1/spaces/:space_id/space_roles/:space_role_id

Path Parameters

  • :space_id

    required number

    Numeric ID of a space

  • :space_role_id

    required number

    Numeric ID of the space role

Request Body Properties

  • space_role

    The Space Role Object
    • allowed_paths

      number[]

      Story ids the user should have access to (acts as whitelist). If no item is selected the user has rights to access all content items.

    • field_permissions

      string[]

      Hide specific fields for this user with an array of strings with the schema: "component_name.field_name"

    • readonly_field_permissions

      string[]

      An array of defined fields that are hidden for the specific role. The schema used is component_name.field_name

    • permissions

      enum[]

      An array of strings that defines the permissions for the a specific role. These are a few examples, but there are more value that can be present or used.

      Try changing the role permissions and retrieve a role to see all the possible values

      PermissionDescription
      publish_storiesAllow publishing of content entries
      save_storiesAllow editing and saving of content entries
      edit_datasourcesAllow editing and saving of datasources
      access_commerceAllow access to commerce app
      edit_story_slugDeny the change of slugs of content entries
      move_storyDeny moving of content entries
      view_composerDeny access to visual composer
    • role

      string

      Role of the collaborator, could be admin, editor or custom roles

    • subtitle

      string

      Description of the role

    • datasource_ids

      number[]

      An array of datasource IDs that can be accessed by the role. If no IDs is added, the user has rights to edit all datasources.

    • component_ids

      number[]

      An array of IDs of components that the user role cannot select/use. If none is present/selected, the user role has rights to all components.

    • branch_ids

      number[]

      An array of IDs of pipelines that the user role has right to deploy. If none is present/selected, the user role can access all the pipelines.

    • allowed_languages

      string[]

      List of languages (language codes) that the user role has access to. If none is present/selected, the user role has right to all the languages.

    • asset_folder_ids

      number[]

      An array of IDs of asset folders that the user role has access to. If none is present/selected, the user role can access all the asset folders.

Response Properties

  • space_role

    The Space Role Object
    • id

      number

      Numeric Unique ID of the space role

    • allowed_paths

      number[]

      Story ids the user should have access to (acts as whitelist). If no item is selected the user has rights to access all content items.

    • resolved_allowed_paths

      string[]

      Resolved allowed_paths for displaying paths

    • field_permissions

      string[]

      Hide specific fields for this user with an array of strings with the schema: "component_name.field_name"

    • readonly_field_permissions

      string[]

      An array of defined fields that are hidden for the specific role. The schema used is component_name.field_name

    • permissions

      enum[]

      An array of strings that defines the permissions for the a specific role. These are a few examples, but there are more value that can be present or used.

      Try changing the role permissions and retrieve a role to see all the possible values

      PermissionDescription
      publish_storiesAllow publishing of content entries
      save_storiesAllow editing and saving of content entries
      edit_datasourcesAllow editing and saving of datasources
      access_commerceAllow access to commerce app
      edit_story_slugDeny the change of slugs of content entries
      move_storyDeny moving of content entries
      view_composerDeny access to visual composer
    • role

      string

      Role of the collaborator, could be admin, editor or custom roles

    • subtitle

      string

      Description of the role

    • datasource_ids

      number[]

      An array of datasource IDs that can be accessed by the role. If no IDs is added, the user has rights to edit all datasources.

    • component_ids

      number[]

      An array of IDs of components that the user role cannot select/use. If none is present/selected, the user role has rights to all components.

    • branch_ids

      number[]

      An array of IDs of pipelines that the user role has right to deploy. If none is present/selected, the user role can access all the pipelines.

    • allowed_languages

      string[]

      List of languages (language codes) that the user role has access to. If none is present/selected, the user role has right to all the languages.

    • asset_folder_ids

      number[]

      An array of IDs of asset folders that the user role has access to. If none is present/selected, the user role can access all the asset folders.

Request
curl "https://mapi.storyblok.com/v1/spaces/606/space_roles/18" \ 
  -X PUT \
  -H "Authorization: YOUR_OAUTH_TOKEN" \
  -H "Content-Type: application/json" \
  -d "{\"space_role\": {\"allowed_paths\": [430937198],\"field_permissions\": [\"a-new-blok.title\",\"A new comppppp.Text_type\",\"a-new-blok.image\",\"page.body\"],\"readonly_field_permissions\": [\"A new comppppp.RichText_type\",\"A new comppppp.TextArea_type\",\"page.body\"],\"permissions\": [\"manage_block_library\",\"deny_component_technical_name_update\",\"deny_component_fields_name_update\",\"edit_image\",\"delete_stories\",\"deploy_stories\",\"unpublish_stories\",\"unpublish_folders\",\"publish_stories\",\"publish_folders\",\"manage-non-translatable-fields\"],\"role\": \"Another new space role\",\"subtitle\": \"new desc\",\"datasource_ids\": [218499],\"component_ids\": [5758347,],\"branch_ids\": [30403],\"allowed_languages\": [\"de\"],\"asset_folder_ids\": [563628]}}"
Request
// Using the Universal JavaScript Client:
// https://github.com/storyblok/storyblok-js-client
Storyblok.put('/spaces/606/space_roles/18', 
{
    "space_role": {
        "allowed_paths": [
            430937198
        ],
        "field_permissions": [
            "a-new-blok.title",
            "A new comppppp.Text_type",
            "a-new-blok.image",
            "page.body"
        ],
        "readonly_field_permissions": [
            "A new comppppp.RichText_type",
            "A new comppppp.TextArea_type",
            "page.body"
        ],
        "permissions": [
            "manage_block_library",
            "deny_component_technical_name_update",
            "deny_component_fields_name_update",
            "edit_image",
            "delete_stories",
            "deploy_stories",
            "unpublish_stories",
            "unpublish_folders",
            "publish_stories",
            "publish_folders",
            "manage-non-translatable-fields"
        ],
        "role": "Another new space role",
        "subtitle": "new desc",
        "datasource_ids": [
            218499
        ],
        "component_ids": [
            5758347,
        ],
        "branch_ids": [
            30403
        ],
        "allowed_languages": [
            "de"
        ],
        "asset_folder_ids": [
            563628
        ]
    }
})
  .then(response => {
    console.log(response)
  }).catch(error => { 
    console.log(error)
  })
Request
$client = new \Storyblok\ManagementClient('YOUR_OAUTH_TOKEN');

$payload = 
[
    "space_role" =>  [
        "allowed_paths" =>  [
            430937198
        ],
        "field_permissions" =>  [
            "a-new-blok.title",
            "A new comppppp.Text_type",
            "a-new-blok.image",
            "page.body"
        ],
        "readonly_field_permissions" =>  [
            "A new comppppp.RichText_type",
            "A new comppppp.TextArea_type",
            "page.body"
        ],
        "permissions" =>  [
            "manage_block_library",
            "deny_component_technical_name_update",
            "deny_component_fields_name_update",
            "edit_image",
            "delete_stories",
            "deploy_stories",
            "unpublish_stories",
            "unpublish_folders",
            "publish_stories",
            "publish_folders",
            "manage-non-translatable-fields"
        ],
        "role" =>  "Another new space role",
        "subtitle" =>  "new desc",
        "datasource_ids" =>  [
            218499
        ],
        "component_ids" =>  [
            5758347,
        ],
        "branch_ids" =>  [
            30403
        ],
        "allowed_languages" =>  [
            "de"
        ],
        "asset_folder_ids" =>  [
            563628
        ]
    ]
];

$client->put('/spaces/606/space_roles/18', $payload)->getBody();
Request
require 'storyblok'
client = Storyblok::Client.new(oauth_token: 'YOUR_OAUTH_TOKEN')

payload = 
{
    "space_role" =>  {
        "allowed_paths" =>  [
            430937198
        ],
        "field_permissions" =>  [
            "a-new-blok.title",
            "A new comppppp.Text_type",
            "a-new-blok.image",
            "page.body"
        ],
        "readonly_field_permissions" =>  [
            "A new comppppp.RichText_type",
            "A new comppppp.TextArea_type",
            "page.body"
        ],
        "permissions" =>  [
            "manage_block_library",
            "deny_component_technical_name_update",
            "deny_component_fields_name_update",
            "edit_image",
            "delete_stories",
            "deploy_stories",
            "unpublish_stories",
            "unpublish_folders",
            "publish_stories",
            "publish_folders",
            "manage-non-translatable-fields"
        ],
        "role" =>  "Another new space role",
        "subtitle" =>  "new desc",
        "datasource_ids" =>  [
            218499
        ],
        "component_ids" =>  [
            5758347,
        ],
        "branch_ids" =>  [
            30403
        ],
        "allowed_languages" =>  [
            "de"
        ],
        "asset_folder_ids" =>  [
            563628
        ]
    }
}

client.put('/spaces/606/space_roles/18', payload)
Request
HttpResponse<String> response = Unirest.put("https://mapi.storyblok.com/v1/spaces/606/space_roles/18")
  .header("Content-Type", "application/json")
  .header("Authorization", "YOUR_OAUTH_TOKEN")
  .body("{\"space_role\": {\"allowed_paths\": [430937198],\"field_permissions\": [\"a-new-blok.title\",\"A new comppppp.Text_type\",\"a-new-blok.image\",\"page.body\"],\"readonly_field_permissions\": [\"A new comppppp.RichText_type\",\"A new comppppp.TextArea_type\",\"page.body\"],\"permissions\": [\"manage_block_library\",\"deny_component_technical_name_update\",\"deny_component_fields_name_update\",\"edit_image\",\"delete_stories\",\"deploy_stories\",\"unpublish_stories\",\"unpublish_folders\",\"publish_stories\",\"publish_folders\",\"manage-non-translatable-fields\"],\"role\": \"Another new space role\",\"subtitle\": \"new desc\",\"datasource_ids\": [218499],\"component_ids\": [5758347,],\"branch_ids\": [30403],\"allowed_languages\": [\"de\"],\"asset_folder_ids\": [563628]}}")
  .asString();
Request
var client = new RestClient("https://mapi.storyblok.com/v1/spaces/606/space_roles/18");
var request = new RestRequest(Method.PUT);

request.AddHeader("Content-Type", "application/json");
request.AddHeader("Authorization", "YOUR_OAUTH_TOKEN");
request.AddParameter("application/json", "{\"space_role\": {\"allowed_paths\": [430937198],\"field_permissions\": [\"a-new-blok.title\",\"A new comppppp.Text_type\",\"a-new-blok.image\",\"page.body\"],\"readonly_field_permissions\": [\"A new comppppp.RichText_type\",\"A new comppppp.TextArea_type\",\"page.body\"],\"permissions\": [\"manage_block_library\",\"deny_component_technical_name_update\",\"deny_component_fields_name_update\",\"edit_image\",\"delete_stories\",\"deploy_stories\",\"unpublish_stories\",\"unpublish_folders\",\"publish_stories\",\"publish_folders\",\"manage-non-translatable-fields\"],\"role\": \"Another new space role\",\"subtitle\": \"new desc\",\"datasource_ids\": [218499],\"component_ids\": [5758347,],\"branch_ids\": [30403],\"allowed_languages\": [\"de\"],\"asset_folder_ids\": [563628]}}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
Request
import Foundation

let headers = [
  "Content-Type": "application/json",
  "Authorization": "YOUR_OAUTH_TOKEN"
]

let postData = NSData(data: "{\"space_role\": {\"allowed_paths\": [430937198],\"field_permissions\": [\"a-new-blok.title\",\"A new comppppp.Text_type\",\"a-new-blok.image\",\"page.body\"],\"readonly_field_permissions\": [\"A new comppppp.RichText_type\",\"A new comppppp.TextArea_type\",\"page.body\"],\"permissions\": [\"manage_block_library\",\"deny_component_technical_name_update\",\"deny_component_fields_name_update\",\"edit_image\",\"delete_stories\",\"deploy_stories\",\"unpublish_stories\",\"unpublish_folders\",\"publish_stories\",\"publish_folders\",\"manage-non-translatable-fields\"],\"role\": \"Another new space role\",\"subtitle\": \"new desc\",\"datasource_ids\": [218499],\"component_ids\": [5758347,],\"branch_ids\": [30403],\"allowed_languages\": [\"de\"],\"asset_folder_ids\": [563628]}}".data(using: String.Encoding.utf8)!)

let request = NSMutableURLRequest(url: NSURL(string: "https://mapi.storyblok.com/v1/spaces/606/space_roles/18")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0)
request.method = "PUT"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
Request
import requests

url = "https://mapi.storyblok.com/v1/spaces/606/space_roles/18"

querystring = {}

payload = "{\"space_role\": {\"allowed_paths\": [430937198],\"field_permissions\": [\"a-new-blok.title\",\"A new comppppp.Text_type\",\"a-new-blok.image\",\"page.body\"],\"readonly_field_permissions\": [\"A new comppppp.RichText_type\",\"A new comppppp.TextArea_type\",\"page.body\"],\"permissions\": [\"manage_block_library\",\"deny_component_technical_name_update\",\"deny_component_fields_name_update\",\"edit_image\",\"delete_stories\",\"deploy_stories\",\"unpublish_stories\",\"unpublish_folders\",\"publish_stories\",\"publish_folders\",\"manage-non-translatable-fields\"],\"role\": \"Another new space role\",\"subtitle\": \"new desc\",\"datasource_ids\": [218499],\"component_ids\": [5758347,],\"branch_ids\": [30403],\"allowed_languages\": [\"de\"],\"asset_folder_ids\": [563628]}}"
headers = {
  'Content-Type': "application/json",
  'Authorization': "YOUR_OAUTH_TOKEN"
}

response = requests.request("PUT", url, data=payload, headers=headers, params=querystring)

print(response.text)