【问题标题】:Is it possible to set permissions on variable groups via the REST API?是否可以通过 REST API 设置变量组的权限?
【发布时间】:2023-03-24 15:37:01
【问题描述】:

我很好奇是否有人知道如何通过 REST API 为变量组设置权限(添加/删除组)。我知道有安全命名空间,但是它需要一个资源 guid,我不确定如何为特定的变量组获取它?

【问题讨论】:

  • 这个案例有什么更新吗?

标签: azure-devops-rest-api


【解决方案1】:

你想要安全 namespace “Library”(你需要 convert 它到正确的 namespace_id )和 token “Library/$project_id/VariableGroup/$variable_group_id”

POST https://dev.azure.com/{organization}/_apis/accesscontrollists/{securityNamespaceId}?api-version=5.1

有关 ACL 管理 REST API,请参阅https://docs.microsoft.com/en-us/rest/api/azure/devops/security/access%20control%20lists/set%20access%20control%20lists?view=azure-devops-rest-5.1

示例请求:

"value": [
    {
      "inheritPermissions": true,
      "token": "Library/$project_id/VariableGroup/$variable_group_id",
      "acesDictionary": {
        "Microsoft.TeamFoundation.Identity;S-1-9-1551374245-1204400969-2402986413-2179408616-0-0-0-0-1": {
          "descriptor": "Microsoft.TeamFoundation.Identity;S-1-9-1551374245-1204400969-2402986413-2179408616-0-0-0-0-1",
          "allow": 31,
          "deny": 0
        }
      }
    }
]

警告1 - 目前关于该主题的 Microsoft 文档非常不完整(例如,请参阅我在 github 上的comment 问题,要求澄清变量组身份验证机制)。

警告2 - 小心处理项目中所有变量组的 ACL 更改请求(例如 token=Library/$project_id/ ),因为您最终可能会删除 Ado 项目中所有用户的权限,并且很难将其更改回来.

【讨论】:

    【解决方案2】:

    恐怕无法通过api设置变量组权限。

    我们只能从下面的变量组 api 中获取组 id,响应中没有资源 id。

     https://dev.azure.com/{organization}/{project}/_apis/distributedtask/variablegroups?api-version=5.1-preview.1
    

    当我尝试使用 F12 chrome 获取 http 请求跟踪时。请求 url 的末尾有一个值,看起来像源 ID。它是项目 id 与变量组 id 的组合。不知道这是否是您正在寻找的资源指南。

    https://dev.azure.com//_apis/securityroles/scopes/distributedtask.variablegroup/roleassignments/resources/39e13f04-cb4e-4fa8-b2f1-0ee8f4fc82c5%241

    【讨论】:

    • @Shawn 太好了,你可以将你的新帖子标记为answer
    【解决方案3】:

    我设法对执行此操作的人员进行了逆向工程。如果有人对它的工作原理感到好奇,请随时查看我为 Azure DevOps 编写的 powershell 库 -- https://github.com/ravensorb/Posh-AzureDevOps

    【讨论】:

      猜你喜欢
      • 2021-03-03
      • 2015-08-21
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多