Set an organization member's groups
Changed onReplace a member's groups, and with them the capabilities they hold.
Replaces the former update-role action. The request names groups -- the one write where a group name is the natural input, since assigning a group is the act of choosing one -- and the response reports the resulting permissions, which is what every authorization check actually reads.
Guards:
- The organization keeps at least one member who can manage members. Restated from "cannot demote the last active admin": the rule counts by capability (organizations.manage_members) rather than by the role column, so it holds for any future group that carries the capability and does not depend on a representation the API no longer exposes.
- A restricted organization may not write at all. See deactivate above for why the check is here rather than in OrganizationService.
Idempotency: assigning the groups a member already holds is a no-op success, including for the sole administrator re-assigning organization_admin to themselves -- the guard fires on losing the capability, not on writing it again.
Request
- The document declares no server URL.
- Auth: one of:
- HTTP bearer
- API key in cookie sessionid
Path parameters
Headers
Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.
Request body
Response
Changes
- ○
endpoint added
- ○