REST API: Users & RBAC Access Control Endpoints
The Users API allows administrators to manage accounts, update passwords, and configure Role-Based Access Control (RBAC).
1. Role-Based Access Control (RBAC) Matrix
| Permission / Subsystem | viewer | operator | admin | service (M2M) |
|---|---|---|---|---|
| Watch Live WebRTC / HLS | ✅ | ✅ | ✅ | ✅ |
| View & Export Archive | ✅ | ✅ | ✅ | ✅ |
| Add / Edit / Delete Cameras | ❌ | ✅ | ✅ | ✅ |
| Manage Tags & Folders | ❌ | ✅ | ✅ | ✅ |
| Manage Users & Security | ❌ | ❌ | ✅ | ❌ |
| System Backup & Restore | ❌ | ❌ | ✅ | ❌ |
2. List Users (GET /api/users)
- Required Role:
admin
bash
curl -H "Authorization: Bearer <ADMIN_TOKEN>" http://localhost:8080/api/usersResponse (200 OK):
json
[
{
"username": "admin",
"role": "admin"
},
{
"username": "operator1",
"role": "operator"
},
{
"username": "guard_john",
"role": "viewer"
}
]3. Create User (POST /api/users)
- Required Role:
admin
bash
curl -X POST http://localhost:8080/api/users \
-H "Authorization: Bearer <ADMIN_TOKEN>" \
-H "Content-Type: application/json" \
-d '{
"username": "operator_john",
"password": "StrongPassword987!",
"role": "operator"
}'Response (201 Created):
json
{
"username": "operator_john",
"role": "operator"
}4. Update Password / Role (PUT /api/users/:username)
bash
curl -X PUT http://localhost:8080/api/users/operator_john \
-H "Authorization: Bearer <ADMIN_TOKEN>" \
-H "Content-Type: application/json" \
-d '{
"password": "NewSecretPassword2026!",
"role": "admin"
}'Response (200 OK).
5. Delete User (DELETE /api/users/:username)
bash
curl -X DELETE http://localhost:8080/api/users/operator_john \
-H "Authorization: Bearer <ADMIN_TOKEN>"Response (200 OK): {"message": "user deleted"}.