Skip to content

REST API: Users & RBAC Access Control Endpoints ​

The Users API allows administrators to manage accounts, update passwords, and configure Role-Based Access Control (RBAC).


1. Role-Based Access Control (RBAC) Matrix ​

Permission / Subsystemvieweroperatoradminservice (M2M)
Watch Live WebRTC / HLS✅✅✅✅
View & Export Archive✅✅✅✅
Add / Edit / Delete Cameras❌✅✅✅
Manage Tags & Folders❌✅✅✅
Manage Users & Security❌❌✅❌
System Backup & Restore❌❌✅❌

2. List Users (GET /api/users) ​

  • Required Role: admin
bash
curl -H "Authorization: Bearer <ADMIN_TOKEN>" http://localhost:8080/api/users

Response (200 OK):

json
[
  {
    "username": "admin",
    "role": "admin"
  },
  {
    "username": "operator1",
    "role": "operator"
  },
  {
    "username": "guard_john",
    "role": "viewer"
  }
]

3. Create User (POST /api/users) ​

  • Required Role: admin
bash
curl -X POST http://localhost:8080/api/users \
  -H "Authorization: Bearer <ADMIN_TOKEN>" \
  -H "Content-Type: application/json" \
  -d '{
    "username": "operator_john",
    "password": "StrongPassword987!",
    "role": "operator"
  }'

Response (201 Created):

json
{
  "username": "operator_john",
  "role": "operator"
}

4. Update Password / Role (PUT /api/users/:username) ​

bash
curl -X PUT http://localhost:8080/api/users/operator_john \
  -H "Authorization: Bearer <ADMIN_TOKEN>" \
  -H "Content-Type: application/json" \
  -d '{
    "password": "NewSecretPassword2026!",
    "role": "admin"
  }'

Response (200 OK).


5. Delete User (DELETE /api/users/:username) ​

bash
curl -X DELETE http://localhost:8080/api/users/operator_john \
  -H "Authorization: Bearer <ADMIN_TOKEN>"

Response (200 OK): {"message": "user deleted"}.

Released under the MIT License.