Members
复制一个包含安装步骤和此插件的完整Markdown指南的设置提示
Capgo 组织的成员是有权访问您的组织的用户。每个成员都有一个特定的角色,决定了他们在组织中的权限。有效地管理成员对于维护团队的安全和协作至关重要。
成员角色
成员角色常规角色
常规角色- 读取: 可以查看资源,但无法进行修改
- 上传: 可以上传新包并查看资源
- 写入: 可以修改资源并上传包
- 管理员: 可以管理组织设置和成员
- 超级管理员: 对组织有完全控制权
邀请角色
标题:邀请角色- 邀请读者: 等待邀请的读取访问
- 邀请上传: 等待上传访问的邀请
- 邀请写入: 等待写入访问的邀请
- 邀请管理员: 等待管理员访问的邀请
- 邀请超级管理员: 等待超级管理员访问的邀请
最佳实践
名为“最佳实践”的章节- 角色分配: 权限最小化原则
- 常规审计: 定期检查成员访问权限并删除未使用的帐户
- 入职: 有明确的流程添加新成员并分配角色
- 离职: 及时移除成员离开组织的访问权限
API
APIPOST
POSThttps://api.capgo.app/organization/members/
添加新成员到组织或更新现有成员角色。请注意,您只能邀请已经有一个Capgo帐户的用户 - 邮件必须与一个现有的Capgo用户对应。
请求体
标题:请求体interface MemberCreate { orgId: string email: string role: "read" | "upload" | "write" | "admin" | "super_admin"}示例请求
标题:示例请求curl -X POST \ -H "authorization: your-api-key" \ -H "Content-Type: application/json" \ -d '{ "orgId": "org_123", "email": "newmember@example.com", "role": "write" }' \ https://api.capgo.app/organization/members/成功响应
标题:成功响应{ "status": "OK", "data": { "uid": "user_789", "email": "newmember@example.com", "role": "invite_write", "image_url": null }}注意:
- 当添加新成员时,他们会收到邀请邮件。他们的角色将以“invite_”开头,直到他们接受邀请。
- 用户必须已经有一个Capgo账户才能被邀请。如果他们没有账户,他们应该先在 https://console.capgo.app/register/
GET
GEThttps://api.capgo.app/organization/members/
获取组织中的所有成员。
请求参数
复制到剪贴板interface MemberQuery { orgId: string}示例请求
GETinterface Member { uid: string; email: string; image_url: string; role: "invite_read" | "invite_upload" | "invite_write" | "invite_admin" | "invite_super_admin" | "read" | "upload" | "write" | "admin" | "super_admin";}curl -H "authorization: your-api-key" \ "https://api.capgo.app/organization/members/?orgId=org_123"{ "data": [ { "uid": "user_123", "email": "john@example.com", "image_url": "https://example.com/avatar.png", "role": "admin" }, { "uid": "user_456", "email": "jane@example.com", "image_url": "https://example.com/avatar2.png", "role": "write" }, { "uid": "user_789", "email": "bob@example.com", "image_url": null, "role": "invite_read" } ]}https://api.capgo.app/organization/members/
从组织中移除一个成员。 这将立即撤销他们的访问权。
interface MemberDelete { orgId: string email: string}示例请求
示例请求curl -X DELETE \ -H "authorization: your-api-key" \ -H "Content-Type: application/json" \ -d '{ "orgId": "org_123", "email": "user@example.com" }' \ https://api.capgo.app/organization/members/成功响应
成功响应{ "status": "OK"}错误处理
错误处理常见错误场景和响应:
// Member not found{ "error": "Member not found", "status": "KO"}
// Invalid role{ "error": "Invalid role specified", "status": "KO"}
// Permission denied{ "error": "Insufficient permissions to manage members", "status": "KO"}
// Cannot remove last admin{ "error": "Cannot remove the last admin from the organization", "status": "KO"}
// Invalid email{ "error": "Invalid email format", "status": "KO"}
// Member already exists{ "error": "Member already exists in organization", "status": "KO"}- 团队扩张: 为适当角色添加新团队成员
- 访问控制: 根据责任变化管理成员权限
- 安全审计: 定期审查成员列表和角色
- 团队重构: 在组织变化期间更新角色
如果您正在使用 成员 用于规划安全性和合规性,连接它 加密 加密的实现细节 合规性 合规性的实现细节 Capgo 安全扫描器 Capgo 安全扫描器的产品工作流程 Capgo 安全 Capgo 安全的产品工作流程 Capgo 信任中心 Capgo 信任中心的产品工作流程