<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SDWAN API RBAC in Network Platform API</title>
    <link>https://community.cisco.com/t5/network-platform-api/sdwan-api-rbac/m-p/5129616#M8699</link>
    <description>&lt;P&gt;Not an expert here, from what i recall when an API endpoint does not specify an "x-roles-required" header, it&amp;nbsp;does not&amp;nbsp;mean that any user can execute the API. Instead, it implies that the API endpoint is&amp;nbsp;accessible to all authenticated users. Therefore, other words, any user who has a valid login credential and is authenticated by the vManage system can access the API endpoint, regardless of their role or permissions.&amp;nbsp;&lt;/P&gt;
&lt;P class="mb-2 last:mb-0"&gt;The "x-roles-required: default" header would indicate that the API endpoint requires a user to have the&amp;nbsp;default&amp;nbsp;role to access it. In the context of vManage, the "default" role is a built-in role that is assigned to all users by default from what i recall this role provides basic read-only access (i do not think this means 'imply unrestricted access' please check this part) I believe to use an API endpoint with "x-roles-required: default", you don't need to assign a specific user group/feature role to the user. You would instead, ensure that the user has a valid login credential and is authenticated by vManage and the user will then be able to access the API endpoint with the default role's permissions.&lt;/P&gt;
&lt;P class="mb-2 last:mb-0"&gt;Ive not seen this listed much in the documentation so would suggest to double check this with the SD-WAN API ENG team at Cisco.&lt;/P&gt;
&lt;P class="mb-2 last:mb-0"&gt;Happy to be corrected on the above too, hope this helps.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jun 2024 13:51:31 GMT</pubDate>
    <dc:creator>bigevilbeard</dc:creator>
    <dc:date>2024-06-13T13:51:31Z</dc:date>
    <item>
      <title>SDWAN API RBAC</title>
      <link>https://community.cisco.com/t5/network-platform-api/sdwan-api-rbac/m-p/5129587#M8698</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I have a couple doubts about the RBAC required to use SDWAN APIs.&lt;/P&gt;
&lt;P&gt;1. When the API doesn't show a "x-roles-required", this means that any users can execute this API?&lt;/P&gt;
&lt;P&gt;2. The x-roles-required: "default" what is the user group that I need to use because seems that is not part of Feature user groups param in vManage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 13:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/sdwan-api-rbac/m-p/5129587#M8698</guid>
      <dc:creator>Heri Diaz</dc:creator>
      <dc:date>2024-06-13T13:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN API RBAC</title>
      <link>https://community.cisco.com/t5/network-platform-api/sdwan-api-rbac/m-p/5129616#M8699</link>
      <description>&lt;P&gt;Not an expert here, from what i recall when an API endpoint does not specify an "x-roles-required" header, it&amp;nbsp;does not&amp;nbsp;mean that any user can execute the API. Instead, it implies that the API endpoint is&amp;nbsp;accessible to all authenticated users. Therefore, other words, any user who has a valid login credential and is authenticated by the vManage system can access the API endpoint, regardless of their role or permissions.&amp;nbsp;&lt;/P&gt;
&lt;P class="mb-2 last:mb-0"&gt;The "x-roles-required: default" header would indicate that the API endpoint requires a user to have the&amp;nbsp;default&amp;nbsp;role to access it. In the context of vManage, the "default" role is a built-in role that is assigned to all users by default from what i recall this role provides basic read-only access (i do not think this means 'imply unrestricted access' please check this part) I believe to use an API endpoint with "x-roles-required: default", you don't need to assign a specific user group/feature role to the user. You would instead, ensure that the user has a valid login credential and is authenticated by vManage and the user will then be able to access the API endpoint with the default role's permissions.&lt;/P&gt;
&lt;P class="mb-2 last:mb-0"&gt;Ive not seen this listed much in the documentation so would suggest to double check this with the SD-WAN API ENG team at Cisco.&lt;/P&gt;
&lt;P class="mb-2 last:mb-0"&gt;Happy to be corrected on the above too, hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 13:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/sdwan-api-rbac/m-p/5129616#M8699</guid>
      <dc:creator>bigevilbeard</dc:creator>
      <dc:date>2024-06-13T13:51:31Z</dc:date>
    </item>
  </channel>
</rss>

