Skip to content
You are reading the unreleased documentation. No version is released yet, and these pages describe code that is not in a release.

Staff (admin API)

Admin routes of the staff module. Every route needs a staff session and the permission named on it; send X-Resolve-Locale: false to receive every locale of a translatable field for editing.

List all staff members

Parameters:

  • page in query (number, min 1, optional).
  • pageSize in query (number, min 1, max 100, optional).
  • role in query ("SUPER_ADMIN", "ADMIN", "MANAGER", "SUPPORT", optional).

Responses:

  • 200: Staff members retrieved.
  • 401: Unauthorized.
  • 403: Insufficient permissions.

Create new staff member

Request body: CreateStaffDto.

Responses:

  • 201: Staff member created.
  • 400: Invalid input.
  • 401: Unauthorized.
  • 403: Insufficient permissions.

Deactivate staff member

Parameters:

  • id in path (string, required).

Responses:

  • 204: Staff member deactivated.
  • 401: Unauthorized.
  • 403: Insufficient permissions.
  • 404: Staff member not found.

Update staff member

Parameters:

  • id in path (string, required).

Request body: UpdateStaffDto.

Responses:

  • 200: Staff member updated.
  • 400: Invalid input.
  • 401: Unauthorized.
  • 403: Insufficient permissions.
  • 404: Staff member not found.
  • email (string, required).
  • password (string, pattern /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)/, min length 8, max length 128, required).
  • firstName (string, max length 100, required).
  • lastName (string, max length 100, required).
  • role ("ADMIN", "MANAGER", "SUPPORT", required).
  • roleId (string, optional).
  • firstName (string, max length 100, optional).
  • lastName (string, max length 100, optional).
  • role ("ADMIN", "MANAGER", "SUPPORT", optional).
  • roleId (string, optional).