hosting
PUT /v1/sites/{siteId}/wordpress/users/{wpUserId}/role
Change a WordPress account's role.
身份验证
请将 API 密钥作为 bearer 令牌发送。该密钥必须具有 sites.view 权限;缺少该权限的密钥将被拒绝并返回 403 状态码,而非 404。
此端点不需要组织 ID。您的密钥已用于识别其所属的组织,且响应范围也仅限于该组织。
免费试用
将尖括号中的内容替换为您自己的值,并将键占位符替换为您仪表板中的一个键。
curl -X PUT https://api.zinndigital.com/v1/sites/{siteId}/wordpress/users/{wpUserId}/role \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "role": <string> }'已登录?您仪表板中的 API 控制台会自动填入您真实的组织 ID 和您自己的密钥,并针对实时 API 运行请求,以便您查看实际的响应。 在 API 控制台中打开此端点
详细信息
Replaces the account's roles with exactly the one in the body — the other half of "add and remove administrators", and the half that lets a customer fix a mistake without deleting somebody's account and their authorship along with it. ⛔ **Replaces, never adds.** WordPress lets one account hold several roles at once, so granting the new role without removing the old one would leave a "demoted" administrator holding both — an account that reads as an editor on every screen and can still do everything. That outcome is indistinguishable from a successful demotion, which is why the distinction is stated here rather than left to the implementation. Its own path rather than a field on the user resource, for the same reason the password reset has one: a role change and a delete must not be two shapes of one request. **Promoting to `administrator` and demoting *from* one both** require the package's administrator-management capability, not merely `wp_users`. The promotion is obvious; the demotion matters just as much, because removing the last administrator's role locks every human out of the site as thoroughly as deleting them would. `422` for a role the install does not define, or a platform with no role field. `404` for a site with no vendor hosting package, and for an id that is not on it. Requires `sites.view` and `sites.panel_access`.
参数
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
siteId (path) | Uuid | 是 | Site ID (UUIDv7). |
wpUserId (path) | string | 是 | The account's WordPress id, as `listSiteWordPressUsers` reports it. |
请求正文
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
role | string | 是 | The role the account should hold, from `listSiteWordPressRoles`. |
响应
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
id | string | 是 | The account's WordPress id, carried as a string because it is the vendor's identifier rather than ours. |
login | string | 是 | The name the account signs in with. |
display_name | string | 是 | The name shown on the site's posts and comments. |
email | string | 是 | The account's email address. Personal data about the customer's **own** users, which is why the whole listing is gated on `sites.panel_access`. |
roles | string | 是 | The account's roles, in the vendor's own spelling. |
registered_at | string | 是 | When WordPress recorded the account, in the vendor's own format. Not typed as a date-time: the platform does not guarantee one, and coercing it would invent precision. |
is_administrator | boolean | 是 | Whether the account is an administrator. ⛔ Set from **which vendor endpoint the row came from**, not guessed from the role string — the two lists sit behind two different capabi… |
此端点可能返回的错误
401 · 403 · 404 · 409 · 422 · 429 · 503