Skip to content

Handler role gating (generated)

Server-side role requirements declared on API handler actions in the 3.7.3 module via the requiresRole annotation, enforced by roleAspect (see security settings for the security.enforceRoleAnnotations switch). A caller passes when they hold any of the listed role tokens.

504 actions scanned — 143 role-gated, 361 not yet annotated.

Gated actions

Handler Action Requires any of Audit label
admin createBlogPermissions edit
admin updateTenders edit
avatar edit edit
avatar doEdit edit Edit Avatar
blog delete admin Delete Blog Post
blog save edit Save Blog Post
branch getCompanyBranches view View Branches
branch getBranch view View Branch Detail
branch save edit Edit Branch
branch delete admin Delete Branch
calendar setStatus edit
calendar save edit Saved Calendar
calendar addRecipients edit
calendar delete admin Delete Event
calendar removeRecipient admin
campaign delete admin
campaign removeRecipient admin Remove Email Campaign Recipient
campaign addRecipients edit Add Email Campaign Recipients
campaign save edit Save Email Campaign
cmt save edit
comment delete admin Delete comment
comment upload edit Upload Comment Attachment
comment add edit Add Comment
company save edit Save Company
company deleteCompany admin Delete Company
company updateMemberMapping edit
company importMemberMappings edit
contact save edit Save Contact
contact saveSetttings edit
contact archive edit Archive Contact
contact delete admin Delete Contact
contact removePermissions admin Remove Contact permissions
contact resetPassword edit Reset Password
documentation save edit
documents categorySave edit Save Folder
documents upload edit Upload Document
documents clone edit Cloned Document
documents importFile edit
documents delete admin Delete Document
documents deleteFolder admin Delete Folder
documents save edit Save Document
documents reject edit Reject Document
documents updateStatus edit Update Document Status
documents approve edit Approve Document
groups saveMeta edit Save Group Meta
groups createGroup edit Save Group Meta
groups delete admin Delete Group
groups deleteFromGroup admin Remove from Group
groups move edit Move Group
groups renameGroup edit Rename Group
groups addToGroup edit Add to Group
import importSuppliers edit
jira updateState edit Update Ticket Status
jira updatePriority edit Update Ticket Priority
jira updateType edit Update Ticket Type
login savesecret edit
login updatePassword edit
login resetPassword edit
pim upload edit Upload PIM File
pim saveChange edit Save PIM Product
pim deleteExportTemplate admin Delete Export Template
pim updatePricesManual edit
pim toggleDigest edit
pim saveExportMappings edit Save PIM Export Mapping
pim deletePrices admin Delete Product Prices
pim deleteProducts admin Delete Products
pim saveMappings edit
pim discontinueSelected edit Discontinue PIM Products
pim deleteSelected admin Discontinue PIM Products
pim activateSelected edit Activaate PIM Products
pim applyPricesSelected edit
psa addTurnoverStream edit Add Turnover Stream
psa deleteTurnoverStream admin Delete Turnover Stream
psa addChain edit Add Chained Agreement
psa updateTags edit Change Agreement TAGS
psa deleteChain admin Delete Chained Agreement
psa deleteDeal admin Delete Agreement
psa updateDeal edit Update Agreement
psa updateInputStreamCode edit
psa importInputStreamMappings edit
psa setCategories edit Set Deal Categories
psa validate edit Validate Deal
psa clone edit Clone Agreement
psa applyTemplate edit Apply Template
psa emailNegotiator edit Email Deal to Negotiator
psa emailSupplier edit Email Deal to Supplier
quickbooks reset edit
quickbooks addCompany edit
rebate merge edit Merge Rebates
rebate distribute edit Distribute Rebate
rebate schedule edit Schedule Payment
rebate delete admin
rebate markPaid edit Mark Rebate Received
rebate save edit Save Manual Rebate
review createReviewRequest edit
review submitReview edit
review deleteReview admin
review createSurvey edit Save Deal review
rfp copyExternal edit
rfp createRFP edit Create Payment Request
rfp createMultiRFP edit Create MultiLine Payment Request
rfp bulkSend edit Bulk Send Payment Request(s)
rfp send edit Send Payment Request(s)
rfp save edit Save Payment Request(s)
rfp delete admin Delete Payment Request
security savePermissions edit Save Permissions
signoff doSign edit Sign Off Agreement
site create edit
site createLiteSite edit
site save edit
site saveSettings edit Save Site Settings
spend flag edit Flag Turnover
spend doQuery edit Query Turnover
spend resolve edit Resolve Turnover Query
spend confirmAmmendments edit Confirm Turnover Amendment
spend rejectAmmendments edit Reject Turnover Amendment
spend upload edit Upload Turnover
spend submit edit Submit Turnover
spend wipe admin Wipe Turnover
spend reclassifyErpLine edit Reclassify ERP Stream
survey addRecipients edit
survey removeRecipient admin
survey deleteSurvey admin
survey save edit Save Survey
survey remindNotification edit Send Survey Reminder
survey submit edit Submit Survey Answers
tags deleteTagReference admin Delete tag
task create edit Create Task
task update edit Update Task
task delete admin Delete Task
task complete edit Complete Task
task claim edit Claim Task
task cancel edit Cancel Task
task addComment edit Add Task Comment
tender archive edit Save Tender
tender createDeal edit Create Deal from Tender
tender saveTenderAnswers edit Save Answers
tender control edit Control Tender
tender delete admin Delete Tender
tender generateITT edit Generate Tender Documents
tender save edit Save Tender
tender upload edit Upload Tender Document
watching savePreferences edit

Not yet annotated

These actions carry no requiresRole yet. Under the current opt-in rollout they are not role-gated server-side; add an annotation as each is reviewed.

  • admin.checkDealPermissions
  • admin.autoCreate2
  • admin.getMetaData
  • admin.fix43s
  • admin.oldDateRestrictions
  • admin.fixDGGroup
  • admin.fixLinear
  • admin.fixMemberRestrictions
  • admin.fixDateRestrictions
  • admin.fixPromos
  • admin.doProjections
  • admin.runTask
  • admin.getSchedule
  • admin.dataSync
  • admin.migrateIndex
  • audit.get
  • audit.getRecentDeals
  • audit.feed
  • audit.search
  • audit.userReport
  • auth.index
  • auth.logout
  • auth.msAuth
  • auth.gAuth
  • auth.signup
  • auth.getDetails
  • avatar.index
  • avatar.company
  • avatar.pathImage
  • avatar.load
  • blog.list
  • blog.detail
  • blog.getCategories
  • blog.viewDigest
  • branch.search
  • calendar.list
  • calendar.recipients
  • calendar.detail
  • campaign.webhook
  • campaign.view
  • campaign.rd
  • campaign.track
  • campaign.send
  • campaign.test
  • campaign.list
  • campaign.indexCampaign
  • campaign.index
  • campaign.templates
  • campaign.recipients
  • chat.auth
  • chat.userTyping
  • chat.seenChat
  • chat.userTyping
  • chat.startStream
  • chat.sendChat
  • chat.history
  • chat.getRecentChats
  • cmt.getCMTS
  • cmt.getCMT
  • cmt.getReview
  • comment.getRelatedComments
  • comment.getComments
  • company.getCompany
  • company.getCompanyByName
  • company.getCompanyOfType
  • company.getCompanies
  • company.scoreData
  • company.getMemberMappings
  • company.getMemberMappingSuggestions
  • company.exportMemberMappings
  • company.scoreCard
  • contact.getCurrentUser
  • contact.getLinkedAccounts
  • contact.list
  • contact.linkedIn
  • contact.linkedInResponse
  • contact.currentUser
  • contact.getContacts
  • contact.queries
  • contact.queryBuilderData
  • contact.listContacts
  • contact.getContactSettings
  • contact.categoryTree
  • contact.switchToContact
  • contact.getContactsOfCompanyType
  • contact.getContactsOfCompany
  • contact.indexContact
  • contact.bootUser
  • crm.comments
  • dashboard.getDashboardLayout
  • dashboard.memberBIData
  • dashboard.chartData
  • dashboard.supplierDeals
  • dashboard.supplierRebateDue
  • dashboard.supplierRebateProjections
  • dashboard.supplierProjections
  • dashboard.supplierDocuments
  • dashboard.supplierSalesHeatmap
  • documentation.getTopics
  • documentation.getTopic
  • documentation.menu
  • documents.related
  • documents.unpack
  • documents.indexDocument
  • documents.thumbnail
  • documents.category
  • documents.document
  • documents.check
  • documents.relatedFix
  • documents.inline
  • documents.search
  • documents.download
  • documents.findLinkable
  • documents.recentlyapproved
  • email.getEmail
  • email.getEmails
  • email.getInboxAggregations
  • email.getAttachments
  • email.download
  • export.logos
  • export.deals
  • export.comments
  • export.reviews
  • export.companies
  • export.contacts
  • export.branches
  • export.CMBC
  • export.psas
  • export.grebates
  • export.spend
  • export.download
  • feed.feedData
  • groups.staticGroups
  • groups.list
  • groups.get
  • groups.getRelationship
  • groups.tree
  • healthcheck.getLogs
  • healthcheck.getFailures
  • healthcheck.getFailuresByApp
  • healthcheck.getFailuresByInstance
  • healthcheck.getFailureDetails
  • healthcheck.getFailuresByStatusCode
  • healthcheck.getTimeouts
  • healthcheck.getTimeoutAnalysis
  • healthcheck.getResponseTimes
  • healthcheck.listLogs
  • healthcheck.listFailures
  • healthcheck.listTimeouts
  • healthcheck.getAuditStats
  • healthcheck.weeklyReport
  • healthcheck.getSummary
  • help.getHelp
  • index.index
  • indexer.indexDocument
  • indexer.doIndexAll
  • indexer.indexComments
  • jira.list
  • jira.detail
  • jira.canonicalFields
  • jira.overview
  • jira.subsystems
  • jira.export
  • login.index
  • login.doLogin
  • login.statusCheck
  • login.authQR
  • login.logout
  • login.checkKey
  • msauth.login
  • msauth.index
  • nmbs.popularProducts
  • nmbs.getSalesBySupplierAndProduct
  • nmbs.reportBuilder
  • notifications.getINotifications
  • notifications.dismissNotification
  • notifications.getRecentNotifications
  • notifications.dismissAllNotifications
  • notifications.getSummary
  • openAI.summaryText
  • openAI.docRead
  • pim.validateFile
  • pim.getImportMappings
  • pim.calendar
  • pim.getFileColumns
  • pim.doDeDupe
  • pim.priceCompare
  • pim.priceCompareExport
  • pim.getSuppliers
  • pim.getZones
  • pim.getPriceDates
  • pim.completenessData
  • pim.exportSetup
  • pim.updates
  • pim.getExportMappingList
  • pim.getExportMappings
  • pim.hasImportMappings
  • pim.getParentDeal
  • pim.checkPopular
  • pim.exportComparison
  • pim.analysePrices
  • pim.index
  • pim.image
  • pim.importReport
  • pim.detail
  • pim.outOfDatePrices
  • pim.outOfDatePrices2
  • pim.searchPrices
  • pim.api
  • pim.download
  • pim.indexSelected
  • pim.indexDataSet
  • pim.indexSupplierProducts
  • pim.doImport
  • pim.nightly
  • pim.indexProducts
  • pim.checkIndex
  • pim.importDone
  • pim.flattenAllProducts
  • pim.indexAllProducts
  • promotions.list
  • promotions.conference
  • psa.getPSA
  • psa.getPSADocuments
  • psa.getDeals
  • psa.getVersions
  • psa.getSuppliersWithActiveDeal
  • psa.getVersion
  • psa.getPrices
  • psa.getKeyDocuments
  • psa.getPromotions
  • psa.getInputTypes
  • psa.exportInputStreamMappings
  • psa.tree
  • psa.pdf
  • psa.getDealUsers
  • psa.categoryTree
  • psa.doSearch
  • psa.indexPSA
  • psa.getInputStreamMappings
  • quickbooks.auth
  • quickbooks.test
  • quickbooks.oauth2
  • quickbooks.index
  • quickbooks.agedDebt
  • quickbooks.getTaxCodes
  • quickbooks.balances
  • quickbooks.statement
  • quickbooks.transactions
  • quickbooks.payments
  • quickbooks.paymentsData
  • quickbooks.invoicesData
  • quickbooks.getInvoice
  • quickbooks.incoming
  • rebate.calcIssues
  • rebate.export
  • rebate.agedDebt
  • rebate.swot
  • rebate.rebateData
  • rebate.remittance
  • rebate.detail
  • rebate.dashboard
  • rebate.indexRebates
  • rebate.calendar
  • rebate.reportBuilder
  • rebate.target
  • rebate.dealSummary
  • rebate.dealEarnings
  • rebate.simulate
  • rebate.calculateAll
  • rebate.calculateRebate
  • rebate.targetting
  • rebate.negotiationQuality
  • review.reviewData
  • review.reviewComments
  • review.getReviewParticipants
  • rfp.download
  • rfp.checkQB
  • rfp.rebategetRFP
  • rfp.related
  • rfp.search
  • rfp.view
  • scheduler.getSchedules
  • scheduler.getSchedule
  • scheduler.runTask
  • scheduler.getTaskByRef
  • search.contacts
  • search.all
  • security.getBasicPermissions
  • security.getPermissions
  • signUp.test
  • signoff.index
  • signoff.get
  • signoff.getNegotiator
  • signoff.detail
  • site.getSite
  • site.getSites
  • site.autoCreate2
  • spend.NMBSMatch
  • spend.getLine
  • spend.indexItem
  • spend.indexDealSpend
  • spend.turnoverPosition
  • spend.getAmmendment
  • spend.ammendments
  • spend.queryData
  • spend.getExternalSummary
  • spend.getNMBSSummary
  • spend.sendReminder
  • spend.returns
  • spend.dodataTablesStruct
  • spend.getNMBSInvoices
  • spend.handsonData
  • spend.entrySpreadsheet
  • spend.positionChartData
  • spend.projectionAccuracy
  • spend.calendarProjections
  • spend.getErpLines
  • spend.getSupplierSpend
  • spend.companySpendSummary
  • spend.calendar
  • spend.reportBuilder
  • stats.activityChartMonth
  • survey.list
  • survey.getDCQ2Results
  • survey.recipients
  • survey.getResponses
  • survey.templateList
  • survey.index
  • tags.search
  • tags.list
  • tags.getRelatedTags
  • tags.getTags
  • task.list
  • task.show
  • task.myTasks
  • task.byRelated
  • task.runReminders
  • tender.detail
  • tender.list
  • tender.compare
  • tender.complete
  • tender.indexTender
  • tender.fixTenderDocs
  • tender.doPSABasedOn
  • tender.start
  • test.testSchedulerCache
  • test.gethost
  • tickets.checkMail
  • tickets.list
  • tickets.get
  • watching.getWatchers
  • watching.start
  • watching.stop
  • watching.getPreferences
  • whatif.census
  • whatif.parity
  • whatif.evaluate
  • whatif.scenario
  • whatif.result
  • whatif.linearReport