Help Center/ CodeArts Artifact/ API Reference/ API/ User Management/ Querying Repository Permissions
Updated on 2026-08-10 GMT+08:00

Querying Repository Permissions

Function

This API is used to query the permissions of a specified repository by repository ID, including the permissions of each role on the repository. When a user needs to specify permissions for a repository, they can call this API to view the roles to be authorized.

Calling Method

For details, see Calling APIs.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

codeartsartifact:repository:read

Read

-

-

-

-

URI

GET /cloudartifact/v5/repositories/{project_id}/{repo_id}/privileges

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition:

Project ID. It can be obtained by calling an API or from the console. For details about how to obtain the project ID, see Obtaining a Project ID (CloudArtifact_api_0015.xml).

Constraints:

The value can contain 32 characters. Only letters and digits are supported.

Value range:

N/A

Default value:

None

repo_id

Yes

String

Definition:

Repository ID. You can view the repository ID on the General page of the repository.

Constraints:

N/A

Value range:

N/A

Default value:

None

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

x-language

No

String

Definition:

Language type.

Constraints:

N/A

Value range:

zh-cn and en-us.

Default value:

zh-cn.

Response Parameters

Status code: 200

Table 3 Response body parameters

Parameter

Type

Description

status

String

Definition

Request status.

Range

success: The request is successful.

error: The request fails.

trace_id

String

Definition

Request ID, which uniquely identifies the current request.

Range

A string of digits and hyphens (-).

result

result object

Definition

Query result.

Range

N/A.

Default value

None

Table 4 result

Parameter

Type

Description

$role_name

Array of Privilege objects

Definition

Permission information. $role_name is a dynamic role name.

Range

N/A.

Default value

None

Table 5 Privilege

Parameter

Type

Description

role_id

String

Definition

Role ID.

Range

N/A.

Default value

None

role_name

String

Definition

Role name.

Range

N/A.

Default value

None

role_chinese_name

String

Definition

Role name (CN).

Range

N/A.

Default value

None

project_id

String

Definition

Project ID.

Range

N/A.

Default value

None

area_service_id

String

Definition

Region service ID.

Range

N/A.

Default value

None

granted_object_path

String

Definition

Authorization object path.

Range

N/A.

Default value

None

granted_object_type_id

String

Definition

Authorization object ID.

Range

N/A.

Default value

None

operations

String

Definition

Operation permission. Use commas (,) to separate multiple permissions.

Range

N/A.

Default value

None

operations_index

Array of integers

Definition

Operation permission index.

Range

N/A.

Default value

None

Example Requests

Query repository permissions.

https://{URL}/cloudartifact/v5/repositories/73e0adda5ace41fxxxxec2a28a06/xx-xxx-x_09d2ca2f5080dxxxc00ae5bad0a0_docker2_5_27/privileges

Example Responses

Status code: 200

OK

{
  "status" : "success",
  "trace_id" : "9d97e8db2a9348xxx046f0b91e78ee",
  "result" : {
    "System engineer" : [ {
      "operations" : "downloadorview,import,upload,export",
      "role_id" : "0e9fa4b22c3cxx3128e2eac3ba17",
      "role_name" : "System engineer",
      "role_chinese_name" : "System engineer.",
      "project_id" : "73e0adda5acexx8a1f869ec2a28a06",
      "area_service_id" : "c0ec24a435axxb07785d882cf23a",
      "granted_object_path" : "/codeartsartifact/artifact/component/xx-xxx-x_09d2ca2f508xx51c00ae5bad0a0_docker2_5_27",
      "granted_object_type_id" : "f1ba90c49e174xxc9316b45408921",
      "operations_index" : null
    }, {
      "operations" : "editrepository,restore,physicdelete",
      "role_id" : "0e9fa4b22c3c41xx3128e2eac3ba17",
      "role_name" : "System engineer",
      "role_chinese_name" : "System engineer.",
      "project_id" : "73e0adda5acexxf869ec2a28a06",
      "area_service_id" : "c0ec24a435a64xxb07785d882cf23a",
      "granted_object_path" : "/codeartsartifact/artifact/repo/xx-xxx-x_09d2ca2f5080dxxxf51c00ae5bad0a0_docker2_5_27",
      "granted_object_type_id" : "f9fa2e82072xxxa7a0b1fa99ce931e",
      "operations_index" : null
    } ],
    "Project manager" : [ {
      "operations" : "deleteorredeploy,downloadorview,import,upload,export",
      "role_id" : "1d87e5606e554xxxx982e4baf1a2",
      "role_name" : "Project manager",
      "role_chinese_name" : "Project manager.",
      "project_id" : "73e0adda5ace41f2xxxxec2a28a06",
      "area_service_id" : "c0ec24a435a64xxxx85d882cf23a",
      "granted_object_path" : "/codeartsartifact/artifact/component/xx-xxx-x_09d2ca2f5xxxx60f51c00ae5bad0a0_docker2_5_27",
      "granted_object_type_id" : "f1ba90c4xxxxfaec9316b45408921",
      "operations_index" : null
    }, {
      "operations" : "createrepository,editrepository,restore,deleterepository,physicdelete,restoreall,clearall",
      "role_id" : "1d87e5606e5xxxxc4982e4baf1a2",
      "role_name" : "Project manager",
      "role_chinese_name" : "Project manager.",
      "project_id" : "73e0adda5ace41fxxxec2a28a06",
      "area_service_id" : "c0ec24a435a6407xxxxd882cf23a",
      "granted_object_path" : "/codeartsartifact/artifact/repo/xx-xxx-x_09d2ca2f50xxxxf51c00ae5bad0a0_docker2_5_27",
      "granted_object_type_id" : "f9fa2e8207254xxxxa0b1fa99ce931e",
      "operations_index" : null
    } ]
  }
}

SDK Sample Code

The SDK sample code is as follows.

Java

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.codeartsartifact.v2.region.CodeArtsArtifactRegion;
import com.huaweicloud.sdk.codeartsartifact.v2.*;
import com.huaweicloud.sdk.codeartsartifact.v2.model.*;


public class ShowRepositoryRolesPrivilegeSolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");

        ICredential auth = new BasicCredentials()
                .withAk(ak)
                .withSk(sk);

        CodeArtsArtifactClient client = CodeArtsArtifactClient.newBuilder()
                .withCredential(auth)
                .withRegion(CodeArtsArtifactRegion.valueOf("<YOUR REGION>"))
                .build();
        ShowRepositoryRolesPrivilegeRequest request = new ShowRepositoryRolesPrivilegeRequest();
        request.withProjectId("{project_id}");
        request.withRepoId("{repo_id}");
        try {
            ShowRepositoryRolesPrivilegeResponse response = client.showRepositoryRolesPrivilege(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}

Python

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
# coding: utf-8

import os
from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdkcodeartsartifact.v2.region.codeartsartifact_region import CodeArtsArtifactRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdkcodeartsartifact.v2 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = os.environ["CLOUD_SDK_AK"]
    sk = os.environ["CLOUD_SDK_SK"]

    credentials = BasicCredentials(ak, sk)

    client = CodeArtsArtifactClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(CodeArtsArtifactRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = ShowRepositoryRolesPrivilegeRequest()
        request.project_id = "{project_id}"
        request.repo_id = "{repo_id}"
        response = client.show_repository_roles_privilege(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)

Go

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    codeartsartifact "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/codeartsartifact/v2"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/codeartsartifact/v2/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/codeartsartifact/v2/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")

    auth, err := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        SafeBuild()

    if err != nil {
        fmt.Println(err)
        return
    }

    hcClient, err := codeartsartifact.CodeArtsArtifactClientBuilder().
         WithRegion(region.ValueOf("<YOUR REGION>")).
         WithCredential(auth).
         SafeBuild()


    if err != nil {
        fmt.Println(err)
        return
    }

    client := codeartsartifact.NewCodeArtsArtifactClient(hcClient)

    request := &model.ShowRepositoryRolesPrivilegeRequest{}
	request.ProjectId = "{project_id}"
	request.RepoId = "{repo_id}"
	response, err := client.ShowRepositoryRolesPrivilege(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

More

For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.

Status Codes

Status Code

Description

200

OK

Error Codes

See Error Codes.