Updated on 2026-08-10 GMT+08:00

Updating Role Permissions

Function

This API is used to update the permissions of a specified role by role ID, such as the permissions for creating and editing a repository, uploading, downloading, importing, and exporting packages, to implement centralized permission management and automated permission assignment.

Calling Method

For details, see Calling APIs.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

codeartsartifact:repository:edit

Write

-

-

-

-

URI

PUT /cloudartifact/v5/repositories/{role_id}/privileges

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

role_id

Yes

String

Definition:

Role ID.

Constraints:

N/A

Value range:

N/A

Default value:

None

Request Parameters

Table 2 Request body parameters

Parameter

Mandatory

Type

Description

privileges

Yes

Array of PrivilegeParam objects

Definition

Permission information.

Constraints

N/A.

Range

N/A.

Default value

None

Table 3 PrivilegeParam

Parameter

Mandatory

Type

Description

role_id

Yes

String

Definition

Role ID.

Constraints

N/A.

Range

N/A.

Default value

None

project_id

Yes

String

Definition

Project ID, which can be obtained by calling an API or from the console. For details about how to obtain the project ID, see Obtaining a Project ID (CloudArtifact_api_0015.xml).

Constraints

The value contains 32 characters. Only letters and digits are supported.

Range

N/A.

Default value

None

area_service_id

Yes

String

Definition

Region service ID.

Constraints

N/A.

Range

N/A.

Default value

None

granted_object_path

Yes

String

Definition

Authorization object path.

Constraints

N/A.

Range

N/A.

Default value

None

granted_object_type_id

Yes

String

Definition

Authorization object ID.

Constraints

N/A.

Range

N/A.

Default value

None

operations

Yes

String

Definition

Operation permission. Use commas (,) to separate multiple permissions.

Constraints

N/A.

Range

createrepository, editrepository, restore, deleterepository, physicdelete, restoreall, clearall, deleteorredeploy, downloadorview, import, upload, and export.

Default value

None

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

status

String

Definition

Request status.

Range

success: The request is successful.

error: The request fails.

trace_id

String

Definition

Request ID, which uniquely identifies the current request.

Range

A string of digits and hyphens (-).

result

Array of Privilege objects

Definition

Permission information.

Range

N/A.

Table 5 Privilege

Parameter

Type

Description

role_id

String

Definition

Role ID.

Range

N/A.

Default value

None

role_name

String

Definition

Role name.

Range

N/A.

Default value

None

role_chinese_name

String

Definition

Role name (CN).

Range

N/A.

Default value

None

project_id

String

Definition

Project ID.

Range

N/A.

Default value

None

area_service_id

String

Definition

Region service ID.

Range

N/A.

Default value

None

granted_object_path

String

Definition

Authorization object path.

Range

N/A.

Default value

None

granted_object_type_id

String

Definition

Authorization object ID.

Range

N/A.

Default value

None

operations

String

Definition

Operation permission. Use commas (,) to separate multiple permissions.

Range

N/A.

Default value

None

operations_index

Array of integers

Definition

Operation permission index.

Range

N/A.

Default value

None

Example Requests

Update repository permissions.

https://{URL}/cloudartifact/v5/repositories/6aa36d3dc51e4c0xxxx4da3047306/privileges

{
  "privileges" : [ {
    "granted_object_type_id" : "f1ba90c4xxxxaec9316b45408921",
    "granted_object_path" : "/codeartsartifact/artifact/component/xx-xxx-x_09d2ca2fxxxx0f51c00ae5bad0a0_docker2_5_27",
    "operations" : "downloadorview,export,import",
    "project_id" : "73e0adda5axxx8a1f869ec2a28a06",
    "role_id" : "6aa36d3dc51e4cxxx54da3047306",
    "area_service_id" : "c0ec24a43xxxx07785d882cf23a"
  }, {
    "granted_object_type_id" : "f9fa2e820725xxx0b1fa99ce931e",
    "granted_object_path" : "/codeartsartifact/artifact/repo/xx-xxx-x_09d2ca2f5080d5xxxxe5bad0a0_docker2_5_27",
    "operations" : "editrepository,restore,physicdelete,createrepository,restoreall",
    "project_id" : "73e0adda5acxxx1f869ec2a28a06",
    "role_id" : "6aa36d3dc51e4xxxx54da3047306",
    "area_service_id" : "c0ec24a435a640xxxx7785d882cf23a"
  } ]
}

Example Responses

Status code: 200

OK

{
  "status" : "success",
  "trace_id" : "20dadb7a95e34xxxxx60e1736ba771",
  "result" : [ {
    "operations" : "downloadorview,export,import",
    "role_id" : "6aa36d3dc51exxx4e154da3047306",
    "role_name" : null,
    "role_chinese_name" : null,
    "project_id" : "73e0adda5ace41f28xxxec2a28a06",
    "area_service_id" : "c0ec24a435a64xxx07785d882cf23a",
    "granted_object_path" : "/codeartsartifact/artifact/component/xx-xxx-x_09d2ca2f5xxxb60f51c00ae5bad0a0_docker2_5_27",
    "granted_object_type_id" : "f1ba90c49e17xxxc9316b45408921",
    "operations_index" : null
  }, {
    "operations" : "editrepository,restore,physicdelete,createrepository,restoreall",
    "role_id" : "6aa36d3dc51e4c088xxxxda3047306",
    "role_name" : null,
    "role_chinese_name" : null,
    "project_id" : "73e0adda5ace41xxxec2a28a06",
    "area_service_id" : "c0ec24a435a640xxxxd882cf23a",
    "granted_object_path" : "/codeartsartifact/artifact/repo/xx-xxx-x_09d2ca2f508xxxx51c00ae5bad0a0_docker2_5_27",
    "granted_object_type_id" : "f9fa2e8207254xxxxa0b1fa99ce931e",
    "operations_index" : null
  } ]
}

SDK Sample Code

The SDK sample code is as follows.

Java

Update repository permissions.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
package com.huaweicloud.sdk.test;

import com.huaweicloud.sdk.core.auth.ICredential;
import com.huaweicloud.sdk.core.auth.BasicCredentials;
import com.huaweicloud.sdk.core.exception.ConnectionException;
import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
import com.huaweicloud.sdk.core.exception.ServiceResponseException;
import com.huaweicloud.sdk.codeartsartifact.v2.region.CodeArtsArtifactRegion;
import com.huaweicloud.sdk.codeartsartifact.v2.*;
import com.huaweicloud.sdk.codeartsartifact.v2.model.*;

import java.util.List;
import java.util.ArrayList;

public class UpdateRepoRolesPrivilegeSolution {

    public static void main(String[] args) {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        String ak = System.getenv("CLOUD_SDK_AK");
        String sk = System.getenv("CLOUD_SDK_SK");

        ICredential auth = new BasicCredentials()
                .withAk(ak)
                .withSk(sk);

        CodeArtsArtifactClient client = CodeArtsArtifactClient.newBuilder()
                .withCredential(auth)
                .withRegion(CodeArtsArtifactRegion.valueOf("<YOUR REGION>"))
                .build();
        UpdateRepoRolesPrivilegeRequest request = new UpdateRepoRolesPrivilegeRequest();
        request.withRoleId("{role_id}");
        RolePrivilegeV5 body = new RolePrivilegeV5();
        List<PrivilegeParam> listbodyPrivileges = new ArrayList<>();
        listbodyPrivileges.add(
            new PrivilegeParam()
                .withRoleId("6aa36d3dc51e4cxxx54da3047306")
                .withProjectId("73e0adda5axxx8a1f869ec2a28a06")
                .withAreaServiceId("c0ec24a43xxxx07785d882cf23a")
                .withGrantedObjectPath("/codeartsartifact/artifact/component/xx-xxx-x_09d2ca2fxxxx0f51c00ae5bad0a0_docker2_5_27")
                .withGrantedObjectTypeId("f1ba90c4xxxxaec9316b45408921")
                .withOperations(PrivilegeParam.OperationsEnum.fromValue("downloadorview,export,import"))
        );
        listbodyPrivileges.add(
            new PrivilegeParam()
                .withRoleId("6aa36d3dc51e4xxxx54da3047306")
                .withProjectId("73e0adda5acxxx1f869ec2a28a06")
                .withAreaServiceId("c0ec24a435a640xxxx7785d882cf23a")
                .withGrantedObjectPath("/codeartsartifact/artifact/repo/xx-xxx-x_09d2ca2f5080d5xxxxe5bad0a0_docker2_5_27")
                .withGrantedObjectTypeId("f9fa2e820725xxx0b1fa99ce931e")
                .withOperations(PrivilegeParam.OperationsEnum.fromValue("editrepository,restore,physicdelete,createrepository,restoreall"))
        );
        body.withPrivileges(listbodyPrivileges);
        request.withBody(body);
        try {
            UpdateRepoRolesPrivilegeResponse response = client.updateRepoRolesPrivilege(request);
            System.out.println(response.toString());
        } catch (ConnectionException e) {
            e.printStackTrace();
        } catch (RequestTimeoutException e) {
            e.printStackTrace();
        } catch (ServiceResponseException e) {
            e.printStackTrace();
            System.out.println(e.getHttpStatusCode());
            System.out.println(e.getRequestId());
            System.out.println(e.getErrorCode());
            System.out.println(e.getErrorMsg());
        }
    }
}

Python

Update repository permissions.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
# coding: utf-8

import os
from huaweicloudsdkcore.auth.credentials import BasicCredentials
from huaweicloudsdkcodeartsartifact.v2.region.codeartsartifact_region import CodeArtsArtifactRegion
from huaweicloudsdkcore.exceptions import exceptions
from huaweicloudsdkcodeartsartifact.v2 import *

if __name__ == "__main__":
    # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak = os.environ["CLOUD_SDK_AK"]
    sk = os.environ["CLOUD_SDK_SK"]

    credentials = BasicCredentials(ak, sk)

    client = CodeArtsArtifactClient.new_builder() \
        .with_credentials(credentials) \
        .with_region(CodeArtsArtifactRegion.value_of("<YOUR REGION>")) \
        .build()

    try:
        request = UpdateRepoRolesPrivilegeRequest()
        request.role_id = "{role_id}"
        listPrivilegesbody = [
            PrivilegeParam(
                role_id="6aa36d3dc51e4cxxx54da3047306",
                project_id="73e0adda5axxx8a1f869ec2a28a06",
                area_service_id="c0ec24a43xxxx07785d882cf23a",
                granted_object_path="/codeartsartifact/artifact/component/xx-xxx-x_09d2ca2fxxxx0f51c00ae5bad0a0_docker2_5_27",
                granted_object_type_id="f1ba90c4xxxxaec9316b45408921",
                operations="downloadorview,export,import"
            ),
            PrivilegeParam(
                role_id="6aa36d3dc51e4xxxx54da3047306",
                project_id="73e0adda5acxxx1f869ec2a28a06",
                area_service_id="c0ec24a435a640xxxx7785d882cf23a",
                granted_object_path="/codeartsartifact/artifact/repo/xx-xxx-x_09d2ca2f5080d5xxxxe5bad0a0_docker2_5_27",
                granted_object_type_id="f9fa2e820725xxx0b1fa99ce931e",
                operations="editrepository,restore,physicdelete,createrepository,restoreall"
            )
        ]
        request.body = RolePrivilegeV5(
            privileges=listPrivilegesbody
        )
        response = client.update_repo_roles_privilege(request)
        print(response)
    except exceptions.ClientRequestException as e:
        print(e.status_code)
        print(e.request_id)
        print(e.error_code)
        print(e.error_msg)

Go

Update repository permissions.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
package main

import (
	"fmt"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
    codeartsartifact "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/codeartsartifact/v2"
	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/codeartsartifact/v2/model"
    region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/codeartsartifact/v2/region"
)

func main() {
    // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
    // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
    ak := os.Getenv("CLOUD_SDK_AK")
    sk := os.Getenv("CLOUD_SDK_SK")

    auth, err := basic.NewCredentialsBuilder().
        WithAk(ak).
        WithSk(sk).
        SafeBuild()

    if err != nil {
        fmt.Println(err)
        return
    }

    hcClient, err := codeartsartifact.CodeArtsArtifactClientBuilder().
         WithRegion(region.ValueOf("<YOUR REGION>")).
         WithCredential(auth).
         SafeBuild()


    if err != nil {
        fmt.Println(err)
        return
    }

    client := codeartsartifact.NewCodeArtsArtifactClient(hcClient)

    request := &model.UpdateRepoRolesPrivilegeRequest{}
	request.RoleId = "{role_id}"
	var listPrivilegesbody = []model.PrivilegeParam{
        {
            RoleId: "6aa36d3dc51e4cxxx54da3047306",
            ProjectId: "73e0adda5axxx8a1f869ec2a28a06",
            AreaServiceId: "c0ec24a43xxxx07785d882cf23a",
            GrantedObjectPath: "/codeartsartifact/artifact/component/xx-xxx-x_09d2ca2fxxxx0f51c00ae5bad0a0_docker2_5_27",
            GrantedObjectTypeId: "f1ba90c4xxxxaec9316b45408921",
            Operations: model.GetPrivilegeParamOperationsEnum().DOWNLOADORVIEW,EXPORT,IMPORT,
        },
        {
            RoleId: "6aa36d3dc51e4xxxx54da3047306",
            ProjectId: "73e0adda5acxxx1f869ec2a28a06",
            AreaServiceId: "c0ec24a435a640xxxx7785d882cf23a",
            GrantedObjectPath: "/codeartsartifact/artifact/repo/xx-xxx-x_09d2ca2f5080d5xxxxe5bad0a0_docker2_5_27",
            GrantedObjectTypeId: "f9fa2e820725xxx0b1fa99ce931e",
            Operations: model.GetPrivilegeParamOperationsEnum().EDITREPOSITORY,RESTORE,PHYSICDELETE,CREATEREPOSITORY,RESTOREALL,
        },
    }
	request.Body = &model.RolePrivilegeV5{
		Privileges: listPrivilegesbody,
	}
	response, err := client.UpdateRepoRolesPrivilege(request)
	if err == nil {
        fmt.Printf("%+v\n", response)
    } else {
        fmt.Println(err)
    }
}

More

For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.

Status Codes

Status Code

Description

200

OK

Error Codes

See Error Codes.