如何通过Azure DevOps REST API为指定Git仓库配置用户读写权限并限制其他仓库
Azure DevOps REST API 配置Git仓库用户权限指南
核心说明
你之前使用的Access Control Entitlement API是用于项目集合级的权限管理,而Git仓库的细粒度权限需要通过Access Control Lists (ACL) API操作,目标命名空间ID固定为2e9eb7ed-3c0a-47d4-87c1-0ffdd275fd87(Git Repository权限空间)。
步骤1:获取必要参数
- 用户descriptor:调用Graph Users API获取目标用户的唯一标识,格式如
aad.MjA...GET https://vssps.dev.azure.com/{organization}/_apis/graph/users?api-version=7.1-preview.1 - 仓库ID:获取所有Git仓库的ID,定位目标仓库
GET https://dev.azure.com/{organization}/{project}/_apis/git/repositories?api-version=7.1-preview.1 - 项目ID:可从项目设置页面或API请求的返回结果中获取
步骤2:为指定仓库添加读写权限
发送PATCH请求到ACL API,设置用户的读写权限:
PATCH https://dev.azure.com/{organization}/{project}/_apis/accesscontrolentries/2e9eb7ed-3c0a-47d4-87c1-0ffdd275fd87?api-version=7.1-preview.1
请求体(替换占位符为实际值):
[ { "descriptor": "{用户descriptor}", "allow": 31, "deny": 0, "inheritPermissions": false, "token": "repoV2/{项目ID}/{目标仓库ID}" } ]
说明:
allow=31是Git仓库读写权限的位掩码总和(Read(1)+Contribute(2)+Create branch/tag(4)+Edit policies(8)+Delete repository(16)),覆盖所有核心读写操作权限。
步骤3:限制用户访问另外两个仓库
通过添加拒绝权限条目覆盖继承的项目权限,确保用户无法访问目标仓库:
同样发送PATCH请求,每个仓库对应一个条目(可批量处理):
PATCH https://dev.azure.com/{organization}/{project}/_apis/accesscontrolentries/2e9eb7ed-3c0a-47d4-87c1-0ffdd275fd87?api-version=7.1-preview.1
请求体:
[ { "descriptor": "{用户descriptor}", "allow": 0, "deny": 31, "inheritPermissions": false, "token": "repoV2/{项目ID}/{被限制仓库1ID}" }, { "descriptor": "{用户descriptor}", "allow": 0, "deny": 31, "inheritPermissions": false, "token": "repoV2/{项目ID}/{被限制仓库2ID}" } ]
步骤4:验证权限配置
调用ACL查询API确认权限是否生效:
GET https://dev.azure.com/{organization}/{project}/_apis/accesscontrolentries/2e9eb7ed-3c0a-47d4-87c1-0ffdd275fd87?token=repoV2/{项目ID}/{仓库ID}&api-version=7.1-preview.1
返回结果中应显示目标用户对应的权限条目。
内容的提问来源于stack exchange,提问作者Jai
相关产品推荐
相关产品推荐

