You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure CLI或REST API重置项目仓库安全组权限为‘未设置’

如何将Azure DevOps项目所有仓库的Contributors组Create branch权限重置为“Not set”

不管用Azure CLI还是REST API,要将权限从“Allow”改为“Not set”,核心是移除之前设置的Allow权限位,而不是设置新的允许/拒绝规则。以下是具体实现方法:

使用Azure CLI

az devops security permission update命令支持通过--remove-allow-bit参数清除指定的允许权限位,从而将权限重置为“Not set”。

完整命令示例

az devops security permission update `
--org "https://dev.azure.com/$orgname/" `
--id "2e9eb7ed-3c0a-47d4-87c1-0ffdd275fd87" ` # 仓库权限的固定命名空间ID
--subject $subject ` # Contributors组的descriptor
--token "repoV2/$projectid" ` # 项目所有仓库的权限令牌
--remove-allow-bit 2 ` # Create branch对应的权限位(固定值为2)
--merge true

关键参数说明

  • --id: 仓库权限的命名空间ID是固定值2e9eb7ed-3c0a-47d4-87c1-0ffdd275fd87,无需修改。
  • --subject: 需要替换为Contributors组的descriptor,可以通过以下命令获取:
    az devops security group list --org "https://dev.azure.com/$orgname/" --project $projectid --query "[?displayName=='Contributors'].descriptor" -o tsv
    
  • --remove-allow-bit: 对应要清除的权限位,Create branch的权限位固定为2。
  • --merge true: 确保只移除指定的权限位,不影响其他已设置的权限。

使用REST API

通过Azure DevOps的Security Permissions PATCH接口,同样可以移除指定的允许权限位。

请求详情

  • 请求方法: PATCH
  • 请求URL:
    https://dev.azure.com/{orgname}/_apis/securitypermissions/2e9eb7ed-3c0a-47d4-87c1-0ffdd275fd87/repoV2/{projectid}?api-version=7.1-preview.2
    
  • 请求体:
    {
      "subjectDescriptor": "{contributors-group-descriptor}",
      "update": {
        "removeAllow": 2
      },
      "merge": true
    }
    

说明

  • subjectDescriptor: 替换为Contributors组的descriptor(获取方式同上)。
  • removeAllow: 设置为2,对应清除Create branch的Allow权限。
  • merge: 设置为true,保证仅修改目标权限位,不覆盖其他权限配置。

内容的提问来源于stack exchange,提问作者Joe_12345

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 16:17:33