Newman Report

Collection
API system role permissions
Description
This is a VERY cut down version of API permissions testing for system roles to serve as an example.
Time
Sun Jun 01 2025 00:00:00 GMT+0300 (Eastern European Summer Time)
Exported with
Newman v6.2.1
 
 
Total
Failed
Iterations
4
0
Requests
72
0
Prerequest Scripts
72
0
Test Scripts
76
0
Assertions
72
11
 
Total run duration
11.5s
Total data received
25.4KB (approx)
Average response time
64ms
 
Total Failures
11

Requests


Description
Log In This endpoint allows to use credentials to Log In into the system and receive Bearer token to send further requests with role permissions in the current session. HTTP Method: POST Endpoint: /auth/sign_in Request Body: { "username": "{{USER_LOGIN}}", "password": "{{USER_PASSWORD}}", "sso_auth_token":"", "station":"web_phone" } Post-response script: try { // get Bearer token const authHeader = pm.response.headers.get('Authorization'); const bearerToken = authHeader.match(/Bearer [\w\d=-_.]{1,}/)[0]; pm.environment.set("BEARER_TOKEN", bearerToken); } catch(error) { console.warn("Error with Sign In: No Authorization in header available: ", error); } try { // get API access token const accessToken = pm.response.json().data.access_token; pm.environment.set("API_ACCESS_TOKEN", accessToken); pm.environment.set("apiKey", accessToken); } catch(error) { console.warn("Error with Sign In: No Access Token in body available: ", error); }
 
Method
POST
URL
 
 
Mean time per request
321ms

Mean size per request
3.48KB

 

Total passed tests
4
Total failed tests
0

 

Status code
200

 
Tests
NamePass countFail count
administrator: Permission granted check: 200 with message: N/A10
supervisor: Permission granted check: 200 with message: N/A10
agent: Permission granted check: 200 with message: N/A10
agentBot: Permission granted check: 200 with message: N/A10

Description
Update Label This endpoint allows you to update an existing label associated with a specific account. HTTP Method: PATCH Endpoint: /api/v1/accounts/{{accountId}}/labels/{{labelId}} Request Parameters: The request body must be in JSON format and should include the following parameters: - title (string): The title of the label. - color (string): The color associated with the label. - description (string): A brief description of the label. - show_on_sidebar (boolean): Indicates whether the label should be displayed on the sidebar. - show_to_agents (boolean): Indicates whether the label should be visible to agents. Expected Response: Upon a successful update, the response will include the following fields: - id (string): The unique identifier of the label. - title (string): The updated title of the label. - color (string): The updated color of the label. - description (string): The updated description of the label. - show_on_sidebar (boolean): The current visibility status on the sidebar. - show_to_agents (boolean): The current visibility status to agents. - deleted (boolean): Indicates if the label has been marked as deleted.
 
Method
PATCH
URL
 
 
Mean time per request
50ms

Mean size per request
160B

 

Total passed tests
4
Total failed tests
0

 

Status code
400

 
Tests
NamePass countFail count
administrator: Permission granted check: 400 with message: show_on_sidebar must be a boolean value,show_to_agents must be a boolean value10
supervisor: Permission granted check: 400 with message: show_on_sidebar must be a boolean value,show_to_agents must be a boolean value10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 400 with message: show_on_sidebar must be a boolean value,show_to_agents must be a boolean value10
Description
Delete Label This endpoint allows users to delete a specific label associated with an account. HTTP Method: DELETE Endpoint: /api/v1/accounts/{{accountId}}/labels/{{labelId}} Request URL Parameters: - accountId (string): The unique identifier of the account from which the label will be deleted. - labelId (string): The unique identifier of the label that needs to be removed. Expected Response: Upon successful deletion, the API will return a response indicating the success of the operation. The response format will typically include a status message confirming that the label has been deleted.
 
Method
DELETE
URL
 
 
Mean time per request
51ms

Mean size per request
28B

 

Total passed tests
4
Total failed tests
0

 

Status code
200

 
Tests
NamePass countFail count
administrator: Permission granted check: 200 with message: N/A10
supervisor: Permission granted check: 200 with message: N/A10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 200 with message: N/A10
Description
Restore Label This endpoint allows users to restore a previously deleted label associated with a specific account. HTTP Method: POST Endpoint: /api/v1/accounts/{{accountId}}/labels/{{labelId}}/restore Request URL Parameters: - accountId (string): The unique identifier of the account to which the label belongs. - labelId (string): The unique identifier of the label that is to be restored. Expected Response: Upon a successful restoration, the API will return a response indicating the status of the operation. The response format will typically include: - status: (string) Indicates the success or failure of the restoration process. - message: (string) A message providing additional information about the operation. - data: (object) Contains details of the restored label, including its current state and associated account information. Example Response: { "status": "success", "message": "Label restored successfully.", "data": { "labelId": "12345", "accountId": "67890", "labelName": "Important", "isDeleted": false } }
 
Method
POST
URL
 
 
Mean time per request
52ms

Mean size per request
30B

 

Total passed tests
4
Total failed tests
0

 

Status code
200

 
Tests
NamePass countFail count
administrator: Permission granted check: 200 with message: N/A10
supervisor: Permission granted check: 200 with message: N/A10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 200 with message: N/A10

Description
### Get Account Labels This endpoint retrieves labels associated with a specific account. ### HTTP Method `GET` #### **Endpoint** `/api/v1/accounts/:accountId/labels` #### Query Parameters - **filter** (string): A filter to narrow down the labels based on the team name. - **q** (string): A query string to search for specific labels. #### Response On a successful request, the response will return a JSON object containing a `payload` array. Each item in the array represents a label associated with the specified account. The structure of the response is as follows: ``` json { "payload": [ { "value": "" } ] } ``` The `value` field will contain the label information, which may vary based on the labels associated with the account.
 
Method
GET
URL
 
 
Mean time per request
48ms

Mean size per request
14B

 

Total passed tests
4
Total failed tests
0

 

Status code
200

 
Tests
NamePass countFail count
administrator: Permission granted check: 200 with message: N/A10
supervisor: Permission granted check: 200 with message: N/A10
agent: Permission granted check: 200 with message: N/A10
agentBot: Permission granted check: 200 with message: N/A10
Description
## Create Label This endpoint allows users to create a new label associated with a specific account. Labels can be used for organizing and categorizing various elements within the account. ### HTTP Method POST #### **Endpoint** `/api/v1/accounts/:accountId/labels` #### Request Body The request body must be in JSON format and should include the following parameters: - **title** (string): The name of the label. This is a required field. - **color** (string): The color code for the label, typically in hexadecimal format. This is a required field. - **description** (string): A brief description of the label. This field is optional. - **show_on_sidebar** (boolean): A flag indicating whether the label should be displayed on the sidebar. This is a required field. - **show_to_agents** (boolean): A flag indicating whether the label should be visible to agents. This is a required field. #### Example Request Body ``` json { "title": "Label 1", "color": "#9E67F0", "description": "description", "show_on_sidebar": "true", "show_to_agents": "true" } ``` ### Response Upon successful creation of a label, the API returns a JSON object with the following structure: - **id** (string): The unique identifier for the created label. - **title** (string): The name of the label. - **color** (string): The color code associated with the label. - **description** (string): The description of the label. - **show_on_sidebar** (boolean): Indicates if the label is shown on the sidebar. - **show_to_agents** (boolean): Indicates if the label is visible to agents. - **deleted** (boolean): Indicates if the label has been marked as deleted. #### Example Response ``` json { "id": "", "title": "", "color": "", "description": "", "show_on_sidebar": "", "show_to_agents": "", "deleted": "" } ``` ### Notes - Ensure that the `accountId` in the URL is replaced with the actual account identifier. - The `show_on_sidebar` and `show_to_agents` parameters should be provided as boolean values (true/false).
 
Method
POST
URL
 
 
Mean time per request
48ms

Mean size per request
158B

 

Total passed tests
4
Total failed tests
0

 

Status code
400

 
Tests
NamePass countFail count
administrator: Permission granted check: 400 with message: show_on_sidebar must be a boolean value,show_to_agents must be a boolean value10
supervisor: Permission granted check: 400 with message: show_on_sidebar must be a boolean value,show_to_agents must be a boolean value10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 400 with message: show_on_sidebar must be a boolean value,show_to_agents must be a boolean value10

Description
### Add Substatus This endpoint allows you to add a substatus to a specific account identified by `accountId`. #### Request Method - **POST** #### Endpoint - `/api/v1/accounts/:accountId/substatus` #### Request Body The request should contain a JSON object with the following parameters: - **sequence** (string): A sequence number for the substatus. - **name** (string): The name of the substatus. - **status** (string): The current status of the account (e.g., busy, available). - **description** (string): A brief description of the substatus. **Example Request Body:** ``` json { "sequence": "7", "name": "Example", "status": "busy", "description": "Substatus description" } ``` #### Response Format On a successful request, the API will return a JSON object containing the details of the created substatus. The response will include the following fields: - **id** (string): Unique identifier for the substatus. - **sequence** (string): The sequence number of the substatus. - **name** (string): The name of the substatus. - **status** (string): The current status of the account. - **description** (string): Description of the substatus. - **system** (string): System-related information (if applicable). - **active** (string): Indicates whether the substatus is active. **Example Response:** ``` json { "id": "", "sequence": "", "name": "", "status": "", "description": "", "system": "", "active": "" } ```
 
Method
POST
URL
 
 
Mean time per request
47ms

Mean size per request
125B

 

Total passed tests
4
Total failed tests
0

 

Status code
400

 
Tests
NamePass countFail count
administrator: Permission granted check: 400 with message: sequence must be a number conforming to the specified constraints10
supervisor: Permission denied check: 403 with message: Forbidden resource10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission denied check: 403 with message: Forbidden resource10
Description
### Update Account Substatus This endpoint allows you to update the substatus of a specific account identified by `accountId`. #### Request - **Method**: PATCH - **Endpoint**: `/api/v1/accounts/:accountId/substatus` - **Request Body** (JSON): - `id` (string): The unique identifier for the substatus. - `name` (string): The name of the substatus. - `status` (string): The current status of the account (e.g., "busy"). - `description` (string): A description providing additional details about the substatus. #### Example Request Body ``` json { "id": "1111", "name": "Example", "status": "busy", "description": "Substatus description" } ``` #### Response Upon a successful request, the response will return a JSON object with the updated details of the substatus. The structure of the response includes: - `id` (string): The unique identifier for the substatus. - `sequence` (string): A sequence number associated with the substatus. - `name` (string): The name of the substatus. - `status` (string): The current status of the account. - `description` (string): The description of the substatus. - `system` (string): Information about the system managing the substatus. - `active` (string): Indicates whether the substatus is active. #### Example Response ``` json { "id": "", "sequence": "", "name": "", "status": "", "description": "", "system": "", "active": "" } ``` #### Notes - Ensure that the `accountId` in the URL is valid and corresponds to an existing account. - The request must include all required fields in the body to successfully update the substatus. - The response will reflect the current state of the substatus after the update.
 
Method
PATCH
URL
 
 
Mean time per request
49ms

Mean size per request
124B

 

Total passed tests
4
Total failed tests
0

 

Status code
400

 
Tests
NamePass countFail count
administrator: Permission granted check: 400 with message: id must be a number conforming to the specified constraints10
supervisor: Permission denied check: 403 with message: Forbidden resource10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission denied check: 403 with message: Forbidden resource10
Description
## Endpoint Description This endpoint retrieves the substatus information for a specific account identified by the `accountId`. ### Request - **HTTP Method**: GET - **Endpoint**: `/api/v1/accounts/:accountId/substatus` - **Path Parameters**: - `accountId` (string): The unique identifier of the account for which the substatus is being requested. ### Response Upon a successful request, the response will return a JSON object containing the following fields: - `id` (string): The unique identifier for the substatus. - `sequence` (string): The sequence number associated with the substatus. - `name` (string): The name of the substatus. - `status` (string): The current status of the substatus. - `description` (string): A brief description of the substatus. - `system` (string): The system associated with the substatus. - `active` (string): Indicates whether the substatus is currently active. ### Notes - Ensure that the `accountId` is valid and corresponds to an existing account to receive a successful response. - The response fields may vary based on the account's substatus configuration.
 
Method
GET
URL
 
 
Mean time per request
49ms

Mean size per request
1.13KB

 

Total passed tests
1
Total failed tests
3

 

Status code
200

 
Tests
NamePass countFail count
administrator: Permission granted check: 200 with message: N/A10
supervisor: Permission denied check: 200 with message: N/A01
agent: Permission denied check: 200 with message: N/A01
agentBot: Permission denied check: 200 with message: N/A01
Description
### DELETE Account Substatus This endpoint allows you to delete a specific substatus associated with an account. By providing the account ID and the substatus ID, you can remove the substatus from the system. #### Request Parameters - **accountId** (path parameter): The unique identifier of the account from which the substatus will be deleted. - **substatusId** (path parameter): The unique identifier of the substatus that you wish to delete. #### Expected Response Format Upon successful deletion, the response will return a JSON object containing the following fields: - **id**: The identifier of the deleted substatus. - **sequence**: The sequence number associated with the substatus. - **name**: The name of the deleted substatus. - **status**: The current status of the deleted substatus. - **description**: A brief description of the deleted substatus. - **system**: Information about the system related to the substatus. - **active**: Indicates whether the substatus was active before deletion. #### Additional Notes - Ensure that the provided `accountId` and `substatusId` are valid and exist in the system before making the request. - This operation is irreversible; once a substatus is deleted, it cannot be recovered. - Proper authentication and authorization may be required to perform this action.
 
Method
DELETE
URL
 
 
Mean time per request
52ms

Mean size per request
118B

 

Total passed tests
4
Total failed tests
0

 

Status code
404

 
Tests
NamePass countFail count
administrator: Permission granted check: 404 with message: substatus not found10
supervisor: Permission denied check: 403 with message: Forbidden resource10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission denied check: 403 with message: Forbidden resource10

Description
Deprecated: The endpoint is deleted from the application!
 
Method
GET
URL
 
 
Mean time per request
42ms

Mean size per request
168B

 

Total passed tests
0
Total failed tests
4

 

Status code
404

 
Tests
NamePass countFail count
administrator: Permission denied check: 404 with message: Cannot GET /api/v1/accounts/1/notifications/unread_count01
supervisor: Permission denied check: 404 with message: Cannot GET /api/v1/accounts/1/notifications/unread_count01
agent: Permission denied check: 404 with message: Cannot GET /api/v1/accounts/1/notifications/unread_count01
agentBot: Permission denied check: 404 with message: Cannot GET /api/v1/accounts/1/notifications/unread_count01
Description
Deprecated: The endpoint is deleted from the application!
 
Method
POST
URL
 
 
Mean time per request
41ms

Mean size per request
161B

 

Total passed tests
0
Total failed tests
4

 

Status code
404

 
Tests
NamePass countFail count
administrator: Permission denied check: 404 with message: Cannot POST /api/v1/accounts/1/notifications/read_all01
supervisor: Permission denied check: 404 with message: Cannot POST /api/v1/accounts/1/notifications/read_all01
agent: Permission denied check: 404 with message: Cannot POST /api/v1/accounts/1/notifications/read_all01
agentBot: Permission denied check: 404 with message: Cannot POST /api/v1/accounts/1/notifications/read_all01

Description
### Retrieve Skill Details This endpoint allows you to retrieve detailed information about a specific skill associated with a given account. #### Request Parameters - **accountId** (path parameter): The unique identifier of the account for which the skill information is being requested. - **skillId** (path parameter): The unique identifier of the skill whose details are to be fetched. #### Expected Response The response will return a JSON object containing the following fields: - **id**: The unique identifier of the skill. - **name**: The name of the skill. - **description**: A brief description of the skill. - **created_at**: The timestamp indicating when the skill was created. - **updated_at**: The timestamp indicating the last time the skill was updated. - **deleted**: A boolean indicating whether the skill has been marked as deleted. #### Notes - Ensure that the provided `accountId` and `skillId` are valid to receive the correct skill details. - The response fields will be populated based on the skill associated with the specified account.
 
Method
GET
URL
 
 
Mean time per request
54ms

Mean size per request
111B

 

Total passed tests
4
Total failed tests
0

 

Status code
200

 
Tests
NamePass countFail count
administrator: Permission granted check: 200 with message: N/A10
supervisor: Permission granted check: 200 with message: N/A10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 200 with message: N/A10
Description
### Update Skill for an Account This endpoint allows you to update the details of a specific skill associated with a user account. You can modify the skill's name and description by sending a PATCH request to the specified URL. #### Request Parameters - **Path Parameters:** - `accountId` (string): The unique identifier for the user account. - `skillId` (string): The unique identifier for the skill to be updated. - **Request Body:** The request body must be in JSON format and include the following parameters: - `name` (string): The new name of the skill. - `description` (string): The new description of the skill. #### Response Structure Upon a successful update, the response will return a JSON object containing the following fields: - `id` (string): The unique identifier of the skill. - `name` (string): The updated name of the skill. - `description` (string): The updated description of the skill. - `created_at` (string): The timestamp when the skill was created. - `updated_at` (string): The timestamp when the skill was last updated. - `deleted` (boolean): A flag indicating whether the skill has been deleted. This endpoint is essential for maintaining the accuracy and relevance of skills associated with user accounts.
 
Method
PATCH
URL
 
 
Mean time per request
60ms

Mean size per request
113B

 

Total passed tests
4
Total failed tests
0

 

Status code
404

 
Tests
NamePass countFail count
administrator: Permission granted check: 404 with message: skill not found10
supervisor: Permission granted check: 404 with message: skill not found10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 404 with message: skill not found10
Description
### DELETE /api/v1/accounts/:accountId/skills/:skillId This endpoint is used to delete a specific skill associated with a user account. By providing the unique identifiers for both the account and the skill, the user can remove the skill from their profile. #### Path Parameters - `accountId` (string): The unique identifier of the user account from which the skill will be deleted. - `skillId` (string): The unique identifier of the skill that needs to be removed. #### Expected Response Upon successful deletion, the server will respond with a status code indicating the result of the operation. The response typically includes: - A confirmation message indicating that the skill has been successfully deleted. - A status code of `204 No Content` if the deletion was successful, indicating that there is no additional content in the response body. In case of an error (e.g., if the account or skill does not exist), the server will return an appropriate error message with a relevant status code (e.g., `404 Not Found`).
 
Method
DELETE
URL
 
 
Mean time per request
49ms

Mean size per request
113B

 

Total passed tests
4
Total failed tests
0

 

Status code
404

 
Tests
NamePass countFail count
administrator: Permission granted check: 404 with message: skill not found10
supervisor: Permission granted check: 404 with message: skill not found10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 404 with message: skill not found10
Description
## Restore Skill for Account This endpoint allows users to restore a previously deleted skill associated with a specific account. It is useful for reactivating skills that may have been removed by mistake. ### Request Format #### **HTTP Method**: POST #### Endpoint `/api/v1/accounts/:accountId/skills/:skillId/restore` #### Request Body The request body should be sent in `application/x-www-form-urlencoded` format and must include the following parameters: - `parameter1` (text): Description of the first parameter. - `parameter2` (text): Description of the second parameter. - `parameter3` (file): Description of the file parameter, if applicable. ### Response Format On a successful request, the API will return a response in JSON format containing the details of the restored skill. The response will typically include: - `status`: Indicates the success or failure of the operation. - `data`: Contains the details of the restored skill, including its properties. ### Example Response ``` json { "status": "success", "data": { "skillId": "12345", "accountId": "67890", "skillName": "Example Skill", "status": "active" } } ``` Ensure that the `accountId` and `skillId` in the URL are correctly specified to target the appropriate skill for restoration.
 
Method
POST
URL
 
 
Mean time per request
46ms

Mean size per request
121B

 

Total passed tests
4
Total failed tests
0

 

Status code
404

 
Tests
NamePass countFail count
administrator: Permission granted check: 404 with message: skill not found10
supervisor: Permission granted check: 404 with message: skill not found10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 404 with message: skill not found10

Description
### Get Account Skills This endpoint retrieves a list of skills associated with a specific account identified by the `accountId`. #### Request Parameters - **accountId** (path parameter): The unique identifier of the account for which skills are being requested. #### Response Structure The response will be a JSON array containing skill objects, each with the following structure: - **id**: An object containing the skill's unique identifier. - **name**: An object representing the name of the skill. - **description**: An object that provides a description of the skill. - **created_at**: An object indicating the timestamp when the skill was created. - **updated_at**: An object indicating the timestamp when the skill was last updated. - **deleted**: An object indicating whether the skill has been marked as deleted. Example response: ``` json [ { "id": {"value": ""}, "name": {"value": ""}, "description": {"value": ""}, "created_at": {"value": ""}, "updated_at": {"value": ""}, "deleted": {"value": ""} } ] ```
 
Method
GET
URL
 
 
Mean time per request
48ms

Mean size per request
112B

 

Total passed tests
4
Total failed tests
0

 

Status code
200

 
Tests
NamePass countFail count
administrator: Permission granted check: 200 with message: N/A10
supervisor: Permission granted check: 200 with message: N/A10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 200 with message: N/A10
Description
## Add Skill to Account This endpoint allows you to add a new skill to a specific account identified by `accountId`. ### HTTP Method `POST` ### Endpoint `/api/v1/accounts/:accountId/skills` ### Request Parameters The request body must be in JSON format and include the following parameters: - **name** (string): The name of the skill being added. - **description** (string): A brief description of the skill. ### Example Request Body ``` json { "name": "string", "description": "string" } ``` ### Expected Response Upon a successful request, the API will return a JSON object containing the following fields: - **id** (string): The unique identifier for the skill. - **name** (string): The name of the skill. - **description** (string): The description of the skill. - **created_at** (string): Timestamp of when the skill was created. - **updated_at** (string): Timestamp of the last update to the skill. - **deleted** (boolean): Indicates if the skill has been deleted. ### Example Response ``` json { "id": "", "name": "", "description": "", "created_at": "", "updated_at": "", "deleted": "" } ``` This endpoint is essential for managing skills associated with accounts, enabling users to enhance their profiles with relevant competencies.
 
Method
POST
URL
 
 
Mean time per request
49ms

Mean size per request
127B

 

Total passed tests
4
Total failed tests
0

 

Status code
409

 
Tests
NamePass countFail count
administrator: Permission granted check: 409 with message: The name of this skill is already in use10
supervisor: Permission granted check: 409 with message: The name of this skill is already in use10
agent: Permission denied check: 403 with message: Forbidden resource10
agentBot: Permission granted check: 409 with message: The name of this skill is already in use10

Failures

 
Description
expected response to have status code 403 but got 404

Location
assertion:0 in test-script

Request
Iteration
1

 
Description
expected response to have status code 403 but got 404

Location
assertion:0 in test-script

Request
Iteration
1

 
Description
expected response to have status code 403 but got 200

Location
assertion:0 in test-script

Request
Iteration
2

 
Description
expected response to have status code 403 but got 404

Location
assertion:0 in test-script

Request
Iteration
2

 
Description
expected response to have status code 403 but got 404

Location
assertion:0 in test-script

Request
Iteration
2

 
Description
expected response to have status code 403 but got 200

Location
assertion:0 in test-script

Request
Iteration
3

 
Description
expected response to have status code 403 but got 404

Location
assertion:0 in test-script

Request
Iteration
3

 
Description
expected response to have status code 403 but got 404

Location
assertion:0 in test-script

Request
Iteration
3

 
Description
expected response to have status code 403 but got 200

Location
assertion:0 in test-script

Request
Iteration
4

 
Description
expected response to have status code 403 but got 404

Location
assertion:0 in test-script

Request
Iteration
4

 
Description
expected response to have status code 403 but got 404

Location
assertion:0 in test-script

Request
Iteration
4