KamoCRM

TeamController — list, create, read, update and delete (KamoCollab CP01 T10)

FeatureSecurityService
Shipped
October 5, 2026 at 7:53 AM UTC
Author
Kamo
Commit
4a91757

GET|POST /api/security/teams and GET|PUT|DELETE /api/security/teams/{id} (spec §5.7). Every handler resolves the caller first (401 without an org); reads are open to any session of the org; writes need CONFIGURE_SYSTEM or an open god window (403 MISSING_RIGHT with requiredRight), checked before the team is looked up. A non-UUID path id, an unknown id and another org's team are all 404 TEAM_NOT_FOUND. A write runs in TeamWriter's transaction, then TeamService.afterWrite outside it; create and update answer {team (the detail, with charter items), rightsRecalculated}, delete {deleted: true, rightsRecalculated}. Refusals keep TeamErrors' body, charter refusals CharterErrors' shape, and a constraint the database enforces against a concurrent save is a 409 asking for a reload, not a 500.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing