I want to check who has permissions to access some of the repos in the project via REST API. I referred to the documentations, but could find anything.
I want to check who has permissions to access some of the repos in the project via REST API. I referred to the documentations, but could find anything.
Using the AzurePipelinesPS PowerShell module you can run the following commands to create a permission report and save the file locally. Where _yourSessionName_ is the name of your session. To learn more about session management with AzurePipelinesPS you can review the documentation here.
Creates a report for a repository in a team project where _myTeamProjectName_ is the name of your team project and _myRepoName_ is the name of your repository. This input object can be modified to create all kinds of permissions reports. See the documentation here.
New-APPermissionReport -Session '_yourSessionName_' -InputObject @{
descriptors = @()
reportName = 'myFirstPermissionReport'
resources = @(
@{
resourceId = '_myTeamProjectName_/_myRepoName_'
resourceName = '_myRepoName_'
resourceType = 'repo'
}
)
}
Returns the report information for the first report in the list
$session = '_yourSessionName_'
$reports = Get-APPermissionReportList -Session $session
Get-APPermissionReport -Session $session -ReportId $reports[0].id
Saves the first report in the list to a file located at c:\temp\myReport.json
$session = '_yourSessionName_'
$reports = Get-APPermissionReportList -Session $session
Save-APPermissionReport -Session $session -ReportId $reports[0].id -OutputPath C:\temp\myReport.json
If you have any issues with the module please feel free to open an issue on the AzurePipelinesPS Github project
How to list the groups/user who has permissions to the project repo with Azure DevOps API?
For now, I am afraid there is no such Rest API to get git repo permissions for each User/Group.
Although the methods are listed in the preview version REST API Permissions Report - List, it seems that such a REST API has not yet been fully implemented:
This REST API will hopefully be released soon.
You could check this similar thread and this thread for some details.
This is a 3 part exercise to get these reports: #Request the report:
$uri= -join("https://dev.azure.com/", $Account, "/_apis/permissionsreport?api-version=6.1-preview.1")
$Report=Invoke-RestMethod -Method Post -Uri $uri -Headers @{Authorization=("Basic {0}" -f $auth)} -ContentType "application/json" -Body $body
$fileUri=-join($Report[0]._Link.href, "?api-version=6.0-preview.1")
do{
#Now wait for it to complete:
sleep -Seconds 45
$ReportObj=Invoke-RestMethod -Method get -Uri $Fileuri -Headers @{Authorization=("Basic {0}" -f $auth)} -ContentType "application/json"
}while($ReportObj.reportStatus -ne "completedSuccessfully" -and $ReportObj.error -eq $null)
#Now get the report
$fileUri=-join($Report[0]._downloadLink.href, "?api-version=6.0-preview.1")
$ReportObj=Invoke-RestMethod -Method get -Uri $Fileuri -Headers @{Authorization=("Basic {0}" -f $auth)} -ContentType "application/json"
#because this isn't designed to be read directly like I've done, you have to clean it up:
$ReportObj=$ReportObj.Replace("", "") | ConvertFrom-Json
I've found it to be too slow for my purposes. I have a project with 1300 items that have to be checked individually, so far, it has been running for 27 hours and I expect it to not be completed until this weekend. The Resource data can only be one. it doesn't support multiples like the Descriptor The descriptor can't handle any more than 70. None of that is documented.
$ReportObj=$ReportObj.Replace("", "") This work only in Powershell 7.* version
PowerShell 5.1: ❌ PowerShell Core 7.1.3: ✔