curl --request DELETE \
--url https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"applied_rule": {
"create": true,
"read": {
"created_by": "{{user.email}}"
},
"update": {
"created_by": "{{user.email}}"
},
"delete": {
"$or": [
{
"created_by": "{{user.email}}"
},
{
"user_condition": {
"role": "admin"
}
}
]
}
}
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}"
payload = { "applied_rule": {
"create": True,
"read": { "created_by": "{{user.email}}" },
"update": { "created_by": "{{user.email}}" },
"delete": { "$or": [{ "created_by": "{{user.email}}" }, { "user_condition": { "role": "admin" } }] }
} }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.delete(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'DELETE',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
applied_rule: {
create: true,
read: {created_by: '{{user.email}}'},
update: {created_by: '{{user.email}}'},
delete: {$or: [{created_by: '{{user.email}}'}, {user_condition: {role: 'admin'}}]}
}
})
};
fetch('https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "DELETE",
CURLOPT_POSTFIELDS => json_encode([
'applied_rule' => [
'create' => true,
'read' => [
'created_by' => '{{user.email}}'
],
'update' => [
'created_by' => '{{user.email}}'
],
'delete' => [
'$or' => [
[
'created_by' => '{{user.email}}'
],
[
'user_condition' => [
'role' => 'admin'
]
]
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}"
payload := strings.NewReader("{\n \"applied_rule\": {\n \"create\": true,\n \"read\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"update\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"delete\": {\n \"$or\": [\n {\n \"created_by\": \"{{user.email}}\"\n },\n {\n \"user_condition\": {\n \"role\": \"admin\"\n }\n }\n ]\n }\n }\n}")
req, _ := http.NewRequest("DELETE", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.delete("https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"applied_rule\": {\n \"create\": true,\n \"read\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"update\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"delete\": {\n \"$or\": [\n {\n \"created_by\": \"{{user.email}}\"\n },\n {\n \"user_condition\": {\n \"role\": \"admin\"\n }\n }\n ]\n }\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Delete.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"applied_rule\": {\n \"create\": true,\n \"read\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"update\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"delete\": {\n \"$or\": [\n {\n \"created_by\": \"{{user.email}}\"\n },\n {\n \"user_condition\": {\n \"role\": \"admin\"\n }\n }\n ]\n }\n }\n}"
response = http.request(request)
puts response.read_body{
"status": "ok"
}Dismiss RLS recommendation
Removes one entity’s row-level security recommendation from the app’s latest security scan result. Get entity_name from rls_recommendations in Get security scan.
The call changes only the scan result, never the entity’s rules. There are two ways to use it:
- To record a fix, apply the rules with Update entity schema first, then send the same rules as
applied_rule. Base44 records them as you send them and doesn’t check them against the entity. - To dismiss the recommendation without changing anything, leave
applied_ruleout.
Either way the recommendation moves into the scan’s resolved history, along with who resolved it, when, and the recommendation as it stood.
The next scan that checks row-level security judges every entity again and clears that history, so a recommendation can come back if the entity’s rules still need to change.
The call is rejected when the latest result no longer holds a recommendation for the entity. That happens when the app has no scan result, when the result came from an earlier version of the scanner, when the recommendation was already resolved, or when a newer scan replaced it. Read the result again with Get security scan before you retry.
This is limited to 30 requests a minute per caller for each app. Some workspaces have a different limit.
curl --request DELETE \
--url https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"applied_rule": {
"create": true,
"read": {
"created_by": "{{user.email}}"
},
"update": {
"created_by": "{{user.email}}"
},
"delete": {
"$or": [
{
"created_by": "{{user.email}}"
},
{
"user_condition": {
"role": "admin"
}
}
]
}
}
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}"
payload = { "applied_rule": {
"create": True,
"read": { "created_by": "{{user.email}}" },
"update": { "created_by": "{{user.email}}" },
"delete": { "$or": [{ "created_by": "{{user.email}}" }, { "user_condition": { "role": "admin" } }] }
} }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.delete(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'DELETE',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
applied_rule: {
create: true,
read: {created_by: '{{user.email}}'},
update: {created_by: '{{user.email}}'},
delete: {$or: [{created_by: '{{user.email}}'}, {user_condition: {role: 'admin'}}]}
}
})
};
fetch('https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "DELETE",
CURLOPT_POSTFIELDS => json_encode([
'applied_rule' => [
'create' => true,
'read' => [
'created_by' => '{{user.email}}'
],
'update' => [
'created_by' => '{{user.email}}'
],
'delete' => [
'$or' => [
[
'created_by' => '{{user.email}}'
],
[
'user_condition' => [
'role' => 'admin'
]
]
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}"
payload := strings.NewReader("{\n \"applied_rule\": {\n \"create\": true,\n \"read\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"update\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"delete\": {\n \"$or\": [\n {\n \"created_by\": \"{{user.email}}\"\n },\n {\n \"user_condition\": {\n \"role\": \"admin\"\n }\n }\n ]\n }\n }\n}")
req, _ := http.NewRequest("DELETE", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.delete("https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"applied_rule\": {\n \"create\": true,\n \"read\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"update\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"delete\": {\n \"$or\": [\n {\n \"created_by\": \"{{user.email}}\"\n },\n {\n \"user_condition\": {\n \"role\": \"admin\"\n }\n }\n ]\n }\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/scan/rls-recommendation/{entity_name}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Delete.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"applied_rule\": {\n \"create\": true,\n \"read\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"update\": {\n \"created_by\": \"{{user.email}}\"\n },\n \"delete\": {\n \"$or\": [\n {\n \"created_by\": \"{{user.email}}\"\n },\n {\n \"user_condition\": {\n \"role\": \"admin\"\n }\n }\n ]\n }\n }\n}"
response = http.request(request)
puts response.read_body{
"status": "ok"
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
Entity whose recommendation to remove, as returned in rls_recommendations by Get security scan. It contains only letters, digits, and underscores.
ID of the app.
Body
The rules you applied to the entity, keyed by operation in the same format as the entity's rls. Send it to record the call as a fix. Leave it out, or send null or an empty object, to record a plain dismissal. Keys other than the five operations are rejected.
A filter can use only the query operators $eq, $ne, $gt, $gte, $lt, $lte, $in, $nin, $and, $or, $not, $nor, $exists, $type, $all, $elemMatch, $size, $regex, $options, $text, $search, $near, $nearSphere, $geoIntersects, and $geoWithin. $and, $or, and $nor take a list. $in, $nin, and $all take a list or a template string such as {{user.data.departments}}. user_condition takes an object.
The whole value can be up to 20,000 bytes as compact JSON, nest up to 8 levels deep, and hold up to 200 keys in total. Lists can hold up to 50 items, keys up to 200 characters, and strings up to 2,000 characters. The keys __proto__, constructor, and prototype aren't allowed.
Show child attributes
Show child attributes
{
"create": true,
"read": { "created_by": "{{user.email}}" },
"update": { "created_by": "{{user.email}}" },
"delete": {
"$or": [
{ "created_by": "{{user.email}}" },
{ "user_condition": { "role": "admin" } }
]
}
}
Response
The recommendation left the scan result.
Confirms that the recommendation left the scan result.
Always ok. The recommendation is no longer in the scan result.
"ok"
Was this page helpful?