curl --request POST \
--url https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"entity_names": [
"Order",
"Customer"
],
"record_security_fix_chat": true,
"security_fix_total_count": 150
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix"
payload = {
"entity_names": ["Order", "Customer"],
"record_security_fix_chat": True,
"security_fix_total_count": 150
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
entity_names: ['Order', 'Customer'],
record_security_fix_chat: true,
security_fix_total_count: 150
})
};
fetch('https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'entity_names' => [
'Order',
'Customer'
],
'record_security_fix_chat' => true,
'security_fix_total_count' => 150
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix"
payload := strings.NewReader("{\n \"entity_names\": [\n \"Order\",\n \"Customer\"\n ],\n \"record_security_fix_chat\": true,\n \"security_fix_total_count\": 150\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"entity_names\": [\n \"Order\",\n \"Customer\"\n ],\n \"record_security_fix_chat\": true,\n \"security_fix_total_count\": 150\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"entity_names\": [\n \"Order\",\n \"Customer\"\n ],\n \"record_security_fix_chat\": true,\n \"security_fix_total_count\": 150\n}"
response = http.request(request)
puts response.read_body{
"fixed": [
"Order"
],
"failed": [
{
"entity_name": "Customer",
"reason": "no_recommendation"
}
]
}Fix RLS recommendations
Applies the row-level security rules the app’s latest security scan recommends, for the entities you name. Get the names from rls_recommendations in Get security scan.
For each entity, Base44 replaces the entity’s rls with the recommendation’s create, read, update, and delete rules, exactly as the scan stored them. An operation the recommendation has no rule for is left with no rule, which doesn’t restrict it. It doesn’t run the scan again or ask an AI model anything, and it uses no credits. The applied recommendations then move into the scan’s resolved history, the same way Dismiss RLS recommendation records a fix.
An entity with nothing to apply doesn’t fail the call. It’s listed in failed with the reason, and the rest are still applied. Those are saved in one step, so if saving fails, every one of them is listed in failed as write_failed. Some of their rules can still have changed in that case, so read the entities’ schemas before you retry. Read both lists rather than treating a successful response as every entity fixed.
By default the fix also shows up in the app’s AI chat, with a checkpoint of the app’s code saved just before it, so you can roll it back from there. Set record_security_fix_chat to false to skip both.
This is limited to 30 requests a minute per caller for each app. Some workspaces have a different limit.
curl --request POST \
--url https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"entity_names": [
"Order",
"Customer"
],
"record_security_fix_chat": true,
"security_fix_total_count": 150
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix"
payload = {
"entity_names": ["Order", "Customer"],
"record_security_fix_chat": True,
"security_fix_total_count": 150
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
entity_names: ['Order', 'Customer'],
record_security_fix_chat: true,
security_fix_total_count: 150
})
};
fetch('https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'entity_names' => [
'Order',
'Customer'
],
'record_security_fix_chat' => true,
'security_fix_total_count' => 150
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix"
payload := strings.NewReader("{\n \"entity_names\": [\n \"Order\",\n \"Customer\"\n ],\n \"record_security_fix_chat\": true,\n \"security_fix_total_count\": 150\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"entity_names\": [\n \"Order\",\n \"Customer\"\n ],\n \"record_security_fix_chat\": true,\n \"security_fix_total_count\": 150\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/scan/rls/fix")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"entity_names\": [\n \"Order\",\n \"Customer\"\n ],\n \"record_security_fix_chat\": true,\n \"security_fix_total_count\": 150\n}"
response = http.request(request)
puts response.read_body{
"fixed": [
"Order"
],
"failed": [
{
"entity_name": "Customer",
"reason": "no_recommendation"
}
]
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
ID of the app.
Body
Which entities to apply the recommended row-level security rules to.
Entities to fix, as returned in rls_recommendations by Get security scan. Name at least one and at most 100. A name listed twice is applied once.
1 - 100 elements["Order", "Customer"]
Whether to add the fix to the app's AI chat and save a checkpoint of the app first (true) or apply it with neither (false). Defaults to true.
true
When you split one fix across several calls, the total number of entities across all of them. It's used only in the chat message, and ignored unless it's larger than the number of names in entity_names.
x >= 1150
Response
Which entities got their recommended rules, and which didn't.
Which entities got their recommended row-level security rules.
Entities whose rls now holds the recommended rules. An entity can also appear in failed as no_recommendation when a newer scan replaced its recommendation while the rules were being applied.
["Order"]
Entities that weren't fixed, each with the reason.
Show child attributes
Show child attributes
[
{
"entity_name": "Customer",
"reason": "no_recommendation"
}
]
Was this page helpful?