> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fix RLS recommendations

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Applies the row-level security rules the app's latest security scan recommends, for the entities you name. Get the names from `rls_recommendations` in [Get security scan](/api-reference/get-security-scan).

For each entity, Base44 replaces the entity's `rls` with the recommendation's create, read, update, and delete rules, exactly as the scan stored them. An operation the recommendation has no rule for is left with no rule, which doesn't restrict it. It doesn't run the scan again or ask an AI model anything, and it uses no credits. The applied recommendations then move into the scan's resolved history, the same way [Dismiss RLS recommendation](/api-reference/dismiss-rls-recommendation) records a fix.

An entity with nothing to apply doesn't fail the call. It's listed in `failed` with the reason, and the rest are still applied. Those are saved in one step, so if saving fails, every one of them is listed in `failed` as `write_failed`. Some of their rules can still have changed in that case, so read the entities' schemas before you retry. Read both lists rather than treating a successful response as every entity fixed.

By default the fix also shows up in the app's AI chat, with a checkpoint of the app's code saved just before it, so you can roll it back from there. Set `record_security_fix_chat` to `false` to skip both.

This is limited to 30 requests a minute per caller for each app. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json post /api/apps/{app_id}/security/scan/rls/fix
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/security/scan/rls/fix:
    post:
      summary: Fix RLS recommendations
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Applies the row-level security rules the app's latest security scan
        recommends, for the entities you name. Get the names from
        `rls_recommendations` in [Get security
        scan](/api-reference/get-security-scan).


        For each entity, Base44 replaces the entity's `rls` with the
        recommendation's create, read, update, and delete rules, exactly as the
        scan stored them. An operation the recommendation has no rule for is
        left with no rule, which doesn't restrict it. It doesn't run the scan
        again or ask an AI model anything, and it uses no credits. The applied
        recommendations then move into the scan's resolved history, the same way
        [Dismiss RLS recommendation](/api-reference/dismiss-rls-recommendation)
        records a fix.


        An entity with nothing to apply doesn't fail the call. It's listed in
        `failed` with the reason, and the rest are still applied. Those are
        saved in one step, so if saving fails, every one of them is listed in
        `failed` as `write_failed`. Some of their rules can still have changed
        in that case, so read the entities' schemas before you retry. Read both
        lists rather than treating a successful response as every entity fixed.


        By default the fix also shows up in the app's AI chat, with a checkpoint
        of the app's code saved just before it, so you can roll it back from
        there. Set `record_security_fix_chat` to `false` to skip both.


        This is limited to 30 requests a minute per caller for each app. Some
        workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: fix_rls_recommendations_api_apps__app_id__security_scan_rls_fix_post
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RlsFixRequest'
      responses:
        '200':
          description: Which entities got their recommended rules, and which didn't.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RlsFixResponse'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key.
        '404':
          description: App not found.
        '409':
          description: >-
            A security scan is running on the app. Apply the fixes once it
            finishes.
        '422':
          description: >-
            The body is missing or has fields other than `entity_names`,
            `record_security_fix_chat`, and `security_fix_total_count`,
            `entity_names` is empty or holds more than 100 names, or a name has
            a character other than a letter, digit, or underscore.
        '429':
          description: Too many fix requests for this app from you in the last minute.
components:
  schemas:
    RlsFixRequest:
      properties:
        entity_names:
          items:
            type: string
          type: array
          maxItems: 100
          minItems: 1
          title: Entity Names
          description: >-
            Entities to fix, as returned in `rls_recommendations` by [Get
            security scan](/api-reference/get-security-scan). Name at least one
            and at most 100. A name listed twice is applied once.
          example:
            - Order
            - Customer
        record_security_fix_chat:
          type: boolean
          title: Record Security Fix Chat
          description: >-
            Whether to add the fix to the app's AI chat and save a checkpoint of
            the app first (`true`) or apply it with neither (`false`). Defaults
            to `true`.
          default: true
          example: true
        security_fix_total_count:
          anyOf:
            - type: integer
              minimum: 1
            - type: 'null'
          title: Security Fix Total Count
          description: >-
            When you split one fix across several calls, the total number of
            entities across all of them. It's used only in the chat message, and
            ignored unless it's larger than the number of names in
            `entity_names`.
          example: 150
      additionalProperties: false
      type: object
      required:
        - entity_names
      title: RlsFixRequest
      description: Which entities to apply the recommended row-level security rules to.
    RlsFixResponse:
      properties:
        fixed:
          items:
            type: string
          type: array
          title: Fixed
          description: >-
            Entities whose `rls` now holds the recommended rules. An entity can
            also appear in `failed` as `no_recommendation` when a newer scan
            replaced its recommendation while the rules were being applied.
          example:
            - Order
        failed:
          items:
            $ref: '#/components/schemas/RlsFixFailure'
          type: array
          title: Failed
          description: Entities that weren't fixed, each with the reason.
          example:
            - entity_name: Customer
              reason: no_recommendation
      type: object
      required:
        - fixed
        - failed
      title: RlsFixResponse
      description: Which entities got their recommended row-level security rules.
    RlsFixFailure:
      properties:
        entity_name:
          type: string
          title: Entity Name
          description: Entity that wasn't fixed.
          example: Customer
        reason:
          type: string
          enum:
            - no_scan
            - no_recommendation
            - entity_not_found
            - write_failed
          title: Reason
          description: >-
            Why it wasn't fixed. `no_scan` means the app has no scan result from
            the current scanner, so run [Run security
            scan](/api-reference/run-security-scan) first. `no_recommendation`
            means the latest result holds no recommendation for the entity,
            because it never had one or it was already resolved.
            `entity_not_found` means the app no longer has the entity.
            `write_failed` means saving the rules failed, though some of them
            may have landed, and the recommendation is kept so you can retry.
          example: no_recommendation
      type: object
      required:
        - entity_name
        - reason
      title: RlsFixFailure
      description: One entity whose recommended rules weren't applied.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````