Forum

Ask, reply and learn. Join the community of Akaunting.

New Discussion

API Use for Self Install

Giles Shaxted   ( User )

Commented 2 hours ago

Is it possible for me to use the api to update my customers in my self installed akaunting set up?

I have an airtable for my crm and I wanted to use my n8n install to add a new customer to akaunting when a new customer is added in airtable.
The airtable is udated from all forms of contact from website and whatsapp.

Giles Shaxted   ( User )

Commented 2 hours ago

Self-hosted API: POST to /api/contacts returns 403 "User does not have any of the necessary access rights", but GET (including GET-based write actions like /enable) works fine with the same user

Akaunting self-hosted, Laravel 10.50.3, authenticating via HTTP Basic Auth (email/password) against /api/... routes.

GET /api/companies → works
GET /api/companies/{id}/enable → works (a write action, but GET verb)
POST /api/contacts with {"type":"customer","name":"...","email":"...","currency_code":"GBP","enabled":true} → {"message":"User does not have any of the necessary access rights.","status_code":403}
Same 403 even with an empty {} body, so it's not content-triggered

I confirmed via php artisan tinker that the authenticated user (admin role) has both read-api and create-sales-customers permissions ($user->hasPermission([...]) returns true for both). So the role/permission system itself says yes, but something in the request pipeline still blocks POST/PUT specifically while GET passes.

Enabling APP_DEBUG/API_DEBUG didn't add a trace to the JSON response, and I couldn't find a route-level permission: or ability: middleware applied differently per HTTP verb in routes/api.php or Kernel.php — the whole contacts resource shares one api middleware group.

Please login or register to leave a response.

Showing 1 to 2 of 2 discussions