Koywe
What's new
FixAPI

Viewing a quote no longer requires payment permissions

Published on

No action needed. The permissions you already have now work as expected.

What was happening

Getting a quote by its ID only accepted permissions to initiate payments:

Terminal
curl 'https://api.koywe.com/api/v1/organizations/{organizationId}/merchants/{merchantId}/quotes/{quoteId}' \
  -H 'Authorization: Bearer <token>'

A user with the Viewer role could read an order, but requesting the quote for that same order returned 403 PER00001.

What changed

The endpoint now also accepts the permission to view transactions, same as getting the order. Whoever can see an order can now see its quote.

Roles and their permissions are in Roles.