Three Access sections
Open Access in Entity settings. Entity CRUD access controls operations; External READ access controls record reads; Generated routes shows future addresses. Question-mark icons provide help.
Entity CRUD access
Choose Admin/external access per operation. Persistent supports List, Get, Create, Update, Delete; virtual supports only enabled reads.
| Setting | Who can use the operation |
|---|---|
| Admin enabled | admin role in administrative API |
| Admin disabled | Does not grant admin this operation; superadmin retains special privileges |
| External: Off | No external route generated |
| Authenticated user | Authenticated user and superadmin; admin alone is insufficient |
| Anonymous | Any client able to reach the API |
Anonymous requires confirming exposure to any API client. Returned data depends on the model and rules below. Website publishing needs reads; it does not require Create/Update/Delete.
External READ access
The server always applies these conditions to external List/Get. Client query parameters cannot remove them. They affect neither admin reads nor writes. If Get denies a record, clients receive 404 rather than its contents.
Click + Add in the relevant section; select field, operator and value. Operators depend on field type. The icon before trash wraps a condition in a group. AND requires all group conditions; OR requires at least one. Trash removes the selected condition/group.
Example: page, blocks and items
Consider a virtual entity based on PageBlock, including page (belongsTo → Page) and items (hasMany → BlockItem). Return visible blocks of published pages, with visible items having titles. Configure three sections:
| Section | Conditions | Restricted data |
|---|---|---|
| PageBlock | isVisible equal true |
Root blocks |
| Page | status equal published |
Root blocks through the related page |
| BlockItem / items | AND: isVisible equal true and title does not equal "" |
Items inside each block |
PageBlock and Page rules both apply to every root block. Do not choose OR between entities: both checks must pass. AND/OR combines conditions within one section only.
"" denotes an empty string. Select Use empty string if offered, or clear Constant value after typing. Do not enter two quotation marks as text. Empty differs from NULL. To exclude NULL from nullable fields, add a separate available NULL check. Whitespace is also not empty; the check does not trim it.
Collection behavior
Items rules filter before total counting and pagination. Without matches, API still returns the parent block with an empty collection. This is not a condition to return parents only when items exist.
Virtual rules and list capabilities are explicit; persistent-source settings are not inherited. Select a collection's own scalar fields. Arbitrary inverse paths such as items.block are not automatically offered.
Generated routes and applying changes
Generated routes previews addresses/access for the draft. Finish, then Generate → Preview changes and inspect Access and route impact. Saving rules does not change the running API: Generate and run the updated backend.
See access parameters and read rules.
Public-response cache
For repeated public reads, open Content → entity settings → Access → External READ access. Enable Cache public responses and set TTL (seconds). Cache defaults off; initial TTL is 30 seconds, allowed 1–3600. Save, Generate and release new code with its Nginx configuration.
Caching requires anonymous external List or Get, including virtual entities. It runs through generated Nginx in production/prod-local. Direct development Go requests bypass it. Authorization/Cookie requests, admin operations and errors are not cached.
TTL bounds how long a response may remain unchanged. Writes do not automatically clear cache; visitors may see old content until expiry. Related data/nested collections are included. Disable caching or reduce TTL where each change must appear immediately. Configure each entity separately: persistent settings do not automatically enable virtual caching.