Admin move an abuse report
const url = 'https://api.deploybase.eu/api/v1/api/v1/admin/abuse-reports/example/status';const options = { method: 'POST', headers: {Authorization: '<Authorization>', 'Content-Type': 'application/json'}, body: '{"resolution":"example","status":"example","team_id":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.deploybase.eu/api/v1/api/v1/admin/abuse-reports/example/status \ --header 'Authorization: <Authorization>' \ --header 'Content-Type: application/json' \ --data '{ "resolution": "example", "status": "example", "team_id": "example" }'Moves a notice: new to reviewing, then reviewing to actioned or rejected. Terminal statuses are final and closing a notice starts its 12-month retention clock. The resolution text is the raw material for the Article 17 statement of reasons sent to the affected customer, so it should name the acceptable-use clause that was breached, or say plainly why the notice was rejected.
Authorizations
Section titled “ Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “ Path Parameters ”Abuse report ID
Request Body
Section titled “ Request Body ”The requested transition
object
Resolution is what we did and why. Written on every transition, so an operator can record a finding while still reviewing rather than only at closure.
TeamID is the team the notice turned out to be about. An outcome of triage, never an access-control key.
Example generated
{ "resolution": "example", "status": "example", "team_id": "example"}Responses
Section titled “ Responses ”OK
object
object
object
ClosedAt is set exactly when Status is terminal (a CHECK constraint enforces the pair) and starts the 12-month retention clock.
GoodFaithDeclared is the Art. 16(2)(d) declaration. Always true on a stored row, kept so the record shows the declaration was actually made rather than assumed.
HandledBy is the Zitadel subject of the admin who last moved the row. Text, not uuid: there is no users table (same reasoning as notices.created_by).
ReportedURLs are the flagged URLs, 1 to 10, deduplicated case-insensitively at submission. NEVER fetched by us — see the service’s validation comment. The admin UI renders them as plain text, never as links.
ReporterEmail is where the acknowledgement and the statement of reasons go. Personal data: it is never written to a log line.
ReporterName is optional and empty when not given: Art. 16(2)(c) requires a name only for notices that are not about certain offences, so a blank is a lawful notice.
Resolution is what we did and why, in the operator’s own words. It is the raw material for the Art. 17 statement of reasons, so it should name the acceptable-use clause that was breached, or say plainly why the notice was rejected.
ResolvedTeamID is the team the notice turned out to be about. ON DELETE SET NULL in the schema: an account erasure must neither be blocked by this record nor destroy it.
Example generated
{ "data": { "category": "example", "closed_at": "example", "created_at": "example", "description": "example", "good_faith_declared": true, "handled_at": "example", "handled_by": "example", "id": "example", "reported_urls": [ "example" ], "reporter_email": "example", "reporter_name": "example", "resolution": "example", "resolved_team_id": "example", "status": "example" }, "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Bad Request
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Unauthorized
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Forbidden
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Not Found
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}The transition is not allowed, or the report moved while you were working on it
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Internal Server Error
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}Service Unavailable
object
object
Example generated
{ "code": "example", "details": "example", "error": "example", "meta": { "request_id": "example", "timestamp": "example", "trace_id": "example" }}