# Create only One Public API

**URL:** <https://community.dreamfactory.com/t/create-only-one-public-api/1923>\
**Category:** Users & Roles\
**Created:** [December 15, 2015, 10:20am UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923 "2015-12-15T10:20:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![tejas](https://avatars.discourse-cdn.com/v4/letter/t/a698b9/32.png) [@tejas](https://community.dreamfactory.com/u/tejas)\
**Post date:** [December 15, 2015, 10:20am UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923/1 "2015-12-15T10:20:35Z")

</div>

How to create a single public api using roles. Added a guest role & allowed access to component “\*” for a service. It worked without login.

But when I change the component from \* to a specific component say “\_table/department/\*”, its returns 401 Unauthorized.

Would be great if somebody could help me on this.

---

<div class="post-metadata">

**Author:** ![sridharsa](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/sridharsa/32/541_2.png) [@sridharsa](https://community.dreamfactory.com/u/sridharsa)\
**Post date:** [December 17, 2015, 1:15am UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923/2 "2015-12-17T01:15:18Z")

</div>

Tejas,  
What version of DreamFactory are you working on?

We had a report similar to this which was fixed late last month. So, if you ran a git pull, it would get the latest code with the fix.

Please let me know about the version and I can guide further.

Sridhar

---

<div class="post-metadata">

**Author:** ![tejas](https://avatars.discourse-cdn.com/v4/letter/t/a698b9/32.png) [@tejas](https://community.dreamfactory.com/u/tejas)\
**Post date:** [December 17, 2015, 3:24am UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923/3 "2015-12-17T03:24:12Z")

</div>

Hey @sridharsa,

Thanks for the reply. I have installed the DreamFactory through Bitnami Installer.

DreamFactory shown on the admin panel is 2.0.2

---

<div class="post-metadata">

**Author:** ![formerstaff](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/formerstaff/32/1133_2.png) [@formerstaff](https://community.dreamfactory.com/u/formerstaff)\
**Post date:** [December 17, 2015, 1:52pm UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923/4 "2015-12-17T13:52:27Z")

</div>

@tejas I duplicated this issue and will be filing a bug.  
I was able to work around this issue though by changing the component access to “\_table/department/” instead of “\_table/department/\*”

---

<div class="post-metadata">

**Author:** ![formerstaff](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/formerstaff/32/1133_2.png) [@formerstaff](https://community.dreamfactory.com/u/formerstaff)\
**Post date:** [December 17, 2015, 3:29pm UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923/5 "2015-12-17T15:29:20Z")

</div>

Clarification:  
This is not a bug. The way the role access configuration works is thus.  
\_table/department/ allows you access to items at that level of the API (think like folder paths.) Get all records, user filters, etc.  
\_table/department/\* allows you access to items in the next level of the of REST path. For SQL tables this individual records by id. I.e. GET on \_table/department/4 retrieves the record whose ID is 4.

---

<div class="post-metadata">

**Author:** ![tejas](https://avatars.discourse-cdn.com/v4/letter/t/a698b9/32.png) [@tejas](https://community.dreamfactory.com/u/tejas)\
**Post date:** [December 18, 2015, 4:52am UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923/6 "2015-12-18T04:52:22Z")

</div>

Hey @formerstaff,

Thanks for the info on how the Roles work.

My scenario is as follows:

- Have 2 tables named X & Y
- X have a Foreign Key Constraint on “id” from Y, named Y\_ID.
- I am fetching the records in X by joining it with Y(Getting “name” from Y)
- I set the GET access to these 2 “\_table/X” & “\_table/Y” for a GUEST role.

Still getting the error "GET access to component ‘/\_table/Y’ of service ‘XYZ’ is not allowed by this user’s role."  
Error Code is 403

How can I handle this situation?

---

<div class="post-metadata">

**Author:** ![formerstaff](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/formerstaff/32/1133_2.png) [@formerstaff](https://community.dreamfactory.com/u/formerstaff)\
**Post date:** [December 18, 2015, 1:37pm UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923/7 "2015-12-18T13:37:41Z")

</div>

in your role, try adding access for both \_table/Y and \_table/Y/\*

---

<div class="post-metadata">

**Author:** ![tejas](https://avatars.discourse-cdn.com/v4/letter/t/a698b9/32.png) [@tejas](https://community.dreamfactory.com/u/tejas)\
**Post date:** [December 21, 2015, 5:46am UTC](https://community.dreamfactory.com/t/create-only-one-public-api/1923/8 "2015-12-21T05:46:51Z")

</div>

Hey @formerstaff,

Tried what you recommended. Didnt helped much.  
Is the sequence of the provided access important?
