MngCheckClientPassword¶
Verifies a client cabinet password without changing it. The answer is a boolean: the stored hash is never returned.
The command is available through the manager command API only; there is no REST
path for it. The kind is fixed by the command name, so customer_kind is not
accepted on input. See
Clients and Leads Commands.
It replaces the deprecated MngCheckCustomerPassword.
Access Control¶
Allowed sessions:
SESSION_MANAGERSESSION_ADMINSESSION_DEALERSESSION_CRM_MANAGERSESSION_CRM_ADMIN
The caller must have CRM access and see_clients_contacts. The record brand and desk
must be inside the manager scope; admin scope bypasses this check.
Request¶
{
"command": "MngCheckClientPassword",
"extID": "1",
"data": {
"customer_id": 1,
"password": "strong-password"
}
}
Request Data¶
| Field | Type | Required | Description |
|---|---|---|---|
customer_id |
int | Yes | Target customer id, 1 or greater |
password |
string | Yes | Password to verify, 6 to 128 characters |
Response Data¶
{
"customer_id": 1,
"valid": true
}
| Field | Type | Description |
|---|---|---|
customer_id |
int | The identifier passed in the request |
valid |
bool | Whether the supplied password matches the stored one |
A wrong password is not an error: the command answers 200 with
valid: false.
Errors¶
| HTTP | Error | Description |
|---|---|---|
400 |
INVALID_DATA |
Request validation failed |
400 |
RET_INVALID_DATA |
The customer exists but is not a client |
403 |
RET_NOT_ENOUGH_RIGHTS |
Missing permission, missing scope, or the record is outside the caller's visibility |
404 |
RET_NOT_FOUND |
No customer with that identifier exists |
Every error carries a message field with free-form text. Its contents are not
part of the contract; branch on error.