{
  "info": {
    "name": "TabGecko Local API",
    "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json",
    "description": "TabGecko Local API 0.5.2. Generated from the matching OpenAPI source. 299 native operations plus MCP examples. Set local environment values after import. Review each request; non-allowlisted operations require allowRequestOnce. Setup: https://docs.tabgecko.com/downloads/"
  },
  "auth": {
    "type": "bearer",
    "bearer": [
      {
        "key": "token",
        "value": "{{bearerToken}}",
        "type": "string"
      }
    ]
  },
  "variable": [
    {
      "key": "baseUrl",
      "value": "http://127.0.0.1:47300",
      "type": "string"
    },
    {
      "key": "bearerToken",
      "value": "",
      "type": "string"
    },
    {
      "key": "mcpToken",
      "value": "",
      "type": "string"
    }
  ],
  "item": [
    {
      "name": "System",
      "item": [
        {
          "name": "GET /status — Erreichbarkeit prüfen (ohne Token)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "noauth"
            },
            "url": {
              "raw": "{{baseUrl}}/status",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "status"
              ],
              "query": [],
              "variable": []
            },
            "description": "Erreichbarkeit prüfen (ohne Token)\n\nFeste Route-Scopes: keine zusätzlichen Route-Scopes. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /status. Tags: System.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/status$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /status\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/status\";",
                  "const authenticated = true;",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/version — Versionen von App, API und Datenbank",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/version",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "version"
              ],
              "query": [],
              "variable": []
            },
            "description": "Versionen von App, API und Datenbank\n\nFeste Route-Scopes: keine zusätzlichen Route-Scopes. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/version. Tags: System.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/version$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/version\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/version\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/system/status — Zustand des Core",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/system/status",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "system",
                "status"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zustand des Core\n\nFeste Route-Scopes: keine zusätzlichen Route-Scopes. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/system/status. Tags: System.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/system/status$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/system/status\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/system/status\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/system/logs — Vorhandene technische Protokolldateien auflisten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/system/logs",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "system",
                "logs"
              ],
              "query": [],
              "variable": []
            },
            "description": "Vorhandene technische Protokolldateien auflisten\n\nFeste Route-Scopes: audit:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/system/logs. Tags: System.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/system/logs“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/system/logs$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/system/logs\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/system/logs\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/system/logs/{stream}/{file} — Bereinigten Auszug einer technischen Protokolldatei lesen (maximal 256 KiB und 1.000 Zeilen)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/system/logs/:stream/:file",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "system",
                "logs",
                ":stream",
                ":file"
              ],
              "query": [],
              "variable": [
                {
                  "key": "stream",
                  "value": "core",
                  "description": "Pflichtfeld. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"core\"]},{\"type\":\"string\",\"enum\":[\"api\"]},{\"type\":\"string\",\"enum\":[\"jobs\"]},{\"type\":\"string\",\"enum\":[\"kernel\"]},{\"type\":\"string\",\"enum\":[\"relay\"]}]}"
                },
                {
                  "key": "file",
                  "value": "core.log",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":155,\"pattern\":\"^[a-zA-Z0-9][a-zA-Z0-9._-]{0,150}\\\\.log$\"}"
                }
              ]
            },
            "description": "Bereinigten Auszug einer technischen Protokolldatei lesen (maximal 256 KiB und 1.000 Zeilen)\n\nFeste Route-Scopes: audit:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/system/logs/{stream}/{file}. Tags: System.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/system/logs/{stream}/{file}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath stream: Pflichtfeld. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"core\"]},{\"type\":\"string\",\"enum\":[\"api\"]},{\"type\":\"string\",\"enum\":[\"jobs\"]},{\"type\":\"string\",\"enum\":[\"kernel\"]},{\"type\":\"string\",\"enum\":[\"relay\"]}]}\npath file: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":155,\"pattern\":\"^[a-zA-Z0-9][a-zA-Z0-9._-]{0,150}\\\\.log$\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/system/logs/[^/?#]+/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/system/logs/{stream}/{file}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/system/logs/{stream}/{file}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/settings/logs — Aufbewahrung der Protokolldateien von Programm und Browser-Kernen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/logs",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "logs"
              ],
              "query": [],
              "variable": []
            },
            "description": "Aufbewahrung der Protokolldateien von Programm und Browser-Kernen\n\nFeste Route-Scopes: keine zusätzlichen Route-Scopes. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/settings/logs. Tags: System.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/settings/logs$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/settings/logs\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/settings/logs\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/settings/logs — Aufbewahrung der Protokolldateien ändern (1–365 Tage); ältere Dateien entfernt der tägliche Aufräumlauf",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/logs",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "logs"
              ],
              "query": [],
              "variable": []
            },
            "description": "Aufbewahrung der Protokolldateien ändern (1–365 Tage); ältere Dateien entfernt der tägliche Aufräumlauf\n\nFeste Route-Scopes: settings:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/settings/logs. Tags: System.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/settings/logs“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"retention_days\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 365\n    },\n    \"kernel_retention_days\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 365\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"retention_days\": 30\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/settings/logs$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/settings/logs\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/settings/logs\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Account",
      "item": [
        {
          "name": "GET /api/v1/account/status — Serverbestätigten Kontostatus abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/account/status",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "account",
                "status"
              ],
              "query": [],
              "variable": []
            },
            "description": "Serverbestätigten Kontostatus abrufen\n\nFeste Route-Scopes: keine zusätzlichen Route-Scopes. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/account/status. Tags: Account.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/account/status“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/account/status$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/account/status\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/account/status\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Automation",
      "item": [
        {
          "name": "GET /api/v1/automation/globals — Globale RPA-Variablen ohne Werte auflisten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/globals",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "globals"
              ],
              "query": [],
              "variable": []
            },
            "description": "Globale RPA-Variablen ohne Werte auflisten\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/globals. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/automation/globals“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/globals$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/globals\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/globals\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/globals/{name} — Globale RPA-Variable lesen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/globals/:name",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "globals",
                ":name"
              ],
              "query": [],
              "variable": [
                {
                  "key": "name",
                  "value": "Beispielprofil",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"pattern\":\"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"}"
                }
              ]
            },
            "description": "Globale RPA-Variable lesen\n\nFeste Route-Scopes: runtime:control, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/globals/{name}. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/automation/globals/{name}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath name: Pflichtfeld. \nSchema: {\"type\":\"string\",\"pattern\":\"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/globals/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/globals/{name}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/globals/{name}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/automation/globals/{name} — Globale RPA-Variable mit Versionsprüfung speichern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/globals/:name",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "globals",
                ":name"
              ],
              "query": [],
              "variable": [
                {
                  "key": "name",
                  "value": "Beispielprofil",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"pattern\":\"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"}"
                }
              ]
            },
            "description": "Globale RPA-Variable mit Versionsprüfung speichern\n\nFeste Route-Scopes: runtime:control, secrets:read, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/automation/globals/{name}. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/automation/globals/{name}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath name: Pflichtfeld. \nSchema: {\"type\":\"string\",\"pattern\":\"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"value\",\n    \"expected_revision\"\n  ],\n  \"properties\": {\n    \"value\": {\n      \"type\": \"string\",\n      \"maxLength\": 1048576\n    },\n    \"expected_revision\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 9007199254740991\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"value\": \"Beispiel\",\n  \"expected_revision\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/automation/globals/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/automation/globals/{name}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/globals/{name}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/automation/globals/{name} — Globale RPA-Variable mit Versionsprüfung löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/globals/:name?expected_revision=1",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "globals",
                ":name"
              ],
              "query": [
                {
                  "key": "expected_revision",
                  "value": "1",
                  "disabled": false,
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}"
                }
              ],
              "variable": [
                {
                  "key": "name",
                  "value": "Beispielprofil",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"pattern\":\"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"}"
                }
              ]
            },
            "description": "Globale RPA-Variable mit Versionsprüfung löschen\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/automation/globals/{name}. Tags: Automation.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/automation/globals/{name}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery expected_revision: Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}\npath name: Pflichtfeld. \nSchema: {\"type\":\"string\",\"pattern\":\"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/automation/globals/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/automation/globals/{name}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/globals/{name}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/shares — Lokale Ablauffreigaben auflisten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/shares",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "shares"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lokale Ablauffreigaben auflisten\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/shares. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/automation/shares“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/shares$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/shares\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/shares\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/shares — Verschlüsselten Freigabecode mit Ablauf und Abruflimit erzeugen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/shares",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "shares"
              ],
              "query": [],
              "variable": []
            },
            "description": "Verschlüsselten Freigabecode mit Ablauf und Abruflimit erzeugen\n\nFeste Route-Scopes: runtime:control, secrets:read, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/shares. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/shares“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"name\",\n    \"expires_in_minutes\",\n    \"max_uses\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000,\n      \"uniqueItems\": true\n    },\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"expires_in_minutes\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 43200\n    },\n    \"max_uses\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 1000\n    },\n    \"include_secrets\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"name\": \"Beispielprofil\",\n  \"expires_in_minutes\": 1,\n  \"max_uses\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/shares$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/shares\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/shares\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/automation/shares/{id} — Ablauffreigabe widerrufen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/shares/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "shares",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Ablauffreigabe widerrufen\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/automation/shares/{id}. Tags: Automation.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/automation/shares/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/automation/shares/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/automation/shares/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/shares/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/shares/redeem — Freigabecode einmal abrufen und Importvorschau erstellen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/shares/redeem",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "shares",
                "redeem"
              ],
              "query": [],
              "variable": []
            },
            "description": "Freigabecode einmal abrufen und Importvorschau erstellen\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/shares/redeem. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/shares/redeem“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"code\"\n  ],\n  \"properties\": {\n    \"code\": {\n      \"type\": \"string\",\n      \"minLength\": 8,\n      \"maxLength\": 2010\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"code\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/shares/redeem$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/shares/redeem\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/shares/redeem\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/shares/import — Vorbereitetes Freigabepaket als neue Abläufe importieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/shares/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "shares",
                "import"
              ],
              "query": [],
              "variable": []
            },
            "description": "Vorbereitetes Freigabepaket als neue Abläufe importieren\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/shares/import. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/shares/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ticket\",\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ticket\": {\n      \"type\": \"string\",\n      \"pattern\": \"^[a-f0-9-]{36}$\"\n    },\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000,\n      \"uniqueItems\": true\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ticket\": \"00000000-0000-4000-8000-000000000001\",\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/shares/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/shares/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/shares/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/files — RPA-Dateien auflisten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/files",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "files"
              ],
              "query": [],
              "variable": []
            },
            "description": "RPA-Dateien auflisten\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/files. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/automation/files“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/files$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/files\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/files\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/files — Eine RPA-Datei importieren, ohne bestehende Dateien zu ersetzen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/files",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "files"
              ],
              "query": [],
              "variable": []
            },
            "description": "Eine RPA-Datei importieren, ohne bestehende Dateien zu ersetzen\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/files. Tags: Automation.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/files“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"base64\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 200\n    },\n    \"base64\": {\n      \"type\": \"string\",\n      \"maxLength\": 5592408,\n      \"pattern\": \"^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"beispiel.txt\",\n  \"base64\": \"QmVpc3BpZWw=\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/files$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/files\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/files\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/files/content — Eine RPA-Datei exportieren",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/files/content?name=Beispielprofil",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "files",
                "content"
              ],
              "query": [
                {
                  "key": "name",
                  "value": "Beispielprofil",
                  "disabled": false,
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":200}"
                }
              ],
              "variable": []
            },
            "description": "Eine RPA-Datei exportieren\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/files/content. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/automation/files/content“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery name: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":200}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/files/content$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/files/content\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/files/content\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/synchronizer — Synchronizer-Status",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/synchronizer",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "synchronizer"
              ],
              "query": [],
              "variable": []
            },
            "description": "Synchronizer-Status\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/synchronizer. Tags: Automation.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/synchronizer$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/synchronizer\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/automation/synchronizer\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/synchronizer/start — Live-Synchronisierung starten",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/synchronizer/start",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "synchronizer",
                "start"
              ],
              "query": [],
              "variable": []
            },
            "description": "Live-Synchronisierung starten\n\nFeste Route-Scopes: runtime:control, sync:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/synchronizer/start. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/synchronizer/start“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"source_id\",\n    \"follower_ids\",\n    \"mode\"\n  ],\n  \"properties\": {\n    \"source_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"follower_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 20,\n      \"uniqueItems\": true\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"element\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"coordinates\"\n          ]\n        }\n      ]\n    },\n    \"options\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"mouse\": {\n          \"type\": \"boolean\"\n        },\n        \"keyboard\": {\n          \"type\": \"boolean\"\n        },\n        \"scroll\": {\n          \"type\": \"boolean\"\n        },\n        \"navigation\": {\n          \"type\": \"boolean\"\n        },\n        \"tabs\": {\n          \"type\": \"boolean\"\n        },\n        \"native_controls\": {\n          \"type\": \"boolean\"\n        },\n        \"extension_pages\": {\n          \"type\": \"boolean\"\n        },\n        \"delay_min_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 5000\n        },\n        \"delay_max_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 5000\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"source_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"follower_ids\": [\n    \"00000000-0000-4000-8000-000000000002\"\n  ],\n  \"mode\": \"element\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/synchronizer/start$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/synchronizer/start\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/synchronizer/start\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/synchronizer/stop — Live-Synchronisierung stoppen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/synchronizer/stop",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "synchronizer",
                "stop"
              ],
              "query": [],
              "variable": []
            },
            "description": "Live-Synchronisierung stoppen\n\nFeste Route-Scopes: runtime:control, sync:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/synchronizer/stop. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/synchronizer/stop“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/synchronizer/stop$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/synchronizer/stop\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/synchronizer/stop\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/automation/synchronizer/options — Synchronizer-Optionen ändern",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/synchronizer/options",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "synchronizer",
                "options"
              ],
              "query": [],
              "variable": []
            },
            "description": "Synchronizer-Optionen ändern\n\nFeste Route-Scopes: runtime:control, sync:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/automation/synchronizer/options. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/automation/synchronizer/options“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"mouse\": {\n      \"type\": \"boolean\"\n    },\n    \"keyboard\": {\n      \"type\": \"boolean\"\n    },\n    \"scroll\": {\n      \"type\": \"boolean\"\n    },\n    \"navigation\": {\n      \"type\": \"boolean\"\n    },\n    \"tabs\": {\n      \"type\": \"boolean\"\n    },\n    \"native_controls\": {\n      \"type\": \"boolean\"\n    },\n    \"extension_pages\": {\n      \"type\": \"boolean\"\n    },\n    \"delay_min_ms\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 5000\n    },\n    \"delay_max_ms\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 5000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/automation/synchronizer/options$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/automation/synchronizer/options\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/synchronizer/options\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/synchronizer/text — Text oder Zufallszahlen auf synchronisierte Fenster verteilen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/synchronizer/text",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "synchronizer",
                "text"
              ],
              "query": [],
              "variable": []
            },
            "description": "Text oder Zufallszahlen auf synchronisierte Fenster verteilen\n\nFeste Route-Scopes: runtime:control, sync:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/synchronizer/text. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/synchronizer/text“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"target_id\",\n    \"mode\"\n  ],\n  \"properties\": {\n    \"target_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 128\n    },\n    \"selector\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 4000\n    },\n    \"frames\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 4000\n      },\n      \"maxItems\": 16\n    },\n    \"include_source\": {\n      \"type\": \"boolean\"\n    },\n    \"append\": {\n      \"type\": \"boolean\"\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"same\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"lines\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"shuffle\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"random\"\n          ]\n        }\n      ]\n    },\n    \"text\": {\n      \"type\": \"string\",\n      \"maxLength\": 210000\n    },\n    \"minimum\": {\n      \"type\": \"integer\",\n      \"minimum\": -1000000000,\n      \"maximum\": 1000000000\n    },\n    \"maximum\": {\n      \"type\": \"integer\",\n      \"minimum\": -1000000000,\n      \"maximum\": 1000000000\n    },\n    \"unique\": {\n      \"type\": \"boolean\"\n    },\n    \"key_min_ms\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 2000\n    },\n    \"key_max_ms\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 2000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"target_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"mode\": \"same\",\n  \"text\": \"Fiktiver Beispieltext\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/synchronizer/text$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/synchronizer/text\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/synchronizer/text\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/synchronizer/tabs — Gemeinsame Tab-Befehle ausführen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/synchronizer/tabs",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "synchronizer",
                "tabs"
              ],
              "query": [],
              "variable": []
            },
            "description": "Gemeinsame Tab-Befehle ausführen\n\nFeste Route-Scopes: runtime:control, sync:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/synchronizer/tabs. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/synchronizer/tabs“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"action\"\n  ],\n  \"properties\": {\n    \"action\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"open\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"align\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"activate\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"reload\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"close\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"close_others\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"close_blank\"\n          ]\n        }\n      ]\n    },\n    \"target_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 128\n    },\n    \"urls\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 16000\n      },\n      \"minItems\": 1,\n      \"maxItems\": 20\n    },\n    \"reuse_current\": {\n      \"type\": \"boolean\"\n    },\n    \"close_extra\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"action\": \"open\",\n  \"urls\": [\n    \"https://example.com/\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/synchronizer/tabs$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/synchronizer/tabs\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/synchronizer/tabs\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/package/export — Ausgewählte Abläufe und Vorlagen als verschlüsseltes Paket exportieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/package/export",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "package",
                "export"
              ],
              "query": [],
              "variable": []
            },
            "description": "Ausgewählte Abläufe und Vorlagen als verschlüsseltes Paket exportieren\n\nFeste Route-Scopes: runtime:control, secrets:read, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/package/export. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/package/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"target_path\",\n    \"password\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000,\n      \"uniqueItems\": true\n    },\n    \"target_path\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 1024\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 12,\n      \"maxLength\": 1024\n    },\n    \"include_secrets\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"target_path\": \"C:/TabGecko-Beispiel/paket.adbrpa\",\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/package/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/package/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/package/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/package/preview — Verschlüsseltes Ablaufpaket prüfen und Inhalte ohne Eingabewerte anzeigen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/package/preview",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "package",
                "preview"
              ],
              "query": [],
              "variable": []
            },
            "description": "Verschlüsseltes Ablaufpaket prüfen und Inhalte ohne Eingabewerte anzeigen\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/package/preview. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/package/preview“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"path\",\n    \"password\"\n  ],\n  \"properties\": {\n    \"path\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 1024\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"path\": \"C:/TabGecko-Beispiel/paket.adbrpa\",\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/package/preview$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/package/preview\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/package/preview\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/package/import — Geprüfte Abläufe als neue Kopien ohne Profile und aktive Zeitpläne importieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/package/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "package",
                "import"
              ],
              "query": [],
              "variable": []
            },
            "description": "Geprüfte Abläufe als neue Kopien ohne Profile und aktive Zeitpläne importieren\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/package/import. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/package/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"path\",\n    \"password\",\n    \"sha256\",\n    \"ids\"\n  ],\n  \"properties\": {\n    \"path\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 1024\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    },\n    \"sha256\": {\n      \"type\": \"string\",\n      \"pattern\": \"^[a-f0-9]{64}$\"\n    },\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000,\n      \"uniqueItems\": true\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"path\": \"C:/TabGecko-Beispiel/paket.adbrpa\",\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\",\n  \"sha256\": \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\",\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/package/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/package/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/package/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/schedule/preview — Die nächsten fünf Startzeiten eines RPA-Zeitplans berechnen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/schedule/preview",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "schedule",
                "preview"
              ],
              "query": [],
              "variable": []
            },
            "description": "Die nächsten fünf Startzeiten eines RPA-Zeitplans berechnen\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/schedule/preview. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/schedule/preview“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"next_at\",\n    \"interval_minutes\"\n  ],\n  \"properties\": {\n    \"next_at\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 253402300799999\n    },\n    \"interval_minutes\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 525600\n    },\n    \"time_zone\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 128\n    },\n    \"remaining_runs\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 100000\n    },\n    \"end_at\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 253402300799999\n    },\n    \"revision\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"calendar\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"frequency\",\n        \"start_date\",\n        \"time\"\n      ],\n      \"properties\": {\n        \"frequency\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"daily\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"weekly\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"monthly\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"yearly\"\n              ]\n            }\n          ]\n        },\n        \"start_date\": {\n          \"type\": \"string\",\n          \"pattern\": \"^[0-9]{4}-[0-9]{2}-[0-9]{2}$\"\n        },\n        \"time\": {\n          \"type\": \"string\",\n          \"pattern\": \"^[0-9]{2}:[0-9]{2}$\"\n        },\n        \"weekdays\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 7\n          },\n          \"minItems\": 1,\n          \"maxItems\": 7,\n          \"uniqueItems\": true\n        },\n        \"month\": {\n          \"type\": \"integer\",\n          \"minimum\": 1,\n          \"maximum\": 12\n        },\n        \"month_day\": {\n          \"anyOf\": [\n            {\n              \"type\": \"number\",\n              \"enum\": [\n                -1\n              ]\n            },\n            {\n              \"type\": \"integer\",\n              \"minimum\": 1,\n              \"maximum\": 31\n            }\n          ]\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"next_at\": 1893499200000,\n  \"interval_minutes\": 60\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/schedule/preview$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/schedule/preview\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/schedule/preview\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/templates — Lokale RPA-Beispielvorlagen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/templates",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "templates"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lokale RPA-Beispielvorlagen\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/templates. Tags: Automation.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/templates$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/templates\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/automation/templates\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/groups — Ablaufgruppen mit Anzahl",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Ablaufgruppen mit Anzahl\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/groups. Tags: Automation.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/automation/groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/automation/groups — Ablaufgruppe umbenennen oder Zuordnung entfernen",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Ablaufgruppe umbenennen oder Zuordnung entfernen\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/automation/groups. Tags: Automation.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/automation/groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"new_name\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 80\n    },\n    \"new_name\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 80\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"new_name\": \"Beispielgruppe-neu\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/automation/groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/automation/groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/workflows/{id}/copy — Ablauf oder eigene Vorlage kopieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/workflows/:id/copy",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "workflows",
                ":id",
                "copy"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Ablauf oder eigene Vorlage kopieren\n\nFeste Route-Scopes: runtime:control, rpa:write, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/workflows/{id}/copy. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/workflows/{id}/copy“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"as_template\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/workflows/[^/?#]+/copy$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/workflows/{id}/copy\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/workflows/{id}/copy\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/workflows — Gespeicherte RPA-Abläufe",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/workflows",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "workflows"
              ],
              "query": [],
              "variable": []
            },
            "description": "Gespeicherte RPA-Abläufe\n\nFeste Route-Scopes: runtime:control, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/workflows. Tags: Automation.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/workflows$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/workflows\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/automation/workflows\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/workflows — RPA-Ablauf speichern",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/workflows",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "workflows"
              ],
              "query": [],
              "variable": []
            },
            "description": "RPA-Ablauf speichern\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/workflows. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/workflows“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"steps\",\n    \"profile_ids\",\n    \"concurrency\",\n    \"close_after\",\n    \"delay_ms\",\n    \"schedule\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"group\": {\n      \"type\": \"string\",\n      \"maxLength\": 80\n    },\n    \"description\": {\n      \"type\": \"string\",\n      \"maxLength\": 2000\n    },\n    \"is_template\": {\n      \"type\": \"boolean\"\n    },\n    \"steps\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"action\"\n        ],\n        \"properties\": {\n          \"action\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"navigate\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"click\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"type\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"key\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"wait\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"wait_selector\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"extract\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"page_data\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_open\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_switch\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_close\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"frame_enter\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"frame_parent\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"frame_top\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"reload\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"hover\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"double_click\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"right_click\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"scroll\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"select\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"attribute\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"screenshot\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"cookies_get\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"cookies_set\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"cookies_delete\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"focus\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"exists\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"attribute_set\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"mouse_move\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"wheel\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"history_back\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"history_forward\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_list\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_activate\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"script\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"workflow_call\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"branch\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_count\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_data\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_elements\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"element_capture\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"element_release\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_while\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_break\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_continue\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"variable_set\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"global\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"data_transform\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"file\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"service\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"network\"\n                ]\n              }\n            ]\n          },\n          \"data\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"operation\"\n            ],\n            \"properties\": {\n              \"operation\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"csv_parse\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"csv_stringify\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_cell\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_set\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_row\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_column\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_append\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_slice\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"json_parse\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"json_get\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"json_keys\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"list_length\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"list_join\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"list_append\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"list_random\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_split\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_replace\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"regex_extract\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"regex_replace\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_trim\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_lower\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_upper\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_add\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_subtract\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_multiply\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_divide\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_remainder\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"url_parse\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"url_parameter\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"random_integer\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"random_text\"\n                    ]\n                  }\n                ]\n              },\n              \"source_variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"global\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"operation\",\n              \"name\"\n            ],\n            \"properties\": {\n              \"operation\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"read\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"write\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"delete\"\n                    ]\n                  }\n                ]\n              },\n              \"name\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 200\n              },\n              \"source_variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              },\n              \"expected_revision\": {\n                \"type\": \"integer\",\n                \"minimum\": 0,\n                \"maximum\": 9007199254740991\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"page_data\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"url\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"title\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"text\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"html\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"links\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"images\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"form_values\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"element_count\"\n                ]\n              }\n            ]\n          },\n          \"file\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"operation\",\n              \"format\",\n              \"name\"\n            ],\n            \"properties\": {\n              \"operation\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"read\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"write\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"append\"\n                    ]\n                  }\n                ]\n              },\n              \"format\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"txt\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"json\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"csv\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"xlsx\"\n                    ]\n                  }\n                ]\n              },\n              \"name\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 200\n              },\n              \"source_variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              },\n              \"delimiter\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \",\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \";\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"\\t\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"|\"\n                    ]\n                  }\n                ]\n              },\n              \"sheet\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 31\n              },\n              \"overwrite\": {\n                \"type\": \"boolean\"\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"service\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"kind\"\n            ],\n            \"properties\": {\n              \"kind\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"http\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"google_sheets\"\n                    ]\n                  }\n                ]\n              },\n              \"source_variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"network\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"operation\"\n            ],\n            \"properties\": {\n              \"operation\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"start\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"read\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"stop\"\n                    ]\n                  }\n                ]\n              },\n              \"url_contains\": {\n                \"type\": \"string\",\n                \"maxLength\": 2000\n              },\n              \"phase\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"all\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"request\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"response\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"error\"\n                    ]\n                  }\n                ]\n              },\n              \"include_headers\": {\n                \"type\": \"boolean\"\n              },\n              \"include_bodies\": {\n                \"type\": \"boolean\"\n              },\n              \"max_events\": {\n                \"type\": \"integer\",\n                \"minimum\": 1,\n                \"maximum\": 1000\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"selector\": {\n            \"type\": \"string\",\n            \"maxLength\": 2000\n          },\n          \"element_ref\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"workflow_id\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[a-zA-Z0-9_-]{1,64}$\"\n          },\n          \"else_workflow_id\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[a-zA-Z0-9_-]{1,64}$\"\n          },\n          \"predicate\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"variable\",\n              \"operator\"\n            ],\n            \"properties\": {\n              \"variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              },\n              \"operator\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"exists\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"not_exists\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"equals\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"not_equals\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"contains\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"not_contains\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"starts_with\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"ends_with\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"less\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"less_equal\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"greater\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"greater_equal\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"one_of\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"not_one_of\"\n                    ]\n                  }\n                ]\n              },\n              \"type\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number\"\n                    ]\n                  }\n                ]\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"data_variable\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"item_variable\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"index_variable\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"loop_start\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 9999\n          },\n          \"max_iterations\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 10000\n          },\n          \"script_variables\": {\n            \"type\": \"array\",\n            \"items\": {\n              \"type\": \"string\",\n              \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n            },\n            \"maxItems\": 64,\n            \"uniqueItems\": true\n          },\n          \"element_index\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 100000\n          },\n          \"element_random_min\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 100000\n          },\n          \"element_random_max\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 100000\n          },\n          \"tab_match\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"id\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"url\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"title\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"next\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"previous\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"index\"\n                ]\n              }\n            ]\n          },\n          \"tab_compare\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"equals\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"not_equals\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"contains\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"not_contains\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"starts_with\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ends_with\"\n                ]\n              }\n            ]\n          },\n          \"tab_wrap\": {\n            \"type\": \"boolean\"\n          },\n          \"scroll_x\": {\n            \"type\": \"integer\",\n            \"minimum\": -100000,\n            \"maximum\": 100000\n          },\n          \"scroll_y\": {\n            \"type\": \"integer\",\n            \"minimum\": -100000,\n            \"maximum\": 100000\n          },\n          \"full_page\": {\n            \"type\": \"boolean\"\n          },\n          \"screenshot_format\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"png\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"jpeg\"\n                ]\n              }\n            ]\n          },\n          \"screenshot_frame_content\": {\n            \"type\": \"boolean\"\n          },\n          \"screenshot_output\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"file\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"base64\"\n                ]\n              }\n            ]\n          },\n          \"screenshot_quality\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 100\n          },\n          \"screenshot_name\": {\n            \"type\": \"string\",\n            \"maxLength\": 100\n          },\n          \"pointer_x\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 100000\n          },\n          \"pointer_y\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 100000\n          },\n          \"wait_ms\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 119000\n          },\n          \"attribute_name\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 256\n          },\n          \"secret_value\": {\n            \"type\": \"boolean\"\n          },\n          \"value_missing\": {\n            \"type\": \"boolean\"\n          },\n          \"cookie_domain\": {\n            \"type\": \"string\",\n            \"maxLength\": 253\n          },\n          \"cookie_name\": {\n            \"type\": \"string\",\n            \"maxLength\": 1024\n          },\n          \"cookie_path\": {\n            \"type\": \"string\",\n            \"maxLength\": 2048\n          },\n          \"cookie_mode\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"merge\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"replace\"\n                ]\n              }\n            ]\n          },\n          \"cookie_output\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"json\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"netscape\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"header\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"value\"\n                ]\n              }\n            ]\n          },\n          \"value\": {\n            \"type\": \"string\",\n            \"maxLength\": 10000\n          },\n          \"save_as\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"repeat\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 100\n          },\n          \"retries\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 5\n          },\n          \"timeout_ms\": {\n            \"type\": \"integer\",\n            \"minimum\": 100,\n            \"maximum\": 120000\n          },\n          \"on_error\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"stop\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"continue\"\n                ]\n              }\n            ]\n          },\n          \"condition\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"variable\",\n              \"equals\"\n            ],\n            \"properties\": {\n              \"variable\": {\n                \"type\": \"string\",\n                \"maxLength\": 64\n              },\n              \"equals\": {\n                \"type\": \"string\",\n                \"maxLength\": 10000\n              }\n            },\n            \"additionalProperties\": false\n          }\n        },\n        \"additionalProperties\": false\n      },\n      \"minItems\": 1,\n      \"maxItems\": 200\n    },\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"maxItems\": 500,\n      \"uniqueItems\": true\n    },\n    \"concurrency\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 20\n    },\n    \"close_after\": {\n      \"type\": \"boolean\"\n    },\n    \"headless\": {\n      \"type\": \"boolean\"\n    },\n    \"delay_ms\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 30000\n    },\n    \"input_timing\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"key_min_ms\",\n        \"key_max_ms\",\n        \"step_jitter_ms\"\n      ],\n      \"properties\": {\n        \"key_min_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 2000\n        },\n        \"key_max_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 2000\n        },\n        \"step_jitter_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 30000\n        },\n        \"mouse_min_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 5000\n        },\n        \"mouse_max_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 5000\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"schedule\": {\n      \"anyOf\": [\n        {\n          \"type\": \"object\",\n          \"required\": [\n            \"next_at\",\n            \"interval_minutes\"\n          ],\n          \"properties\": {\n            \"next_at\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 253402300799999\n            },\n            \"interval_minutes\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 525600\n            },\n            \"time_zone\": {\n              \"type\": \"string\",\n              \"minLength\": 1,\n              \"maxLength\": 128\n            },\n            \"remaining_runs\": {\n              \"type\": \"integer\",\n              \"minimum\": 1,\n              \"maximum\": 100000\n            },\n            \"end_at\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 253402300799999\n            },\n            \"revision\": {\n              \"type\": \"string\",\n              \"minLength\": 1,\n              \"maxLength\": 64\n            },\n            \"calendar\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"frequency\",\n                \"start_date\",\n                \"time\"\n              ],\n              \"properties\": {\n                \"frequency\": {\n                  \"anyOf\": [\n                    {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"daily\"\n                      ]\n                    },\n                    {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"weekly\"\n                      ]\n                    },\n                    {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"monthly\"\n                      ]\n                    },\n                    {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"yearly\"\n                      ]\n                    }\n                  ]\n                },\n                \"start_date\": {\n                  \"type\": \"string\",\n                  \"pattern\": \"^[0-9]{4}-[0-9]{2}-[0-9]{2}$\"\n                },\n                \"time\": {\n                  \"type\": \"string\",\n                  \"pattern\": \"^[0-9]{2}:[0-9]{2}$\"\n                },\n                \"weekdays\": {\n                  \"type\": \"array\",\n                  \"items\": {\n                    \"type\": \"integer\",\n                    \"minimum\": 1,\n                    \"maximum\": 7\n                  },\n                  \"minItems\": 1,\n                  \"maxItems\": 7,\n                  \"uniqueItems\": true\n                },\n                \"month\": {\n                  \"type\": \"integer\",\n                  \"minimum\": 1,\n                  \"maximum\": 12\n                },\n                \"month_day\": {\n                  \"anyOf\": [\n                    {\n                      \"type\": \"number\",\n                      \"enum\": [\n                        -1\n                      ]\n                    },\n                    {\n                      \"type\": \"integer\",\n                      \"minimum\": 1,\n                      \"maximum\": 31\n                    }\n                  ]\n                }\n              },\n              \"additionalProperties\": false\n            }\n          },\n          \"additionalProperties\": false\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"steps\": [\n    {\n      \"action\": \"navigate\",\n      \"value\": \"https://example.com/\"\n    }\n  ],\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"concurrency\": 1,\n  \"close_after\": true,\n  \"delay_ms\": 1,\n  \"schedule\": null\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/workflows$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/workflows\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/workflows\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/automation/workflows/{id} — RPA-Ablauf ändern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/workflows/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "workflows",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "RPA-Ablauf ändern\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/automation/workflows/{id}. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/automation/workflows/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"steps\",\n    \"profile_ids\",\n    \"concurrency\",\n    \"close_after\",\n    \"delay_ms\",\n    \"schedule\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"group\": {\n      \"type\": \"string\",\n      \"maxLength\": 80\n    },\n    \"description\": {\n      \"type\": \"string\",\n      \"maxLength\": 2000\n    },\n    \"is_template\": {\n      \"type\": \"boolean\"\n    },\n    \"steps\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"action\"\n        ],\n        \"properties\": {\n          \"action\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"navigate\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"click\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"type\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"key\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"wait\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"wait_selector\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"extract\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"page_data\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_open\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_switch\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_close\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"frame_enter\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"frame_parent\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"frame_top\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"reload\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"hover\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"double_click\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"right_click\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"scroll\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"select\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"attribute\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"screenshot\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"cookies_get\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"cookies_set\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"cookies_delete\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"focus\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"exists\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"attribute_set\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"mouse_move\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"wheel\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"history_back\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"history_forward\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_list\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tab_activate\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"script\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"workflow_call\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"branch\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_count\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_data\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_elements\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"element_capture\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"element_release\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_while\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_break\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"loop_continue\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"variable_set\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"global\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"data_transform\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"file\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"service\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"network\"\n                ]\n              }\n            ]\n          },\n          \"data\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"operation\"\n            ],\n            \"properties\": {\n              \"operation\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"csv_parse\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"csv_stringify\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_cell\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_set\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_row\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_column\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_append\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"table_slice\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"json_parse\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"json_get\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"json_keys\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"list_length\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"list_join\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"list_append\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"list_random\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_split\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_replace\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"regex_extract\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"regex_replace\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_trim\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_lower\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text_upper\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_add\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_subtract\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_multiply\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_divide\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number_remainder\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"url_parse\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"url_parameter\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"random_integer\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"random_text\"\n                    ]\n                  }\n                ]\n              },\n              \"source_variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"global\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"operation\",\n              \"name\"\n            ],\n            \"properties\": {\n              \"operation\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"read\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"write\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"delete\"\n                    ]\n                  }\n                ]\n              },\n              \"name\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 200\n              },\n              \"source_variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              },\n              \"expected_revision\": {\n                \"type\": \"integer\",\n                \"minimum\": 0,\n                \"maximum\": 9007199254740991\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"page_data\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"url\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"title\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"text\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"html\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"links\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"images\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"form_values\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"element_count\"\n                ]\n              }\n            ]\n          },\n          \"file\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"operation\",\n              \"format\",\n              \"name\"\n            ],\n            \"properties\": {\n              \"operation\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"read\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"write\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"append\"\n                    ]\n                  }\n                ]\n              },\n              \"format\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"txt\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"json\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"csv\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"xlsx\"\n                    ]\n                  }\n                ]\n              },\n              \"name\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 200\n              },\n              \"source_variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              },\n              \"delimiter\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \",\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \";\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"\\t\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"|\"\n                    ]\n                  }\n                ]\n              },\n              \"sheet\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 31\n              },\n              \"overwrite\": {\n                \"type\": \"boolean\"\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"service\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"kind\"\n            ],\n            \"properties\": {\n              \"kind\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"http\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"google_sheets\"\n                    ]\n                  }\n                ]\n              },\n              \"source_variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"network\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"operation\"\n            ],\n            \"properties\": {\n              \"operation\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"start\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"read\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"stop\"\n                    ]\n                  }\n                ]\n              },\n              \"url_contains\": {\n                \"type\": \"string\",\n                \"maxLength\": 2000\n              },\n              \"phase\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"all\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"request\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"response\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"error\"\n                    ]\n                  }\n                ]\n              },\n              \"include_headers\": {\n                \"type\": \"boolean\"\n              },\n              \"include_bodies\": {\n                \"type\": \"boolean\"\n              },\n              \"max_events\": {\n                \"type\": \"integer\",\n                \"minimum\": 1,\n                \"maximum\": 1000\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"selector\": {\n            \"type\": \"string\",\n            \"maxLength\": 2000\n          },\n          \"element_ref\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"workflow_id\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[a-zA-Z0-9_-]{1,64}$\"\n          },\n          \"else_workflow_id\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[a-zA-Z0-9_-]{1,64}$\"\n          },\n          \"predicate\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"variable\",\n              \"operator\"\n            ],\n            \"properties\": {\n              \"variable\": {\n                \"type\": \"string\",\n                \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n              },\n              \"operator\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"exists\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"not_exists\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"equals\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"not_equals\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"contains\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"not_contains\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"starts_with\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"ends_with\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"less\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"less_equal\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"greater\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"greater_equal\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"one_of\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"not_one_of\"\n                    ]\n                  }\n                ]\n              },\n              \"type\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"text\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"number\"\n                    ]\n                  }\n                ]\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"data_variable\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"item_variable\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"index_variable\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"loop_start\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 9999\n          },\n          \"max_iterations\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 10000\n          },\n          \"script_variables\": {\n            \"type\": \"array\",\n            \"items\": {\n              \"type\": \"string\",\n              \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n            },\n            \"maxItems\": 64,\n            \"uniqueItems\": true\n          },\n          \"element_index\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 100000\n          },\n          \"element_random_min\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 100000\n          },\n          \"element_random_max\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 100000\n          },\n          \"tab_match\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"id\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"url\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"title\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"next\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"previous\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"index\"\n                ]\n              }\n            ]\n          },\n          \"tab_compare\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"equals\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"not_equals\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"contains\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"not_contains\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"starts_with\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ends_with\"\n                ]\n              }\n            ]\n          },\n          \"tab_wrap\": {\n            \"type\": \"boolean\"\n          },\n          \"scroll_x\": {\n            \"type\": \"integer\",\n            \"minimum\": -100000,\n            \"maximum\": 100000\n          },\n          \"scroll_y\": {\n            \"type\": \"integer\",\n            \"minimum\": -100000,\n            \"maximum\": 100000\n          },\n          \"full_page\": {\n            \"type\": \"boolean\"\n          },\n          \"screenshot_format\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"png\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"jpeg\"\n                ]\n              }\n            ]\n          },\n          \"screenshot_frame_content\": {\n            \"type\": \"boolean\"\n          },\n          \"screenshot_output\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"file\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"base64\"\n                ]\n              }\n            ]\n          },\n          \"screenshot_quality\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 100\n          },\n          \"screenshot_name\": {\n            \"type\": \"string\",\n            \"maxLength\": 100\n          },\n          \"pointer_x\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 100000\n          },\n          \"pointer_y\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 100000\n          },\n          \"wait_ms\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 119000\n          },\n          \"attribute_name\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 256\n          },\n          \"secret_value\": {\n            \"type\": \"boolean\"\n          },\n          \"value_missing\": {\n            \"type\": \"boolean\"\n          },\n          \"cookie_domain\": {\n            \"type\": \"string\",\n            \"maxLength\": 253\n          },\n          \"cookie_name\": {\n            \"type\": \"string\",\n            \"maxLength\": 1024\n          },\n          \"cookie_path\": {\n            \"type\": \"string\",\n            \"maxLength\": 2048\n          },\n          \"cookie_mode\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"merge\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"replace\"\n                ]\n              }\n            ]\n          },\n          \"cookie_output\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"json\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"netscape\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"header\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"value\"\n                ]\n              }\n            ]\n          },\n          \"value\": {\n            \"type\": \"string\",\n            \"maxLength\": 10000\n          },\n          \"save_as\": {\n            \"type\": \"string\",\n            \"pattern\": \"^[A-Za-z_][A-Za-z0-9_]{0,63}$\"\n          },\n          \"repeat\": {\n            \"type\": \"integer\",\n            \"minimum\": 1,\n            \"maximum\": 100\n          },\n          \"retries\": {\n            \"type\": \"integer\",\n            \"minimum\": 0,\n            \"maximum\": 5\n          },\n          \"timeout_ms\": {\n            \"type\": \"integer\",\n            \"minimum\": 100,\n            \"maximum\": 120000\n          },\n          \"on_error\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"stop\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"continue\"\n                ]\n              }\n            ]\n          },\n          \"condition\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"variable\",\n              \"equals\"\n            ],\n            \"properties\": {\n              \"variable\": {\n                \"type\": \"string\",\n                \"maxLength\": 64\n              },\n              \"equals\": {\n                \"type\": \"string\",\n                \"maxLength\": 10000\n              }\n            },\n            \"additionalProperties\": false\n          }\n        },\n        \"additionalProperties\": false\n      },\n      \"minItems\": 1,\n      \"maxItems\": 200\n    },\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"maxItems\": 500,\n      \"uniqueItems\": true\n    },\n    \"concurrency\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 20\n    },\n    \"close_after\": {\n      \"type\": \"boolean\"\n    },\n    \"headless\": {\n      \"type\": \"boolean\"\n    },\n    \"delay_ms\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 30000\n    },\n    \"input_timing\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"key_min_ms\",\n        \"key_max_ms\",\n        \"step_jitter_ms\"\n      ],\n      \"properties\": {\n        \"key_min_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 2000\n        },\n        \"key_max_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 2000\n        },\n        \"step_jitter_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 30000\n        },\n        \"mouse_min_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 5000\n        },\n        \"mouse_max_ms\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 5000\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"schedule\": {\n      \"anyOf\": [\n        {\n          \"type\": \"object\",\n          \"required\": [\n            \"next_at\",\n            \"interval_minutes\"\n          ],\n          \"properties\": {\n            \"next_at\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 253402300799999\n            },\n            \"interval_minutes\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 525600\n            },\n            \"time_zone\": {\n              \"type\": \"string\",\n              \"minLength\": 1,\n              \"maxLength\": 128\n            },\n            \"remaining_runs\": {\n              \"type\": \"integer\",\n              \"minimum\": 1,\n              \"maximum\": 100000\n            },\n            \"end_at\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 253402300799999\n            },\n            \"revision\": {\n              \"type\": \"string\",\n              \"minLength\": 1,\n              \"maxLength\": 64\n            },\n            \"calendar\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"frequency\",\n                \"start_date\",\n                \"time\"\n              ],\n              \"properties\": {\n                \"frequency\": {\n                  \"anyOf\": [\n                    {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"daily\"\n                      ]\n                    },\n                    {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"weekly\"\n                      ]\n                    },\n                    {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"monthly\"\n                      ]\n                    },\n                    {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"yearly\"\n                      ]\n                    }\n                  ]\n                },\n                \"start_date\": {\n                  \"type\": \"string\",\n                  \"pattern\": \"^[0-9]{4}-[0-9]{2}-[0-9]{2}$\"\n                },\n                \"time\": {\n                  \"type\": \"string\",\n                  \"pattern\": \"^[0-9]{2}:[0-9]{2}$\"\n                },\n                \"weekdays\": {\n                  \"type\": \"array\",\n                  \"items\": {\n                    \"type\": \"integer\",\n                    \"minimum\": 1,\n                    \"maximum\": 7\n                  },\n                  \"minItems\": 1,\n                  \"maxItems\": 7,\n                  \"uniqueItems\": true\n                },\n                \"month\": {\n                  \"type\": \"integer\",\n                  \"minimum\": 1,\n                  \"maximum\": 12\n                },\n                \"month_day\": {\n                  \"anyOf\": [\n                    {\n                      \"type\": \"number\",\n                      \"enum\": [\n                        -1\n                      ]\n                    },\n                    {\n                      \"type\": \"integer\",\n                      \"minimum\": 1,\n                      \"maximum\": 31\n                    }\n                  ]\n                }\n              },\n              \"additionalProperties\": false\n            }\n          },\n          \"additionalProperties\": false\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"steps\": [\n    {\n      \"action\": \"navigate\",\n      \"value\": \"https://example.com/\"\n    }\n  ],\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"concurrency\": 1,\n  \"close_after\": true,\n  \"delay_ms\": 1,\n  \"schedule\": null\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/automation/workflows/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/automation/workflows/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/workflows/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/automation/workflows/{id} — RPA-Ablauf löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/workflows/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "workflows",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "RPA-Ablauf löschen\n\nFeste Route-Scopes: runtime:control, rpa:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/automation/workflows/{id}. Tags: Automation.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/automation/workflows/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/automation/workflows/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/automation/workflows/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/workflows/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/workflows/{id}/run — RPA-Aufgabe starten",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/workflows/:id/run",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "workflows",
                ":id",
                "run"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "RPA-Aufgabe starten\n\nFeste Route-Scopes: runtime:control, rpa:run. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/workflows/{id}/run. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/workflows/{id}/run“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/workflows/[^/?#]+/run$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/workflows/{id}/run\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/workflows/{id}/run\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/automation/runs — RPA-Ausführungen und Ergebnisse",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/runs",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "runs"
              ],
              "query": [],
              "variable": []
            },
            "description": "RPA-Ausführungen und Ergebnisse\n\nFeste Route-Scopes: runtime:control, rpa:run. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/automation/runs. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/automation/runs“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/automation/runs$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/automation/runs\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/runs\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/automation/runs/{id}/cancel — RPA-Aufgabe abbrechen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/automation/runs/:id/cancel",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "automation",
                "runs",
                ":id",
                "cancel"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "RPA-Aufgabe abbrechen\n\nFeste Route-Scopes: runtime:control, rpa:run. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/automation/runs/{id}/cancel. Tags: Automation.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/automation/runs/{id}/cancel“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/automation/runs/[^/?#]+/cancel$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/automation/runs/{id}/cancel\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/automation/runs/{id}/cancel\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Team",
      "item": [
        {
          "name": "GET /api/v1/team/conflicts — Aktuelle Synchronisierungskonflikte anzeigen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/conflicts",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "conflicts"
              ],
              "query": [],
              "variable": []
            },
            "description": "Aktuelle Synchronisierungskonflikte anzeigen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/conflicts. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/conflicts“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/conflicts$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/conflicts\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/conflicts\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/conflicts/resolve — Angezeigten Synchronisierungskonflikt auflösen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/conflicts/resolve",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "conflicts",
                "resolve"
              ],
              "query": [],
              "variable": []
            },
            "description": "Angezeigten Synchronisierungskonflikt auflösen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/conflicts/resolve. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/conflicts/resolve“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"token\",\n    \"choice\"\n  ],\n  \"properties\": {\n    \"token\": {\n      \"type\": \"string\",\n      \"minLength\": 64,\n      \"maxLength\": 64\n    },\n    \"choice\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"local\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"cloud\"\n          ]\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"token\": \"NUR-FIKTIVES-BEISPIELxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\",\n  \"choice\": \"local\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/conflicts/resolve$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/conflicts/resolve\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/conflicts/resolve\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/synchronize — Automatischen Cloud-Profilabgleich jetzt ausführen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/synchronize",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "synchronize"
              ],
              "query": [],
              "variable": []
            },
            "description": "Automatischen Cloud-Profilabgleich jetzt ausführen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/synchronize. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/synchronize“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/synchronize$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/synchronize\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/synchronize\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/team/group-sync/{id} — Automatischen Cookie- oder Browserdatenabgleich einer lokalen Gruppe einstellen",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/group-sync/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "group-sync",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Automatischen Cookie- oder Browserdatenabgleich einer lokalen Gruppe einstellen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/team/group-sync/{id}. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/team/group-sync/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"anyOf\": [\n    {\n      \"type\": \"null\"\n    },\n    {\n      \"type\": \"object\",\n      \"required\": [\n        \"remote_group_id\",\n        \"mode\"\n      ],\n      \"properties\": {\n        \"remote_group_id\": {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 64\n        },\n        \"mode\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"cookies\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"browser\"\n              ]\n            }\n          ]\n        }\n      },\n      \"additionalProperties\": false\n    }\n  ]\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"remote_group_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"mode\": \"cookies\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/team/group-sync/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/team/group-sync/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/group-sync/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/team/profiles/{id} — Team-Freigabe einschließlich aller Serverversionen löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Team-Freigabe einschließlich aller Serverversionen löschen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/team/profiles/{id}. Tags: Team.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/team/profiles/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/team/profiles/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/team/profiles/{id}/versions/{version} — Alte Serverversion einer Team-Freigabe löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/versions/:version",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "versions",
                ":version"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                },
                {
                  "key": "version",
                  "value": "1",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}"
                }
              ]
            },
            "description": "Alte Serverversion einer Team-Freigabe löschen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/team/profiles/{id}/versions/{version}. Tags: Team.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/team/profiles/{id}/versions/{version}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\npath version: Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/versions/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/team/profiles/{id}/versions/{version}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/versions/{version}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/hosted/config — Freigabe der lokalen Browserausführung anzeigen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/hosted/config",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "hosted",
                "config"
              ],
              "query": [],
              "variable": []
            },
            "description": "Freigabe der lokalen Browserausführung anzeigen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/hosted/config. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/hosted/config“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/hosted/config$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/hosted/config\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/hosted/config\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/team/hosted/config — Lokale Profile zur Browserausführung auf dem Teamhost freigeben",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/hosted/config",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "hosted",
                "config"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lokale Profile zur Browserausführung auf dem Teamhost freigeben\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/team/hosted/config. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/team/hosted/config“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"enabled\",\n    \"profile_ids\",\n    \"max_sessions\"\n  ],\n  \"properties\": {\n    \"enabled\": {\n      \"type\": \"boolean\"\n    },\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"maxItems\": 500,\n      \"uniqueItems\": true\n    },\n    \"max_sessions\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 20\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"enabled\": false,\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"max_sessions\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/team/hosted/config$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/team/hosted/config\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/hosted/config\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/hosted/profiles — Ausführbare Profile und Sitzungen auf dem Teamhost",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/hosted/profiles",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "hosted",
                "profiles"
              ],
              "query": [],
              "variable": []
            },
            "description": "Ausführbare Profile und Sitzungen auf dem Teamhost\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/hosted/profiles. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/hosted/profiles“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/hosted/profiles$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/hosted/profiles\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/hosted/profiles\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/hosted/profiles/{id}/start — Freigegebenen Browser auf dem lokalen Teamhost starten",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/hosted/profiles/:id/start",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "hosted",
                "profiles",
                ":id",
                "start"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Freigegebenen Browser auf dem lokalen Teamhost starten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/hosted/profiles/{id}/start. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/hosted/profiles/{id}/start“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/hosted/profiles/[^/?#]+/start$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/hosted/profiles/{id}/start\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/hosted/profiles/{id}/start\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/hosted/profiles/{id}/stop — Eigene Host-Sitzung beenden",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/hosted/profiles/:id/stop",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "hosted",
                "profiles",
                ":id",
                "stop"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Eigene Host-Sitzung beenden\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/hosted/profiles/{id}/stop. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/hosted/profiles/{id}/stop“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/hosted/profiles/[^/?#]+/stop$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/hosted/profiles/{id}/stop\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/hosted/profiles/{id}/stop\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/profile-groups — Zugängliche Team-Profilgruppen auflisten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profile-groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profile-groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zugängliche Team-Profilgruppen auflisten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/profile-groups. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/profile-groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/profile-groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/profile-groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profile-groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profile-groups — Team-Profilgruppe erstellen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profile-groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profile-groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Team-Profilgruppe erstellen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profile-groups. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profile-groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"member_ids\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"member_ids\": {\n      \"anyOf\": [\n        {\n          \"type\": \"null\"\n        },\n        {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 64\n          },\n          \"maxItems\": 100,\n          \"uniqueItems\": true\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"member_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profile-groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profile-groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profile-groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/team/profile-groups/{id} — Team-Profilgruppe ändern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profile-groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profile-groups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Team-Profilgruppe ändern\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/team/profile-groups/{id}. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/team/profile-groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"member_ids\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"member_ids\": {\n      \"anyOf\": [\n        {\n          \"type\": \"null\"\n        },\n        {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 64\n          },\n          \"maxItems\": 100,\n          \"uniqueItems\": true\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"member_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/team/profile-groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/team/profile-groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profile-groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/team/profile-groups/{id} — Nicht verwendete Team-Profilgruppe löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profile-groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profile-groups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Nicht verwendete Team-Profilgruppe löschen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/team/profile-groups/{id}. Tags: Team.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/team/profile-groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/team/profile-groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/team/profile-groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profile-groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/permission-groups — Team-Berechtigungsgruppen auflisten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/permission-groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "permission-groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Team-Berechtigungsgruppen auflisten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/permission-groups. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/permission-groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/permission-groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/permission-groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/permission-groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/permission-groups — Team-Berechtigungsgruppe erstellen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/permission-groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "permission-groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Team-Berechtigungsgruppe erstellen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/permission-groups. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/permission-groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"permissions\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"permissions\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"anyOf\": [\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:create\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:publish\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:hosted\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:delete\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:history_delete\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"workflows:share\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"members:manage\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"vaults:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"vaults:publish\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"vaults:delete\"\n            ]\n          }\n        ]\n      },\n      \"maxItems\": 11,\n      \"uniqueItems\": true\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"permissions\": [\n    \"profiles:read\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/permission-groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/permission-groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/permission-groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/team/permission-groups/{id} — Team-Berechtigungsgruppe ändern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/permission-groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "permission-groups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Team-Berechtigungsgruppe ändern\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/team/permission-groups/{id}. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/team/permission-groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"permissions\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"permissions\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"anyOf\": [\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:create\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:publish\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:hosted\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:delete\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:history_delete\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"workflows:share\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"members:manage\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"vaults:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"vaults:publish\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"vaults:delete\"\n            ]\n          }\n        ]\n      },\n      \"maxItems\": 11,\n      \"uniqueItems\": true\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"permissions\": [\n    \"profiles:read\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/team/permission-groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/team/permission-groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/permission-groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/team/permission-groups/{id} — Nicht zugewiesene Team-Berechtigungsgruppe löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/permission-groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "permission-groups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Nicht zugewiesene Team-Berechtigungsgruppe löschen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/team/permission-groups/{id}. Tags: Team.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/team/permission-groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/team/permission-groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/team/permission-groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/permission-groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/team/members/{id}/permission-group — Berechtigungsgruppe einem Teammitglied zuweisen",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/members/:id/permission-group",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "members",
                ":id",
                "permission-group"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Berechtigungsgruppe einem Teammitglied zuweisen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/team/members/{id}/permission-group. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/team/members/{id}/permission-group“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"group_id\"\n  ],\n  \"properties\": {\n    \"group_id\": {\n      \"anyOf\": [\n        {\n          \"type\": \"null\"\n        },\n        {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 64\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"group_id\": \"00000000-0000-4000-8000-000000000001\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/team/members/[^/?#]+/permission-group$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/team/members/{id}/permission-group\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/members/{id}/permission-group\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/profiles/{id}/access — Empfängerauswahl einer Team-Freigabe",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/access",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "access"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Empfängerauswahl einer Team-Freigabe\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/profiles/{id}/access. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/profiles/{id}/access“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/access$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/profiles/{id}/access\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/access\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/team/profiles/{id}/access — Zugriff auf eine Team-Freigabe beschränken",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/access",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "access"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Zugriff auf eine Team-Freigabe beschränken\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/team/profiles/{id}/access. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/team/profiles/{id}/access“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"member_ids\": {\n      \"anyOf\": [\n        {\n          \"type\": \"null\"\n        },\n        {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 64\n          },\n          \"maxItems\": 100,\n          \"uniqueItems\": true\n        }\n      ]\n    },\n    \"group_id\": {\n      \"anyOf\": [\n        {\n          \"type\": \"null\"\n        },\n        {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 64\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"member_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/access$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/team/profiles/{id}/access\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/access\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/team/members/{id}/role — Team-Rolle ändern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/members/:id/role",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "members",
                ":id",
                "role"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Team-Rolle ändern\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/team/members/{id}/role. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/team/members/{id}/role“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"role\"\n  ],\n  \"properties\": {\n    \"role\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"admin\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"editor\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"viewer\"\n          ]\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"role\": \"viewer\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/team/members/[^/?#]+/role$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/team/members/{id}/role\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/members/{id}/role\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/profiles/{id}/versions — Zugängliche Versionen einer Team-Freigabe",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/versions",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "versions"
              ],
              "query": [
                {
                  "key": "before",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Zugängliche Versionen einer Team-Freigabe\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/profiles/{id}/versions. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/profiles/{id}/versions“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery before: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/versions$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/profiles/{id}/versions\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/versions\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/team/profiles/{id}/versions — Frühere Cloud-Versionen löschen und aktuellen Stand behalten",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/versions?base_version=1",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "versions"
              ],
              "query": [
                {
                  "key": "base_version",
                  "value": "1",
                  "disabled": false,
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Frühere Cloud-Versionen löschen und aktuellen Stand behalten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/team/profiles/{id}/versions. Tags: Team.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/team/profiles/{id}/versions“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery base_version: Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/versions$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/team/profiles/{id}/versions\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/versions\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profiles/{id}/versions/{version}/restore — Frühere Cloud-Version im bestehenden Profil wiederherstellen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/versions/:version/restore",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "versions",
                ":version",
                "restore"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                },
                {
                  "key": "version",
                  "value": "1",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}"
                }
              ]
            },
            "description": "Frühere Cloud-Version im bestehenden Profil wiederherstellen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profiles/{id}/versions/{version}/restore. Tags: Team.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profiles/{id}/versions/{version}/restore“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\npath version: Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"profile_id\",\n    \"row_version\"\n  ],\n  \"properties\": {\n    \"profile_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"row_version\": {\n      \"type\": \"integer\",\n      \"minimum\": 1\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"profile_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"row_version\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/versions/[^/?#]+/restore$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profiles/{id}/versions/{version}/restore\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/versions/{version}/restore\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profiles/{id}/versions/{version}/download — Frühere Team-Version als unabhängige lokale Kopie laden",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/versions/:version/download",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "versions",
                ":version",
                "download"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                },
                {
                  "key": "version",
                  "value": "1",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}"
                }
              ]
            },
            "description": "Frühere Team-Version als unabhängige lokale Kopie laden\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profiles/{id}/versions/{version}/download. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profiles/{id}/versions/{version}/download“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\npath version: Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":9007199254740991}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/versions/[^/?#]+/download$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profiles/{id}/versions/{version}/download\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/versions/{version}/download\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team — Team- und Synchronisierungsstatus",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team"
              ],
              "query": [],
              "variable": []
            },
            "description": "Team- und Synchronisierungsstatus\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/info — Team-Mitgliedschaft und Speicherlimit",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/info",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "info"
              ],
              "query": [],
              "variable": []
            },
            "description": "Team-Mitgliedschaft und Speicherlimit\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/info. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/info“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/info$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/info\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/info\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/members — Team-Mitglieder",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/members",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "members"
              ],
              "query": [],
              "variable": []
            },
            "description": "Team-Mitglieder\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/members. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/members“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/members$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/members\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/members\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/profiles — Für dieses Mitglied verschlüsselte Profile",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles"
              ],
              "query": [],
              "variable": []
            },
            "description": "Für dieses Mitglied verschlüsselte Profile\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/profiles. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/profiles“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/profiles$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/profiles\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/cloud/connect — Cloud-Abgleich mit dem angemeldeten Kontoteam verbinden",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/cloud/connect",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "cloud",
                "connect"
              ],
              "query": [],
              "variable": []
            },
            "description": "Cloud-Abgleich mit dem angemeldeten Kontoteam verbinden\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/cloud/connect. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/cloud/connect“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/cloud/connect$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/cloud/connect\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/cloud/connect\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/host — Lokalen Teamdienst starten",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/host",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "host"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lokalen Teamdienst starten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/host. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/host“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/host$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/host\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/host\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/host/stop — Lokalen Teamdienst stoppen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/host/stop",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "host",
                "stop"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lokalen Teamdienst stoppen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/host/stop. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/host/stop“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/host/stop$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/host/stop\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/host/stop\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/invitations — Einmalige Team-Einladung erstellen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/invitations",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "invitations"
              ],
              "query": [],
              "variable": []
            },
            "description": "Einmalige Team-Einladung erstellen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/invitations. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/invitations“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"role\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 120\n    },\n    \"role\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"admin\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"editor\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"viewer\"\n          ]\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"role\": \"viewer\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/invitations$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/invitations\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/invitations\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/join — Lokaler Team-Einladung beitreten",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/join",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "join"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lokaler Team-Einladung beitreten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/join. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/join“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"invitation_code\"\n  ],\n  \"properties\": {\n    \"invitation_code\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 4096\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"invitation_code\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/join$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/join\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/join\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/disconnect — Team-Zugang auf diesem Gerät trennen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/disconnect",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "disconnect"
              ],
              "query": [],
              "variable": []
            },
            "description": "Team-Zugang auf diesem Gerät trennen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/disconnect. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/disconnect“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/disconnect$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/disconnect\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/disconnect\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/team/members/{id} — Team-Zugang widerrufen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/members/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "members",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Team-Zugang widerrufen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/team/members/{id}. Tags: Team.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/team/members/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/team/members/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/team/members/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/members/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profiles/{id}/transfer/cancel — Noch nicht übernommene Teamübertragung abbrechen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/transfer/cancel",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "transfer",
                "cancel"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Noch nicht übernommene Teamübertragung abbrechen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profiles/{id}/transfer/cancel. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profiles/{id}/transfer/cancel“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/transfer/cancel$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profiles/{id}/transfer/cancel\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/transfer/cancel\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profiles/{id}/transfer/keep-local — Bestätigte Teamübertragung abschließen und lokale Kopie behalten",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/transfer/keep-local",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "transfer",
                "keep-local"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Bestätigte Teamübertragung abschließen und lokale Kopie behalten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profiles/{id}/transfer/keep-local. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profiles/{id}/transfer/keep-local“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/transfer/keep-local$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profiles/{id}/transfer/keep-local\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/transfer/keep-local\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profiles/{id}/transfer — Profil in ein anderes Kontoteam übertragen oder teilen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/transfer",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "transfer"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profil in ein anderes Kontoteam übertragen oder teilen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profiles/{id}/transfer. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profiles/{id}/transfer“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"target_team_id\",\n    \"mode\",\n    \"password\"\n  ],\n  \"properties\": {\n    \"target_team_id\": {\n      \"type\": \"string\",\n      \"pattern\": \"^team_[A-Za-z0-9_-]{1,128}$\",\n      \"example\": \"team_example\"\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"transfer\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"share\"\n          ]\n        }\n      ]\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"target_team_id\": \"team_example\",\n  \"mode\": \"transfer\",\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/transfer$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profiles/{id}/transfer\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/transfer\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profiles/{id}/publish — Geschlossenes Profil verschlüsselt im Team veröffentlichen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/publish",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "publish"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Geschlossenes Profil verschlüsselt im Team veröffentlichen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profiles/{id}/publish. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profiles/{id}/publish“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"member_ids\": {\n      \"anyOf\": [\n        {\n          \"type\": \"null\"\n        },\n        {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 64\n          },\n          \"maxItems\": 100,\n          \"uniqueItems\": true\n        }\n      ]\n    },\n    \"group_id\": {\n      \"anyOf\": [\n        {\n          \"type\": \"null\"\n        },\n        {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 64\n        }\n      ]\n    }\n  }\n}",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/publish$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profiles/{id}/publish\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/publish\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profiles/{id}/download — Freigabe als neues lokales Profil laden",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/download",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "download"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Freigabe als neues lokales Profil laden\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profiles/{id}/download. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profiles/{id}/download“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/download$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profiles/{id}/download\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/download\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/profiles/{id}/unlink — Lokales Profil von der Team-Freigabe lösen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/profiles/:id/unlink",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "profiles",
                ":id",
                "unlink"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Lokales Profil von der Team-Freigabe lösen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/profiles/{id}/unlink. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/profiles/{id}/unlink“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/profiles/[^/?#]+/unlink$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/profiles/{id}/unlink\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/profiles/{id}/unlink\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/group-vaults — Zugängliche verschlüsselte Team-Gruppentresore",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/group-vaults",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "group-vaults"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zugängliche verschlüsselte Team-Gruppentresore\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/group-vaults. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/group-vaults“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/group-vaults$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/group-vaults\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/group-vaults\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/team/group-vaults/{id}/recipients — Aktuelle Version und Empfänger vor Veröffentlichung eines Gruppentresors",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/group-vaults/:id/recipients",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "group-vaults",
                ":id",
                "recipients"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Aktuelle Version und Empfänger vor Veröffentlichung eines Gruppentresors\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/team/group-vaults/{id}/recipients. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/team/group-vaults/{id}/recipients“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/team/group-vaults/[^/?#]+/recipients$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/team/group-vaults/{id}/recipients\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/group-vaults/{id}/recipients\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/group-vaults/{id}/publish — Lokalen Gruppentresor ausdrücklich für die ausgewählten Teamempfänger verschlüsseln",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/group-vaults/:id/publish",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "group-vaults",
                ":id",
                "publish"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Lokalen Gruppentresor ausdrücklich für die ausgewählten Teamempfänger verschlüsseln\n\nFeste Route-Scopes: admin, profiles:read, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/group-vaults/{id}/publish. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/group-vaults/{id}/publish“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"local_group_id\",\n    \"base_version\",\n    \"confirm\",\n    \"recipient_ids\"\n  ],\n  \"properties\": {\n    \"local_group_id\": {\n      \"type\": \"string\"\n    },\n    \"base_version\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 9007199254740990\n    },\n    \"confirm\": {\n      \"type\": \"boolean\",\n      \"enum\": [\n        true\n      ]\n    },\n    \"recipient_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\"\n      },\n      \"minItems\": 1,\n      \"maxItems\": 100,\n      \"uniqueItems\": true\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"local_group_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"base_version\": 1,\n  \"confirm\": true,\n  \"recipient_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/group-vaults/[^/?#]+/publish$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/group-vaults/{id}/publish\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/group-vaults/{id}/publish\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/group-vaults/{id}/import — Team-Gruppentresor in eine lokale Gruppe importieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/group-vaults/:id/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "group-vaults",
                ":id",
                "import"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Team-Gruppentresor in eine lokale Gruppe importieren\n\nFeste Route-Scopes: admin, profiles:write, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/group-vaults/{id}/import. Tags: Team.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/group-vaults/{id}/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"local_group_id\",\n    \"version\",\n    \"update_existing\",\n    \"confirm\"\n  ],\n  \"properties\": {\n    \"local_group_id\": {\n      \"type\": \"string\"\n    },\n    \"version\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 9007199254740990\n    },\n    \"update_existing\": {\n      \"type\": \"boolean\"\n    },\n    \"confirm\": {\n      \"type\": \"boolean\",\n      \"enum\": [\n        true\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"local_group_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"version\": 1,\n  \"update_existing\": false,\n  \"confirm\": true\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/group-vaults/[^/?#]+/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/group-vaults/{id}/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/group-vaults/{id}/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/team/group-vaults/{id}/remove — Veröffentlichten Gruppentresor entfernen; lokale Kopien behalten",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/team/group-vaults/:id/remove",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "team",
                "group-vaults",
                ":id",
                "remove"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Veröffentlichten Gruppentresor entfernen; lokale Kopien behalten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/team/group-vaults/{id}/remove. Tags: Team.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/team/group-vaults/{id}/remove“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"version\",\n    \"confirm\"\n  ],\n  \"properties\": {\n    \"version\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 9007199254740990\n    },\n    \"confirm\": {\n      \"type\": \"boolean\",\n      \"enum\": [\n        true\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"version\": 1,\n  \"confirm\": true\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/team/group-vaults/[^/?#]+/remove$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/team/group-vaults/{id}/remove\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/team/group-vaults/{id}/remove\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Tokens",
      "item": [
        {
          "name": "GET /api/v1/tokens — API-Tokens auflisten (ohne Klartext)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/tokens",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "tokens"
              ],
              "query": [],
              "variable": []
            },
            "description": "API-Tokens auflisten (ohne Klartext)\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/tokens. Tags: Tokens.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/tokens“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/tokens$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/tokens\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/tokens\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/tokens — API-Token erzeugen; der Klartext wird nur in dieser Antwort geliefert",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/tokens",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "tokens"
              ],
              "query": [],
              "variable": []
            },
            "description": "API-Token erzeugen; der Klartext wird nur in dieser Antwort geliefert\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/tokens. Tags: Tokens.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/tokens“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"kind\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"native\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"mcp\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"compat\"\n          ]\n        }\n      ]\n    },\n    \"scope_set\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"full\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"scripts\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"mcp\"\n          ]\n        }\n      ]\n    },\n    \"scopes\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"anyOf\": [\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:write\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"profiles:delete\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"runtime:control\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"proxies:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"proxies:write\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"secrets:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"secrets:totp\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"cookies:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"cookies:write\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"extensions:write\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"kernels:manage\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"trash:manage\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"rpa:run\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"rpa:write\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"sync:control\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"settings:write\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"audit:read\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"admin\"\n            ]\n          }\n        ]\n      },\n      \"minItems\": 1,\n      \"uniqueItems\": true\n    },\n    \"expires_at\": {\n      \"type\": [\n        \"integer\",\n        \"null\"\n      ],\n      \"minimum\": 0\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Postman Lesetoken\",\n  \"kind\": \"native\",\n  \"scopes\": [\n    \"profiles:read\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/tokens$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/tokens\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/tokens\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/tokens/{id} — API-Token widerrufen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/tokens/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "tokens",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "API-Token widerrufen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/tokens/{id}. Tags: Tokens.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/tokens/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/tokens/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/tokens/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/tokens/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Tresor",
      "item": [
        {
          "name": "GET /api/v1/vault — Zustand des Tresors",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zustand des Tresors\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/vault. Tags: Tresor.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/vault$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/vault\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/vault\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/vault/password — Masterpasswort einrichten oder ändern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/password",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "password"
              ],
              "query": [],
              "variable": []
            },
            "description": "Masterpasswort einrichten oder ändern\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/vault/password. Tags: Tresor.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/vault/password“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"password\"\n  ],\n  \"properties\": {\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 12,\n      \"maxLength\": 1024\n    },\n    \"current_password\": {\n      \"type\": \"string\",\n      \"maxLength\": 1024\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"password\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"password+dpapi\"\n          ]\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/vault/password$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/vault/password\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/password\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/password/remove — Masterpasswort entfernen und Windows-Entsperrung verwenden",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/password/remove",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "password",
                "remove"
              ],
              "query": [],
              "variable": []
            },
            "description": "Masterpasswort entfernen und Windows-Entsperrung verwenden\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/password/remove. Tags: Tresor.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/password/remove“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"current_password\"\n  ],\n  \"properties\": {\n    \"current_password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"current_password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/password/remove$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/password/remove\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/password/remove\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/unlock — Tresor mit Masterpasswort entsperren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/unlock",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "unlock"
              ],
              "query": [],
              "variable": []
            },
            "description": "Tresor mit Masterpasswort entsperren\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/unlock. Tags: Tresor.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/unlock“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"password\"\n  ],\n  \"properties\": {\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/unlock$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/unlock\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/unlock\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/lock — Tresor sperren, wenn alle Profile und Profilaktionen beendet sind",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/lock",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "lock"
              ],
              "query": [],
              "variable": []
            },
            "description": "Tresor sperren, wenn alle Profile und Profilaktionen beendet sind\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/lock. Tags: Tresor.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/lock“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/lock$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/lock\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/lock\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/activity — Bedienaktivität für die automatische Tresorsperre melden",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/activity",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "activity"
              ],
              "query": [],
              "variable": []
            },
            "description": "Bedienaktivität für die automatische Tresorsperre melden\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/activity. Tags: Tresor.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/activity“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/activity$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/activity\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/activity\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/vault/settings — Automatische Sperre nach Inaktivität einstellen; null Minuten deaktiviert sie",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/settings",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "settings"
              ],
              "query": [],
              "variable": []
            },
            "description": "Automatische Sperre nach Inaktivität einstellen; null Minuten deaktiviert sie\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/vault/settings. Tags: Tresor.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/vault/settings“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"auto_lock_minutes\"\n  ],\n  \"properties\": {\n    \"auto_lock_minutes\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 1440\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"auto_lock_minutes\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/vault/settings$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/vault/settings\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/settings\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/recovery-key — Wiederherstellungsschlüssel erzeugen; erst nach Bestätigung aktiv",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/recovery-key",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "recovery-key"
              ],
              "query": [],
              "variable": []
            },
            "description": "Wiederherstellungsschlüssel erzeugen; erst nach Bestätigung aktiv\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/recovery-key. Tags: Tresor.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/recovery-key“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/recovery-key$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/recovery-key\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/recovery-key\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/recovery-key/confirm — Wiederherstellungsschlüssel mit den letzten acht Zeichen bestätigen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/recovery-key/confirm",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "recovery-key",
                "confirm"
              ],
              "query": [],
              "variable": []
            },
            "description": "Wiederherstellungsschlüssel mit den letzten acht Zeichen bestätigen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/recovery-key/confirm. Tags: Tresor.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/recovery-key/confirm“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"suffix\"\n  ],\n  \"properties\": {\n    \"suffix\": {\n      \"type\": \"string\",\n      \"minLength\": 8,\n      \"maxLength\": 16\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"suffix\": \"NUR-FIKTIVES-BEI\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/recovery-key/confirm$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/recovery-key/confirm\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/recovery-key/confirm\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/recover — Tresor mit Wiederherstellungsschlüssel für den aktuellen Windows-Benutzer entsperren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/recover",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "recover"
              ],
              "query": [],
              "variable": []
            },
            "description": "Tresor mit Wiederherstellungsschlüssel für den aktuellen Windows-Benutzer entsperren\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/recover. Tags: Tresor.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/recover“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"recovery_key\"\n  ],\n  \"properties\": {\n    \"recovery_key\": {\n      \"type\": \"string\",\n      \"minLength\": 52,\n      \"maxLength\": 128\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"recovery_key\": \"NUR-FIKTIVES-BEISPIELxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/recover$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/recover\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/recover\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/vault/missing — Nach dem Zurücksetzen des Tresors noch fehlende Geheimnisse (Proxys, Konten, eigene Proxys)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/missing",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "missing"
              ],
              "query": [],
              "variable": []
            },
            "description": "Nach dem Zurücksetzen des Tresors noch fehlende Geheimnisse (Proxys, Konten, eigene Proxys)\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/vault/missing. Tags: Tresor.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/vault/missing“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/vault/missing$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/vault/missing\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/missing\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/reset — Defekten Tresor neu anlegen: nicht mehr lesbare Geheimnisse werden entfernt und als fehlend gemeldet; die alte vault.json bleibt als Kopie erhalten",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/reset",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "reset"
              ],
              "query": [],
              "variable": []
            },
            "description": "Defekten Tresor neu anlegen: nicht mehr lesbare Geheimnisse werden entfernt und als fehlend gemeldet; die alte vault.json bleibt als Kopie erhalten\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/reset. Tags: Tresor.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/reset“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"confirm\"\n  ],\n  \"properties\": {\n    \"confirm\": {\n      \"type\": \"boolean\",\n      \"enum\": [\n        true\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"confirm\": true\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/reset$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/reset\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/reset\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/restore-secrets — Fehlende Geheimnisse aus einem .adbbackup-Vollbackup oder .adbprofile-Paket wiederherstellen (Proxys über Protokoll/Host/Port/Benutzer, Konten über Plattform und Benutzer)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/restore-secrets",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "restore-secrets"
              ],
              "query": [],
              "variable": []
            },
            "description": "Fehlende Geheimnisse aus einem .adbbackup-Vollbackup oder .adbprofile-Paket wiederherstellen (Proxys über Protokoll/Host/Port/Benutzer, Konten über Plattform und Benutzer)\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/restore-secrets. Tags: Tresor.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/restore-secrets“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"path\",\n    \"password\"\n  ],\n  \"properties\": {\n    \"path\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 1024\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"path\": \"C:/TabGecko-Beispiel/paket.adbprofile\",\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/restore-secrets$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/restore-secrets\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/restore-secrets\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/vault/rotate — Tresorschlüssel erneuern und alle Geheimnisse neu verschlüsseln",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/vault/rotate",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "vault",
                "rotate"
              ],
              "query": [],
              "variable": []
            },
            "description": "Tresorschlüssel erneuern und alle Geheimnisse neu verschlüsseln\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/vault/rotate. Tags: Tresor.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/vault/rotate“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/vault/rotate$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/vault/rotate\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/vault/rotate\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Profile",
      "item": [
        {
          "name": "GET /api/v1/profiles — Profile suchen, filtern, sortieren und seitenweise abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles"
              ],
              "query": [
                {
                  "key": "page",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}"
                },
                {
                  "key": "limit",
                  "value": "10",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":1000}"
                },
                {
                  "key": "cursor",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":512}"
                },
                {
                  "key": "search",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}"
                },
                {
                  "key": "ids",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. Kommagetrennte Profil-IDs\nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "group_id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "tag_ids",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. Kommagetrennte Tag-IDs\nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "tag_mode",
                  "value": "any",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"any\"]},{\"type\":\"string\",\"enum\":[\"all\"]}]}"
                },
                {
                  "key": "exclude_tag_ids",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "status_id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "engine",
                  "value": "chromium",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"chromium\"]},{\"type\":\"string\",\"enum\":[\"firefox\"]}]}"
                },
                {
                  "key": "os",
                  "value": "windows",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"windows\"]},{\"type\":\"string\",\"enum\":[\"macos\"]},{\"type\":\"string\",\"enum\":[\"linux\"]},{\"type\":\"string\",\"enum\":[\"android\"]},{\"type\":\"string\",\"enum\":[\"ios\"]}]}"
                },
                {
                  "key": "runtime_state",
                  "value": "stopped",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"stopped\"]},{\"type\":\"string\",\"enum\":[\"starting\"]},{\"type\":\"string\",\"enum\":[\"running\"]},{\"type\":\"string\",\"enum\":[\"stopping\"]},{\"type\":\"string\",\"enum\":[\"crashed\"]},{\"type\":\"string\",\"enum\":[\"locked\"]}]}"
                },
                {
                  "key": "pinned",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}"
                },
                {
                  "key": "proxy_id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "sort",
                  "value": "no",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"no\"]},{\"type\":\"string\",\"enum\":[\"custom_no\"]},{\"type\":\"string\",\"enum\":[\"name\"]},{\"type\":\"string\",\"enum\":[\"created_at\"]},{\"type\":\"string\",\"enum\":[\"updated_at\"]},{\"type\":\"string\",\"enum\":[\"last_opened_at\"]}]}"
                },
                {
                  "key": "order",
                  "value": "asc",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"asc\"]},{\"type\":\"string\",\"enum\":[\"desc\"]}]}"
                },
                {
                  "key": "pinned_first",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}"
                }
              ],
              "variable": []
            },
            "description": "Profile suchen, filtern, sortieren und seitenweise abrufen\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles. Tags: Profile.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery page: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}\nquery limit: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":1000}\nquery cursor: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":512}\nquery search: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}\nquery ids: Optional; zunächst deaktiviert. Kommagetrennte Profil-IDs\nSchema: {\"type\":\"string\"}\nquery group_id: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}\nquery tag_ids: Optional; zunächst deaktiviert. Kommagetrennte Tag-IDs\nSchema: {\"type\":\"string\"}\nquery tag_mode: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"any\"]},{\"type\":\"string\",\"enum\":[\"all\"]}]}\nquery exclude_tag_ids: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}\nquery status_id: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}\nquery engine: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"chromium\"]},{\"type\":\"string\",\"enum\":[\"firefox\"]}]}\nquery os: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"windows\"]},{\"type\":\"string\",\"enum\":[\"macos\"]},{\"type\":\"string\",\"enum\":[\"linux\"]},{\"type\":\"string\",\"enum\":[\"android\"]},{\"type\":\"string\",\"enum\":[\"ios\"]}]}\nquery runtime_state: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"stopped\"]},{\"type\":\"string\",\"enum\":[\"starting\"]},{\"type\":\"string\",\"enum\":[\"running\"]},{\"type\":\"string\",\"enum\":[\"stopping\"]},{\"type\":\"string\",\"enum\":[\"crashed\"]},{\"type\":\"string\",\"enum\":[\"locked\"]}]}\nquery pinned: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}\nquery proxy_id: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}\nquery sort: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"no\"]},{\"type\":\"string\",\"enum\":[\"custom_no\"]},{\"type\":\"string\",\"enum\":[\"name\"]},{\"type\":\"string\",\"enum\":[\"created_at\"]},{\"type\":\"string\",\"enum\":[\"updated_at\"]},{\"type\":\"string\",\"enum\":[\"last_opened_at\"]}]}\nquery order: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"asc\"]},{\"type\":\"string\",\"enum\":[\"desc\"]}]}\nquery pinned_first: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/profiles\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles — Profil anlegen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profil anlegen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"maxLength\": 100\n    },\n    \"notes\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 400\n    },\n    \"group_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ]\n    },\n    \"group_name\": {\n      \"type\": \"string\",\n      \"maxLength\": 100\n    },\n    \"tag_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\"\n      },\n      \"maxItems\": 30\n    },\n    \"tags\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 50\n      },\n      \"maxItems\": 30\n    },\n    \"status_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ]\n    },\n    \"pinned\": {\n      \"type\": \"boolean\"\n    },\n    \"color\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"custom_no\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 64\n    },\n    \"engine\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"chromium\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"firefox\"\n          ]\n        }\n      ]\n    },\n    \"engine_version\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 16\n    },\n    \"engine_auto_update\": {\n      \"type\": \"boolean\"\n    },\n    \"os\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"windows\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"macos\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"linux\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"android\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"ios\"\n          ]\n        }\n      ]\n    },\n    \"os_version\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"user_agent\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"fingerprint_overrides\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {}\n    },\n    \"proxy\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"mode\"\n      ],\n      \"properties\": {\n        \"ssh_private_key\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 65536\n        },\n        \"ssh_key_passphrase\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 1024\n        },\n        \"mode\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"none\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ref\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"inline\"\n              ]\n            }\n          ]\n        },\n        \"proxy_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"ssh_host_key\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"pattern\": \"^SHA256:[A-Za-z0-9+/]{43}$\"\n        },\n        \"protocol\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"http\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"https\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks4\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks4a\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks5\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks5h\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ssh\"\n              ]\n            }\n          ]\n        },\n        \"host\": {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 255\n        },\n        \"port\": {\n          \"type\": \"integer\",\n          \"minimum\": 1,\n          \"maximum\": 65535\n        },\n        \"username\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"password\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 1024\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"ip_checker\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"browser_options\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"block_images\": {\n          \"type\": \"boolean\"\n        },\n        \"block_video\": {\n          \"type\": \"boolean\"\n        },\n        \"block_audio\": {\n          \"type\": \"boolean\"\n        },\n        \"block_notifications\": {\n          \"type\": \"boolean\"\n        },\n        \"block_password_view\": {\n          \"type\": \"boolean\"\n        },\n        \"block_password_save\": {\n          \"type\": \"boolean\"\n        },\n        \"block_extension_pages\": {\n          \"type\": \"boolean\"\n        },\n        \"block_translation\": {\n          \"type\": \"boolean\"\n        },\n        \"block_devtools\": {\n          \"type\": \"boolean\"\n        },\n        \"local_network\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"blocked\",\n            \"allowed_ports\"\n          ],\n          \"properties\": {\n            \"blocked\": {\n              \"type\": \"boolean\"\n            },\n            \"allowed_ports\": {\n              \"type\": \"string\",\n              \"maxLength\": 1536\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"taskbar_icon\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"minLength\": 50,\n              \"maxLength\": 393216\n            },\n            {\n              \"type\": \"null\"\n            }\n          ]\n        },\n        \"ui_language\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"minLength\": 2,\n              \"maxLength\": 35\n            },\n            {\n              \"type\": \"null\"\n            }\n          ]\n        },\n        \"tls_cipher_blocklist\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"minLength\": 1,\n              \"maxLength\": 256\n            },\n            {\n              \"type\": \"null\"\n            }\n          ]\n        },\n        \"secure_dns\": {\n          \"anyOf\": [\n            {\n              \"type\": \"object\",\n              \"required\": [\n                \"mode\"\n              ],\n              \"properties\": {\n                \"mode\": {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"off\"\n                  ]\n                }\n              },\n              \"additionalProperties\": false\n            },\n            {\n              \"type\": \"object\",\n              \"required\": [\n                \"mode\",\n                \"server\"\n              ],\n              \"properties\": {\n                \"mode\": {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"secure\"\n                  ]\n                },\n                \"server\": {\n                  \"type\": \"string\",\n                  \"minLength\": 9,\n                  \"maxLength\": 2048\n                }\n              },\n              \"additionalProperties\": false\n            }\n          ]\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"net\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {}\n    },\n    \"start_mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"new_tab\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"last_tabs\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"urls\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"last_and_urls\"\n          ]\n        }\n      ]\n    },\n    \"start_urls\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"maxLength\": 2048\n      },\n      \"maxItems\": 20\n    },\n    \"open_account_pages\": {\n      \"type\": \"boolean\"\n    },\n    \"homepage\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"launch_args\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"maxLength\": 1024\n      },\n      \"maxItems\": 100\n    },\n    \"extension_set_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ]\n    },\n    \"storage_options\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"type\": \"boolean\"\n      }\n    },\n    \"clear_on_close\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"type\": \"boolean\"\n      }\n    },\n    \"cache_dir_override\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"fingerprint_seeds\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"identity\",\n        \"canvas\",\n        \"webgl\",\n        \"audio\",\n        \"clientRects\"\n      ],\n      \"properties\": {\n        \"identity\": {\n          \"type\": \"integer\",\n          \"minimum\": 1,\n          \"maximum\": 9007199254740991\n        },\n        \"canvas\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"webgl\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"audio\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"clientRects\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"accounts\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"platform_url\"\n        ],\n        \"properties\": {\n          \"platform_url\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 256\n          },\n          \"username\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 256\n          },\n          \"password\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 1024\n          },\n          \"totp_secret\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 1024\n          },\n          \"notes\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 1024\n          },\n          \"sort_order\": {\n            \"type\": \"integer\",\n            \"minimum\": 0\n          }\n        },\n        \"additionalProperties\": false\n      },\n      \"maxItems\": 50\n    },\n    \"imported_from\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 64\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"engine\": \"chromium\",\n  \"os\": \"windows\",\n  \"start_mode\": \"new_tab\",\n  \"proxy\": {\n    \"mode\": \"none\"\n  }\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/batch — Mehrere Profile anlegen; Ergebnis je Eintrag",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch"
              ],
              "query": [],
              "variable": []
            },
            "description": "Mehrere Profile anlegen; Ergebnis je Eintrag\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/batch. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/batch“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"profiles\"\n  ],\n  \"properties\": {\n    \"profiles\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"properties\": {\n          \"name\": {\n            \"type\": \"string\",\n            \"maxLength\": 100\n          },\n          \"notes\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 400\n          },\n          \"group_id\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ]\n          },\n          \"group_name\": {\n            \"type\": \"string\",\n            \"maxLength\": 100\n          },\n          \"tag_ids\": {\n            \"type\": \"array\",\n            \"items\": {\n              \"type\": \"string\"\n            },\n            \"maxItems\": 30\n          },\n          \"tags\": {\n            \"type\": \"array\",\n            \"items\": {\n              \"type\": \"string\",\n              \"minLength\": 1,\n              \"maxLength\": 50\n            },\n            \"maxItems\": 30\n          },\n          \"status_id\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ]\n          },\n          \"pinned\": {\n            \"type\": \"boolean\"\n          },\n          \"color\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 32\n          },\n          \"custom_no\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 64\n          },\n          \"engine\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"chromium\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"firefox\"\n                ]\n              }\n            ]\n          },\n          \"engine_version\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 16\n          },\n          \"engine_auto_update\": {\n            \"type\": \"boolean\"\n          },\n          \"os\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"windows\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"macos\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"linux\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"android\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ios\"\n                ]\n              }\n            ]\n          },\n          \"os_version\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 32\n          },\n          \"user_agent\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 512\n          },\n          \"fingerprint_overrides\": {\n            \"type\": \"object\",\n            \"additionalProperties\": {}\n          },\n          \"proxy\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"mode\"\n            ],\n            \"properties\": {\n              \"ssh_private_key\": {\n                \"type\": [\n                  \"string\",\n                  \"null\"\n                ],\n                \"maxLength\": 65536\n              },\n              \"ssh_key_passphrase\": {\n                \"type\": [\n                  \"string\",\n                  \"null\"\n                ],\n                \"maxLength\": 1024\n              },\n              \"mode\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"none\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"ref\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"inline\"\n                    ]\n                  }\n                ]\n              },\n              \"proxy_id\": {\n                \"type\": [\n                  \"string\",\n                  \"null\"\n                ]\n              },\n              \"ssh_host_key\": {\n                \"type\": [\n                  \"string\",\n                  \"null\"\n                ],\n                \"pattern\": \"^SHA256:[A-Za-z0-9+/]{43}$\"\n              },\n              \"protocol\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"http\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"https\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"socks4\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"socks4a\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"socks5\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"socks5h\"\n                    ]\n                  },\n                  {\n                    \"type\": \"string\",\n                    \"enum\": [\n                      \"ssh\"\n                    ]\n                  }\n                ]\n              },\n              \"host\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 255\n              },\n              \"port\": {\n                \"type\": \"integer\",\n                \"minimum\": 1,\n                \"maximum\": 65535\n              },\n              \"username\": {\n                \"type\": [\n                  \"string\",\n                  \"null\"\n                ],\n                \"maxLength\": 512\n              },\n              \"password\": {\n                \"type\": [\n                  \"string\",\n                  \"null\"\n                ],\n                \"maxLength\": 1024\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"ip_checker\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 32\n          },\n          \"browser_options\": {\n            \"type\": \"object\",\n            \"properties\": {\n              \"block_images\": {\n                \"type\": \"boolean\"\n              },\n              \"block_video\": {\n                \"type\": \"boolean\"\n              },\n              \"block_audio\": {\n                \"type\": \"boolean\"\n              },\n              \"block_notifications\": {\n                \"type\": \"boolean\"\n              },\n              \"block_password_view\": {\n                \"type\": \"boolean\"\n              },\n              \"block_password_save\": {\n                \"type\": \"boolean\"\n              },\n              \"block_extension_pages\": {\n                \"type\": \"boolean\"\n              },\n              \"block_translation\": {\n                \"type\": \"boolean\"\n              },\n              \"block_devtools\": {\n                \"type\": \"boolean\"\n              },\n              \"local_network\": {\n                \"type\": \"object\",\n                \"required\": [\n                  \"blocked\",\n                  \"allowed_ports\"\n                ],\n                \"properties\": {\n                  \"blocked\": {\n                    \"type\": \"boolean\"\n                  },\n                  \"allowed_ports\": {\n                    \"type\": \"string\",\n                    \"maxLength\": 1536\n                  }\n                },\n                \"additionalProperties\": false\n              },\n              \"taskbar_icon\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"minLength\": 50,\n                    \"maxLength\": 393216\n                  },\n                  {\n                    \"type\": \"null\"\n                  }\n                ]\n              },\n              \"ui_language\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"minLength\": 2,\n                    \"maxLength\": 35\n                  },\n                  {\n                    \"type\": \"null\"\n                  }\n                ]\n              },\n              \"tls_cipher_blocklist\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"minLength\": 1,\n                    \"maxLength\": 256\n                  },\n                  {\n                    \"type\": \"null\"\n                  }\n                ]\n              },\n              \"secure_dns\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"object\",\n                    \"required\": [\n                      \"mode\"\n                    ],\n                    \"properties\": {\n                      \"mode\": {\n                        \"type\": \"string\",\n                        \"enum\": [\n                          \"off\"\n                        ]\n                      }\n                    },\n                    \"additionalProperties\": false\n                  },\n                  {\n                    \"type\": \"object\",\n                    \"required\": [\n                      \"mode\",\n                      \"server\"\n                    ],\n                    \"properties\": {\n                      \"mode\": {\n                        \"type\": \"string\",\n                        \"enum\": [\n                          \"secure\"\n                        ]\n                      },\n                      \"server\": {\n                        \"type\": \"string\",\n                        \"minLength\": 9,\n                        \"maxLength\": 2048\n                      }\n                    },\n                    \"additionalProperties\": false\n                  }\n                ]\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"net\": {\n            \"type\": \"object\",\n            \"additionalProperties\": {}\n          },\n          \"start_mode\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"new_tab\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"last_tabs\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"urls\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"last_and_urls\"\n                ]\n              }\n            ]\n          },\n          \"start_urls\": {\n            \"type\": \"array\",\n            \"items\": {\n              \"type\": \"string\",\n              \"maxLength\": 2048\n            },\n            \"maxItems\": 20\n          },\n          \"open_account_pages\": {\n            \"type\": \"boolean\"\n          },\n          \"homepage\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 512\n          },\n          \"launch_args\": {\n            \"type\": \"array\",\n            \"items\": {\n              \"type\": \"string\",\n              \"maxLength\": 1024\n            },\n            \"maxItems\": 100\n          },\n          \"extension_set_id\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ]\n          },\n          \"storage_options\": {\n            \"type\": \"object\",\n            \"additionalProperties\": {\n              \"type\": \"boolean\"\n            }\n          },\n          \"clear_on_close\": {\n            \"type\": \"object\",\n            \"additionalProperties\": {\n              \"type\": \"boolean\"\n            }\n          },\n          \"cache_dir_override\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 512\n          },\n          \"fingerprint_seeds\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"identity\",\n              \"canvas\",\n              \"webgl\",\n              \"audio\",\n              \"clientRects\"\n            ],\n            \"properties\": {\n              \"identity\": {\n                \"type\": \"integer\",\n                \"minimum\": 1,\n                \"maximum\": 9007199254740991\n              },\n              \"canvas\": {\n                \"type\": \"integer\",\n                \"minimum\": 0,\n                \"maximum\": 4294967295\n              },\n              \"webgl\": {\n                \"type\": \"integer\",\n                \"minimum\": 0,\n                \"maximum\": 4294967295\n              },\n              \"audio\": {\n                \"type\": \"integer\",\n                \"minimum\": 0,\n                \"maximum\": 4294967295\n              },\n              \"clientRects\": {\n                \"type\": \"integer\",\n                \"minimum\": 0,\n                \"maximum\": 4294967295\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"accounts\": {\n            \"type\": \"array\",\n            \"items\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"platform_url\"\n              ],\n              \"properties\": {\n                \"platform_url\": {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 256\n                },\n                \"username\": {\n                  \"type\": [\n                    \"string\",\n                    \"null\"\n                  ],\n                  \"maxLength\": 256\n                },\n                \"password\": {\n                  \"type\": [\n                    \"string\",\n                    \"null\"\n                  ],\n                  \"maxLength\": 1024\n                },\n                \"totp_secret\": {\n                  \"type\": [\n                    \"string\",\n                    \"null\"\n                  ],\n                  \"maxLength\": 1024\n                },\n                \"notes\": {\n                  \"type\": [\n                    \"string\",\n                    \"null\"\n                  ],\n                  \"maxLength\": 1024\n                },\n                \"sort_order\": {\n                  \"type\": \"integer\",\n                  \"minimum\": 0\n                }\n              },\n              \"additionalProperties\": false\n            },\n            \"maxItems\": 50\n          },\n          \"imported_from\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 64\n          }\n        },\n        \"additionalProperties\": false\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"balance_gpu\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"profiles\": [\n    {\n      \"name\": \"Beispielprofil\"\n    }\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/batch$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/batch\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/profiles/batch — Mehrere Profile bearbeiten; nur angegebene Felder werden geändert",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch"
              ],
              "query": [],
              "variable": []
            },
            "description": "Mehrere Profile bearbeiten; nur angegebene Felder werden geändert\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/profiles/batch. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/profiles/batch“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"patch\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"patch\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"name\": {\n          \"type\": \"string\",\n          \"maxLength\": 100\n        },\n        \"notes\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 5000,\n          \"description\": \"Changed notes may contain up to 400 Unicode code points. Unchanged existing notes are preserved.\"\n        },\n        \"group_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"group_name\": {\n          \"type\": \"string\",\n          \"maxLength\": 100\n        },\n        \"tag_ids\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\"\n          },\n          \"maxItems\": 30\n        },\n        \"tags\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 50\n          },\n          \"maxItems\": 30\n        },\n        \"status_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"pinned\": {\n          \"type\": \"boolean\"\n        },\n        \"color\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"custom_no\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 64\n        },\n        \"engine\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"chromium\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"firefox\"\n              ]\n            }\n          ]\n        },\n        \"engine_version\": {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 16\n        },\n        \"engine_auto_update\": {\n          \"type\": \"boolean\"\n        },\n        \"os\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"windows\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"macos\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"linux\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"android\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ios\"\n              ]\n            }\n          ]\n        },\n        \"os_version\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"user_agent\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"fingerprint_overrides\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {}\n        },\n        \"proxy\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"mode\"\n          ],\n          \"properties\": {\n            \"ssh_private_key\": {\n              \"type\": [\n                \"string\",\n                \"null\"\n              ],\n              \"maxLength\": 65536\n            },\n            \"ssh_key_passphrase\": {\n              \"type\": [\n                \"string\",\n                \"null\"\n              ],\n              \"maxLength\": 1024\n            },\n            \"mode\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"none\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"ref\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"inline\"\n                  ]\n                }\n              ]\n            },\n            \"proxy_id\": {\n              \"type\": [\n                \"string\",\n                \"null\"\n              ]\n            },\n            \"ssh_host_key\": {\n              \"type\": [\n                \"string\",\n                \"null\"\n              ],\n              \"pattern\": \"^SHA256:[A-Za-z0-9+/]{43}$\"\n            },\n            \"protocol\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"http\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"https\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"socks4\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"socks4a\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"socks5\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"socks5h\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"ssh\"\n                  ]\n                }\n              ]\n            },\n            \"host\": {\n              \"type\": \"string\",\n              \"minLength\": 1,\n              \"maxLength\": 255\n            },\n            \"port\": {\n              \"type\": \"integer\",\n              \"minimum\": 1,\n              \"maximum\": 65535\n            },\n            \"username\": {\n              \"type\": [\n                \"string\",\n                \"null\"\n              ],\n              \"maxLength\": 512\n            },\n            \"password\": {\n              \"type\": [\n                \"string\",\n                \"null\"\n              ],\n              \"maxLength\": 1024\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"ip_checker\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"browser_options\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"block_images\": {\n              \"type\": \"boolean\"\n            },\n            \"block_video\": {\n              \"type\": \"boolean\"\n            },\n            \"block_audio\": {\n              \"type\": \"boolean\"\n            },\n            \"block_notifications\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_view\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_save\": {\n              \"type\": \"boolean\"\n            },\n            \"block_extension_pages\": {\n              \"type\": \"boolean\"\n            },\n            \"block_translation\": {\n              \"type\": \"boolean\"\n            },\n            \"block_devtools\": {\n              \"type\": \"boolean\"\n            },\n            \"local_network\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"blocked\",\n                \"allowed_ports\"\n              ],\n              \"properties\": {\n                \"blocked\": {\n                  \"type\": \"boolean\"\n                },\n                \"allowed_ports\": {\n                  \"type\": \"string\",\n                  \"maxLength\": 1536\n                }\n              },\n              \"additionalProperties\": false\n            },\n            \"taskbar_icon\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 50,\n                  \"maxLength\": 393216\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"ui_language\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 2,\n                  \"maxLength\": 35\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"tls_cipher_blocklist\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 256\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"secure_dns\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"off\"\n                      ]\n                    }\n                  },\n                  \"additionalProperties\": false\n                },\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\",\n                    \"server\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"secure\"\n                      ]\n                    },\n                    \"server\": {\n                      \"type\": \"string\",\n                      \"minLength\": 9,\n                      \"maxLength\": 2048\n                    }\n                  },\n                  \"additionalProperties\": false\n                }\n              ]\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"net\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {}\n        },\n        \"start_mode\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"new_tab\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"last_tabs\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"urls\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"last_and_urls\"\n              ]\n            }\n          ]\n        },\n        \"start_urls\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"maxLength\": 2048\n          },\n          \"maxItems\": 20\n        },\n        \"open_account_pages\": {\n          \"type\": \"boolean\"\n        },\n        \"homepage\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"launch_args\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"maxLength\": 1024\n          },\n          \"maxItems\": 100\n        },\n        \"extension_set_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"storage_options\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        },\n        \"clear_on_close\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        },\n        \"cache_dir_override\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"regenerate_fingerprint\": {\n          \"type\": \"boolean\"\n        },\n        \"notes_append\": {\n          \"type\": \"string\",\n          \"maxLength\": 400\n        },\n        \"custom_no_sequence\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"mode\"\n          ],\n          \"properties\": {\n            \"mode\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"increment\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"decrement\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"constant\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"random\"\n                  ]\n                }\n              ]\n            },\n            \"start\": {\n              \"type\": \"integer\",\n              \"minimum\": -1000000000,\n              \"maximum\": 1000000000\n            },\n            \"step\": {\n              \"type\": \"integer\",\n              \"minimum\": 1,\n              \"maximum\": 1000000\n            },\n            \"prefix\": {\n              \"type\": \"string\",\n              \"maxLength\": 32\n            },\n            \"pad\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 12\n            }\n          },\n          \"additionalProperties\": false\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"patch\": {\n    \"name\": \"Beispielprofil\"\n  }\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/profiles/batch$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/profiles/batch\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/quick-create — Mehrere Profile nach Anzahl anlegen: Namensschema mit {NR}, {N}, {DATUM}, {LOGIN}, {ZUFALL:6}; eigener Fingerprint je Profil",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/quick-create",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "quick-create"
              ],
              "query": [],
              "variable": []
            },
            "description": "Mehrere Profile nach Anzahl anlegen: Namensschema mit {NR}, {N}, {DATUM}, {LOGIN}, {ZUFALL:6}; eigener Fingerprint je Profil\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/quick-create. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/quick-create“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"count\"\n  ],\n  \"properties\": {\n    \"count\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 500\n    },\n    \"balance_gpu\": {\n      \"type\": \"boolean\"\n    },\n    \"name_pattern\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"template_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"template\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"notes\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 400\n        },\n        \"group_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"group_name\": {\n          \"type\": \"string\",\n          \"maxLength\": 100\n        },\n        \"tag_ids\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\"\n          },\n          \"maxItems\": 30\n        },\n        \"tags\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 50\n          },\n          \"maxItems\": 30\n        },\n        \"status_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"pinned\": {\n          \"type\": \"boolean\"\n        },\n        \"color\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"engine\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"chromium\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"firefox\"\n              ]\n            }\n          ]\n        },\n        \"engine_version\": {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 16\n        },\n        \"engine_auto_update\": {\n          \"type\": \"boolean\"\n        },\n        \"os\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"windows\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"macos\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"linux\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"android\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ios\"\n              ]\n            }\n          ]\n        },\n        \"os_version\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"user_agent\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"fingerprint_overrides\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {}\n        },\n        \"ip_checker\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"browser_options\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"block_images\": {\n              \"type\": \"boolean\"\n            },\n            \"block_video\": {\n              \"type\": \"boolean\"\n            },\n            \"block_audio\": {\n              \"type\": \"boolean\"\n            },\n            \"block_notifications\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_view\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_save\": {\n              \"type\": \"boolean\"\n            },\n            \"block_extension_pages\": {\n              \"type\": \"boolean\"\n            },\n            \"block_translation\": {\n              \"type\": \"boolean\"\n            },\n            \"block_devtools\": {\n              \"type\": \"boolean\"\n            },\n            \"local_network\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"blocked\",\n                \"allowed_ports\"\n              ],\n              \"properties\": {\n                \"blocked\": {\n                  \"type\": \"boolean\"\n                },\n                \"allowed_ports\": {\n                  \"type\": \"string\",\n                  \"maxLength\": 1536\n                }\n              },\n              \"additionalProperties\": false\n            },\n            \"taskbar_icon\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 50,\n                  \"maxLength\": 393216\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"ui_language\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 2,\n                  \"maxLength\": 35\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"tls_cipher_blocklist\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 256\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"secure_dns\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"off\"\n                      ]\n                    }\n                  },\n                  \"additionalProperties\": false\n                },\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\",\n                    \"server\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"secure\"\n                      ]\n                    },\n                    \"server\": {\n                      \"type\": \"string\",\n                      \"minLength\": 9,\n                      \"maxLength\": 2048\n                    }\n                  },\n                  \"additionalProperties\": false\n                }\n              ]\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"net\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {}\n        },\n        \"start_mode\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"new_tab\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"last_tabs\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"urls\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"last_and_urls\"\n              ]\n            }\n          ]\n        },\n        \"start_urls\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"maxLength\": 2048\n          },\n          \"maxItems\": 20\n        },\n        \"open_account_pages\": {\n          \"type\": \"boolean\"\n        },\n        \"homepage\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"launch_args\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"maxLength\": 1024\n          },\n          \"maxItems\": 100\n        },\n        \"extension_set_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"storage_options\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        },\n        \"clear_on_close\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        },\n        \"cache_dir_override\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"fingerprint_seeds\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"identity\",\n            \"canvas\",\n            \"webgl\",\n            \"audio\",\n            \"clientRects\"\n          ],\n          \"properties\": {\n            \"identity\": {\n              \"type\": \"integer\",\n              \"minimum\": 1,\n              \"maximum\": 9007199254740991\n            },\n            \"canvas\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"webgl\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"audio\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"clientRects\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"imported_from\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 64\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"proxy\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"mode\"\n      ],\n      \"properties\": {\n        \"mode\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"none\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"one\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"sequential\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"random\"\n              ]\n            }\n          ]\n        },\n        \"proxy_ids\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\"\n          },\n          \"maxItems\": 5000\n        },\n        \"only_unused\": {\n          \"type\": \"boolean\"\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"count\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/quick-create$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/quick-create\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/quick-create\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/batch/assign-group — Profile einer Gruppe zuordnen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch/assign-group",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch",
                "assign-group"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profile einer Gruppe zuordnen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/batch/assign-group. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/batch/assign-group“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"group_id\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"group_id\": {\n      \"type\": \"string\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"group_id\": \"00000000-0000-4000-8000-000000000001\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/batch/assign-group$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/batch/assign-group\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch/assign-group\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/batch/assign-tags — Tags hinzufügen, entfernen oder ersetzen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch/assign-tags",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch",
                "assign-tags"
              ],
              "query": [],
              "variable": []
            },
            "description": "Tags hinzufügen, entfernen oder ersetzen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/batch/assign-tags. Tags: Profile.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/batch/assign-tags“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"tag_ids\",\n    \"mode\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"tag_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\"\n      },\n      \"maxItems\": 30\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"add\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"remove\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"replace\"\n          ]\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"tag_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"mode\": \"add\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/batch/assign-tags$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/batch/assign-tags\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch/assign-tags\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/by-no/{no} — Profil über die fortlaufende Nummer abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/by-no/:no",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "by-no",
                ":no"
              ],
              "query": [],
              "variable": [
                {
                  "key": "no",
                  "value": "1",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1}"
                }
              ]
            },
            "description": "Profil über die fortlaufende Nummer abrufen\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/by-no/{no}. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/by-no/{no}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath no: Pflichtfeld. \nSchema: {\"type\":\"integer\",\"minimum\":1}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/by-no/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/by-no/{no}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/by-no/{no}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id} — Profil mit Konten (Passwörter maskiert) abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profil mit Konten (Passwörter maskiert) abrufen\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/profiles/{id} — Profil bearbeiten; Kern und Betriebssystem sind nach der Anlage fest",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profil bearbeiten; Kern und Betriebssystem sind nach der Anlage fest\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/profiles/{id}. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/profiles/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"maxLength\": 100\n    },\n    \"notes\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 5000,\n      \"description\": \"Changed notes may contain up to 400 Unicode code points. Unchanged existing notes are preserved.\"\n    },\n    \"group_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ]\n    },\n    \"group_name\": {\n      \"type\": \"string\",\n      \"maxLength\": 100\n    },\n    \"tag_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\"\n      },\n      \"maxItems\": 30\n    },\n    \"tags\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 50\n      },\n      \"maxItems\": 30\n    },\n    \"status_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ]\n    },\n    \"pinned\": {\n      \"type\": \"boolean\"\n    },\n    \"color\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"custom_no\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 64\n    },\n    \"engine\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"chromium\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"firefox\"\n          ]\n        }\n      ]\n    },\n    \"engine_version\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 16\n    },\n    \"engine_auto_update\": {\n      \"type\": \"boolean\"\n    },\n    \"os\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"windows\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"macos\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"linux\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"android\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"ios\"\n          ]\n        }\n      ]\n    },\n    \"os_version\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"user_agent\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"fingerprint_overrides\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {}\n    },\n    \"proxy\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"mode\"\n      ],\n      \"properties\": {\n        \"ssh_private_key\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 65536\n        },\n        \"ssh_key_passphrase\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 1024\n        },\n        \"mode\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"none\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ref\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"inline\"\n              ]\n            }\n          ]\n        },\n        \"proxy_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"ssh_host_key\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"pattern\": \"^SHA256:[A-Za-z0-9+/]{43}$\"\n        },\n        \"protocol\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"http\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"https\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks4\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks4a\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks5\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks5h\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ssh\"\n              ]\n            }\n          ]\n        },\n        \"host\": {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 255\n        },\n        \"port\": {\n          \"type\": \"integer\",\n          \"minimum\": 1,\n          \"maximum\": 65535\n        },\n        \"username\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"password\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 1024\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"ip_checker\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"browser_options\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"block_images\": {\n          \"type\": \"boolean\"\n        },\n        \"block_video\": {\n          \"type\": \"boolean\"\n        },\n        \"block_audio\": {\n          \"type\": \"boolean\"\n        },\n        \"block_notifications\": {\n          \"type\": \"boolean\"\n        },\n        \"block_password_view\": {\n          \"type\": \"boolean\"\n        },\n        \"block_password_save\": {\n          \"type\": \"boolean\"\n        },\n        \"block_extension_pages\": {\n          \"type\": \"boolean\"\n        },\n        \"block_translation\": {\n          \"type\": \"boolean\"\n        },\n        \"block_devtools\": {\n          \"type\": \"boolean\"\n        },\n        \"local_network\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"blocked\",\n            \"allowed_ports\"\n          ],\n          \"properties\": {\n            \"blocked\": {\n              \"type\": \"boolean\"\n            },\n            \"allowed_ports\": {\n              \"type\": \"string\",\n              \"maxLength\": 1536\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"taskbar_icon\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"minLength\": 50,\n              \"maxLength\": 393216\n            },\n            {\n              \"type\": \"null\"\n            }\n          ]\n        },\n        \"ui_language\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"minLength\": 2,\n              \"maxLength\": 35\n            },\n            {\n              \"type\": \"null\"\n            }\n          ]\n        },\n        \"tls_cipher_blocklist\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"minLength\": 1,\n              \"maxLength\": 256\n            },\n            {\n              \"type\": \"null\"\n            }\n          ]\n        },\n        \"secure_dns\": {\n          \"anyOf\": [\n            {\n              \"type\": \"object\",\n              \"required\": [\n                \"mode\"\n              ],\n              \"properties\": {\n                \"mode\": {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"off\"\n                  ]\n                }\n              },\n              \"additionalProperties\": false\n            },\n            {\n              \"type\": \"object\",\n              \"required\": [\n                \"mode\",\n                \"server\"\n              ],\n              \"properties\": {\n                \"mode\": {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"secure\"\n                  ]\n                },\n                \"server\": {\n                  \"type\": \"string\",\n                  \"minLength\": 9,\n                  \"maxLength\": 2048\n                }\n              },\n              \"additionalProperties\": false\n            }\n          ]\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"net\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {}\n    },\n    \"start_mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"new_tab\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"last_tabs\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"urls\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"last_and_urls\"\n          ]\n        }\n      ]\n    },\n    \"start_urls\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"maxLength\": 2048\n      },\n      \"maxItems\": 20\n    },\n    \"open_account_pages\": {\n      \"type\": \"boolean\"\n    },\n    \"homepage\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"launch_args\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"maxLength\": 1024\n      },\n      \"maxItems\": 100\n    },\n    \"extension_set_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ]\n    },\n    \"storage_options\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"type\": \"boolean\"\n      }\n    },\n    \"clear_on_close\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"type\": \"boolean\"\n      }\n    },\n    \"cache_dir_override\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"fingerprint_seeds\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"identity\",\n        \"canvas\",\n        \"webgl\",\n        \"audio\",\n        \"clientRects\"\n      ],\n      \"properties\": {\n        \"identity\": {\n          \"type\": \"integer\",\n          \"minimum\": 1,\n          \"maximum\": 9007199254740991\n        },\n        \"canvas\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"webgl\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"audio\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"clientRects\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"row_version\": {\n      \"type\": \"integer\",\n      \"minimum\": 1\n    },\n    \"regenerate_fingerprint\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/profiles/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/profiles/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/encryption — Zustand der Verschlüsselung ruhender Profildaten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/encryption",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "encryption"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Zustand der Verschlüsselung ruhender Profildaten\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/encryption. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/encryption“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/encryption$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/encryption\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/encryption\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/profiles/{id}/encryption — Verschlüsselung ruhender Profildaten ändern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/encryption",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "encryption"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Verschlüsselung ruhender Profildaten ändern\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/profiles/{id}/encryption. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/profiles/{id}/encryption“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"enabled\"\n  ],\n  \"properties\": {\n    \"enabled\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"enabled\": false\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/encryption$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/profiles/{id}/encryption\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/encryption\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/encryption/rotate — Profilschlüssel erneuern und ruhende Dateien ohne Klartextkopie neu verschlüsseln",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/encryption/rotate",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "encryption",
                "rotate"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profilschlüssel erneuern und ruhende Dateien ohne Klartextkopie neu verschlüsseln\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/encryption/rotate. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/encryption/rotate“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"confirm\"\n  ],\n  \"properties\": {\n    \"confirm\": {\n      \"type\": \"boolean\",\n      \"enum\": [\n        true\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"confirm\": true\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/encryption/rotate$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/encryption/rotate\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/encryption/rotate\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/batch/assign-proxy — Proxys zuweisen: ein Proxy für alle, der Reihe nach oder zufällig, optional nur unbenutzte",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch/assign-proxy",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch",
                "assign-proxy"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxys zuweisen: ein Proxy für alle, der Reihe nach oder zufällig, optional nur unbenutzte\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/batch/assign-proxy. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/batch/assign-proxy“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"mode\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"one\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"sequential\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"random\"\n          ]\n        }\n      ]\n    },\n    \"proxy_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\"\n      },\n      \"maxItems\": 5000\n    },\n    \"only_unused\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"mode\": \"one\",\n  \"proxy_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/batch/assign-proxy$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/batch/assign-proxy\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch/assign-proxy\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/proxy/test — Gespeicherte Profilverbindung ohne Browserstart prüfen; Ausgangs-IP und Land bei unveränderter Konfiguration speichern",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/proxy/test",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "proxy",
                "test"
              ],
              "query": [
                {
                  "key": "ip_checker",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":32}"
                },
                {
                  "key": "detect_protocol",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. HTTP, HTTPS oder SOCKS5 mit gespeicherten Zugangsdaten erkennen; nur Vorschau, ohne Konfiguration oder Messstand zu ändern.\nSchema: {\"type\":\"boolean\"}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gespeicherte Profilverbindung ohne Browserstart prüfen; Ausgangs-IP und Land bei unveränderter Konfiguration speichern\n\nFeste Route-Scopes: profiles:write, proxies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/proxy/test. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/proxy/test“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery ip_checker: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":32}\nquery detect_protocol: Optional; zunächst deaktiviert. HTTP, HTTPS oder SOCKS5 mit gespeicherten Zugangsdaten erkennen; nur Vorschau, ohne Konfiguration oder Messstand zu ändern.\nSchema: {\"type\":\"boolean\"}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/proxy/test$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/proxy/test\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/proxy/test\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/clone — Profil klonen: neue ID und Nr.; Fingerprint neu (Standard) oder gleich; Cookies, Proxy, Konten und Browserdaten nur auf Wunsch",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/clone",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "clone"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profil klonen: neue ID und Nr.; Fingerprint neu (Standard) oder gleich; Cookies, Proxy, Konten und Browserdaten nur auf Wunsch\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/clone. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/clone“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"count\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 50\n    },\n    \"name_pattern\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"fingerprint\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"new\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"same\"\n          ]\n        }\n      ]\n    },\n    \"cookies\": {\n      \"type\": \"boolean\"\n    },\n    \"proxy\": {\n      \"type\": \"boolean\"\n    },\n    \"accounts\": {\n      \"type\": \"boolean\"\n    },\n    \"storage\": {\n      \"type\": \"boolean\"\n    },\n    \"group_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/clone$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/clone\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/clone\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profile-templates — Benannte Vorlagen für neue Profile („Mehrere erstellen“, quick-create mit template_id)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profile-templates",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profile-templates"
              ],
              "query": [],
              "variable": []
            },
            "description": "Benannte Vorlagen für neue Profile („Mehrere erstellen“, quick-create mit template_id)\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profile-templates. Tags: Profile.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profile-templates$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profile-templates\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/profile-templates\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profile-templates — Vorlage anlegen (Felder wie beim Anlegen eines Profils, ohne Name, Proxy und Konten)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profile-templates",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profile-templates"
              ],
              "query": [],
              "variable": []
            },
            "description": "Vorlage anlegen (Felder wie beim Anlegen eines Profils, ohne Name, Proxy und Konten)\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profile-templates. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profile-templates“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"template\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"name_pattern\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 100\n    },\n    \"template\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"notes\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 400\n        },\n        \"group_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"group_name\": {\n          \"type\": \"string\",\n          \"maxLength\": 100\n        },\n        \"tag_ids\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\"\n          },\n          \"maxItems\": 30\n        },\n        \"tags\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 50\n          },\n          \"maxItems\": 30\n        },\n        \"status_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"pinned\": {\n          \"type\": \"boolean\"\n        },\n        \"color\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"engine\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"chromium\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"firefox\"\n              ]\n            }\n          ]\n        },\n        \"engine_version\": {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 16\n        },\n        \"engine_auto_update\": {\n          \"type\": \"boolean\"\n        },\n        \"os\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"windows\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"macos\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"linux\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"android\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ios\"\n              ]\n            }\n          ]\n        },\n        \"os_version\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"user_agent\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"fingerprint_overrides\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {}\n        },\n        \"ip_checker\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"browser_options\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"block_images\": {\n              \"type\": \"boolean\"\n            },\n            \"block_video\": {\n              \"type\": \"boolean\"\n            },\n            \"block_audio\": {\n              \"type\": \"boolean\"\n            },\n            \"block_notifications\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_view\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_save\": {\n              \"type\": \"boolean\"\n            },\n            \"block_extension_pages\": {\n              \"type\": \"boolean\"\n            },\n            \"block_translation\": {\n              \"type\": \"boolean\"\n            },\n            \"block_devtools\": {\n              \"type\": \"boolean\"\n            },\n            \"local_network\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"blocked\",\n                \"allowed_ports\"\n              ],\n              \"properties\": {\n                \"blocked\": {\n                  \"type\": \"boolean\"\n                },\n                \"allowed_ports\": {\n                  \"type\": \"string\",\n                  \"maxLength\": 1536\n                }\n              },\n              \"additionalProperties\": false\n            },\n            \"taskbar_icon\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 50,\n                  \"maxLength\": 393216\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"ui_language\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 2,\n                  \"maxLength\": 35\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"tls_cipher_blocklist\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 256\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"secure_dns\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"off\"\n                      ]\n                    }\n                  },\n                  \"additionalProperties\": false\n                },\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\",\n                    \"server\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"secure\"\n                      ]\n                    },\n                    \"server\": {\n                      \"type\": \"string\",\n                      \"minLength\": 9,\n                      \"maxLength\": 2048\n                    }\n                  },\n                  \"additionalProperties\": false\n                }\n              ]\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"net\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {}\n        },\n        \"start_mode\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"new_tab\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"last_tabs\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"urls\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"last_and_urls\"\n              ]\n            }\n          ]\n        },\n        \"start_urls\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"maxLength\": 2048\n          },\n          \"maxItems\": 20\n        },\n        \"open_account_pages\": {\n          \"type\": \"boolean\"\n        },\n        \"homepage\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"launch_args\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"maxLength\": 1024\n          },\n          \"maxItems\": 100\n        },\n        \"extension_set_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"storage_options\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        },\n        \"clear_on_close\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        },\n        \"cache_dir_override\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"fingerprint_seeds\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"identity\",\n            \"canvas\",\n            \"webgl\",\n            \"audio\",\n            \"clientRects\"\n          ],\n          \"properties\": {\n            \"identity\": {\n              \"type\": \"integer\",\n              \"minimum\": 1,\n              \"maximum\": 9007199254740991\n            },\n            \"canvas\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"webgl\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"audio\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"clientRects\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            }\n          },\n          \"additionalProperties\": false\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"template\": {}\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profile-templates$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profile-templates\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profile-templates\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profile-templates/from-profile — Vorlage aus den Einstellungen eines Profils erzeugen (ohne Name, Notiz, Fingerabdruck, Proxy, Konten)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profile-templates/from-profile",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profile-templates",
                "from-profile"
              ],
              "query": [],
              "variable": []
            },
            "description": "Vorlage aus den Einstellungen eines Profils erzeugen (ohne Name, Notiz, Fingerabdruck, Proxy, Konten)\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profile-templates/from-profile. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profile-templates/from-profile“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"profile_id\",\n    \"name\"\n  ],\n  \"properties\": {\n    \"profile_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"profile_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profile-templates/from-profile$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profile-templates/from-profile\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profile-templates/from-profile\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/profile-templates/{id} — Vorlage ändern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profile-templates/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profile-templates",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Vorlage ändern\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/profile-templates/{id}. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/profile-templates/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"name_pattern\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 100\n    },\n    \"template\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"notes\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 400\n        },\n        \"group_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"group_name\": {\n          \"type\": \"string\",\n          \"maxLength\": 100\n        },\n        \"tag_ids\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\"\n          },\n          \"maxItems\": 30\n        },\n        \"tags\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 50\n          },\n          \"maxItems\": 30\n        },\n        \"status_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"pinned\": {\n          \"type\": \"boolean\"\n        },\n        \"color\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"engine\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"chromium\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"firefox\"\n              ]\n            }\n          ]\n        },\n        \"engine_version\": {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 16\n        },\n        \"engine_auto_update\": {\n          \"type\": \"boolean\"\n        },\n        \"os\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"windows\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"macos\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"linux\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"android\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ios\"\n              ]\n            }\n          ]\n        },\n        \"os_version\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"user_agent\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"fingerprint_overrides\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {}\n        },\n        \"ip_checker\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"browser_options\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"block_images\": {\n              \"type\": \"boolean\"\n            },\n            \"block_video\": {\n              \"type\": \"boolean\"\n            },\n            \"block_audio\": {\n              \"type\": \"boolean\"\n            },\n            \"block_notifications\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_view\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_save\": {\n              \"type\": \"boolean\"\n            },\n            \"block_extension_pages\": {\n              \"type\": \"boolean\"\n            },\n            \"block_translation\": {\n              \"type\": \"boolean\"\n            },\n            \"block_devtools\": {\n              \"type\": \"boolean\"\n            },\n            \"local_network\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"blocked\",\n                \"allowed_ports\"\n              ],\n              \"properties\": {\n                \"blocked\": {\n                  \"type\": \"boolean\"\n                },\n                \"allowed_ports\": {\n                  \"type\": \"string\",\n                  \"maxLength\": 1536\n                }\n              },\n              \"additionalProperties\": false\n            },\n            \"taskbar_icon\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 50,\n                  \"maxLength\": 393216\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"ui_language\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 2,\n                  \"maxLength\": 35\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"tls_cipher_blocklist\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 256\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"secure_dns\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"off\"\n                      ]\n                    }\n                  },\n                  \"additionalProperties\": false\n                },\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\",\n                    \"server\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"secure\"\n                      ]\n                    },\n                    \"server\": {\n                      \"type\": \"string\",\n                      \"minLength\": 9,\n                      \"maxLength\": 2048\n                    }\n                  },\n                  \"additionalProperties\": false\n                }\n              ]\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"net\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {}\n        },\n        \"start_mode\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"new_tab\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"last_tabs\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"urls\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"last_and_urls\"\n              ]\n            }\n          ]\n        },\n        \"start_urls\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"maxLength\": 2048\n          },\n          \"maxItems\": 20\n        },\n        \"open_account_pages\": {\n          \"type\": \"boolean\"\n        },\n        \"homepage\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"launch_args\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"maxLength\": 1024\n          },\n          \"maxItems\": 100\n        },\n        \"extension_set_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"storage_options\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        },\n        \"clear_on_close\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        },\n        \"cache_dir_override\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"fingerprint_seeds\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"identity\",\n            \"canvas\",\n            \"webgl\",\n            \"audio\",\n            \"clientRects\"\n          ],\n          \"properties\": {\n            \"identity\": {\n              \"type\": \"integer\",\n              \"minimum\": 1,\n              \"maximum\": 9007199254740991\n            },\n            \"canvas\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"webgl\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"audio\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            },\n            \"clientRects\": {\n              \"type\": \"integer\",\n              \"minimum\": 0,\n              \"maximum\": 4294967295\n            }\n          },\n          \"additionalProperties\": false\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/profile-templates/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/profile-templates/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profile-templates/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/profile-templates/{id} — Vorlage löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profile-templates/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profile-templates",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Vorlage löschen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/profile-templates/{id}. Tags: Profile.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/profile-templates/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/profile-templates/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/profile-templates/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profile-templates/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/fingerprint/preview — Fingerprint-Entwurf erzeugen und prüfen, ohne ein Profil zu speichern",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/fingerprint/preview",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "fingerprint",
                "preview"
              ],
              "query": [],
              "variable": []
            },
            "description": "Fingerprint-Entwurf erzeugen und prüfen, ohne ein Profil zu speichern\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/fingerprint/preview. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/fingerprint/preview“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"engine\",\n    \"os\",\n    \"fingerprint_overrides\"\n  ],\n  \"properties\": {\n    \"engine\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"chromium\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"firefox\"\n          ]\n        }\n      ]\n    },\n    \"os\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"windows\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"macos\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"linux\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"android\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"ios\"\n          ]\n        }\n      ]\n    },\n    \"engine_version\": {\n      \"type\": \"string\",\n      \"maxLength\": 16\n    },\n    \"engine_auto_update\": {\n      \"type\": \"boolean\"\n    },\n    \"os_version\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"user_agent\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"fingerprint_overrides\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {}\n    },\n    \"seeds\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"identity\",\n        \"canvas\",\n        \"webgl\",\n        \"audio\",\n        \"clientRects\"\n      ],\n      \"properties\": {\n        \"identity\": {\n          \"type\": \"integer\",\n          \"minimum\": 1,\n          \"maximum\": 9007199254740991\n        },\n        \"canvas\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"webgl\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"audio\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        },\n        \"clientRects\": {\n          \"type\": \"integer\",\n          \"minimum\": 0,\n          \"maximum\": 4294967295\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"engine\": \"chromium\",\n  \"os\": \"windows\",\n  \"fingerprint_overrides\": {}\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/fingerprint/preview$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/fingerprint/preview\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/fingerprint/preview\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/fingerprint/report — Fingerprint im laufenden Profil lokal messen und mit der Startkonfiguration vergleichen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/fingerprint/report",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "fingerprint",
                "report"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Fingerprint im laufenden Profil lokal messen und mit der Startkonfiguration vergleichen\n\nFeste Route-Scopes: profiles:read, runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/fingerprint/report. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/fingerprint/report“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/fingerprint/report$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/fingerprint/report\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/fingerprint/report\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/fingerprint — Aufgelöster Fingerprint eines Profils (Werte, die der Kern beim Start erhält) mit Konsistenzprüfung",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/fingerprint",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "fingerprint"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Aufgelöster Fingerprint eines Profils (Werte, die der Kern beim Start erhält) mit Konsistenzprüfung\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/fingerprint. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/fingerprint“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/fingerprint$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/fingerprint\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/fingerprint\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/fingerprint/preview — Fingerprint mit geänderten Überschreibungen prüfen, ohne zu speichern",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/fingerprint/preview",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "fingerprint",
                "preview"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Fingerprint mit geänderten Überschreibungen prüfen, ohne zu speichern\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/fingerprint/preview. Tags: Profile.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/fingerprint/preview“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"fingerprint_overrides\"\n  ],\n  \"properties\": {\n    \"fingerprint_overrides\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {}\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"fingerprint_overrides\": {}\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/fingerprint/preview$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/fingerprint/preview\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/fingerprint/preview\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Papierkorb",
      "item": [
        {
          "name": "DELETE /api/v1/profiles/{id} — Profil in den Papierkorb legen; permanent=true löscht sofort endgültig (zusätzlich trash:manage)",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id"
              ],
              "query": [
                {
                  "key": "permanent",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profil in den Papierkorb legen; permanent=true löscht sofort endgültig (zusätzlich trash:manage)\n\nFeste Route-Scopes: profiles:delete. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/profiles/{id}. Tags: Papierkorb.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/profiles/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery permanent: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/profiles/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/profiles/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/batch/delete — Mehrere Profile in den Papierkorb legen; Ergebnis je Profil",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch/delete",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch",
                "delete"
              ],
              "query": [],
              "variable": []
            },
            "description": "Mehrere Profile in den Papierkorb legen; Ergebnis je Profil\n\nFeste Route-Scopes: profiles:delete. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/batch/delete. Tags: Papierkorb.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/batch/delete“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"permanent\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/batch/delete$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/batch/delete\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch/delete\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/trash — Profile im Papierkorb mit Löschzeitpunkt, Ablauf und Restzeit",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/trash",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "trash"
              ],
              "query": [
                {
                  "key": "limit",
                  "value": "10",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":1000}"
                },
                {
                  "key": "cursor",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":256}"
                },
                {
                  "key": "search",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}"
                },
                {
                  "key": "delete_source",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}"
                }
              ],
              "variable": []
            },
            "description": "Profile im Papierkorb mit Löschzeitpunkt, Ablauf und Restzeit\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/trash. Tags: Papierkorb.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/trash“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery limit: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":1000}\nquery cursor: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":256}\nquery search: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}\nquery delete_source: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/trash$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/trash\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/trash\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/trash/restore — Profile wiederherstellen (Ursprungsgruppe, Namenskonflikt mit Zusatz)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/trash/restore",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "trash",
                "restore"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profile wiederherstellen (Ursprungsgruppe, Namenskonflikt mit Zusatz)\n\nFeste Route-Scopes: trash:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/trash/restore. Tags: Papierkorb.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/trash/restore“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"profile_ids\"\n  ],\n  \"properties\": {\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"restore_proxies\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/trash/restore$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/trash/restore\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/trash/restore\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/trash/backup-coverage — Profilinhalt vorhandener Datenbanksicherungen und entschlüsselbarer Vollbackups im Zielordner prüfen; unprüfbare Dateien separat zählen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/trash/backup-coverage",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "trash",
                "backup-coverage"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profilinhalt vorhandener Datenbanksicherungen und entschlüsselbarer Vollbackups im Zielordner prüfen; unprüfbare Dateien separat zählen\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/trash/backup-coverage. Tags: Papierkorb.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/trash/backup-coverage“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"profile_ids\"\n  ],\n  \"properties\": {\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/trash/backup-coverage$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/trash/backup-coverage\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/trash/backup-coverage\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/trash/purge — Ausgewählte Profile endgültig löschen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/trash/purge",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "trash",
                "purge"
              ],
              "query": [],
              "variable": []
            },
            "description": "Ausgewählte Profile endgültig löschen\n\nFeste Route-Scopes: trash:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/trash/purge. Tags: Papierkorb.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/trash/purge“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"profile_ids\"\n  ],\n  \"properties\": {\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/trash/purge$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/trash/purge\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/trash/purge\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/trash/{id} — Endlöschung aussetzen oder fortsetzen",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/trash/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "trash",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Endlöschung aussetzen oder fortsetzen\n\nFeste Route-Scopes: trash:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/trash/{id}. Tags: Papierkorb.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/trash/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"purge_hold\"\n  ],\n  \"properties\": {\n    \"purge_hold\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"purge_hold\": false\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/trash/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/trash/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/trash/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/trash/{id} — Einen Eintrag endgültig löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/trash/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "trash",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Einen Eintrag endgültig löschen\n\nFeste Route-Scopes: trash:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/trash/{id}. Tags: Papierkorb.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/trash/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 204 No content.; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/trash/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/trash/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/trash/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/trash/empty — Papierkorb leeren; confirm_count muss der tatsächlichen Anzahl entsprechen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/trash/empty",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "trash",
                "empty"
              ],
              "query": [],
              "variable": []
            },
            "description": "Papierkorb leeren; confirm_count muss der tatsächlichen Anzahl entsprechen\n\nFeste Route-Scopes: trash:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/trash/empty. Tags: Papierkorb.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/trash/empty“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"confirm_count\"\n  ],\n  \"properties\": {\n    \"confirm_count\": {\n      \"type\": \"integer\",\n      \"minimum\": 0\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"confirm_count\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/trash/empty$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/trash/empty\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/trash/empty\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/trash/resume-purge — Nach Prüfung der Systemzeit die angehaltene Endlöschung fortsetzen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/trash/resume-purge",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "trash",
                "resume-purge"
              ],
              "query": [],
              "variable": []
            },
            "description": "Nach Prüfung der Systemzeit die angehaltene Endlöschung fortsetzen\n\nFeste Route-Scopes: trash:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/trash/resume-purge. Tags: Papierkorb.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/trash/resume-purge“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/trash/resume-purge$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/trash/resume-purge\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/trash/resume-purge\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/settings/trash — Einstellungen des Papierkorbs",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/trash",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "trash"
              ],
              "query": [],
              "variable": []
            },
            "description": "Einstellungen des Papierkorbs\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/settings/trash. Tags: Papierkorb.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/settings/trash$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/settings/trash\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/settings/trash\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/settings/trash — Aufbewahrungsfrist ändern (0–365 Tage); wirkt rückwirkend auf alle Einträge",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/trash",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "trash"
              ],
              "query": [],
              "variable": []
            },
            "description": "Aufbewahrungsfrist ändern (0–365 Tage); wirkt rückwirkend auf alle Einträge\n\nFeste Route-Scopes: settings:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/settings/trash. Tags: Papierkorb.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/settings/trash“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"retention_days\"\n  ],\n  \"properties\": {\n    \"retention_days\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 365\n    },\n    \"confirm_shorten\": {\n      \"type\": \"boolean\"\n    },\n    \"confirm_immediate\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"retention_days\": 30\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/settings/trash$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/settings/trash\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/settings/trash\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Konten",
      "item": [
        {
          "name": "GET /api/v1/profiles/{id}/accounts — Plattformkonten eines Profils (Passwörter maskiert)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/accounts",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "accounts"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Plattformkonten eines Profils (Passwörter maskiert)\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/accounts. Tags: Konten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/accounts“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/accounts$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/accounts\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/accounts\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/accounts — Plattformkonto anlegen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/accounts",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "accounts"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Plattformkonto anlegen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/accounts. Tags: Konten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/accounts“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"platform_url\"\n  ],\n  \"properties\": {\n    \"platform_url\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 256\n    },\n    \"username\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 256\n    },\n    \"password\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"totp_secret\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"notes\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"sort_order\": {\n      \"type\": \"integer\",\n      \"minimum\": 0\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"platform_url\": \"https://example.com/\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/accounts$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/accounts\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/accounts\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/profiles/{id}/accounts/{accountId} — Plattformkonto ändern; password/totp_secret null entfernt den Wert",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/accounts/:accountId",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "accounts",
                ":accountId"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Plattformkonto ändern; password/totp_secret null entfernt den Wert\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/profiles/{id}/accounts/{accountId}. Tags: Konten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/profiles/{id}/accounts/{accountId}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"platform_url\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 256\n    },\n    \"username\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 256\n    },\n    \"password\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"totp_secret\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"notes\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"sort_order\": {\n      \"type\": \"integer\",\n      \"minimum\": 0\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/accounts/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/profiles/{id}/accounts/{accountId}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/accounts/{accountId}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/profiles/{id}/accounts/{accountId} — Plattformkonto löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/accounts/:accountId",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "accounts",
                ":accountId"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Plattformkonto löschen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/profiles/{id}/accounts/{accountId}. Tags: Konten.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/profiles/{id}/accounts/{accountId}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 204 No content.; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/accounts/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/profiles/{id}/accounts/{accountId}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/accounts/{accountId}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/accounts/{accountId}/password — Passwort im Klartext abrufen (wird protokolliert)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/accounts/:accountId/password",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "accounts",
                ":accountId",
                "password"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Passwort im Klartext abrufen (wird protokolliert)\n\nFeste Route-Scopes: secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/accounts/{accountId}/password. Tags: Konten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/accounts/{accountId}/password“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/accounts/[^/?#]+/password$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/accounts/{accountId}/password\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/accounts/{accountId}/password\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/accounts/{accountId}/totp — Aktuellen 2FA-Code erzeugen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/accounts/:accountId/totp",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "accounts",
                ":accountId",
                "totp"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Aktuellen 2FA-Code erzeugen\n\nFeste Route-Scopes: secrets:totp. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/accounts/{accountId}/totp. Tags: Konten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/accounts/{accountId}/totp“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/accounts/[^/?#]+/totp$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/accounts/{accountId}/totp\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/accounts/{accountId}/totp\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Gruppen",
      "item": [
        {
          "name": "GET /api/v1/groups — Gruppen mit Profilanzahl",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Gruppen mit Profilanzahl\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/groups. Tags: Gruppen.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/groups — Gruppe anlegen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Gruppe anlegen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/groups. Tags: Gruppen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\"\n  ],\n  \"properties\": {\n    \"accounts_enabled\": {\n      \"type\": \"boolean\"\n    },\n    \"browser_defaults\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"browser_options\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"block_images\": {\n              \"type\": \"boolean\"\n            },\n            \"block_video\": {\n              \"type\": \"boolean\"\n            },\n            \"block_audio\": {\n              \"type\": \"boolean\"\n            },\n            \"block_notifications\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_view\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_save\": {\n              \"type\": \"boolean\"\n            },\n            \"block_extension_pages\": {\n              \"type\": \"boolean\"\n            },\n            \"block_translation\": {\n              \"type\": \"boolean\"\n            },\n            \"block_devtools\": {\n              \"type\": \"boolean\"\n            },\n            \"local_network\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"blocked\",\n                \"allowed_ports\"\n              ],\n              \"properties\": {\n                \"blocked\": {\n                  \"type\": \"boolean\"\n                },\n                \"allowed_ports\": {\n                  \"type\": \"string\",\n                  \"maxLength\": 1536\n                }\n              },\n              \"additionalProperties\": false\n            },\n            \"taskbar_icon\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 50,\n                  \"maxLength\": 393216\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"ui_language\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 2,\n                  \"maxLength\": 35\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"tls_cipher_blocklist\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 256\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"secure_dns\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"off\"\n                      ]\n                    }\n                  },\n                  \"additionalProperties\": false\n                },\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\",\n                    \"server\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"secure\"\n                      ]\n                    },\n                    \"server\": {\n                      \"type\": \"string\",\n                      \"minLength\": 9,\n                      \"maxLength\": 2048\n                    }\n                  },\n                  \"additionalProperties\": false\n                }\n              ]\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"startup\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"mode\",\n            \"urls\"\n          ],\n          \"properties\": {\n            \"mode\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"new_tab\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"last_tabs\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"urls\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"last_and_urls\"\n                  ]\n                }\n              ]\n            },\n            \"urls\": {\n              \"type\": \"array\",\n              \"items\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 2048\n              },\n              \"maxItems\": 20\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"launch_args\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"chromium\": {\n              \"type\": \"array\",\n              \"items\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 2048\n              },\n              \"maxItems\": 100\n            },\n            \"firefox\": {\n              \"type\": \"array\",\n              \"items\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 2048\n              },\n              \"maxItems\": 100\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"extension_sets\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"chromium\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 100\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"firefox\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 100\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"bookmarks\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"title\",\n              \"url\",\n              \"folder\"\n            ],\n            \"properties\": {\n              \"title\": {\n                \"type\": \"string\",\n                \"maxLength\": 512\n              },\n              \"url\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 2048\n              },\n              \"folder\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"maxLength\": 256\n                  },\n                  {\n                    \"type\": \"null\"\n                  }\n                ]\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"maxItems\": 1000\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"remark\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1000\n    },\n    \"color\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"sort_order\": {\n      \"type\": \"integer\"\n    },\n    \"pinned\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/groups/order — Reihenfolge aller Gruppen speichern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/order",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                "order"
              ],
              "query": [],
              "variable": []
            },
            "description": "Reihenfolge aller Gruppen speichern\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/groups/order. Tags: Gruppen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/groups/order“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 20000,\n      \"uniqueItems\": true\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/groups/order$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/groups/order\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/order\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/groups/{id} — Gruppe abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gruppe abrufen\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/groups/{id}. Tags: Gruppen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/groups/{id} — Gruppe ändern",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gruppe ändern\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/groups/{id}. Tags: Gruppen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"accounts_enabled\": {\n      \"type\": \"boolean\"\n    },\n    \"browser_defaults\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"browser_options\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"block_images\": {\n              \"type\": \"boolean\"\n            },\n            \"block_video\": {\n              \"type\": \"boolean\"\n            },\n            \"block_audio\": {\n              \"type\": \"boolean\"\n            },\n            \"block_notifications\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_view\": {\n              \"type\": \"boolean\"\n            },\n            \"block_password_save\": {\n              \"type\": \"boolean\"\n            },\n            \"block_extension_pages\": {\n              \"type\": \"boolean\"\n            },\n            \"block_translation\": {\n              \"type\": \"boolean\"\n            },\n            \"block_devtools\": {\n              \"type\": \"boolean\"\n            },\n            \"local_network\": {\n              \"type\": \"object\",\n              \"required\": [\n                \"blocked\",\n                \"allowed_ports\"\n              ],\n              \"properties\": {\n                \"blocked\": {\n                  \"type\": \"boolean\"\n                },\n                \"allowed_ports\": {\n                  \"type\": \"string\",\n                  \"maxLength\": 1536\n                }\n              },\n              \"additionalProperties\": false\n            },\n            \"taskbar_icon\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 50,\n                  \"maxLength\": 393216\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"ui_language\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 2,\n                  \"maxLength\": 35\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"tls_cipher_blocklist\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 256\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"secure_dns\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"off\"\n                      ]\n                    }\n                  },\n                  \"additionalProperties\": false\n                },\n                {\n                  \"type\": \"object\",\n                  \"required\": [\n                    \"mode\",\n                    \"server\"\n                  ],\n                  \"properties\": {\n                    \"mode\": {\n                      \"type\": \"string\",\n                      \"enum\": [\n                        \"secure\"\n                      ]\n                    },\n                    \"server\": {\n                      \"type\": \"string\",\n                      \"minLength\": 9,\n                      \"maxLength\": 2048\n                    }\n                  },\n                  \"additionalProperties\": false\n                }\n              ]\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"startup\": {\n          \"type\": \"object\",\n          \"required\": [\n            \"mode\",\n            \"urls\"\n          ],\n          \"properties\": {\n            \"mode\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"new_tab\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"last_tabs\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"urls\"\n                  ]\n                },\n                {\n                  \"type\": \"string\",\n                  \"enum\": [\n                    \"last_and_urls\"\n                  ]\n                }\n              ]\n            },\n            \"urls\": {\n              \"type\": \"array\",\n              \"items\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 2048\n              },\n              \"maxItems\": 20\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"launch_args\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"chromium\": {\n              \"type\": \"array\",\n              \"items\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 2048\n              },\n              \"maxItems\": 100\n            },\n            \"firefox\": {\n              \"type\": \"array\",\n              \"items\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 2048\n              },\n              \"maxItems\": 100\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"extension_sets\": {\n          \"type\": \"object\",\n          \"properties\": {\n            \"chromium\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 100\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            },\n            \"firefox\": {\n              \"anyOf\": [\n                {\n                  \"type\": \"string\",\n                  \"minLength\": 1,\n                  \"maxLength\": 100\n                },\n                {\n                  \"type\": \"null\"\n                }\n              ]\n            }\n          },\n          \"additionalProperties\": false\n        },\n        \"bookmarks\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"title\",\n              \"url\",\n              \"folder\"\n            ],\n            \"properties\": {\n              \"title\": {\n                \"type\": \"string\",\n                \"maxLength\": 512\n              },\n              \"url\": {\n                \"type\": \"string\",\n                \"minLength\": 1,\n                \"maxLength\": 2048\n              },\n              \"folder\": {\n                \"anyOf\": [\n                  {\n                    \"type\": \"string\",\n                    \"maxLength\": 256\n                  },\n                  {\n                    \"type\": \"null\"\n                  }\n                ]\n              }\n            },\n            \"additionalProperties\": false\n          },\n          \"maxItems\": 1000\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"remark\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1000\n    },\n    \"color\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"sort_order\": {\n      \"type\": \"integer\"\n    },\n    \"pinned\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/groups/{id} — Gruppe löschen; Profile werden verschoben oder in den Papierkorb gelegt, nie endgültig gelöscht",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id"
              ],
              "query": [
                {
                  "key": "mode",
                  "value": "move_to_default",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"move_to_default\"]},{\"type\":\"string\",\"enum\":[\"move_to_group\"]},{\"type\":\"string\",\"enum\":[\"trash_profiles\"]}]}"
                },
                {
                  "key": "target_group_id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gruppe löschen; Profile werden verschoben oder in den Papierkorb gelegt, nie endgültig gelöscht\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/groups/{id}. Tags: Gruppen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery mode: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"move_to_default\"]},{\"type\":\"string\",\"enum\":[\"move_to_group\"]},{\"type\":\"string\",\"enum\":[\"trash_profiles\"]}]}\nquery target_group_id: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Tags",
      "item": [
        {
          "name": "GET /api/v1/tags — Tags mit Profilanzahl",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/tags",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "tags"
              ],
              "query": [],
              "variable": []
            },
            "description": "Tags mit Profilanzahl\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/tags. Tags: Tags.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/tags$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/tags\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/tags\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/tags — Tag anlegen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/tags",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "tags"
              ],
              "query": [],
              "variable": []
            },
            "description": "Tag anlegen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/tags. Tags: Tags.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/tags“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 50\n    },\n    \"color\": {\n      \"anyOf\": [\n        {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"darkBlue\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"blue\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"purple\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"red\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"yellow\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"orange\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"green\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"lightGreen\"\n              ]\n            }\n          ]\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/tags$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/tags\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/tags\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/tags/{id} — Tag ändern",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/tags/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "tags",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Tag ändern\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/tags/{id}. Tags: Tags.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/tags/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 50\n    },\n    \"color\": {\n      \"anyOf\": [\n        {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"darkBlue\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"blue\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"purple\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"red\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"yellow\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"orange\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"green\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"lightGreen\"\n              ]\n            }\n          ]\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/tags/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/tags/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/tags/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/tags/{id} — Tag löschen; Zuordnungen werden entfernt",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/tags/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "tags",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Tag löschen; Zuordnungen werden entfernt\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/tags/{id}. Tags: Tags.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/tags/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 204 No content.; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/tags/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/tags/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/tags/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Status",
      "item": [
        {
          "name": "GET /api/v1/statuses — Frei definierbare Status",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/statuses",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "statuses"
              ],
              "query": [],
              "variable": []
            },
            "description": "Frei definierbare Status\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/statuses. Tags: Status.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/statuses$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/statuses\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/statuses\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/statuses — Status anlegen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/statuses",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "statuses"
              ],
              "query": [],
              "variable": []
            },
            "description": "Status anlegen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/statuses. Tags: Status.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/statuses“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"color\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 50\n    },\n    \"color\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 32\n    },\n    \"sort_order\": {\n      \"type\": \"integer\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"color\": \"blue\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/statuses$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/statuses\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/statuses\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/statuses/{id} — Status ändern",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/statuses/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "statuses",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Status ändern\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/statuses/{id}. Tags: Status.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/statuses/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 50\n    },\n    \"color\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 32\n    },\n    \"sort_order\": {\n      \"type\": \"integer\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/statuses/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/statuses/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/statuses/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/statuses/{id} — Status löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/statuses/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "statuses",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Status löschen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/statuses/{id}. Tags: Status.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/statuses/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 204 No content.; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/statuses/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/statuses/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/statuses/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Gruppenkonten",
      "item": [
        {
          "name": "GET /api/v1/groups/{id}/accounts — Gemeinsame Konten einer Gruppe ohne Geheimnisse",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/accounts",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "accounts"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gemeinsame Konten einer Gruppe ohne Geheimnisse\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/groups/{id}/accounts. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/groups/{id}/accounts“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/groups/[^/?#]+/accounts$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/groups/{id}/accounts\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/accounts\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/groups/{id}/accounts — Gemeinsames Gruppenkonto anlegen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/accounts",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "accounts"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gemeinsames Gruppenkonto anlegen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/groups/{id}/accounts. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/groups/{id}/accounts“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"platform_url\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"platform_url\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 2048\n    },\n    \"username\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 256\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    },\n    \"password\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 1024\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    },\n    \"totp_secret\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 1024\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    },\n    \"notes\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 1024\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"platform_url\": \"https://example.com/\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/groups/[^/?#]+/accounts$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/groups/{id}/accounts\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/accounts\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/groups/{id}/accounts/{accountId} — Gemeinsames Gruppenkonto ändern",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/accounts/:accountId",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "accounts",
                ":accountId"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Gemeinsames Gruppenkonto ändern\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/groups/{id}/accounts/{accountId}. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/groups/{id}/accounts/{accountId}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"platform_url\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 2048\n    },\n    \"username\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 256\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    },\n    \"password\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 1024\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    },\n    \"totp_secret\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 1024\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    },\n    \"notes\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 1024\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    }\n  }\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/groups/[^/?#]+/accounts/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/groups/{id}/accounts/{accountId}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/accounts/{accountId}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/groups/{id}/accounts/{accountId} — Gemeinsames Gruppenkonto und seine Geheimnisse entfernen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/accounts/:accountId",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "accounts",
                ":accountId"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Gemeinsames Gruppenkonto und seine Geheimnisse entfernen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/groups/{id}/accounts/{accountId}. Tags: Gruppenkonten.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/groups/{id}/accounts/{accountId}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 204 No content.; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/groups/[^/?#]+/accounts/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/groups/{id}/accounts/{accountId}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/accounts/{accountId}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/groups/{id}/accounts/{accountId}/password — Gruppenkonto-Passwort protokolliert abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/accounts/:accountId/password",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "accounts",
                ":accountId",
                "password"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Gruppenkonto-Passwort protokolliert abrufen\n\nFeste Route-Scopes: secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/groups/{id}/accounts/{accountId}/password. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/groups/{id}/accounts/{accountId}/password“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/groups/[^/?#]+/accounts/[^/?#]+/password$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/groups/{id}/accounts/{accountId}/password\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/accounts/{accountId}/password\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/groups/{id}/accounts/{accountId}/totp — 2FA-Code eines Gruppenkontos abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/accounts/:accountId/totp",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "accounts",
                ":accountId",
                "totp"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "2FA-Code eines Gruppenkontos abrufen\n\nFeste Route-Scopes: secrets:totp. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/groups/{id}/accounts/{accountId}/totp. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/groups/{id}/accounts/{accountId}/totp“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/groups/[^/?#]+/accounts/[^/?#]+/totp$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/groups/{id}/accounts/{accountId}/totp\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/accounts/{accountId}/totp\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/groups/{id}/accounts/import — Gruppenkonten importieren; bestehende Namen mit identischer Adresse und Benutzer bleiben erhalten",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/accounts/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "accounts",
                "import"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gruppenkonten importieren; bestehende Namen mit identischer Adresse und Benutzer bleiben erhalten\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/groups/{id}/accounts/import. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/groups/{id}/accounts/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"items\"\n  ],\n  \"properties\": {\n    \"items\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"name\",\n          \"platform_url\"\n        ],\n        \"properties\": {\n          \"name\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 100\n          },\n          \"platform_url\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 2048\n          },\n          \"username\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"maxLength\": 256\n              },\n              {\n                \"type\": \"null\"\n              }\n            ]\n          },\n          \"password\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"maxLength\": 1024\n              },\n              {\n                \"type\": \"null\"\n              }\n            ]\n          },\n          \"totp_secret\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"maxLength\": 1024\n              },\n              {\n                \"type\": \"null\"\n              }\n            ]\n          },\n          \"notes\": {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"maxLength\": 1024\n              },\n              {\n                \"type\": \"null\"\n              }\n            ]\n          }\n        },\n        \"additionalProperties\": false\n      },\n      \"maxItems\": 500\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"items\": [\n    {\n      \"name\": \"Beispielprofil\",\n      \"platform_url\": \"https://example.com/\"\n    }\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/groups/[^/?#]+/accounts/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/groups/{id}/accounts/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/accounts/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/groups/{id}/accounts/export — Gruppenkonten einschließlich Passwörtern und TOTP-Schlüsseln exportieren",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/accounts/export",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "accounts",
                "export"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gruppenkonten einschließlich Passwörtern und TOTP-Schlüsseln exportieren\n\nFeste Route-Scopes: profiles:read, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/groups/{id}/accounts/export. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/groups/{id}/accounts/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/groups/[^/?#]+/accounts/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/groups/{id}/accounts/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/accounts/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/group-accounts — Für ein Profil freigegebene Gruppenkonten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/group-accounts",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "group-accounts"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Für ein Profil freigegebene Gruppenkonten\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/group-accounts. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/group-accounts“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/group-accounts$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/group-accounts\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/group-accounts\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/group-accounts/{accountId}/password — Passwort eines aktuell freigegebenen Gruppenkontos abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/group-accounts/:accountId/password",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "group-accounts",
                ":accountId",
                "password"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Passwort eines aktuell freigegebenen Gruppenkontos abrufen\n\nFeste Route-Scopes: secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/group-accounts/{accountId}/password. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/group-accounts/{accountId}/password“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/group-accounts/[^/?#]+/password$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/group-accounts/{accountId}/password\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/group-accounts/{accountId}/password\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/group-accounts/{accountId}/totp — 2FA-Code eines aktuell freigegebenen Gruppenkontos abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/group-accounts/:accountId/totp",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "group-accounts",
                ":accountId",
                "totp"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "accountId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "2FA-Code eines aktuell freigegebenen Gruppenkontos abrufen\n\nFeste Route-Scopes: secrets:totp. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/group-accounts/{accountId}/totp. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/group-accounts/{accountId}/totp“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath accountId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/group-accounts/[^/?#]+/totp$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/group-accounts/{accountId}/totp\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/group-accounts/{accountId}/totp\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/browser-accounts/tabs — Geöffnete HTTP-/HTTPS-Tabs für Gruppenkonten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/browser-accounts/tabs",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "browser-accounts",
                "tabs"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Geöffnete HTTP-/HTTPS-Tabs für Gruppenkonten\n\nFeste Route-Scopes: profiles:read, runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/browser-accounts/tabs. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/browser-accounts/tabs“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/browser-accounts/tabs$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/browser-accounts/tabs\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/browser-accounts/tabs\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/browser-accounts/tabs/{target}/frames — HTTP-/HTTPS-Dokumente des ausgewählten Tabs",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/browser-accounts/tabs/:target/frames",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "browser-accounts",
                "tabs",
                ":target",
                "frames"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "target",
                  "value": "Beispiel",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":200}"
                }
              ]
            },
            "description": "HTTP-/HTTPS-Dokumente des ausgewählten Tabs\n\nFeste Route-Scopes: profiles:read, runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/browser-accounts/tabs/{target}/frames. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/browser-accounts/tabs/{target}/frames“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath target: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":200}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/browser-accounts/tabs/[^/?#]+/frames$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/browser-accounts/tabs/{target}/frames\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/browser-accounts/tabs/{target}/frames\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/browser-accounts/inspect — Anmeldefelder ohne Werte erfassen; Auswahl zwei Minuten gültig",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/browser-accounts/inspect",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "browser-accounts",
                "inspect"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Anmeldefelder ohne Werte erfassen; Auswahl zwei Minuten gültig\n\nFeste Route-Scopes: profiles:read, runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/browser-accounts/inspect. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/browser-accounts/inspect“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"target_id\",\n    \"origin\"\n  ],\n  \"properties\": {\n    \"target_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 200\n    },\n    \"origin\": {\n      \"type\": \"string\",\n      \"maxLength\": 2048\n    },\n    \"frame_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 200\n    },\n    \"top_origin\": {\n      \"type\": \"string\",\n      \"maxLength\": 2048\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"target_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"origin\": \"https://example.com/\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/browser-accounts/inspect$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/browser-accounts/inspect\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/browser-accounts/inspect\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/profiles/{id}/browser-accounts/{ticket} — Temporäre Feldauswahl schließen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/browser-accounts/:ticket",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "browser-accounts",
                ":ticket"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "ticket",
                  "value": "NUR-FIKTIVES-BEISPIEL",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Temporäre Feldauswahl schließen\n\nFeste Route-Scopes: profiles:read, runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/profiles/{id}/browser-accounts/{ticket}. Tags: Gruppenkonten.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/profiles/{id}/browser-accounts/{ticket}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 204 No content.; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath ticket: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/browser-accounts/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/profiles/{id}/browser-accounts/{ticket}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/browser-accounts/{ticket}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/browser-accounts/fill — Ausgewählte Anmeldefelder mit einem passenden Gruppenkonto ausfüllen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/browser-accounts/fill",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "browser-accounts",
                "fill"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Ausgewählte Anmeldefelder mit einem passenden Gruppenkonto ausfüllen\n\nFeste Route-Scopes: profiles:read, runtime:control, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/browser-accounts/fill. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/browser-accounts/fill“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ticket\",\n    \"username_field\",\n    \"password_field\",\n    \"account_id\"\n  ],\n  \"properties\": {\n    \"ticket\": {\n      \"type\": \"string\",\n      \"format\": \"uuid\"\n    },\n    \"username_field\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 10\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    },\n    \"password_field\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 10\n    },\n    \"account_id\": {\n      \"type\": \"string\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ticket\": \"00000000-0000-4000-8000-000000000001\",\n  \"username_field\": \"Beispielpr\",\n  \"password_field\": \"NUR-FIKTIV\",\n  \"account_id\": \"00000000-0000-4000-8000-000000000001\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/browser-accounts/fill$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/browser-accounts/fill\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/browser-accounts/fill\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/browser-accounts/capture — Ausgewählte Anmeldefelder ausdrücklich im Gruppentresor speichern",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/browser-accounts/capture",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "browser-accounts",
                "capture"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Ausgewählte Anmeldefelder ausdrücklich im Gruppentresor speichern\n\nFeste Route-Scopes: profiles:read, profiles:write, runtime:control, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/browser-accounts/capture. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/browser-accounts/capture“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ticket\",\n    \"username_field\",\n    \"password_field\",\n    \"name\"\n  ],\n  \"properties\": {\n    \"ticket\": {\n      \"type\": \"string\",\n      \"format\": \"uuid\"\n    },\n    \"username_field\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"maxLength\": 10\n        },\n        {\n          \"type\": \"null\"\n        }\n      ]\n    },\n    \"password_field\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 10\n    },\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"account_id\": {\n      \"type\": \"string\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ticket\": \"00000000-0000-4000-8000-000000000001\",\n  \"username_field\": \"Beispielpr\",\n  \"password_field\": \"NUR-FIKTIV\",\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/browser-accounts/capture$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/browser-accounts/capture\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/browser-accounts/capture\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/groups/{id}/browser-vault — Lokale Freigabe der Browser-Tresorerweiterung",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/browser-vault",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "browser-vault"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Lokale Freigabe der Browser-Tresorerweiterung\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/groups/{id}/browser-vault. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/groups/{id}/browser-vault“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/groups/[^/?#]+/browser-vault$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/groups/{id}/browser-vault\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/browser-vault\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/groups/{id}/browser-vault — Browser-Tresorerweiterung für diese Gruppe auf diesem Gerät freigeben",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/groups/:id/browser-vault",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "groups",
                ":id",
                "browser-vault"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Browser-Tresorerweiterung für diese Gruppe auf diesem Gerät freigeben\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/groups/{id}/browser-vault. Tags: Gruppenkonten.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/groups/{id}/browser-vault“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"enabled\"\n  ],\n  \"properties\": {\n    \"enabled\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"enabled\": false\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/groups/[^/?#]+/browser-vault$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/groups/{id}/browser-vault\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/groups/{id}/browser-vault\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Proxys",
      "item": [
        {
          "name": "GET /api/v1/proxy-groups — Proxygruppen einschließlich Default auflisten",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxy-groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxy-groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxygruppen einschließlich Default auflisten\n\nFeste Route-Scopes: proxies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/proxy-groups. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/proxy-groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/proxy-groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/proxy-groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxy-groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxy-groups — Proxygruppe anlegen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxy-groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxy-groups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxygruppe anlegen\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxy-groups. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxy-groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxy-groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxy-groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxy-groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/proxy-groups/{id} — Proxygruppe umbenennen",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxy-groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxy-groups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Proxygruppe umbenennen\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/proxy-groups/{id}. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/proxy-groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/proxy-groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/proxy-groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxy-groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/proxy-groups/{id} — Proxygruppe löschen und enthaltene Proxys nach Default verschieben",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxy-groups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxy-groups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Proxygruppe löschen und enthaltene Proxys nach Default verschieben\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/proxy-groups/{id}. Tags: Proxys.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/proxy-groups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/proxy-groups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/proxy-groups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxy-groups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/batch/group — Ausgewählte Proxys einer Gruppe zuordnen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/batch/group",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "batch",
                "group"
              ],
              "query": [],
              "variable": []
            },
            "description": "Ausgewählte Proxys einer Gruppe zuordnen\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/batch/group. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/batch/group“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"group_id\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"group_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"minLength\": 1,\n      \"maxLength\": 64\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"group_id\": \"00000000-0000-4000-8000-000000000001\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/batch/group$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/batch/group\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/batch/group\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/sticky — Proxys aus einer Benutzervorlage mit je einer eigenen dauerhaft gespeicherten Session erstellen; Platzhalter {session}, {country}, {index}",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/sticky",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "sticky"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxys aus einer Benutzervorlage mit je einer eigenen dauerhaft gespeicherten Session erstellen; Platzhalter {session}, {country}, {index}\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/sticky. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/sticky“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"proxy\",\n    \"username_template\",\n    \"count\"\n  ],\n  \"properties\": {\n    \"proxy\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"protocol\",\n        \"host\",\n        \"port\"\n      ],\n      \"properties\": {\n        \"group_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"minLength\": 1,\n          \"maxLength\": 64\n        },\n        \"ssh_private_key\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 65536\n        },\n        \"ssh_key_passphrase\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 1024\n        },\n        \"name\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 100\n        },\n        \"protocol\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"http\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"https\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks4\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks4a\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks5\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"socks5h\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"ssh\"\n              ]\n            }\n          ]\n        },\n        \"host\": {\n          \"type\": \"string\",\n          \"minLength\": 1,\n          \"maxLength\": 255\n        },\n        \"port\": {\n          \"type\": \"integer\",\n          \"minimum\": 1,\n          \"maximum\": 65535\n        },\n        \"username\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 512\n        },\n        \"password\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 1024\n        },\n        \"change_ip_url\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 2048\n        },\n        \"change_ip_cooldown_s\": {\n          \"type\": [\n            \"integer\",\n            \"null\"\n          ],\n          \"minimum\": 0,\n          \"maximum\": 86400\n        },\n        \"provider\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"provider_params\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"string\"\n          }\n        },\n        \"ip_checker\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 32\n        },\n        \"remark\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ],\n          \"maxLength\": 1000\n        },\n        \"tags\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 50\n          },\n          \"maxItems\": 30\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"username_template\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 512\n    },\n    \"count\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 500\n    },\n    \"country\": {\n      \"type\": \"string\",\n      \"maxLength\": 2\n    },\n    \"session_prefix\": {\n      \"type\": \"string\",\n      \"maxLength\": 24\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"proxy\": {\n    \"protocol\": \"http\",\n    \"host\": \"proxy.example.invalid\",\n    \"port\": 8080\n  },\n  \"username_template\": \"beispiel-session-{session}\",\n  \"count\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/sticky$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/sticky\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/sticky\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/proxies — Proxys auflisten (Passwörter maskiert)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies"
              ],
              "query": [
                {
                  "key": "group_id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                },
                {
                  "key": "check_status",
                  "value": "unverified",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"unverified\"]},{\"type\":\"string\",\"enum\":[\"passed\"]},{\"type\":\"string\",\"enum\":[\"failed\"]}]}"
                },
                {
                  "key": "sort",
                  "value": "dsn",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"dsn\"]},{\"type\":\"string\",\"enum\":[\"name\"]},{\"type\":\"string\",\"enum\":[\"created_at\"]},{\"type\":\"string\",\"enum\":[\"last_check_at\"]},{\"type\":\"string\",\"enum\":[\"profile_count\"]}]}"
                },
                {
                  "key": "order",
                  "value": "asc",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"asc\"]},{\"type\":\"string\",\"enum\":[\"desc\"]}]}"
                },
                {
                  "key": "search",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}"
                },
                {
                  "key": "protocol",
                  "value": "http",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"http\"]},{\"type\":\"string\",\"enum\":[\"https\"]},{\"type\":\"string\",\"enum\":[\"socks4\"]},{\"type\":\"string\",\"enum\":[\"socks4a\"]},{\"type\":\"string\",\"enum\":[\"socks5\"]},{\"type\":\"string\",\"enum\":[\"socks5h\"]},{\"type\":\"string\",\"enum\":[\"ssh\"]}]}"
                },
                {
                  "key": "tag",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":50}"
                },
                {
                  "key": "unused",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}"
                },
                {
                  "key": "trash",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}"
                },
                {
                  "key": "page",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}"
                },
                {
                  "key": "limit",
                  "value": "10",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":1000}"
                }
              ],
              "variable": []
            },
            "description": "Proxys auflisten (Passwörter maskiert)\n\nFeste Route-Scopes: proxies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/proxies. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/proxies“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery group_id: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\nquery check_status: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"unverified\"]},{\"type\":\"string\",\"enum\":[\"passed\"]},{\"type\":\"string\",\"enum\":[\"failed\"]}]}\nquery sort: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"dsn\"]},{\"type\":\"string\",\"enum\":[\"name\"]},{\"type\":\"string\",\"enum\":[\"created_at\"]},{\"type\":\"string\",\"enum\":[\"last_check_at\"]},{\"type\":\"string\",\"enum\":[\"profile_count\"]}]}\nquery order: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"asc\"]},{\"type\":\"string\",\"enum\":[\"desc\"]}]}\nquery search: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}\nquery protocol: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"http\"]},{\"type\":\"string\",\"enum\":[\"https\"]},{\"type\":\"string\",\"enum\":[\"socks4\"]},{\"type\":\"string\",\"enum\":[\"socks4a\"]},{\"type\":\"string\",\"enum\":[\"socks5\"]},{\"type\":\"string\",\"enum\":[\"socks5h\"]},{\"type\":\"string\",\"enum\":[\"ssh\"]}]}\nquery tag: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":50}\nquery unused: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}\nquery trash: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}\nquery page: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}\nquery limit: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":1000}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/proxies$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/proxies\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies — Proxy anlegen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxy anlegen\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 201 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"protocol\",\n    \"host\",\n    \"port\"\n  ],\n  \"properties\": {\n    \"group_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"ssh_private_key\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 65536\n    },\n    \"ssh_key_passphrase\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"name\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 100\n    },\n    \"protocol\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"http\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"https\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4a\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5h\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"ssh\"\n          ]\n        }\n      ]\n    },\n    \"host\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 255\n    },\n    \"port\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 65535\n    },\n    \"username\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"password\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"change_ip_url\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 2048\n    },\n    \"change_ip_cooldown_s\": {\n      \"type\": [\n        \"integer\",\n        \"null\"\n      ],\n      \"minimum\": 0,\n      \"maximum\": 86400\n    },\n    \"provider\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"provider_params\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"type\": \"string\"\n      }\n    },\n    \"ip_checker\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"remark\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1000\n    },\n    \"tags\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 50\n      },\n      \"maxItems\": 30\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"protocol\": \"http\",\n  \"host\": \"proxy.example.invalid\",\n  \"port\": 8080\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/parse — Proxy-Zeilen erkennen und als Vorschau zurückgeben (ohne Speichern, ohne Passwörter)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/parse",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "parse"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxy-Zeilen erkennen und als Vorschau zurückgeben (ohne Speichern, ohne Passwörter)\n\nFeste Route-Scopes: proxies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/parse. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/parse“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"text\"\n  ],\n  \"properties\": {\n    \"text\": {\n      \"type\": \"string\",\n      \"maxLength\": 5000000\n    },\n    \"default_protocol\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"http\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"https\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4a\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5h\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"ssh\"\n          ]\n        }\n      ]\n    },\n    \"columns\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"maxLength\": 40\n      },\n      \"maxItems\": 20\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"text\": \"http://proxy.example.invalid:8080\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/parse$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/parse\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/parse\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/import — Proxy-Zeilen importieren; Ergebnis je Zeile, nichts wird still verworfen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "import"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxy-Zeilen importieren; Ergebnis je Zeile, nichts wird still verworfen\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/import. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"text\"\n  ],\n  \"properties\": {\n    \"text\": {\n      \"type\": \"string\",\n      \"maxLength\": 5000000\n    },\n    \"default_protocol\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"http\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"https\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4a\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5h\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"ssh\"\n          ]\n        }\n      ]\n    },\n    \"columns\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"maxLength\": 40\n      },\n      \"maxItems\": 20\n    },\n    \"tags\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 50\n      },\n      \"maxItems\": 30\n    },\n    \"group_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"ip_checker\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"skip_duplicates\": {\n      \"type\": \"boolean\"\n    },\n    \"accept_ambiguous\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"text\": \"http://proxy.example.invalid:8080\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/batch/delete — Proxys in den Papierkorb legen; zugeordnete Profile behalten die Zuordnung oder erhalten einen Ersatz",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/batch/delete",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "batch",
                "delete"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxys in den Papierkorb legen; zugeordnete Profile behalten die Zuordnung oder erhalten einen Ersatz\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/batch/delete. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/batch/delete“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"reassign_to\": {\n      \"type\": \"string\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/batch/delete$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/batch/delete\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/batch/delete\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/restore — Proxys aus dem Papierkorb wiederherstellen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/restore",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "restore"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxys aus dem Papierkorb wiederherstellen\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/restore. Tags: Proxys.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/restore“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/restore$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/restore\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/restore\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/purge — Proxys aus dem Papierkorb sofort endgültig löschen (nur ohne zugeordnete Profile, auch keine im Papierkorb)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/purge",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "purge"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxys aus dem Papierkorb sofort endgültig löschen (nur ohne zugeordnete Profile, auch keine im Papierkorb)\n\nFeste Route-Scopes: trash:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/purge. Tags: Proxys.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/purge“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/purge$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/purge\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/purge\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/proxies/{id} — Proxy abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Proxy abrufen\n\nFeste Route-Scopes: proxies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/proxies/{id}. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/proxies/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/proxies/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/proxies/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/proxies/{id} — Proxy ändern; password null entfernt das Passwort",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Proxy ändern; password null entfernt das Passwort\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/proxies/{id}. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/proxies/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"group_id\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"ssh_private_key\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 65536\n    },\n    \"ssh_key_passphrase\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"name\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 100\n    },\n    \"protocol\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"http\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"https\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4a\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5h\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"ssh\"\n          ]\n        }\n      ]\n    },\n    \"host\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 255\n    },\n    \"port\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 65535\n    },\n    \"username\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"password\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"change_ip_url\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 2048\n    },\n    \"change_ip_cooldown_s\": {\n      \"type\": [\n        \"integer\",\n        \"null\"\n      ],\n      \"minimum\": 0,\n      \"maximum\": 86400\n    },\n    \"provider\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"provider_params\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"type\": \"string\"\n      }\n    },\n    \"ip_checker\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"remark\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1000\n    },\n    \"tags\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 50\n      },\n      \"maxItems\": 30\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/proxies/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/proxies/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/proxies/{id} — Proxy in den Papierkorb legen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                ":id"
              ],
              "query": [
                {
                  "key": "reassign_to",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Proxy in den Papierkorb legen\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/proxies/{id}. Tags: Proxys.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/proxies/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery reassign_to: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\"}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/proxies/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/proxies/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/{id}/change-ip — Change-IP-URL aufrufen; verify=true misst die Ausgangs-IP davor und danach. changed bestätigt den URL-Aufruf, ip_changed den gemessenen Wechsel (null: nicht bestätigt)",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/:id/change-ip",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                ":id",
                "change-ip"
              ],
              "query": [
                {
                  "key": "verify",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Change-IP-URL aufrufen; verify=true misst die Ausgangs-IP davor und danach. changed bestätigt den URL-Aufruf, ip_changed den gemessenen Wechsel (null: nicht bestätigt)\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/{id}/change-ip. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/{id}/change-ip“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery verify: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"boolean\"}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/[^/?#]+/change-ip$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/{id}/change-ip\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/{id}/change-ip\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/proxies/{id}/password — Proxy-Passwort im Klartext abrufen (wird protokolliert)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/:id/password",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                ":id",
                "password"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Proxy-Passwort im Klartext abrufen (wird protokolliert)\n\nFeste Route-Scopes: secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/proxies/{id}/password. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/proxies/{id}/password“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/proxies/[^/?#]+/password$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/proxies/{id}/password\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/{id}/password\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/proxies/checkers — Verfügbare IP-Prüfdienste",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/checkers",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "checkers"
              ],
              "query": [],
              "variable": []
            },
            "description": "Verfügbare IP-Prüfdienste\n\nFeste Route-Scopes: proxies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/proxies/checkers. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/proxies/checkers“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/proxies/checkers$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/proxies/checkers\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/checkers\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/{id}/test — Proxy prüfen: Erreichbarkeit, Exit-IP v4/v6, Standort, Zeitzone, ASN, Latenz; Ergebnis wird gespeichert",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/:id/test",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                ":id",
                "test"
              ],
              "query": [
                {
                  "key": "ip_checker",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":32}"
                },
                {
                  "key": "apply_protocol",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. Nur zusammen mit detect_protocol=true: erfolgreich erkanntes HTTP-/HTTPS-/SOCKS5-Protokoll bei unveränderter Proxyversion übernehmen. Prüfergebnis wird dabei nicht gespeichert.\nSchema: {\"type\":\"boolean\"}"
                },
                {
                  "key": "detect_protocol",
                  "value": "false",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. Gespeicherte Zugangsdaten zur HTTP-/HTTPS-/SOCKS5-Erkennung verwenden, ohne Protokoll oder Prüfergebnis zu speichern.\nSchema: {\"type\":\"boolean\"}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Proxy prüfen: Erreichbarkeit, Exit-IP v4/v6, Standort, Zeitzone, ASN, Latenz; Ergebnis wird gespeichert\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/{id}/test. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/{id}/test“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery ip_checker: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":32}\nquery apply_protocol: Optional; zunächst deaktiviert. Nur zusammen mit detect_protocol=true: erfolgreich erkanntes HTTP-/HTTPS-/SOCKS5-Protokoll bei unveränderter Proxyversion übernehmen. Prüfergebnis wird dabei nicht gespeichert.\nSchema: {\"type\":\"boolean\"}\nquery detect_protocol: Optional; zunächst deaktiviert. Gespeicherte Zugangsdaten zur HTTP-/HTTPS-/SOCKS5-Erkennung verwenden, ohne Protokoll oder Prüfergebnis zu speichern.\nSchema: {\"type\":\"boolean\"}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/[^/?#]+/test$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/{id}/test\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/{id}/test\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/batch/test — Mehrere Proxys prüfen (höchstens 5 gleichzeitig)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/batch/test",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "batch",
                "test"
              ],
              "query": [],
              "variable": []
            },
            "description": "Mehrere Proxys prüfen (höchstens 5 gleichzeitig)\n\nFeste Route-Scopes: proxies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/batch/test. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/batch/test“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/batch/test$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/batch/test\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/batch/test\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/proxies/test — Proxy-Angaben prüfen, ohne zu speichern; Protokoll optional automatisch erkennen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/proxies/test",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "proxies",
                "test"
              ],
              "query": [],
              "variable": []
            },
            "description": "Proxy-Angaben prüfen, ohne zu speichern; Protokoll optional automatisch erkennen\n\nFeste Route-Scopes: proxies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/proxies/test. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/proxies/test“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"host\",\n    \"port\"\n  ],\n  \"properties\": {\n    \"ssh_private_key\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 65536\n    },\n    \"ssh_key_passphrase\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"ip_checker\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 32\n    },\n    \"protocol\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"http\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"https\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks4a\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"socks5h\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"ssh\"\n          ]\n        }\n      ]\n    },\n    \"detect_protocol\": {\n      \"type\": \"boolean\",\n      \"description\": \"HTTP, HTTPS oder SOCKS5 durch Handshake erkennen; protocol wird zuerst geprüft. Kein Speichern.\"\n    },\n    \"host\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 255\n    },\n    \"port\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 65535\n    },\n    \"username\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 512\n    },\n    \"password\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    },\n    \"ssh_host_key\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"pattern\": \"^SHA256:[A-Za-z0-9+/]{43}$\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"host\": \"proxy.example.invalid\",\n  \"port\": 8080\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/proxies/test$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/proxies/test\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/proxies/test\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/geo — Zustand der lokalen IP-Geo-Datenbank",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/geo",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "geo"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zustand der lokalen IP-Geo-Datenbank\n\nFeste Route-Scopes: proxies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/geo. Tags: Proxys.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/geo$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/geo\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/geo\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/geo/update — IP-Geo-Datenbank (DB-IP Lite, CC BY 4.0) herunterladen oder aktualisieren",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/geo/update",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "geo",
                "update"
              ],
              "query": [],
              "variable": []
            },
            "description": "IP-Geo-Datenbank (DB-IP Lite, CC BY 4.0) herunterladen oder aktualisieren\n\nFeste Route-Scopes: settings:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/geo/update. Tags: Proxys.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/geo/update“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/geo/update$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/geo/update\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/geo/update\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Laufzeit",
      "item": [
        {
          "name": "POST /api/v1/profiles/{id}/start — Profil starten: Relay, Proxy-Prüfung (Kill-Switch), Kern-Start; liefert DevTools-Endpunkt",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/start",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "start"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profil starten: Relay, Proxy-Prüfung (Kill-Switch), Kern-Start; liefert DevTools-Endpunkt\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/start. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/start“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"skip_proxy_check\": {\n      \"type\": \"boolean\"\n    },\n    \"urls\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 4096\n      },\n      \"maxItems\": 50\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/start$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/start\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/start\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/stop — Profil regulär beenden (Browser.close, nach Zeitlimit hart)",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/stop",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "stop"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profil regulär beenden (Browser.close, nach Zeitlimit hart)\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/stop. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/stop“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/stop$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/stop\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/stop\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/kill — Profil sofort hart beenden",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/kill",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "kill"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Profil sofort hart beenden\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/kill. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/kill“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/kill$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/kill\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/kill\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/{id}/runtime — Laufzeitstatus eines Profils",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/runtime",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "runtime"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Laufzeitstatus eines Profils\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/runtime. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/runtime“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/runtime$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/runtime\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/runtime\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/runtime — Alle laufenden Profile",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/runtime",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "runtime"
              ],
              "query": [],
              "variable": []
            },
            "description": "Alle laufenden Profile\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/runtime. Tags: Laufzeit.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/runtime$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/runtime\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/runtime\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/runtime/batch/start — Mehrere Profile starten (Warteschlange, Parallelität laut Einstellung)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/runtime/batch/start",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "runtime",
                "batch",
                "start"
              ],
              "query": [],
              "variable": []
            },
            "description": "Mehrere Profile starten (Warteschlange, Parallelität laut Einstellung)\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/runtime/batch/start. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/runtime/batch/start“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"skip_proxy_check\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/runtime/batch/start$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/runtime/batch/start\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/runtime/batch/start\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/runtime/batch/stop — Mehrere Profile beenden",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/runtime/batch/stop",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "runtime",
                "batch",
                "stop"
              ],
              "query": [],
              "variable": []
            },
            "description": "Mehrere Profile beenden\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/runtime/batch/stop. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/runtime/batch/stop“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"force\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/runtime/batch/stop$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/runtime/batch/stop\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/runtime/batch/stop\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/cache/clear — Browserdaten eines gestoppten Profils löschen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/cache/clear",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "cache",
                "clear"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Browserdaten eines gestoppten Profils löschen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/cache/clear. Tags: Laufzeit.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/cache/clear“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"types\"\n  ],\n  \"properties\": {\n    \"types\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"anyOf\": [\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"cookies\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"local_storage\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"indexed_db\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"service_workers\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"history\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"passwords\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"bookmarks\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"extensions\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"extension_data\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"cache\"\n            ]\n          }\n        ]\n      },\n      \"minItems\": 1\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"types\": [\n    \"cookies\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/cache/clear$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/cache/clear\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/cache/clear\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/settings/cache — Automatisches Leeren des Caches von Profilen, die N Tage nicht geöffnet wurden (0 = aus)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/cache",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "cache"
              ],
              "query": [],
              "variable": []
            },
            "description": "Automatisches Leeren des Caches von Profilen, die N Tage nicht geöffnet wurden (0 = aus)\n\nFeste Route-Scopes: keine zusätzlichen Route-Scopes. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/settings/cache. Tags: Laufzeit.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/settings/cache$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/settings/cache\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/settings/cache\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/settings/cache — Automatisches Cache-Leeren einstellen (0 = aus, sonst 7–365 Tage ohne Öffnen)",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/cache",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "cache"
              ],
              "query": [],
              "variable": []
            },
            "description": "Automatisches Cache-Leeren einstellen (0 = aus, sonst 7–365 Tage ohne Öffnen)\n\nFeste Route-Scopes: settings:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/settings/cache. Tags: Laufzeit.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/settings/cache“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"auto_clear_days\"\n  ],\n  \"properties\": {\n    \"auto_clear_days\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 365\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"auto_clear_days\": 0\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/settings/cache$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/settings/cache\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/settings/cache\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/settings/runtime — Einstellungen für den Profilstart",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/runtime",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "runtime"
              ],
              "query": [],
              "variable": []
            },
            "description": "Einstellungen für den Profilstart\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/settings/runtime. Tags: Laufzeit.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/settings/runtime$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/settings/runtime\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/settings/runtime\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/settings/runtime — Einstellungen für den Profilstart ändern",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/runtime",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "runtime"
              ],
              "query": [],
              "variable": []
            },
            "description": "Einstellungen für den Profilstart ändern\n\nFeste Route-Scopes: settings:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/settings/runtime. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/settings/runtime“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"hardware_acceleration\": {\n      \"type\": [\n        \"boolean\",\n        \"null\"\n      ]\n    },\n    \"download_directory\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    },\n    \"info_page\": {\n      \"type\": \"boolean\"\n    },\n    \"max_parallel_starts\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 20\n    },\n    \"stop_timeout_ms\": {\n      \"type\": \"integer\",\n      \"minimum\": 1000,\n      \"maximum\": 120000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"max_parallel_starts\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/settings/runtime$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/settings/runtime\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/settings/runtime\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/windows/uniform — Fenstergröße des Steuerprofils auf ausgewählte Profile übertragen, Positionen erhalten",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/windows/uniform",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "windows",
                "uniform"
              ],
              "query": [],
              "variable": []
            },
            "description": "Fenstergröße des Steuerprofils auf ausgewählte Profile übertragen, Positionen erhalten\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/windows/uniform. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/windows/uniform“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"source_id\",\n    \"profile_ids\"\n  ],\n  \"properties\": {\n    \"source_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 64\n    },\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 200,\n      \"uniqueItems\": true\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"source_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/windows/uniform$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/windows/uniform\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/windows/uniform\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/displays — Aktuelle Bildschirme des Managers mit Arbeitsbereichen in geräteunabhängigen Pixeln und Skalierung abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/displays",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "displays"
              ],
              "query": [],
              "variable": []
            },
            "description": "Aktuelle Bildschirme des Managers mit Arbeitsbereichen in geräteunabhängigen Pixeln und Skalierung abrufen\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/displays. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/displays“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/displays$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/displays\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/displays\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/windows/arrange — Fenster geöffneter Profile anordnen (grid: gleich große Kacheln, cascade: versetzt übereinander) in einem Bildschirmbereich (Koordinaten in geräteunabhängigen Pixeln)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/windows/arrange",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "windows",
                "arrange"
              ],
              "query": [],
              "variable": []
            },
            "description": "Fenster geöffneter Profile anordnen (grid: gleich große Kacheln, cascade: versetzt übereinander) in einem Bildschirmbereich (Koordinaten in geräteunabhängigen Pixeln)\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/windows/arrange. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/windows/arrange“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"mode\",\n    \"area\"\n  ],\n  \"properties\": {\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"grid\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"cascade\"\n          ]\n        }\n      ]\n    },\n    \"area\": {\n      \"type\": \"object\",\n      \"required\": [\n        \"x\",\n        \"y\",\n        \"width\",\n        \"height\"\n      ],\n      \"properties\": {\n        \"x\": {\n          \"type\": \"integer\",\n          \"minimum\": -100000,\n          \"maximum\": 100000\n        },\n        \"y\": {\n          \"type\": \"integer\",\n          \"minimum\": -100000,\n          \"maximum\": 100000\n        },\n        \"width\": {\n          \"type\": \"integer\",\n          \"minimum\": 200,\n          \"maximum\": 100000\n        },\n        \"height\": {\n          \"type\": \"integer\",\n          \"minimum\": 200,\n          \"maximum\": 100000\n        }\n      },\n      \"additionalProperties\": false\n    },\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 200\n    },\n    \"columns\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 20\n    },\n    \"gap\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 200\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"mode\": \"grid\",\n  \"area\": {\n    \"x\": 1,\n    \"y\": 1,\n    \"width\": 200,\n    \"height\": 200\n  }\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/windows/arrange$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/windows/arrange\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/windows/arrange\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/windows/{id}/bounds — Position und Größe eines Profilfensters setzen oder es minimieren bzw. maximieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/windows/:id/bounds",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "windows",
                ":id",
                "bounds"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Position und Größe eines Profilfensters setzen oder es minimieren bzw. maximieren\n\nFeste Route-Scopes: runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/windows/{id}/bounds. Tags: Laufzeit.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/windows/{id}/bounds“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"anyOf\": [\n    {\n      \"type\": \"object\",\n      \"required\": [\n        \"x\",\n        \"y\",\n        \"width\",\n        \"height\"\n      ],\n      \"properties\": {\n        \"x\": {\n          \"type\": \"integer\",\n          \"minimum\": -100000,\n          \"maximum\": 100000\n        },\n        \"y\": {\n          \"type\": \"integer\",\n          \"minimum\": -100000,\n          \"maximum\": 100000\n        },\n        \"width\": {\n          \"type\": \"integer\",\n          \"minimum\": 200,\n          \"maximum\": 100000\n        },\n        \"height\": {\n          \"type\": \"integer\",\n          \"minimum\": 200,\n          \"maximum\": 100000\n        }\n      },\n      \"additionalProperties\": false\n    },\n    {\n      \"type\": \"object\",\n      \"required\": [\n        \"state\"\n      ],\n      \"properties\": {\n        \"state\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"minimized\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"maximized\"\n              ]\n            }\n          ]\n        }\n      },\n      \"additionalProperties\": false\n    }\n  ]\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"x\": 1,\n  \"y\": 1,\n  \"width\": 200,\n  \"height\": 200\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/windows/[^/?#]+/bounds$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/windows/{id}/bounds\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/windows/{id}/bounds\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Kerne",
      "item": [
        {
          "name": "GET /api/v1/kernels — Installierte Browserkerne",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels"
              ],
              "query": [],
              "variable": []
            },
            "description": "Installierte Browserkerne\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/kernels. Tags: Kerne.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/kernels$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/kernels\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/kernels\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/kernels/candidates — Gefundene, noch nicht registrierte Browser-Installationen auf diesem Rechner",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels/candidates",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels",
                "candidates"
              ],
              "query": [],
              "variable": []
            },
            "description": "Gefundene, noch nicht registrierte Browser-Installationen auf diesem Rechner\n\nFeste Route-Scopes: kernels:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/kernels/candidates. Tags: Kerne.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/kernels/candidates“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/kernels/candidates$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/kernels/candidates\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/kernels/candidates\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/kernels/local — Lokal installierten Browserkern registrieren (Version wird erkannt)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels/local",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels",
                "local"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lokal installierten Browserkern registrieren (Version wird erkannt)\n\nFeste Route-Scopes: kernels:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/kernels/local. Tags: Kerne.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/kernels/local“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"engine\",\n    \"path\"\n  ],\n  \"properties\": {\n    \"engine\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"chromium\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"firefox\"\n          ]\n        }\n      ]\n    },\n    \"path\": {\n      \"type\": \"string\",\n      \"minLength\": 3,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"engine\": \"chromium\",\n  \"path\": \"C:/TabGecko-Beispiel/browser/chrome.exe\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/kernels/local$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/kernels/local\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/kernels/local\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/kernels/install — Kern-Paket (ZIP aus kern-chromium mit build-info.json) in die Datenwurzel installieren; eigene Kerne unterstützen den Fingerprint",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels/install",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels",
                "install"
              ],
              "query": [],
              "variable": []
            },
            "description": "Kern-Paket (ZIP aus kern-chromium mit build-info.json) in die Datenwurzel installieren; eigene Kerne unterstützen den Fingerprint\n\nFeste Route-Scopes: kernels:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/kernels/install. Tags: Kerne.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/kernels/install“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"path\"\n  ],\n  \"properties\": {\n    \"path\": {\n      \"type\": \"string\",\n      \"minLength\": 3,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"path\": \"C:/TabGecko-Beispiel/browserkern.zip\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/kernels/install$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/kernels/install\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/kernels/install\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/kernels/{id} — Kern entfernen (lokal registrierte Kerne: nur die Registrierung; installierte Kern-Pakete: auch die Dateien)",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Kern entfernen (lokal registrierte Kerne: nur die Registrierung; installierte Kern-Pakete: auch die Dateien)\n\nFeste Route-Scopes: kernels:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/kernels/{id}. Tags: Kerne.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/kernels/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/kernels/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/kernels/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/kernels/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/kernels/updates — Status und signierte verfügbare Kernel-Updates",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels/updates",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels",
                "updates"
              ],
              "query": [],
              "variable": []
            },
            "description": "Status und signierte verfügbare Kernel-Updates\n\nFeste Route-Scopes: kernels:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/kernels/updates. Tags: Kerne.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/kernels/updates$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/kernels/updates\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/kernels/updates\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/kernels/updates/settings — Automatische Prüfung auf Kernel-Updates einstellen",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels/updates/settings",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels",
                "updates",
                "settings"
              ],
              "query": [],
              "variable": []
            },
            "description": "Automatische Prüfung auf Kernel-Updates einstellen\n\nFeste Route-Scopes: kernels:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/kernels/updates/settings. Tags: Kerne.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/kernels/updates/settings“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"auto_check\": {\n      \"type\": \"boolean\"\n    },\n    \"auto_download\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false,\n  \"minProperties\": 1\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"auto_check\": false\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/kernels/updates/settings$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/kernels/updates/settings\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/kernels/updates/settings\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/kernels/updates/check — Signiertes Kernel-Manifest laden und prüfen",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels/updates/check",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels",
                "updates",
                "check"
              ],
              "query": [],
              "variable": []
            },
            "description": "Signiertes Kernel-Manifest laden und prüfen\n\nFeste Route-Scopes: kernels:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/kernels/updates/check. Tags: Kerne.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/kernels/updates/check“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/kernels/updates/check$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/kernels/updates/check\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/kernels/updates/check\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/kernels/updates/install — Signierten Kernel herunterladen, prüfen und installieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/kernels/updates/install",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "kernels",
                "updates",
                "install"
              ],
              "query": [],
              "variable": []
            },
            "description": "Signierten Kernel herunterladen, prüfen und installieren\n\nFeste Route-Scopes: kernels:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/kernels/updates/install. Tags: Kerne.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/kernels/updates/install“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"build\"\n  ],\n  \"properties\": {\n    \"build\": {\n      \"type\": \"string\",\n      \"minLength\": 7,\n      \"maxLength\": 80\n    },\n    \"engine\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"chromium\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"firefox\"\n          ]\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"build\": \"Beispiel\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/kernels/updates/install$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/kernels/updates/install\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/kernels/updates/install\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "AdsPower-Kompatibilität",
      "item": [
        {
          "name": "GET /api/v1/settings/compat — Einstellungen der AdsPower-kompatiblen Schnittstelle",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/compat",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "compat"
              ],
              "query": [],
              "variable": []
            },
            "description": "Einstellungen der AdsPower-kompatiblen Schnittstelle\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/settings/compat. Tags: AdsPower-Kompatibilität.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/settings/compat$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/settings/compat\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/settings/compat\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/settings/compat — AdsPower-kompatible Schnittstelle ein-/ausschalten und konfigurieren; legacy_key übernimmt einen vorhandenen AdsPower-API-Schlüssel (nur als Hash gespeichert)",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/compat",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "compat"
              ],
              "query": [],
              "variable": []
            },
            "description": "AdsPower-kompatible Schnittstelle ein-/ausschalten und konfigurieren; legacy_key übernimmt einen vorhandenen AdsPower-API-Schlüssel (nur als Hash gespeichert)\n\nFeste Route-Scopes: settings:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/settings/compat. Tags: AdsPower-Kompatibilität.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/settings/compat“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"enabled\": {\n      \"type\": \"boolean\"\n    },\n    \"port\": {\n      \"type\": \"integer\",\n      \"minimum\": 1024,\n      \"maximum\": 65535\n    },\n    \"require_token\": {\n      \"type\": \"boolean\"\n    },\n    \"rate_limit\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 100\n    },\n    \"legacy_key\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"minLength\": 8,\n      \"maxLength\": 256\n    },\n    \"webdriver_path\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"enabled\": false\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/settings/compat$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/settings/compat\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/settings/compat\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Cookies",
      "item": [
        {
          "name": "GET /api/v1/profiles/{id}/cookies — Cookies eines Profils lesen (laufend über CDP, sonst über eine unsichtbare Wartungssitzung des Kerns)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/cookies",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "cookies"
              ],
              "query": [
                {
                  "key": "format",
                  "value": "json",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"json\"]},{\"type\":\"string\",\"enum\":[\"netscape\"]},{\"type\":\"string\",\"enum\":[\"header\"]}]}"
                }
              ],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Cookies eines Profils lesen (laufend über CDP, sonst über eine unsichtbare Wartungssitzung des Kerns)\n\nFeste Route-Scopes: cookies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/cookies. Tags: Cookies.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/cookies“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery format: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"json\"]},{\"type\":\"string\",\"enum\":[\"netscape\"]},{\"type\":\"string\",\"enum\":[\"header\"]}]}\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/cookies$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/cookies\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/cookies\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/profiles/{id}/cookies — Cookies importieren (JSON, Netscape, Name=Wert, Base64, storageState); Einspielen über den Browser, nie per Datei",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/cookies",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "cookies"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Cookies importieren (JSON, Netscape, Name=Wert, Base64, storageState); Einspielen über den Browser, nie per Datei\n\nFeste Route-Scopes: cookies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/profiles/{id}/cookies. Tags: Cookies.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/profiles/{id}/cookies“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"cookies\"\n  ],\n  \"properties\": {\n    \"cookies\": {\n      \"description\": \"Cookies als Text (JSON, Netscape, Name=Wert, Base64) oder als JSON-Array\"\n    },\n    \"format\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"auto\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"json\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"netscape\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"header\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"storage_state\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"base64\"\n          ]\n        }\n      ]\n    },\n    \"domain\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 253\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"merge\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"replace\"\n          ]\n        }\n      ]\n    },\n    \"ignore_errors\": {\n      \"type\": \"boolean\"\n    },\n    \"skip_expired\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"cookies\": [\n    {\n      \"name\": \"beispiel\",\n      \"value\": \"fiktiv\",\n      \"domain\": \"example.com\",\n      \"path\": \"/\",\n      \"secure\": true,\n      \"httpOnly\": false\n    }\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/cookies$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/profiles/{id}/cookies\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/cookies\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/profiles/{id}/cookies — Alle Cookies eines Profils löschen, auch noch nicht eingespielte Importe",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/cookies",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "cookies"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Alle Cookies eines Profils löschen, auch noch nicht eingespielte Importe\n\nFeste Route-Scopes: cookies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/profiles/{id}/cookies. Tags: Cookies.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/profiles/{id}/cookies“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/cookies$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/profiles/{id}/cookies\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/cookies\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/batch/cookies — Dieselben Cookies in mehrere Profile importieren: je Profil vorgemerkt und im Hintergrund über den Browser eingespielt (laufende Profile sofort)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch/cookies",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch",
                "cookies"
              ],
              "query": [],
              "variable": []
            },
            "description": "Dieselben Cookies in mehrere Profile importieren: je Profil vorgemerkt und im Hintergrund über den Browser eingespielt (laufende Profile sofort)\n\nFeste Route-Scopes: cookies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/batch/cookies. Tags: Cookies.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/batch/cookies“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"cookies\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"cookies\": {\n      \"description\": \"Cookies als Text (JSON, Netscape, Name=Wert, Base64) oder als JSON-Array\"\n    },\n    \"format\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"auto\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"json\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"netscape\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"header\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"storage_state\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"base64\"\n          ]\n        }\n      ]\n    },\n    \"domain\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 253\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"merge\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"replace\"\n          ]\n        }\n      ]\n    },\n    \"ignore_errors\": {\n      \"type\": \"boolean\"\n    },\n    \"skip_expired\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"cookies\": [\n    {\n      \"name\": \"beispiel\",\n      \"value\": \"fiktiv\",\n      \"domain\": \"example.com\",\n      \"path\": \"/\",\n      \"secure\": true,\n      \"httpOnly\": false\n    }\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/batch/cookies$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/batch/cookies\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch/cookies\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/batch/cookies/export — Cookies mehrerer Profile lesen (höchstens 100) und als ZIP mit einer Datei je Profil zurückgeben",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch/cookies/export",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch",
                "cookies",
                "export"
              ],
              "query": [],
              "variable": []
            },
            "description": "Cookies mehrerer Profile lesen (höchstens 100) und als ZIP mit einer Datei je Profil zurückgeben\n\nFeste Route-Scopes: cookies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/batch/cookies/export. Tags: Cookies.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/batch/cookies/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 100\n    },\n    \"format\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"json\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"netscape\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"header\"\n          ]\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/batch/cookies/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/batch/cookies/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch/cookies/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/cookies/remove — Ausgewählte Cookies einschließlich vorgemerkter Kopien löschen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/cookies/remove",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "cookies",
                "remove"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Ausgewählte Cookies einschließlich vorgemerkter Kopien löschen\n\nFeste Route-Scopes: cookies:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/cookies/remove. Tags: Cookies.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/cookies/remove“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"cookies\"\n  ],\n  \"properties\": {\n    \"cookies\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"name\",\n          \"value\",\n          \"domain\",\n          \"host_only\",\n          \"path\",\n          \"expires\",\n          \"http_only\",\n          \"secure\",\n          \"same_site\",\n          \"session\",\n          \"partition_key\",\n          \"priority\",\n          \"source_scheme\",\n          \"source_port\",\n          \"creation\",\n          \"last_access\"\n        ],\n        \"properties\": {\n          \"firefox\": {\n            \"type\": \"object\",\n            \"required\": [\n              \"partition_key\",\n              \"partitioned\",\n              \"user_context_id\"\n            ],\n            \"properties\": {\n              \"partition_key\": {\n                \"type\": \"string\"\n              },\n              \"partitioned\": {\n                \"type\": \"boolean\"\n              },\n              \"user_context_id\": {\n                \"type\": \"integer\"\n              }\n            }\n          },\n          \"name\": {\n            \"type\": \"string\"\n          },\n          \"value\": {\n            \"type\": \"string\"\n          },\n          \"domain\": {\n            \"type\": \"string\"\n          },\n          \"host_only\": {\n            \"type\": \"boolean\"\n          },\n          \"path\": {\n            \"type\": \"string\"\n          },\n          \"expires\": {\n            \"type\": [\n              \"null\",\n              \"number\"\n            ]\n          },\n          \"http_only\": {\n            \"type\": \"boolean\"\n          },\n          \"secure\": {\n            \"type\": \"boolean\"\n          },\n          \"same_site\": {\n            \"type\": \"string\"\n          },\n          \"session\": {\n            \"type\": \"boolean\"\n          },\n          \"partition_key\": {\n            \"anyOf\": [\n              {\n                \"type\": \"object\",\n                \"required\": [\n                  \"top_level_site\",\n                  \"has_cross_site_ancestor\"\n                ],\n                \"properties\": {\n                  \"top_level_site\": {\n                    \"type\": \"string\"\n                  },\n                  \"has_cross_site_ancestor\": {\n                    \"type\": \"boolean\"\n                  }\n                }\n              },\n              {\n                \"type\": \"null\"\n              }\n            ]\n          },\n          \"priority\": {\n            \"type\": [\n              \"null\",\n              \"string\"\n            ]\n          },\n          \"source_scheme\": {\n            \"type\": [\n              \"null\",\n              \"string\"\n            ]\n          },\n          \"source_port\": {\n            \"type\": [\n              \"null\",\n              \"integer\"\n            ]\n          },\n          \"creation\": {\n            \"type\": [\n              \"null\",\n              \"number\"\n            ]\n          },\n          \"last_access\": {\n            \"type\": [\n              \"null\",\n              \"number\"\n            ]\n          }\n        }\n      },\n      \"minItems\": 1,\n      \"maxItems\": 20000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"cookies\": [\n    {\n      \"name\": \"beispiel\",\n      \"value\": \"fiktiv\",\n      \"domain\": \"example.com\",\n      \"path\": \"/\",\n      \"secure\": true,\n      \"httpOnly\": false\n    }\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/cookies/remove$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/cookies/remove\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/cookies/remove\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/cookies/convert — Cookie-Formate umwandeln und prüfen, ohne ein Profil zu ändern",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/cookies/convert",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "cookies",
                "convert"
              ],
              "query": [],
              "variable": []
            },
            "description": "Cookie-Formate umwandeln und prüfen, ohne ein Profil zu ändern\n\nFeste Route-Scopes: cookies:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/cookies/convert. Tags: Cookies.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/cookies/convert“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"cookies\",\n    \"to\"\n  ],\n  \"properties\": {\n    \"cookies\": {\n      \"description\": \"Cookies als Text (JSON, Netscape, Name=Wert, Base64) oder als JSON-Array\"\n    },\n    \"from\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"auto\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"json\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"netscape\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"header\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"storage_state\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"base64\"\n          ]\n        }\n      ]\n    },\n    \"to\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"json\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"netscape\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"header\"\n          ]\n        }\n      ]\n    },\n    \"domain\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 253\n    },\n    \"skip_expired\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"cookies\": [\n    {\n      \"name\": \"beispiel\",\n      \"value\": \"fiktiv\",\n      \"domain\": \"example.com\",\n      \"path\": \"/\",\n      \"secure\": true,\n      \"httpOnly\": false\n    }\n  ],\n  \"to\": \"json\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/cookies/convert$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/cookies/convert\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/cookies/convert\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Import/Export",
      "item": [
        {
          "name": "POST /api/v1/profiles/{id}/local-storage/export — Local Storage für explizite Origins ohne Abruf der Webseiten exportieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/local-storage/export",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "local-storage",
                "export"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Local Storage für explizite Origins ohne Abruf der Webseiten exportieren\n\nFeste Route-Scopes: profiles:read, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/local-storage/export. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/local-storage/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"origins\"\n  ],\n  \"properties\": {\n    \"origins\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 2048\n      },\n      \"minItems\": 1,\n      \"maxItems\": 50\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"origins\": [\n    \"https://example.com/\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/local-storage/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/local-storage/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/local-storage/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/session-storage/export — Session Storage geöffneter Tabs für explizite Origins exportieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/session-storage/export",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "session-storage",
                "export"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Session Storage geöffneter Tabs für explizite Origins exportieren\n\nFeste Route-Scopes: profiles:read, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/session-storage/export. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/session-storage/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"origins\"\n  ],\n  \"properties\": {\n    \"origins\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 2048\n      },\n      \"minItems\": 1,\n      \"maxItems\": 50\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"origins\": [\n    \"https://example.com/\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/session-storage/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/session-storage/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/session-storage/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/website-storage/indexeddb/import — Eine neue IndexedDB-Datenbank aus einem Website-Speicherexport in ein geöffnetes Dokument importieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/website-storage/indexeddb/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "website-storage",
                "indexeddb",
                "import"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Eine neue IndexedDB-Datenbank aus einem Website-Speicherexport in ein geöffnetes Dokument importieren\n\nFeste Route-Scopes: profiles:write, runtime:control. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/website-storage/indexeddb/import. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/website-storage/indexeddb/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"data\",\n    \"document_index\",\n    \"database_index\",\n    \"target_id\",\n    \"frame_id\"\n  ],\n  \"properties\": {\n    \"data\": {},\n    \"document_index\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 499\n    },\n    \"database_index\": {\n      \"type\": \"integer\",\n      \"minimum\": 0,\n      \"maximum\": 99\n    },\n    \"target_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 512\n    },\n    \"frame_id\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 512\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"data\": \"Beispielwert\",\n  \"document_index\": 1,\n  \"database_index\": 1,\n  \"target_id\": \"00000000-0000-4000-8000-000000000001\",\n  \"frame_id\": \"00000000-0000-4000-8000-000000000001\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/website-storage/indexeddb/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/website-storage/indexeddb/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/website-storage/indexeddb/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/website-storage/export — Website-Speicher geöffneter Tabs und Frames mit Partitionenzuordnung exportieren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/website-storage/export",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "website-storage",
                "export"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Website-Speicher geöffneter Tabs und Frames mit Partitionenzuordnung exportieren\n\nFeste Route-Scopes: profiles:read, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/website-storage/export. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/website-storage/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"origins\",\n    \"kinds\"\n  ],\n  \"properties\": {\n    \"origins\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 2048\n      },\n      \"minItems\": 1,\n      \"maxItems\": 50\n    },\n    \"kinds\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"anyOf\": [\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"local\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"session\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"indexeddb\"\n            ]\n          }\n        ]\n      },\n      \"minItems\": 1,\n      \"maxItems\": 3,\n      \"uniqueItems\": true\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"origins\": [\n    \"https://example.com/\"\n  ],\n  \"kinds\": [\n    \"local\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/website-storage/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/website-storage/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/website-storage/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/import/preview — Profil-Import prüfen (CSV, XLSX, TXT im AdsPower-Format): Spaltenerkennung, Vorschau je Zeile",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/import/preview",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "import",
                "preview"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profil-Import prüfen (CSV, XLSX, TXT im AdsPower-Format): Spaltenerkennung, Vorschau je Zeile\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/import/preview. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/import/preview“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"file_name\",\n    \"content_base64\"\n  ],\n  \"properties\": {\n    \"file_name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 260\n    },\n    \"content_base64\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 20971520\n    },\n    \"sheet\": {\n      \"type\": \"string\",\n      \"maxLength\": 64\n    },\n    \"mapping\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"anyOf\": [\n          {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"id\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"no\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"external_id\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ip\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"name\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"custom_no\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"group\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tags\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"status\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"notes\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"engine\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"engine_version\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"os\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ua\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"resolution\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"platform\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"username\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"password\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"totp_secret\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"cookie\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"proxytype\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"proxy\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"proxy_url\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"proxy_id\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ip_checker\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"countrycode\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"regioncode\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"citycode\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"start_urls\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"extensions_set\"\n                ]\n              }\n            ]\n          },\n          {\n            \"type\": \"null\"\n          }\n        ]\n      }\n    },\n    \"duplicate_check\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"none\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"account\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"account_password\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"cookie\"\n          ]\n        }\n      ]\n    },\n    \"ignore_cookie_errors\": {\n      \"type\": \"boolean\"\n    },\n    \"exclude_lines\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"integer\",\n        \"minimum\": 1\n      },\n      \"maxItems\": 1000\n    },\n    \"defaults\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"group_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"engine\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"chromium\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"firefox\"\n              ]\n            }\n          ]\n        },\n        \"engine_version\": {\n          \"type\": \"string\",\n          \"pattern\": \"^[0-9]{2,4}$\"\n        },\n        \"os\": {\n          \"type\": \"string\",\n          \"maxLength\": 16\n        },\n        \"tag_ids\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\"\n          },\n          \"maxItems\": 30\n        },\n        \"tags\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 50\n          },\n          \"maxItems\": 30\n        },\n        \"storage_options\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"file_name\": \"beispiel.csv\",\n  \"content_base64\": \"bmFtZSxlbmdpbmUsb3MKQmVpc3BpZWxwcm9maWwsY2hyb21pdW0sd2luZG93cwo=\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/import/preview$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/import/preview\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/import/preview\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/import — Profile aus Datei anlegen oder über die Spalte id aktualisieren; Ergebnis je Zeile",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "import"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profile aus Datei anlegen oder über die Spalte id aktualisieren; Ergebnis je Zeile\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/import. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"file_name\",\n    \"content_base64\"\n  ],\n  \"properties\": {\n    \"file_name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 260\n    },\n    \"content_base64\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 20971520\n    },\n    \"sheet\": {\n      \"type\": \"string\",\n      \"maxLength\": 64\n    },\n    \"mapping\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"anyOf\": [\n          {\n            \"anyOf\": [\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"id\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"no\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"external_id\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ip\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"name\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"custom_no\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"group\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"tags\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"status\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"notes\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"engine\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"engine_version\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"os\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ua\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"resolution\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"platform\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"username\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"password\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"totp_secret\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"cookie\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"proxytype\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"proxy\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"proxy_url\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"proxy_id\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"ip_checker\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"countrycode\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"regioncode\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"citycode\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"start_urls\"\n                ]\n              },\n              {\n                \"type\": \"string\",\n                \"enum\": [\n                  \"extensions_set\"\n                ]\n              }\n            ]\n          },\n          {\n            \"type\": \"null\"\n          }\n        ]\n      }\n    },\n    \"duplicate_check\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"none\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"account\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"account_password\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"cookie\"\n          ]\n        }\n      ]\n    },\n    \"ignore_cookie_errors\": {\n      \"type\": \"boolean\"\n    },\n    \"exclude_lines\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"integer\",\n        \"minimum\": 1\n      },\n      \"maxItems\": 1000\n    },\n    \"defaults\": {\n      \"type\": \"object\",\n      \"properties\": {\n        \"group_id\": {\n          \"type\": [\n            \"string\",\n            \"null\"\n          ]\n        },\n        \"engine\": {\n          \"anyOf\": [\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"chromium\"\n              ]\n            },\n            {\n              \"type\": \"string\",\n              \"enum\": [\n                \"firefox\"\n              ]\n            }\n          ]\n        },\n        \"engine_version\": {\n          \"type\": \"string\",\n          \"pattern\": \"^[0-9]{2,4}$\"\n        },\n        \"os\": {\n          \"type\": \"string\",\n          \"maxLength\": 16\n        },\n        \"tag_ids\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\"\n          },\n          \"maxItems\": 30\n        },\n        \"tags\": {\n          \"type\": \"array\",\n          \"items\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 50\n          },\n          \"maxItems\": 30\n        },\n        \"storage_options\": {\n          \"type\": \"object\",\n          \"additionalProperties\": {\n            \"type\": \"boolean\"\n          }\n        }\n      },\n      \"additionalProperties\": false\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"file_name\": \"beispiel.csv\",\n  \"content_base64\": \"bmFtZSxlbmdpbmUsb3MKQmVpc3BpZWxwcm9maWwsY2hyb21pdW0sd2luZG93cwo=\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/profiles/import/template — Import-Vorlage mit allen Spalten (XLSX mit Blatt „Zusatzkonten“, CSV oder TXT)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/import/template",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "import",
                "template"
              ],
              "query": [
                {
                  "key": "format",
                  "value": "xlsx",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"xlsx\"]},{\"type\":\"string\",\"enum\":[\"csv\"]},{\"type\":\"string\",\"enum\":[\"txt\"]}]}"
                }
              ],
              "variable": []
            },
            "description": "Import-Vorlage mit allen Spalten (XLSX mit Blatt „Zusatzkonten“, CSV oder TXT)\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/import/template. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/import/template“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery format: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"xlsx\"]},{\"type\":\"string\",\"enum\":[\"csv\"]},{\"type\":\"string\",\"enum\":[\"txt\"]}]}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/import/template$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/import/template\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/import/template\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/export — Profile als XLSX, CSV oder TXT exportieren (wieder importierbar, Spalten id/no für Aktualisierung); Passwörter nur mit secrets:read",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/export",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "export"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profile als XLSX, CSV oder TXT exportieren (wieder importierbar, Spalten id/no für Aktualisierung); Passwörter nur mit secrets:read\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/export. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"format\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"all\": {\n      \"type\": \"boolean\"\n    },\n    \"format\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"xlsx\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"csv\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"txt\"\n          ]\n        }\n      ]\n    },\n    \"include_secrets\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"format\": \"xlsx\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/integrations/transfers/list — GoLogin-, Dolphin- oder Multilogin-X-Profile ohne lokale Änderungen auflisten",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/integrations/transfers/list",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "integrations",
                "transfers",
                "list"
              ],
              "query": [],
              "variable": []
            },
            "description": "GoLogin-, Dolphin- oder Multilogin-X-Profile ohne lokale Änderungen auflisten\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/integrations/transfers/list. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/integrations/transfers/list“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"source\",\n    \"token\"\n  ],\n  \"properties\": {\n    \"source\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"gologin\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"dolphin\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"multilogin\"\n          ]\n        }\n      ]\n    },\n    \"token\": {\n      \"type\": \"string\",\n      \"minLength\": 8,\n      \"maxLength\": 8192\n    },\n    \"page\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 10000\n    },\n    \"cursor\": {\n      \"type\": \"string\",\n      \"maxLength\": 4096\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"source\": \"gologin\",\n  \"token\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/integrations/transfers/list$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/integrations/transfers/list\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/integrations/transfers/list\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/integrations/transfers/preview — Direkttransfer von bis zu 20 ausgewählten Profilen prüfen; zehn Minuten gültige Vorschau",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/integrations/transfers/preview",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "integrations",
                "transfers",
                "preview"
              ],
              "query": [],
              "variable": []
            },
            "description": "Direkttransfer von bis zu 20 ausgewählten Profilen prüfen; zehn Minuten gültige Vorschau\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/integrations/transfers/preview. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/integrations/transfers/preview“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"source\",\n    \"token\",\n    \"ids\",\n    \"cookies\"\n  ],\n  \"properties\": {\n    \"source\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"gologin\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"dolphin\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"multilogin\"\n          ]\n        }\n      ]\n    },\n    \"token\": {\n      \"type\": \"string\",\n      \"minLength\": 8,\n      \"maxLength\": 8192\n    },\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 100\n      },\n      \"minItems\": 1,\n      \"maxItems\": 20,\n      \"uniqueItems\": true\n    },\n    \"cookies\": {\n      \"type\": \"boolean\"\n    },\n    \"group_id\": {\n      \"type\": \"string\",\n      \"maxLength\": 64\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"source\": \"gologin\",\n  \"token\": \"NUR-FIKTIVES-BEISPIEL\",\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"cookies\": false\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/integrations/transfers/preview$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/integrations/transfers/preview\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/integrations/transfers/preview\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/integrations/transfers/execute — Geprüften Direkttransfer einmalig ausführen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/integrations/transfers/execute",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "integrations",
                "transfers",
                "execute"
              ],
              "query": [],
              "variable": []
            },
            "description": "Geprüften Direkttransfer einmalig ausführen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/integrations/transfers/execute. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/integrations/transfers/execute“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"id\"\n  ],\n  \"properties\": {\n    \"id\": {\n      \"type\": \"string\",\n      \"format\": \"uuid\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"id\": \"00000000-0000-4000-8000-000000000001\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/integrations/transfers/execute$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/integrations/transfers/execute\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/integrations/transfers/execute\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/package/export — Profile als verschlüsseltes .adbprofile-Paket exportieren (Argon2id + XChaCha20-Poly1305): Einstellungen, Konten, Proxy, Cookies neutral, Browserdaten ohne Cache; unterstützte Windows-DPAPI-Schlüssel werden im Paket übertragen und beim Import neu geschützt, App-Bound-Daten werden ausgelassen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/package/export",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "package",
                "export"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profile als verschlüsseltes .adbprofile-Paket exportieren (Argon2id + XChaCha20-Poly1305): Einstellungen, Konten, Proxy, Cookies neutral, Browserdaten ohne Cache; unterstützte Windows-DPAPI-Schlüssel werden im Paket übertragen und beim Import neu geschützt, App-Bound-Daten werden ausgelassen\n\nFeste Route-Scopes: profiles:read, secrets:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/package/export. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/package/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"password\",\n    \"target_path\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 12,\n      \"maxLength\": 1024\n    },\n    \"target_path\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 1024\n    },\n    \"include_cookies\": {\n      \"type\": \"boolean\"\n    },\n    \"include_browser_data\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\",\n  \"target_path\": \"C:/TabGecko-Beispiel/paket.adbprofile\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/package/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/package/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/package/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/package/preview — Inhalt eines .adbprofile-Pakets oder .adbbackup-Vollbackups anzeigen und bereits vorhandene Profile erkennen (ohne etwas einzuspielen)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/package/preview",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "package",
                "preview"
              ],
              "query": [],
              "variable": []
            },
            "description": "Inhalt eines .adbprofile-Pakets oder .adbbackup-Vollbackups anzeigen und bereits vorhandene Profile erkennen (ohne etwas einzuspielen)\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/package/preview. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/package/preview“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"path\",\n    \"password\"\n  ],\n  \"properties\": {\n    \"path\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 1024\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"path\": \"C:/TabGecko-Beispiel/paket.adbprofile\",\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/package/preview$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/package/preview\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/package/preview\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/package/import — Profile aus einem .adbprofile-Paket oder .adbbackup-Vollbackup importieren: neue ID und Nr., Fingerprint-Seeds erhalten, Cookies über den Browser eingespielt; on_conflict: new (Standard), skip oder replace (vorhandenes Profil in den Papierkorb)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/package/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "package",
                "import"
              ],
              "query": [],
              "variable": []
            },
            "description": "Profile aus einem .adbprofile-Paket oder .adbbackup-Vollbackup importieren: neue ID und Nr., Fingerprint-Seeds erhalten, Cookies über den Browser eingespielt; on_conflict: new (Standard), skip oder replace (vorhandenes Profil in den Papierkorb)\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/package/import. Tags: Import/Export.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/package/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"path\",\n    \"password\"\n  ],\n  \"properties\": {\n    \"path\": {\n      \"type\": \"string\",\n      \"minLength\": 4,\n      \"maxLength\": 1024\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    },\n    \"on_conflict\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"new\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"skip\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"replace\"\n          ]\n        }\n      ]\n    },\n    \"decisions\": {\n      \"type\": \"object\",\n      \"additionalProperties\": {\n        \"anyOf\": [\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"new\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"skip\"\n            ]\n          },\n          {\n            \"type\": \"string\",\n            \"enum\": [\n              \"replace\"\n            ]\n          }\n        ]\n      }\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"path\": \"C:/TabGecko-Beispiel/paket.adbprofile\",\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/package/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/package/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/package/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Lesezeichen",
      "item": [
        {
          "name": "GET /api/v1/profiles/{id}/bookmarks — Verwaltete Lesezeichen eines Profils",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/bookmarks",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "bookmarks"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Verwaltete Lesezeichen eines Profils\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/bookmarks. Tags: Lesezeichen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/bookmarks“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/bookmarks$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/bookmarks\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/bookmarks\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/profiles/{id}/bookmarks — Lesezeichen ersetzen; wirksam beim nächsten Start (eigene Lesezeichen im Browser bleiben erhalten)",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/bookmarks",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "bookmarks"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Lesezeichen ersetzen; wirksam beim nächsten Start (eigene Lesezeichen im Browser bleiben erhalten)\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/profiles/{id}/bookmarks. Tags: Lesezeichen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/profiles/{id}/bookmarks“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"bookmarks\"\n  ],\n  \"properties\": {\n    \"bookmarks\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"title\",\n          \"url\"\n        ],\n        \"properties\": {\n          \"title\": {\n            \"type\": \"string\",\n            \"maxLength\": 512\n          },\n          \"url\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 2048\n          },\n          \"folder\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 256\n          }\n        }\n      },\n      \"maxItems\": 1000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"bookmarks\": [\n    {\n      \"title\": \"Beispiel\",\n      \"url\": \"https://example.com/\"\n    }\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/bookmarks$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/profiles/{id}/bookmarks\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/bookmarks\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/batch/bookmarks — Lesezeichen für mehrere Profile hinzufügen, ersetzen oder leeren",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/batch/bookmarks",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                "batch",
                "bookmarks"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lesezeichen für mehrere Profile hinzufügen, ersetzen oder leeren\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/batch/bookmarks. Tags: Lesezeichen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/batch/bookmarks“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"ids\",\n    \"mode\"\n  ],\n  \"properties\": {\n    \"ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"add\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"replace\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"clear\"\n          ]\n        }\n      ]\n    },\n    \"bookmarks\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"title\",\n          \"url\"\n        ],\n        \"properties\": {\n          \"title\": {\n            \"type\": \"string\",\n            \"maxLength\": 512\n          },\n          \"url\": {\n            \"type\": \"string\",\n            \"minLength\": 1,\n            \"maxLength\": 2048\n          },\n          \"folder\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ],\n            \"maxLength\": 256\n          }\n        }\n      },\n      \"maxItems\": 1000\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"mode\": \"add\",\n  \"bookmarks\": [\n    {\n      \"title\": \"Beispiel\",\n      \"url\": \"https://example.com/\"\n    }\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/batch/bookmarks$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/batch/bookmarks\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/batch/bookmarks\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/bookmarks/parse — Lesezeichen aus Zeilen („Ordner::Name::URL“, „Name::URL“, „URL“) oder HTML-Lesezeichendatei lesen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/bookmarks/parse",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "bookmarks",
                "parse"
              ],
              "query": [],
              "variable": []
            },
            "description": "Lesezeichen aus Zeilen („Ordner::Name::URL“, „Name::URL“, „URL“) oder HTML-Lesezeichendatei lesen\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/bookmarks/parse. Tags: Lesezeichen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/bookmarks/parse“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"text\"\n  ],\n  \"properties\": {\n    \"text\": {\n      \"type\": \"string\",\n      \"maxLength\": 16777216\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"text\": \"Beispiel::https://example.com/\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/bookmarks/parse$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/bookmarks/parse\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/bookmarks/parse\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Erweiterungen",
      "item": [
        {
          "name": "GET /api/v1/extensions/store-metadata — Store-Versionen und Veröffentlichungsdaten ohne Paketdownload abrufen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extensions/store-metadata",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extensions",
                "store-metadata"
              ],
              "query": [
                {
                  "key": "engine",
                  "value": "chromium",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"chromium\"]},{\"type\":\"string\",\"enum\":[\"firefox\"]}]}"
                }
              ],
              "variable": []
            },
            "description": "Store-Versionen und Veröffentlichungsdaten ohne Paketdownload abrufen\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/extensions/store-metadata. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/extensions/store-metadata“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery engine: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"chromium\"]},{\"type\":\"string\",\"enum\":[\"firefox\"]}]}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/extensions/store-metadata$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/extensions/store-metadata\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extensions/store-metadata\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/extensions — Erweiterungsbibliothek (Chromium und Firefox getrennt)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extensions",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extensions"
              ],
              "query": [
                {
                  "key": "engine",
                  "value": "chromium",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"chromium\"]},{\"type\":\"string\",\"enum\":[\"firefox\"]}]}"
                }
              ],
              "variable": []
            },
            "description": "Erweiterungsbibliothek (Chromium und Firefox getrennt)\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/extensions. Tags: Erweiterungen.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery engine: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"chromium\"]},{\"type\":\"string\",\"enum\":[\"firefox\"]}]}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/extensions$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/extensions\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/extensions\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/extensions — Erweiterung hinzufügen: Store-Adresse (Chrome Web Store, addons.mozilla.org), CRX/ZIP/XPI-Datei oder entpackter Ordner",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extensions",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extensions"
              ],
              "query": [],
              "variable": []
            },
            "description": "Erweiterung hinzufügen: Store-Adresse (Chrome Web Store, addons.mozilla.org), CRX/ZIP/XPI-Datei oder entpackter Ordner\n\nFeste Route-Scopes: extensions:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/extensions. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/extensions“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"source\"\n  ],\n  \"properties\": {\n    \"source\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"store_url\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"file\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"unpacked\"\n          ]\n        }\n      ]\n    },\n    \"url\": {\n      \"type\": \"string\",\n      \"maxLength\": 2048\n    },\n    \"file_name\": {\n      \"type\": \"string\",\n      \"maxLength\": 260\n    },\n    \"content_base64\": {\n      \"type\": \"string\",\n      \"maxLength\": 146800640\n    },\n    \"path\": {\n      \"type\": \"string\",\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"source\": \"file\",\n  \"path\": \"C:/TabGecko-Beispiel/erweiterung.zip\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/extensions$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/extensions\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extensions\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/extensions/{id}/groups — Dauerhafte Gruppenzuordnung einer Erweiterung",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extensions/:id/groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extensions",
                ":id",
                "groups"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Dauerhafte Gruppenzuordnung einer Erweiterung\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/extensions/{id}/groups. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/extensions/{id}/groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/extensions/[^/?#]+/groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/extensions/{id}/groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extensions/{id}/groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/extensions/{id}/groups — Gruppenzuordnung atomar ändern; gilt auch für neue Profile und beim nächsten Start",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extensions/:id/groups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extensions",
                ":id",
                "groups"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Gruppenzuordnung atomar ändern; gilt auch für neue Profile und beim nächsten Start\n\nFeste Route-Scopes: extensions:write, profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/extensions/{id}/groups. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/extensions/{id}/groups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"group_ids\",\n    \"revision\"\n  ],\n  \"properties\": {\n    \"group_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\"\n      },\n      \"maxItems\": 10000\n    },\n    \"revision\": {\n      \"type\": \"string\",\n      \"minLength\": 64,\n      \"maxLength\": 64\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"group_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ],\n  \"revision\": \"Beispielxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/extensions/[^/?#]+/groups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/extensions/{id}/groups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extensions/{id}/groups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/extensions/{id} — Name oder Update-Modus (automatisch, manuell, gesperrt) ändern",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extensions/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extensions",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Name oder Update-Modus (automatisch, manuell, gesperrt) ändern\n\nFeste Route-Scopes: extensions:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/extensions/{id}. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/extensions/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 200\n    },\n    \"update_mode\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"auto\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"manual\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"locked\"\n          ]\n        }\n      ]\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/extensions/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/extensions/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extensions/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/extensions/{id} — Erweiterung aus Bibliothek und Sätzen entfernen (nicht bei laufenden Profilen)",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extensions/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extensions",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Erweiterung aus Bibliothek und Sätzen entfernen (nicht bei laufenden Profilen)\n\nFeste Route-Scopes: extensions:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/extensions/{id}. Tags: Erweiterungen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/extensions/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/extensions/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/extensions/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extensions/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/extensions/{id}/update — Neue Version aus dem Store laden",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extensions/:id/update",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extensions",
                ":id",
                "update"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Neue Version aus dem Store laden\n\nFeste Route-Scopes: extensions:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/extensions/{id}/update. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/extensions/{id}/update“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/extensions/[^/?#]+/update$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/extensions/{id}/update\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extensions/{id}/update\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/extension-sets — Erweiterungssätze",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extension-sets",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extension-sets"
              ],
              "query": [
                {
                  "key": "engine",
                  "value": "chromium",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"chromium\"]},{\"type\":\"string\",\"enum\":[\"firefox\"]}]}"
                }
              ],
              "variable": []
            },
            "description": "Erweiterungssätze\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/extension-sets. Tags: Erweiterungen.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery engine: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"chromium\"]},{\"type\":\"string\",\"enum\":[\"firefox\"]}]}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/extension-sets$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/extension-sets\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/extension-sets\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/extension-sets — Erweiterungssatz anlegen (höchstens 20 Erweiterungen)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extension-sets",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extension-sets"
              ],
              "query": [],
              "variable": []
            },
            "description": "Erweiterungssatz anlegen (höchstens 20 Erweiterungen)\n\nFeste Route-Scopes: extensions:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/extension-sets. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/extension-sets“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"name\",\n    \"engine\"\n  ],\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"engine\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"chromium\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"firefox\"\n          ]\n        }\n      ]\n    },\n    \"items\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"extension_id\"\n        ],\n        \"properties\": {\n          \"extension_id\": {\n            \"type\": \"string\"\n          },\n          \"enabled\": {\n            \"type\": \"boolean\"\n          },\n          \"pinned_version_id\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ]\n          }\n        },\n        \"additionalProperties\": false\n      },\n      \"maxItems\": 20\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\",\n  \"engine\": \"chromium\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/extension-sets$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/extension-sets\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extension-sets\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PATCH /api/v1/extension-sets/{id} — Erweiterungssatz ändern",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extension-sets/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extension-sets",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Erweiterungssatz ändern\n\nFeste Route-Scopes: extensions:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PATCH /api/v1/extension-sets/{id}. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PATCH /api/v1/extension-sets/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"name\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 100\n    },\n    \"items\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"object\",\n        \"required\": [\n          \"extension_id\"\n        ],\n        \"properties\": {\n          \"extension_id\": {\n            \"type\": \"string\"\n          },\n          \"enabled\": {\n            \"type\": \"boolean\"\n          },\n          \"pinned_version_id\": {\n            \"type\": [\n              \"string\",\n              \"null\"\n            ]\n          }\n        },\n        \"additionalProperties\": false\n      },\n      \"maxItems\": 20\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"name\": \"Beispielprofil\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PATCH\" && new RegExp(\"^/api/v1/extension-sets/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PATCH /api/v1/extension-sets/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extension-sets/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/extension-sets/{id} — Erweiterungssatz löschen; Profile verlieren die Zuweisung",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extension-sets/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extension-sets",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Erweiterungssatz löschen; Profile verlieren die Zuweisung\n\nFeste Route-Scopes: extensions:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/extension-sets/{id}. Tags: Erweiterungen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/extension-sets/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/extension-sets/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/extension-sets/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extension-sets/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/extension-sets/{id}/assign — Satz Profilen zuweisen: Auswahl, Gruppe, Tag oder alle (nur Profile desselben Kerns)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extension-sets/:id/assign",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extension-sets",
                ":id",
                "assign"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Satz Profilen zuweisen: Auswahl, Gruppe, Tag oder alle (nur Profile desselben Kerns)\n\nFeste Route-Scopes: extensions:write, profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/extension-sets/{id}/assign. Tags: Erweiterungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/extension-sets/{id}/assign“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"group_id\": {\n      \"type\": \"string\"\n    },\n    \"tag_id\": {\n      \"type\": \"string\"\n    },\n    \"all\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/extension-sets/[^/?#]+/assign$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/extension-sets/{id}/assign\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extension-sets/{id}/assign\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/extension-sets/unassign — Zuweisung von Erweiterungssätzen entfernen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/extension-sets/unassign",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "extension-sets",
                "unassign"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zuweisung von Erweiterungssätzen entfernen\n\nFeste Route-Scopes: extensions:write, profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/extension-sets/unassign. Tags: Erweiterungen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/extension-sets/unassign“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"profile_ids\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"minLength\": 1,\n        \"maxLength\": 64\n      },\n      \"minItems\": 1,\n      \"maxItems\": 1000\n    },\n    \"group_id\": {\n      \"type\": \"string\"\n    },\n    \"tag_id\": {\n      \"type\": \"string\"\n    },\n    \"all\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"profile_ids\": [\n    \"00000000-0000-4000-8000-000000000001\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/extension-sets/unassign$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/extension-sets/unassign\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/extension-sets/unassign\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Audit-Log",
      "item": [
        {
          "name": "GET /api/v1/audit — Audit-Log mit Filtern, neueste zuerst; Weiterblättern über before_seq",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/audit",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "audit"
              ],
              "query": [
                {
                  "key": "category",
                  "value": "account",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"account\"]},{\"type\":\"string\",\"enum\":[\"profile\"]},{\"type\":\"string\",\"enum\":[\"startup\"]},{\"type\":\"string\",\"enum\":[\"proxy\"]},{\"type\":\"string\",\"enum\":[\"team\"]}]}"
                },
                {
                  "key": "from",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":0}"
                },
                {
                  "key": "to",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":0}"
                },
                {
                  "key": "action",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":100}"
                },
                {
                  "key": "source",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}"
                },
                {
                  "key": "actor_type",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}"
                },
                {
                  "key": "entity_id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":64}"
                },
                {
                  "key": "entity_no",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}"
                },
                {
                  "key": "result",
                  "value": "ok",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"ok\"]},{\"type\":\"string\",\"enum\":[\"denied\"]},{\"type\":\"string\",\"enum\":[\"error\"]}]}"
                },
                {
                  "key": "search",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}"
                },
                {
                  "key": "before_seq",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}"
                },
                {
                  "key": "limit",
                  "value": "10",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":1000}"
                }
              ],
              "variable": []
            },
            "description": "Audit-Log mit Filtern, neueste zuerst; Weiterblättern über before_seq\n\nFeste Route-Scopes: audit:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/audit. Tags: Audit-Log.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/audit“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery category: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"account\"]},{\"type\":\"string\",\"enum\":[\"profile\"]},{\"type\":\"string\",\"enum\":[\"startup\"]},{\"type\":\"string\",\"enum\":[\"proxy\"]},{\"type\":\"string\",\"enum\":[\"team\"]}]}\nquery from: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":0}\nquery to: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":0}\nquery action: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":100}\nquery source: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}\nquery actor_type: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}\nquery entity_id: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":64}\nquery entity_no: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}\nquery result: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"ok\"]},{\"type\":\"string\",\"enum\":[\"denied\"]},{\"type\":\"string\",\"enum\":[\"error\"]}]}\nquery search: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}\nquery before_seq: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}\nquery limit: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1,\"maximum\":1000}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/audit$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/audit\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/audit\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/audit/verify — Hash-Kette und Tagesanker prüfen; meldet die erste Abweichung",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/audit/verify",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "audit",
                "verify"
              ],
              "query": [],
              "variable": []
            },
            "description": "Hash-Kette und Tagesanker prüfen; meldet die erste Abweichung\n\nFeste Route-Scopes: audit:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/audit/verify. Tags: Audit-Log.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/audit/verify“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/audit/verify$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/audit/verify\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/audit/verify\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/audit/export — Audit-Log als CSV oder JSONL exportieren (Filter wie bei der Liste)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/audit/export?format=csv",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "audit",
                "export"
              ],
              "query": [
                {
                  "key": "category",
                  "value": "account",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"account\"]},{\"type\":\"string\",\"enum\":[\"profile\"]},{\"type\":\"string\",\"enum\":[\"startup\"]},{\"type\":\"string\",\"enum\":[\"proxy\"]},{\"type\":\"string\",\"enum\":[\"team\"]}]}"
                },
                {
                  "key": "from",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":0}"
                },
                {
                  "key": "to",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":0}"
                },
                {
                  "key": "action",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":100}"
                },
                {
                  "key": "source",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}"
                },
                {
                  "key": "actor_type",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}"
                },
                {
                  "key": "entity_id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":64}"
                },
                {
                  "key": "entity_no",
                  "value": "1",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}"
                },
                {
                  "key": "result",
                  "value": "ok",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"ok\"]},{\"type\":\"string\",\"enum\":[\"denied\"]},{\"type\":\"string\",\"enum\":[\"error\"]}]}"
                },
                {
                  "key": "search",
                  "value": "Beispiel",
                  "disabled": true,
                  "description": "Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}"
                },
                {
                  "key": "format",
                  "value": "csv",
                  "disabled": false,
                  "description": "Pflichtfeld. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"csv\"]},{\"type\":\"string\",\"enum\":[\"jsonl\"]}]}"
                }
              ],
              "variable": []
            },
            "description": "Audit-Log als CSV oder JSONL exportieren (Filter wie bei der Liste)\n\nFeste Route-Scopes: audit:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/audit/export. Tags: Audit-Log.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/audit/export“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\nquery category: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"account\"]},{\"type\":\"string\",\"enum\":[\"profile\"]},{\"type\":\"string\",\"enum\":[\"startup\"]},{\"type\":\"string\",\"enum\":[\"proxy\"]},{\"type\":\"string\",\"enum\":[\"team\"]}]}\nquery from: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":0}\nquery to: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":0}\nquery action: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":100}\nquery source: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}\nquery actor_type: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":20}\nquery entity_id: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":64}\nquery entity_no: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"integer\",\"minimum\":1}\nquery result: Optional; zunächst deaktiviert. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"ok\"]},{\"type\":\"string\",\"enum\":[\"denied\"]},{\"type\":\"string\",\"enum\":[\"error\"]}]}\nquery search: Optional; zunächst deaktiviert. \nSchema: {\"type\":\"string\",\"maxLength\":200}\nquery format: Pflichtfeld. \nSchema: {\"anyOf\":[{\"type\":\"string\",\"enum\":[\"csv\"]},{\"type\":\"string\",\"enum\":[\"jsonl\"]}]}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/audit/export$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/audit/export\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/audit/export\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/settings/audit — Aufbewahrung des Audit-Logs",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/audit",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "audit"
              ],
              "query": [],
              "variable": []
            },
            "description": "Aufbewahrung des Audit-Logs\n\nFeste Route-Scopes: audit:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/settings/audit. Tags: Audit-Log.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/settings/audit$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/settings/audit\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/settings/audit\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/settings/audit — Aufbewahrung des Audit-Logs ändern (30–1.095 Tage)",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/audit",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "audit"
              ],
              "query": [],
              "variable": []
            },
            "description": "Aufbewahrung des Audit-Logs ändern (30–1.095 Tage)\n\nFeste Route-Scopes: settings:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/settings/audit. Tags: Audit-Log.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/settings/audit“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"retention_days\"\n  ],\n  \"properties\": {\n    \"retention_days\": {\n      \"type\": \"integer\",\n      \"minimum\": 30,\n      \"maximum\": 1095\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"retention_days\": 30\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/settings/audit$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/settings/audit\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/settings/audit\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Sicherungen",
      "item": [
        {
          "name": "GET /api/v1/backups/full — Einstellungen und Stand des verschlüsselten Vollbackups (.adbbackup) und der Prüfung",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups/full",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups",
                "full"
              ],
              "query": [],
              "variable": []
            },
            "description": "Einstellungen und Stand des verschlüsselten Vollbackups (.adbbackup) und der Prüfung\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/backups/full. Tags: Sicherungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/backups/full“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/backups/full$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/backups/full\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups/full\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/backups/full — Vollbackup jetzt erstellen: alle Profile portabel, Proxys, Gruppen, Tags, Erweiterungsbibliothek und RPA-Abläufe; verschlüsselt, geprüft und erst dann in den Zielordner verschoben",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups/full",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups",
                "full"
              ],
              "query": [],
              "variable": []
            },
            "description": "Vollbackup jetzt erstellen: alle Profile portabel, Proxys, Gruppen, Tags, Erweiterungsbibliothek und RPA-Abläufe; verschlüsselt, geprüft und erst dann in den Zielordner verschoben\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/backups/full. Tags: Sicherungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/backups/full“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"target_dir\": {\n      \"type\": \"string\",\n      \"minLength\": 3,\n      \"maxLength\": 1024\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"target_dir\": \"C:/TabGecko-Beispiel/sicherungen\",\n  \"password\": \"NUR-FIKTIVES-BEISPIEL\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/backups/full$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/backups/full\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups/full\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/backups/full/settings — Zeitplan, Zielordner und gespeichertes Passwort für Vollbackups festlegen (Passwort liegt dann im Tresor)",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups/full/settings",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups",
                "full",
                "settings"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zeitplan, Zielordner und gespeichertes Passwort für Vollbackups festlegen (Passwort liegt dann im Tresor)\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/backups/full/settings. Tags: Sicherungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/backups/full/settings“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"schedule\": {\n      \"anyOf\": [\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"off\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"daily\"\n          ]\n        },\n        {\n          \"type\": \"string\",\n          \"enum\": [\n            \"weekly\"\n          ]\n        }\n      ]\n    },\n    \"target_dir\": {\n      \"type\": [\n        \"string\",\n        \"null\"\n      ],\n      \"minLength\": 3,\n      \"maxLength\": 1024\n    },\n    \"include_cookies\": {\n      \"type\": \"boolean\"\n    },\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 12,\n      \"maxLength\": 1024\n    },\n    \"clear_password\": {\n      \"type\": \"boolean\"\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"schedule\": \"off\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/backups/full/settings$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/backups/full/settings\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups/full/settings\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/backups/verify — Sicherungen prüfen: neueste Datenbanksicherung (integrity_check an einer Kopie) und neuestes Vollbackup entschlüsseln und Prüfsummen vergleichen, ohne etwas einzuspielen",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups/verify",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups",
                "verify"
              ],
              "query": [],
              "variable": []
            },
            "description": "Sicherungen prüfen: neueste Datenbanksicherung (integrity_check an einer Kopie) und neuestes Vollbackup entschlüsseln und Prüfsummen vergleichen, ohne etwas einzuspielen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/backups/verify. Tags: Sicherungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/backups/verify“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"password\": {\n      \"type\": \"string\",\n      \"minLength\": 1,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/backups/verify$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/backups/verify\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups/verify\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/backups — Datenbanksicherungen (täglich, vor Migrationen, vor Massenänderungen)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups"
              ],
              "query": [],
              "variable": []
            },
            "description": "Datenbanksicherungen (täglich, vor Migrationen, vor Massenänderungen)\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/backups. Tags: Sicherungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/backups“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/backups$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/backups\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/backups/db — Datenbank jetzt sichern (VACUUM INTO)",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups/db",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups",
                "db"
              ],
              "query": [],
              "variable": []
            },
            "description": "Datenbank jetzt sichern (VACUUM INTO)\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/backups/db. Tags: Sicherungen.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/backups/db“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/backups/db$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/backups/db\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups/db\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/backups/{id}/restore — Wiederherstellung vormerken: Die Sicherung wird geprüft und beim nächsten Core-Start eingespielt; der aktuelle Stand wird vorher gesichert",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups/:id/restore",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups",
                ":id",
                "restore"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Wiederherstellung vormerken: Die Sicherung wird geprüft und beim nächsten Core-Start eingespielt; der aktuelle Stand wird vorher gesichert\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/backups/{id}/restore. Tags: Sicherungen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/backups/{id}/restore“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/backups/[^/?#]+/restore$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/backups/{id}/restore\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups/{id}/restore\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/backups/restore-pending — Vorgemerkte Wiederherstellung verwerfen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups/restore-pending",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups",
                "restore-pending"
              ],
              "query": [],
              "variable": []
            },
            "description": "Vorgemerkte Wiederherstellung verwerfen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/backups/restore-pending. Tags: Sicherungen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/backups/restore-pending“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/backups/restore-pending$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/backups/restore-pending\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups/restore-pending\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/backups/{id} — Sicherung löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/backups/:id",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "backups",
                ":id"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Sicherung löschen\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/backups/{id}. Tags: Sicherungen.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/backups/{id}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/backups/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/backups/{id}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/backups/{id}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Snapshots",
      "item": [
        {
          "name": "GET /api/v1/profiles/{id}/snapshots — Lokale Snapshots eines Profils (gerätegebunden, ohne Cache)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/snapshots",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "snapshots"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Lokale Snapshots eines Profils (gerätegebunden, ohne Cache)\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/profiles/{id}/snapshots. Tags: Snapshots.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/profiles/{id}/snapshots“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/snapshots$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/profiles/{id}/snapshots\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/snapshots\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/snapshots — Snapshot jetzt anlegen (Profil muss geschlossen sein)",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/snapshots",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "snapshots"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
                }
              ]
            },
            "description": "Snapshot jetzt anlegen (Profil muss geschlossen sein)\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/snapshots. Tags: Snapshots.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/snapshots“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\",\"minLength\":1,\"maxLength\":64}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/snapshots$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/snapshots\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/snapshots\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/profiles/{id}/snapshots/{snapshotId}/restore — Snapshot wiederherstellen; vorher wird der aktuelle Stand gesichert, engine_build_last_used wird auf den Build des Snapshots gesetzt",
          "request": {
            "method": "POST",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/snapshots/:snapshotId/restore",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "snapshots",
                ":snapshotId",
                "restore"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "snapshotId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Snapshot wiederherstellen; vorher wird der aktuelle Stand gesichert, engine_build_last_used wird auf den Build des Snapshots gesetzt\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/profiles/{id}/snapshots/{snapshotId}/restore. Tags: Snapshots.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/profiles/{id}/snapshots/{snapshotId}/restore“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath snapshotId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/snapshots/[^/?#]+/restore$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/profiles/{id}/snapshots/{snapshotId}/restore\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/snapshots/{snapshotId}/restore\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "DELETE /api/v1/profiles/{id}/snapshots/{snapshotId} — Snapshot löschen",
          "request": {
            "method": "DELETE",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/profiles/:id/snapshots/:snapshotId",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "profiles",
                ":id",
                "snapshots",
                ":snapshotId"
              ],
              "query": [],
              "variable": [
                {
                  "key": "id",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                },
                {
                  "key": "snapshotId",
                  "value": "00000000-0000-4000-8000-000000000001",
                  "description": "Pflichtfeld. \nSchema: {\"type\":\"string\"}"
                }
              ]
            },
            "description": "Snapshot löschen\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; DELETE /api/v1/profiles/{id}/snapshots/{snapshotId}. Tags: Snapshots.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „DELETE /api/v1/profiles/{id}/snapshots/{snapshotId}“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nParameter:\npath id: Pflichtfeld. \nSchema: {\"type\":\"string\"}\npath snapshotId: Pflichtfeld. \nSchema: {\"type\":\"string\"}"
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"DELETE\" && new RegExp(\"^/api/v1/profiles/[^/?#]+/snapshots/[^/?#]+$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"DELETE /api/v1/profiles/{id}/snapshots/{snapshotId}\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/profiles/{id}/snapshots/{snapshotId}\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/settings/snapshots — Snapshot-Einstellungen",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/snapshots",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "snapshots"
              ],
              "query": [],
              "variable": []
            },
            "description": "Snapshot-Einstellungen\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/settings/snapshots. Tags: Snapshots.\n\nStandardmäßig freigegebener Lesezugriff. Keine Profilstarts oder Fachdatenschreiboperationen.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/settings/snapshots$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/settings/snapshots\";",
                  "const approved = permission === expected;",
                  "const readOnly = true && actual.split(\"?\")[0] === base + \"/api/v1/settings/snapshots\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "PUT /api/v1/settings/snapshots — Snapshot beim Schließen ein-/ausschalten und Anzahl je Profil (1–20) festlegen",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/settings/snapshots",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "settings",
                "snapshots"
              ],
              "query": [],
              "variable": []
            },
            "description": "Snapshot beim Schließen ein-/ausschalten und Anzahl je Profil (1–20) festlegen\n\nFeste Route-Scopes: settings:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; PUT /api/v1/settings/snapshots. Tags: Snapshots.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „PUT /api/v1/settings/snapshots“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"properties\": {\n    \"on_close\": {\n      \"type\": \"boolean\"\n    },\n    \"per_profile\": {\n      \"type\": \"integer\",\n      \"minimum\": 1,\n      \"maximum\": 20\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"on_close\": false,\n  \"per_profile\": 5\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"PUT\" && new RegExp(\"^/api/v1/settings/snapshots$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"PUT /api/v1/settings/snapshots\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/settings/snapshots\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "Wartung",
      "item": [
        {
          "name": "GET /api/v1/maintenance/orphans — Unbekannte Profilordner: Ordner im Profilbereich ohne Datenbankeintrag (z. B. nach Wiederherstellung einer älteren Datenbanksicherung)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/maintenance/orphans",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "maintenance",
                "orphans"
              ],
              "query": [],
              "variable": []
            },
            "description": "Unbekannte Profilordner: Ordner im Profilbereich ohne Datenbankeintrag (z. B. nach Wiederherstellung einer älteren Datenbanksicherung)\n\nFeste Route-Scopes: profiles:read. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/maintenance/orphans. Tags: Wartung.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/maintenance/orphans“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/maintenance/orphans$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/maintenance/orphans\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/maintenance/orphans\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/maintenance/orphans/import — Unbekannte Profilordner über profile.json wieder als Profile aufnehmen (Nr. und Kurz-ID bleiben, wenn frei; Geheimnisse müssen neu gesetzt werden)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/maintenance/orphans/import",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "maintenance",
                "orphans",
                "import"
              ],
              "query": [],
              "variable": []
            },
            "description": "Unbekannte Profilordner über profile.json wieder als Profile aufnehmen (Nr. und Kurz-ID bleiben, wenn frei; Geheimnisse müssen neu gesetzt werden)\n\nFeste Route-Scopes: profiles:write. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/maintenance/orphans/import. Tags: Wartung.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/maintenance/orphans/import“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"folder_keys\"\n  ],\n  \"properties\": {\n    \"folder_keys\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"pattern\": \"^[0-9A-Z]{12}$\"\n      },\n      \"minItems\": 1,\n      \"maxItems\": 500\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"folder_keys\": [\n    \"ABCDEFGHIJKL\"\n  ]\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/maintenance/orphans/import$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/maintenance/orphans/import\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/maintenance/orphans/import\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/maintenance/orphans/delete — Unbekannte Profilordner endgültig löschen (confirm_count muss der Anzahl entsprechen)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/maintenance/orphans/delete",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "maintenance",
                "orphans",
                "delete"
              ],
              "query": [],
              "variable": []
            },
            "description": "Unbekannte Profilordner endgültig löschen (confirm_count muss der Anzahl entsprechen)\n\nFeste Route-Scopes: trash:manage. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/maintenance/orphans/delete. Tags: Wartung.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/maintenance/orphans/delete“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"folder_keys\",\n    \"confirm_count\"\n  ],\n  \"properties\": {\n    \"folder_keys\": {\n      \"type\": \"array\",\n      \"items\": {\n        \"type\": \"string\",\n        \"pattern\": \"^[0-9A-Z]{12}$\"\n      },\n      \"minItems\": 1,\n      \"maxItems\": 500\n    },\n    \"confirm_count\": {\n      \"type\": \"integer\",\n      \"minimum\": 1\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"folder_keys\": [\n    \"ABCDEFGHIJKL\"\n  ],\n  \"confirm_count\": 1\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/maintenance/orphans/delete$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/maintenance/orphans/delete\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/maintenance/orphans/delete\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/storage/move/check — Zielordner für das Verschieben der Datenwurzel prüfen (lokal, leer, beschreibbar, genug Platz); das Verschieben selbst startet die Manager-App bei beendetem Core",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/storage/move/check",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "storage",
                "move",
                "check"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zielordner für das Verschieben der Datenwurzel prüfen (lokal, leer, beschreibbar, genug Platz); das Verschieben selbst startet die Manager-App bei beendetem Core\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/storage/move/check. Tags: Wartung.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/storage/move/check“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"target\"\n  ],\n  \"properties\": {\n    \"target\": {\n      \"type\": \"string\",\n      \"minLength\": 3,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"target\": \"C:/TabGecko-Beispiel/neue-datenwurzel\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/storage/move/check$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/storage/move/check\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/storage/move/check\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "GET /api/v1/storage/previous-root — Alte Datenwurzel nach dem Verschieben (bleibt bis zur Bestätigung erhalten)",
          "request": {
            "method": "GET",
            "header": [],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/storage/previous-root",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "storage",
                "previous-root"
              ],
              "query": [],
              "variable": []
            },
            "description": "Alte Datenwurzel nach dem Verschieben (bleibt bis zur Bestätigung erhalten)\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; GET /api/v1/storage/previous-root. Tags: Wartung.\n\nGeschützte Aktion: kann Daten ändern, Geheimnisse lesen, Browser starten oder externe Dienste erreichen. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „GET /api/v1/storage/previous-root“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure.."
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"GET\" && new RegExp(\"^/api/v1/storage/previous-root$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"GET /api/v1/storage/previous-root\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/storage/previous-root\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /api/v1/storage/previous-root/delete — Alte Datenwurzel löschen (path muss der gemeldeten alten Datenwurzel entsprechen)",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{bearerToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/api/v1/storage/previous-root/delete",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "api",
                "v1",
                "storage",
                "previous-root",
                "delete"
              ],
              "query": [],
              "variable": []
            },
            "description": "Alte Datenwurzel löschen (path muss der gemeldeten alten Datenwurzel entsprechen)\n\nFeste Route-Scopes: admin. Alle genannten Scopes sind erforderlich; Admin-/Sitzungsprivilegien und zusätzliche aktionsabhängige Prüfungen bleiben maßgeblich. Eine leere Liste bedeutet nicht anonymen Zugriff.\n\nQuelle: sdk/openapi.json; POST /api/v1/storage/previous-root/delete. Tags: Wartung.\n\nACHTUNG: destruktive oder ersetzende Aktion möglich. Vor Versand Ziel, Body, Berechtigungen und Auswirkungen prüfen. Für genau einen Versand im aktiven Environment allowRequestOnce auf „POST /api/v1/storage/previous-root/delete“ setzen und diese Anfrage einzeln senden. Die Freigabe wird beim nächsten Request verbraucht, auch bei Nichtübereinstimmung.\n\nIDs, Nummern und Beispiele sind fiktiv. Pfadvariablen im URL-Tab ersetzen. Optionale Query-Parameter sind deaktiviert. Kein Token wird mitgeliefert. Erfolg kann vorhandene Ressourcen, aktuelle row_version/Revisionen, passende Scopes, installierte Kerne oder einen laufenden Browser voraussetzen.\n\nDokumentierte Antworten: 200 laut OpenAPI; default HTTP error envelope. The status and error.code identify the failure..\n\nJSON-Body: fiktives Ausgangsbeispiel, vor Freigabe anpassen. Alle optionalen Felder und Grenzen stehen im folgenden Originalschema; nicht alle Kombinationen sind fachlich zulässig.\n\n{\n  \"type\": \"object\",\n  \"required\": [\n    \"path\"\n  ],\n  \"properties\": {\n    \"path\": {\n      \"type\": \"string\",\n      \"minLength\": 3,\n      \"maxLength\": 1024\n    }\n  },\n  \"additionalProperties\": false\n}",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"path\": \"C:/TabGecko-Beispiel/datei.json\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/api/v1/storage/previous-root/delete$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /api/v1/storage/previous-root/delete\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/api/v1/storage/previous-root/delete\";",
                  "const authenticated = Boolean(pm.variables.get(\"bearerToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    },
    {
      "name": "MCP (zusätzliche reale Route)",
      "item": [
        {
          "name": "POST /mcp — initialize",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json, text/event-stream"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{mcpToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/mcp",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "mcp"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zusätzliches, nicht in OpenAPI enthaltenes Beispiel. Reale zustandslose POST-Route aus packages/core/src/api/mcp/server.ts. initialize meldet Protokoll/Fähigkeiten; tools/list listet die für das Token erlaubten Werkzeuge. Keine tools/call-Ausführung. Eigenes lokales MCP-Token in mcpToken nötig. HTTP 200 kann einen JSON-RPC-Fehler enthalten. Einmalig allowRequestOnce = POST /mcp setzen; jedes Beispiel separat freigeben. Eine Änderung zu tools/call kann schreiben oder Browser steuern.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"jsonrpc\": \"2.0\",\n  \"id\": 1,\n  \"method\": \"initialize\",\n  \"params\": {\n    \"protocolVersion\": \"2025-06-18\",\n    \"capabilities\": {},\n    \"clientInfo\": {\n      \"name\": \"TabGecko-Postman-Beispiel\",\n      \"version\": \"1.0\"\n    }\n  }\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/mcp$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /mcp\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/mcp\";",
                  "const authenticated = Boolean(pm.variables.get(\"mcpToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        },
        {
          "name": "POST /mcp — tools/list",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Content-Type",
                "value": "application/json"
              },
              {
                "key": "Accept",
                "value": "application/json, text/event-stream"
              }
            ],
            "auth": {
              "type": "bearer",
              "bearer": [
                {
                  "key": "token",
                  "value": "{{mcpToken}}",
                  "type": "string"
                }
              ]
            },
            "url": {
              "raw": "{{baseUrl}}/mcp",
              "host": [
                "{{baseUrl}}"
              ],
              "path": [
                "mcp"
              ],
              "query": [],
              "variable": []
            },
            "description": "Zusätzliches, nicht in OpenAPI enthaltenes Beispiel. Reale zustandslose POST-Route aus packages/core/src/api/mcp/server.ts. initialize meldet Protokoll/Fähigkeiten; tools/list listet die für das Token erlaubten Werkzeuge. Keine tools/call-Ausführung. Eigenes lokales MCP-Token in mcpToken nötig. HTTP 200 kann einen JSON-RPC-Fehler enthalten. Einmalig allowRequestOnce = POST /mcp setzen; jedes Beispiel separat freigeben. Eine Änderung zu tools/call kann schreiben oder Browser steuern.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"jsonrpc\": \"2.0\",\n  \"id\": 2,\n  \"method\": \"tools/list\"\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "event": [
            {
              "listen": "prerequest",
              "script": {
                "type": "text/javascript",
                "exec": [
                  "const base = pm.variables.replaceIn(\"{{baseUrl}}\");",
                  "const actual = pm.variables.replaceIn(pm.request.url.toString());",
                  "const local = /^http:\\/\\/(127\\.0\\.0\\.1|localhost|\\[::1\\]):[0-9]{1,5}$/.test(base);",
                  "const matches = actual.startsWith(base + \"/\") && pm.request.method === \"POST\" && new RegExp(\"^/mcp$\").test(actual.slice(base.length).split(\"?\")[0]);",
                  "const permission = pm.environment.get(\"allowRequestOnce\");",
                  "pm.environment.unset(\"allowRequestOnce\");",
                  "const expected = \"POST /mcp\";",
                  "const approved = permission === expected;",
                  "const readOnly = false && actual.split(\"?\")[0] === base + \"/mcp\";",
                  "const authenticated = Boolean(pm.variables.get(\"mcpToken\"));",
                  "if (!local || !matches || !authenticated || (!readOnly && !approved)) {",
                  "  if (!pm.execution || typeof pm.execution.skipRequest !== \"function\") {",
                  "    pm.request.url.update(\"http://127.0.0.1:1/__blocked__\");",
                  "    pm.request.headers.remove(\"Authorization\");",
                  "    throw new Error(\"Postman mit pm.execution.skipRequest erforderlich. Anfrage gesperrt.\");",
                  "  }",
                  "  console.warn(\"Anfrage übersprungen: Loopback/Token prüfen; einzelne Freigabe über allowRequestOnce: \" + expected);",
                  "  pm.execution.skipRequest();",
                  "}"
                ]
              }
            }
          ],
          "protocolProfileBehavior": {
            "followRedirects": false
          },
          "response": []
        }
      ]
    }
  ]
}
