Domma CMS User Manual

Views API

Updated by Darryl Waterhouse on 29 September 2026 2 min read

Views work on every storage adapter - no MongoDB connection is needed: a view over a MongoDB collection runs a native aggregation, and one over a file collection runs the built-in pipeline evaluator. View configs are JSON files in content/views/<slug>.json. The admin endpoints need the views permission for the action named (read, create, update, delete).

Admin Endpoints

GET /api/views

Requires: views read permission

Every view you may see, newest first.

POST /api/views

Requires: views create permission

Create a view. Answers 201. Pipeline stages may be $match, $lookup, $sort, $project, $unwind, $addFields, $group, $count, $skip and $limit; $out, $merge, $function, $accumulator and $graphLookup are refused. Field paths are document paths such as data.status or meta.createdAt.

{
  "title": "Active Members",
  "slug": "active-members",
  "connection": "default",
  "pipeline": {
    "source": "members",
    "stages": [
      { "type": "$match",   "config": { "data.status": "active" } },
      { "type": "$sort",    "config": { "meta.createdAt": -1 } },
      { "type": "$project", "config": { "data.name": 1, "data.email": 1 } }
    ]
  },
  "display": { "mode": "table", "columns": [ { "key": "data.name", "label": "Name" } ], "pageSize": 25 },
  "access": { "roles": ["admin"], "public": false, "rowLevel": null }
}

GET /api/views/:slug

Requires: views read permission

One view config.

PUT /api/views/:slug

Requires: views update permission

Update a view. The same body as POST; every field is optional.

DELETE /api/views/:slug

Requires: views delete permission

Delete a view.

GET /api/views/:slug/execute

Requires: views read permission

Run the view and return a page of results. Query params: page (default 1), limit (default 25).

// Response
{ "results": [ ... ], "total": 142, "page": 1, "limit": 25 }

POST /api/views/_preview

Requires: views update permission

Run an unsaved pipeline (the view editor's Results tab) and return up to 50 rows.

// Request body
{ "source": "members", "connection": "default", "stages": [ ... ], "limit": 10 }

GET /api/views/collection/:slug

Requires: views read permission

The views whose pipeline.source is the given collection.

Public Endpoint

GET /api/views/:slug/public

Access level: per view access config

Run the view for a visitor. This is the same decision [view] on a page makes:

  • access.public: true - anyone.
  • Otherwise a signed-in user holding any role in access.roles, or a more senior one (the page visibility ladder; =role means that role exactly). A role name the site does not have admits only the level-0 role.
  • No roles listed - the admin tier (role levels 0 and 1).

A row-level rule (access.rowLevel: owner, field or reference) is applied as the viewer, so each person sees only their rows and the totals count only those; an anonymous visitor gets no rows. Refused: 401 when not signed in, 403 otherwise.

// Response
{ "results": [ ... ], "total": 12, "page": 1, "limit": 25 }