Class AccessProfileRequest.Builder
- All Implemented Interfaces:
AccessProfileRequest._FinalStage,AccessProfileRequest.PrincipalIdStage
- Enclosing class:
AccessProfileRequest
-
Method Summary
Modifier and TypeMethodDescriptionadditionalProperties(Map<String, Object> additionalProperties) additionalProperty(String key, Object value) build()from(AccessProfileRequest other) identityOverrides(Map<String, Object> identityOverrides) Optional per-context identity overrides, keyed by ownership namespace inscope:<namespace>form —scope:organdscope:clientfor the reserved namespaces, or any namespace you have registered (for examplescope:group).identityOverrides(Optional<Map<String, Object>> identityOverrides) Optional per-context identity overrides, keyed by ownership namespace inscope:<namespace>form —scope:organdscope:clientfor the reserved namespaces, or any namespace you have registered (for examplescope:group).principalId(@NotNull String principalId) Principal this profile applies to.Reference to a role within the same context that supplies this principal's scopes.Reference to a role within the same context that supplies this principal's scopes.scopes(List<ScopeClause> scopes) Inline scope clauses to grant the principal.scopes(Optional<List<ScopeClause>> scopes) Inline scope clauses to grant the principal.status(AccessProfileRequestStatus status) Profile lifecycle status.status(Optional<AccessProfileRequestStatus> status) Profile lifecycle status.
-
Method Details
-
from
- Specified by:
fromin interfaceAccessProfileRequest.PrincipalIdStage
-
principalId
Principal this profile applies to. Must start with
usr_(an authenticated user — the suffix is the user id) orkey_(a scoped API key acting as its own principal — the suffix is the key id). The suffix may contain only letters, digits, underscores, and hyphens. Required when creating (POST); ignored when updating (PUT), where it is taken from the path.Principal this profile applies to. Must start with
usr_(an authenticated user — the suffix is the user id) orkey_(a scoped API key acting as its own principal — the suffix is the key id). The suffix may contain only letters, digits, underscores, and hyphens. Required when creating (POST); ignored when updating (PUT), where it is taken from the path.- Specified by:
principalIdin interfaceAccessProfileRequest.PrincipalIdStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
status
Profile lifecycle status.
activepermits token minting;suspendeddenies it (minting returns a uniform 403). Defaults toactivewhen omitted.- Specified by:
statusin interfaceAccessProfileRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
status
Profile lifecycle status.
activepermits token minting;suspendeddenies it (minting returns a uniform 403). Defaults toactivewhen omitted.- Specified by:
statusin interfaceAccessProfileRequest._FinalStage
-
identityOverrides
Optional per-context identity overrides, keyed by ownership namespace in
scope:<namespace>form —scope:organdscope:clientfor the reserved namespaces, or any namespace you have registered (for examplescope:group). At most two namespaces may be overridden; any other key is rejected. Each value is 1-128 characters: a letter or digit first, then letters, digits,_or-. Omitting the field leaves any existing overrides unchanged; sending an empty map clears them, and sending a populated map replaces them wholesale — a namespace absent from the map you send is removed. If you use a scoped credential, two bounds apply and either returns 403: you may only set a value your own identity holds, and you may only change or clear a value the profile already holds if that value is yours as well — so clearing or repointing another principal's established identity is refused. A root API key (sk_) is exempt from both.- Specified by:
identityOverridesin interfaceAccessProfileRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
identityOverrides
public AccessProfileRequest._FinalStage identityOverrides(Optional<Map<String, Object>> identityOverrides) Optional per-context identity overrides, keyed by ownership namespace in
scope:<namespace>form —scope:organdscope:clientfor the reserved namespaces, or any namespace you have registered (for examplescope:group). At most two namespaces may be overridden; any other key is rejected. Each value is 1-128 characters: a letter or digit first, then letters, digits,_or-. Omitting the field leaves any existing overrides unchanged; sending an empty map clears them, and sending a populated map replaces them wholesale — a namespace absent from the map you send is removed. If you use a scoped credential, two bounds apply and either returns 403: you may only set a value your own identity holds, and you may only change or clear a value the profile already holds if that value is yours as well — so clearing or repointing another principal's established identity is refused. A root API key (sk_) is exempt from both.- Specified by:
identityOverridesin interfaceAccessProfileRequest._FinalStage
-
roleId
Reference to a role within the same context that supplies this principal's scopes. Provide exactly one of
scopesorroleId— setting both, or neither, returns a 400. Changes to the role's scopes take effect for all referencing profiles.- Specified by:
roleIdin interfaceAccessProfileRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
roleId
Reference to a role within the same context that supplies this principal's scopes. Provide exactly one of
scopesorroleId— setting both, or neither, returns a 400. Changes to the role's scopes take effect for all referencing profiles.- Specified by:
roleIdin interfaceAccessProfileRequest._FinalStage
-
scopes
Inline scope clauses to grant the principal. Provide exactly one of
scopesorroleId— setting both, or neither, returns a 400.- Specified by:
scopesin interfaceAccessProfileRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
scopes
Inline scope clauses to grant the principal. Provide exactly one of
scopesorroleId— setting both, or neither, returns a 400.- Specified by:
scopesin interfaceAccessProfileRequest._FinalStage
-
build
- Specified by:
buildin interfaceAccessProfileRequest._FinalStage
-
additionalProperty
- Specified by:
additionalPropertyin interfaceAccessProfileRequest._FinalStage
-
additionalProperties
- Specified by:
additionalPropertiesin interfaceAccessProfileRequest._FinalStage
-