Class ScopeRequest.Builder
- Enclosing class:
ScopeRequest
-
Method Summary
Modifier and TypeMethodDescriptionadditionalProperties(Map<String, Object> additionalProperties) additionalProperty(String key, Object value) allowedActions(List<String> allowedActions) allowedActions(Optional<List<String>> allowedActions) The actions this token may perform.build()Restricts which records the token can access, and authorizes where it may place them.from(ScopeRequest other) Default ownership values stamped onto resources created with this token.
-
Method Details
-
from
-
allowedActions
The actions this token may perform. Each entry has the form
resource:operations, whereoperationsis one ofr(read),c(create),u(update),d(delete),crud(all four), or a colon-separated combination. For records you may append a type qualifier, e.g.records:r:intake_form. For identity entities the grammar isentities:<verb>:<namespace>, e.g.entities:r:orgorentities:c:client(reserved namespacesorgandclient). Valid resources are:entities,users,documents,folders,records,schemas, andsearch.namespacesis deliberately not among them: reading the namespace registry is open to any credential, and registering, updating, or deleting a namespace requires a root API key — so anamespaces:<verb>entry would neither grant nor withhold anything. -
allowedActions
-
identity
Default ownership values stamped onto resources created with this token. Optional. Keys are ownership dimensions:
userId, or any scope namespace in canonicalscope:<namespace>form (e.g.scope:org,scope:client,scope:group). Entity values must be Vectros UUIDs — look them up withGET /v1/usersorGET /v1/entities/{namespace}; custom-scope values are identifiers you define, of 1-128 characters: a letter or digit first, then letters, digits,_or-. These are the values used when a create does not state its own, and the values${{ self.* }}resolves to insidedata_scope. They may be narrowed per create via thescopesrequest field. Identity does NOT bound what this token may stamp —data_scopedoes. To confine a token to its own value in a dimension, name that dimension indata_scopeas${{ self.scope.<namespace> }}. -
identity
-
dataScope
Restricts which records the token can access, and authorizes where it may place them. Optional. Keys are ownership dimensions:
userId, or any scope namespace in canonicalscope:<namespace>form (e.g.scope:org,scope:client,scope:group); values are arrays of permitted values — the token can only access records whose dimension matches one of these values. Use*as the key to state a rule for every dimension not named explicitly; a named dimension always takes precedence over it. Every non-null entity UUID must be a real entity in your account, and each dimension may be named only once. Include a JSONnullin the array (e.g.["uuid", null]) to ALSO match records with no value in THAT dimension — an explicit per-dimension sentinel, NOT a wildcard.${{ any }}matches any value in the dimension but NOT records lacking one, so combine it with null to cover both;${{ self.userId }}/${{ self.scope.<namespace> }}resolve to the credential's own value per request;${{ under.self.userId }}/${{ under.self.scope.<namespace> }}match values whose immediate parent is the credential's own. Reads and writes differ where a dimension is OMITTED: reading is not narrowed by a dimension the data scope says nothing about, but writing a value into that dimension is not authorized by silence — name the dimension (or*) to place data there. An empty object therefore reads tenant-wide and authorizes no placement. -
dataScope
-
build
-
additionalProperty
-
additionalProperties
-