Package ai.vectros.types
Class ScopeRequest
java.lang.Object
ai.vectros.types.ScopeRequest
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionstatic ScopeRequest.Builderbuilder()booleaninthashCode()toString()
-
Method Details
-
getAllowedActions
- Returns:
- The actions this token may perform. Each entry has the form
resource:operations, whereoperationsis one ofr(read),c(create),u(update),d(delete),crud(all four), or a colon-separated combination. For records you may append a type qualifier, e.g.records:r:intake_form. For identity entities the grammar isentities:<verb>:<namespace>, e.g.entities:r:orgorentities:c:client(reserved namespacesorgandclient). Valid resources are:entities,users,documents,folders,records,schemas, andsearch.namespacesis deliberately not among them: reading the namespace registry is open to any credential, and registering, updating, or deleting a namespace requires a root API key — so anamespaces:<verb>entry would neither grant nor withhold anything.
-
getIdentity
- Returns:
- Default ownership values stamped onto resources created with this token. Optional. Keys are ownership dimensions:
userId, or any scope namespace in canonicalscope:<namespace>form (e.g.scope:org,scope:client,scope:group). Entity values must be Vectros UUIDs — look them up withGET /v1/usersorGET /v1/entities/{namespace}; custom-scope values are identifiers you define, of 1-128 characters: a letter or digit first, then letters, digits,_or-. These are the values used when a create does not state its own, and the values${{ self.* }}resolves to insidedata_scope. They may be narrowed per create via thescopesrequest field. Identity does NOT bound what this token may stamp —data_scopedoes. To confine a token to its own value in a dimension, name that dimension indata_scopeas${{ self.scope.<namespace> }}.
-
getDataScope
- Returns:
- Restricts which records the token can access, and authorizes where it may place them. Optional. Keys are ownership dimensions:
userId, or any scope namespace in canonicalscope:<namespace>form (e.g.scope:org,scope:client,scope:group); values are arrays of permitted values — the token can only access records whose dimension matches one of these values. Use*as the key to state a rule for every dimension not named explicitly; a named dimension always takes precedence over it. Every non-null entity UUID must be a real entity in your account, and each dimension may be named only once. Include a JSONnullin the array (e.g.["uuid", null]) to ALSO match records with no value in THAT dimension — an explicit per-dimension sentinel, NOT a wildcard.${{ any }}matches any value in the dimension but NOT records lacking one, so combine it with null to cover both;${{ self.userId }}/${{ self.scope.<namespace> }}resolve to the credential's own value per request;${{ under.self.userId }}/${{ under.self.scope.<namespace> }}match values whose immediate parent is the credential's own. Reads and writes differ where a dimension is OMITTED: reading is not narrowed by a dimension the data scope says nothing about, but writing a value into that dimension is not authorized by silence — name the dimension (or*) to place data there. An empty object therefore reads tenant-wide and authorizes no placement.
-
equals
-
getAdditionalProperties
-
hashCode
public int hashCode() -
toString
-
builder
-