Package ai.vectros.types
Class AccessProfileRequest
java.lang.Object
ai.vectros.types.AccessProfileRequest
-
Method Details
-
getPrincipalId
- Returns:
- Principal this profile applies to. Must start with
usr_(an authenticated user — the suffix is the user id) orkey_(a scoped API key acting as its own principal — the suffix is the key id). The suffix may contain only letters, digits, underscores, and hyphens. Required when creating (POST); ignored when updating (PUT), where it is taken from the path.
-
getScopes
- Returns:
- Inline scope clauses to grant the principal. Provide exactly one of
scopesorroleIds— setting both, or neither, returns a 400.
-
getRoleIds
- Returns:
- References to one or more roles within the same context that together supply this principal's scopes. The effective grant is each named role's own clauses, concatenated in the order you list them — roles are composed additively, never merged, so each clause keeps meaning exactly what its own author wrote. Provide exactly one of
scopesorroleIds— setting both, or neither, returns a 400. Every id must name a role that exists in this same app context, and no id may repeat. Changes to a role's scopes take effect for all referencing profiles.Composition also decides what
POST /v1/auth/token/assumewill let this principal become: that check is made against ONE role's ownassumablegrant at a time, never against the combination, so listing two roles never creates an entitlement neither role granted on its own.
-
getRoleId
- Returns:
- Deprecated single-role form of
roleIds, accepted for backward compatibility and equivalent toroleIds: ["<value>"]. Setting both is a 400 — sendroleIdsalone. Reads always returnroleIds;roleIdis also returned, but only when exactly one role composes.
-
getIdentityOverrides
- Returns:
- Optional per-context identity overrides, keyed by ownership namespace in
scope:<namespace>form —scope:organdscope:clientfor the reserved namespaces, or any namespace you have registered (for examplescope:group). At most two namespaces may be overridden; any other key is rejected. Each value is 1-128 characters: a letter or digit first, then letters, digits,_or-. Omitting the field leaves any existing overrides unchanged; sending an empty map clears them, and sending a populated map replaces them wholesale — a namespace absent from the map you send is removed. If you use a scoped credential, two bounds apply and either returns 403: you may only set a value your own identity holds, and you may only change or clear a value the profile already holds if that value is yours as well — so clearing or repointing another principal's established identity is refused. A root API key (sk_) is exempt from both.
-
getAssumable
- Returns:
- The
POST /v1/auth/token/assumeentitlement grant: which values, perscope:<namespace>, a holder of THIS profile may assume via/assume. Only meaningful (and only accepted) alongside inlinescopes— aroleId-referencing profile has no clause list of its own to pair a grant with; author the grant on the referenced Role instead, where every profile referencing that role picks it up uniformly. The principal (userId) can never be named — it is never assumable. Each value list accepts a plain literal,${{ under.self.userId }}, or${{ member.scope.<namespace>[:level] }}— never${{ under.self.scope.<namespace> }}(it resolves against the caller's CURRENT value for a namespace/assumecan itself change, so what it admitted would depend on what was last assumed; that form stays valid indata_scope, where it's re-derived per write), a bare${{ self.<dim> }}, or${{ any }}, all rejected at authoring time. Omitting the field grants no assumption of anything, the safe default.
-
getStatus
- Returns:
- Profile lifecycle status.
activepermits token minting;suspendeddenies it (minting returns a uniform 403). Defaults toactivewhen omitted.
-
equals
-
getAdditionalProperties
-
hashCode
public int hashCode() -
toString
-
builder
-