Class NamespaceRequest.Builder
- All Implemented Interfaces:
NamespaceRequest._FinalStage,NamespaceRequest.NamespaceStage,NamespaceRequest.SpecificityRankStage
- Enclosing class:
NamespaceRequest
-
Method Summary
Modifier and TypeMethodDescriptionadditionalProperties(Map<String, Object> additionalProperties) additionalProperty(String key, Object value) build()defaultSchemaId(String defaultSchemaId) Optional ID of a record schema (created viaPOST /v1/schemas) bound as the default governing schema for entities created in this namespace.defaultSchemaId(Optional<String> defaultSchemaId) Optional ID of a record schema (created viaPOST /v1/schemas) bound as the default governing schema for entities created in this namespace.entityBacked(Boolean entityBacked) Whentrue, everyscope:<namespace>value in this namespace must resolve to an existing identity entity of the same account and namespace (create entities viaPOST /v1/entities/{namespace}), and the namespace gains the full identity-entity surface — list its entities, look them up by schema field, and filter other resources by them as a parent.entityBacked(Optional<Boolean> entityBacked) Whentrue, everyscope:<namespace>value in this namespace must resolve to an existing identity entity of the same account and namespace (create entities viaPOST /v1/entities/{namespace}), and the namespace gains the full identity-entity surface — list its entities, look them up by schema field, and filter other resources by them as a parent.from(NamespaceRequest other) membershipContextId(String membershipContextId) Optional.membershipContextId(Optional<String> membershipContextId) Optional.membershipLevelField(String membershipLevelField) Optional.membershipLevelField(Optional<String> membershipLevelField) Optional.membershipLevels(List<String> membershipLevels) Optional.membershipLevels(Optional<List<String>> membershipLevels) Optional.membershipRecordType(String membershipRecordType) Optional.membershipRecordType(Optional<String> membershipRecordType) Optional.membershipTargetField(String membershipTargetField) Optional.membershipTargetField(Optional<String> membershipTargetField) Optional.The namespace to register: 2-32 characters, a lowercase letter first, then lowercase letters, digits,_or-.specificityRank(int specificityRank) This namespace's position in your account's specificity order, used to break a tie when a caller holds two scope dimensions at once during recordType schema resolution — the higher-ranked (more specific) dimension's schema wins.
-
Method Details
-
from
- Specified by:
fromin interfaceNamespaceRequest.NamespaceStage
-
namespace
The namespace to register: 2-32 characters, a lowercase letter first, then lowercase letters, digits,
_or-.organdclientare reserved names, registered the same way as any other namespace. Deleting any namespace — these two included — is refused while entities still reference it. Required on registration; on update it must match the path and is otherwise ignored (the namespace is immutable).The namespace to register: 2-32 characters, a lowercase letter first, then lowercase letters, digits,
_or-.organdclientare reserved names, registered the same way as any other namespace. Deleting any namespace — these two included — is refused while entities still reference it. Required on registration; on update it must match the path and is otherwise ignored (the namespace is immutable).- Specified by:
namespacein interfaceNamespaceRequest.NamespaceStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
specificityRank
This namespace's position in your account's specificity order, used to break a tie when a caller holds two scope dimensions at once during recordType schema resolution — the higher-ranked (more specific) dimension's schema wins. Required on registration (no default); must be an integer between 0 and 1000000, and unique across every namespace in your account — including
organdclient, once registered (org=1000,client=2000). Optional on update — omit to leave it unchanged.This namespace's position in your account's specificity order, used to break a tie when a caller holds two scope dimensions at once during recordType schema resolution — the higher-ranked (more specific) dimension's schema wins. Required on registration (no default); must be an integer between 0 and 1000000, and unique across every namespace in your account — including
organdclient, once registered (org=1000,client=2000). Optional on update — omit to leave it unchanged.- Specified by:
specificityRankin interfaceNamespaceRequest.SpecificityRankStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
membershipLevels
Optional. The complete set of level labels this namespace allows, each following the namespace grammar. A role naming a level that is not in this list is rejected when it is authored, rather than silently matching nothing — so a typo is reported to whoever can fix it. Required alongside
membershipLevelField.- Specified by:
membershipLevelsin interfaceNamespaceRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
membershipLevels
Optional. The complete set of level labels this namespace allows, each following the namespace grammar. A role naming a level that is not in this list is rejected when it is authored, rather than silently matching nothing — so a typo is reported to whoever can fix it. Required alongside
membershipLevelField.- Specified by:
membershipLevelsin interfaceNamespaceRequest._FinalStage
-
membershipLevelField
Optional. The field on
membershipRecordTypenaming a grant's LEVEL, so the same user can hold different levels in different values of this namespace — an admin of one team and a viewer of another. Supply it together withmembershipLevels, or omit both for plain in-or-out membership. A role selects a level by naming${{ member.scope.<namespace>:<level> }}. Because the level is an ordinary field on an ordinary record, it is only as trustworthy as who may write that record type: grant create/update/delete onmembershipRecordTypeto the people who ISSUE grants, never to the members those grants govern — a member who can update their own grant row can raise their own level, and it takes effect on their next request.- Specified by:
membershipLevelFieldin interfaceNamespaceRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
membershipLevelField
Optional. The field on
membershipRecordTypenaming a grant's LEVEL, so the same user can hold different levels in different values of this namespace — an admin of one team and a viewer of another. Supply it together withmembershipLevels, or omit both for plain in-or-out membership. A role selects a level by naming${{ member.scope.<namespace>:<level> }}. Because the level is an ordinary field on an ordinary record, it is only as trustworthy as who may write that record type: grant create/update/delete onmembershipRecordTypeto the people who ISSUE grants, never to the members those grants govern — a member who can update their own grant row can raise their own level, and it takes effect on their next request.- Specified by:
membershipLevelFieldin interfaceNamespaceRequest._FinalStage
-
membershipContextId
Optional. Which app context holds the membership records. Required alongside the other membership fields on a TENANT-WIDE registration (records always belong to one app context, while a tenant-wide registration is account-wide). Meaningless — and rejected if it disagrees — on a registration owned by one context via
?contextId=: that context's grants live in its own context by construction, so this field need not repeat it.- Specified by:
membershipContextIdin interfaceNamespaceRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
membershipContextId
Optional. Which app context holds the membership records. Required alongside the other membership fields on a TENANT-WIDE registration (records always belong to one app context, while a tenant-wide registration is account-wide). Meaningless — and rejected if it disagrees — on a registration owned by one context via
?contextId=: that context's grants live in its own context by construction, so this field need not repeat it.- Specified by:
membershipContextIdin interfaceNamespaceRequest._FinalStage
-
membershipTargetField
Optional. The field on
membershipRecordTypenaming the user a grant is FOR. It is an ordinary reference field, not an ownership field — the grant is owned by whoever created it, and the namespace value it applies to is the grant's own scope stamp, which is what your placement authority is checked against when you write it.- Specified by:
membershipTargetFieldin interfaceNamespaceRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
membershipTargetField
Optional. The field on
membershipRecordTypenaming the user a grant is FOR. It is an ordinary reference field, not an ownership field — the grant is owned by whoever created it, and the namespace value it applies to is the grant's own scope stamp, which is what your placement authority is checked against when you write it.- Specified by:
membershipTargetFieldin interfaceNamespaceRequest._FinalStage
-
membershipRecordType
Optional. The record type holding this namespace's MEMBERSHIP grants — the records that say which values of this namespace a given user belongs to. Supply it together with
membershipTargetFieldandmembershipContextId, or omit all three. Declaring it grants nobody anything on its own: a credential receives membership-derived access only if its own role or access profile asks for it by naming${{ member.scope.<namespace> }}indata_scope.- Specified by:
membershipRecordTypein interfaceNamespaceRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
membershipRecordType
Optional. The record type holding this namespace's MEMBERSHIP grants — the records that say which values of this namespace a given user belongs to. Supply it together with
membershipTargetFieldandmembershipContextId, or omit all three. Declaring it grants nobody anything on its own: a credential receives membership-derived access only if its own role or access profile asks for it by naming${{ member.scope.<namespace> }}indata_scope.- Specified by:
membershipRecordTypein interfaceNamespaceRequest._FinalStage
-
defaultSchemaId
Optional ID of a record schema (created via
POST /v1/schemas) bound as the default governing schema for entities created in this namespace. Must belong to your account.- Specified by:
defaultSchemaIdin interfaceNamespaceRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
defaultSchemaId
Optional ID of a record schema (created via
POST /v1/schemas) bound as the default governing schema for entities created in this namespace. Must belong to your account.- Specified by:
defaultSchemaIdin interfaceNamespaceRequest._FinalStage
-
entityBacked
When
true, everyscope:<namespace>value in this namespace must resolve to an existing identity entity of the same account and namespace (create entities viaPOST /v1/entities/{namespace}), and the namespace gains the full identity-entity surface — list its entities, look them up by schema field, and filter other resources by them as a parent. Whenfalse(the default), values in this namespace are free-form strings validated by grammar only.- Specified by:
entityBackedin interfaceNamespaceRequest._FinalStage- Returns:
- Reference to
thisso that method calls can be chained together.
-
entityBacked
When
true, everyscope:<namespace>value in this namespace must resolve to an existing identity entity of the same account and namespace (create entities viaPOST /v1/entities/{namespace}), and the namespace gains the full identity-entity surface — list its entities, look them up by schema field, and filter other resources by them as a parent. Whenfalse(the default), values in this namespace are free-form strings validated by grammar only.- Specified by:
entityBackedin interfaceNamespaceRequest._FinalStage
-
build
- Specified by:
buildin interfaceNamespaceRequest._FinalStage
-
additionalProperty
- Specified by:
additionalPropertyin interfaceNamespaceRequest._FinalStage
-
additionalProperties
- Specified by:
additionalPropertiesin interfaceNamespaceRequest._FinalStage
-