Interface NamespaceRequest._FinalStage

All Known Implementing Classes:
NamespaceRequest.Builder
Enclosing class:
NamespaceRequest

public static interface NamespaceRequest._FinalStage
  • Method Details

    • build

    • additionalProperty

      NamespaceRequest._FinalStage additionalProperty(String key, Object value)
    • additionalProperties

      NamespaceRequest._FinalStage additionalProperties(Map<String,Object> additionalProperties)
    • entityBacked

      NamespaceRequest._FinalStage entityBacked(Optional<Boolean> entityBacked)

      When true, every scope:<namespace> value in this namespace must resolve to an existing identity entity of the same account and namespace (create entities via POST /v1/entities/{namespace}), and the namespace gains the full identity-entity surface — list its entities, look them up by schema field, and filter other resources by them as a parent. When false (the default), values in this namespace are free-form strings validated by grammar only.

    • entityBacked

      NamespaceRequest._FinalStage entityBacked(Boolean entityBacked)
    • defaultSchemaId

      NamespaceRequest._FinalStage defaultSchemaId(Optional<String> defaultSchemaId)

      Optional ID of a record schema (created via POST /v1/schemas) bound as the default governing schema for entities created in this namespace. Must belong to your account.

    • defaultSchemaId

      NamespaceRequest._FinalStage defaultSchemaId(String defaultSchemaId)
    • membershipRecordType

      NamespaceRequest._FinalStage membershipRecordType(Optional<String> membershipRecordType)

      Optional. The record type holding this namespace's MEMBERSHIP grants — the records that say which values of this namespace a given user belongs to. Supply it together with membershipTargetField and membershipContextId, or omit all three. Declaring it grants nobody anything on its own: a credential receives membership-derived access only if its own role or access profile asks for it by naming ${{ member.scope.<namespace> }} in data_scope.

    • membershipRecordType

      NamespaceRequest._FinalStage membershipRecordType(String membershipRecordType)
    • membershipTargetField

      NamespaceRequest._FinalStage membershipTargetField(Optional<String> membershipTargetField)

      Optional. The field on membershipRecordType naming the user a grant is FOR. It is an ordinary reference field, not an ownership field — the grant is owned by whoever created it, and the namespace value it applies to is the grant's own scope stamp, which is what your placement authority is checked against when you write it.

    • membershipTargetField

      NamespaceRequest._FinalStage membershipTargetField(String membershipTargetField)
    • membershipContextId

      NamespaceRequest._FinalStage membershipContextId(Optional<String> membershipContextId)

      Optional. Which app context holds the membership records. Required alongside the other membership fields on a TENANT-WIDE registration (records always belong to one app context, while a tenant-wide registration is account-wide). Meaningless — and rejected if it disagrees — on a registration owned by one context via ?contextId=: that context's grants live in its own context by construction, so this field need not repeat it.

    • membershipContextId

      NamespaceRequest._FinalStage membershipContextId(String membershipContextId)
    • membershipLevelField

      NamespaceRequest._FinalStage membershipLevelField(Optional<String> membershipLevelField)

      Optional. The field on membershipRecordType naming a grant's LEVEL, so the same user can hold different levels in different values of this namespace — an admin of one team and a viewer of another. Supply it together with membershipLevels, or omit both for plain in-or-out membership. A role selects a level by naming ${{ member.scope.<namespace>:<level> }}. Because the level is an ordinary field on an ordinary record, it is only as trustworthy as who may write that record type: grant create/update/delete on membershipRecordType to the people who ISSUE grants, never to the members those grants govern — a member who can update their own grant row can raise their own level, and it takes effect on their next request.

    • membershipLevelField

      NamespaceRequest._FinalStage membershipLevelField(String membershipLevelField)
    • membershipLevels

      NamespaceRequest._FinalStage membershipLevels(Optional<List<String>> membershipLevels)

      Optional. The complete set of level labels this namespace allows, each following the namespace grammar. A role naming a level that is not in this list is rejected when it is authored, rather than silently matching nothing — so a typo is reported to whoever can fix it. Required alongside membershipLevelField.

    • membershipLevels

      NamespaceRequest._FinalStage membershipLevels(List<String> membershipLevels)