Skip to main content
Version: 3.4.0-rc.1

cmind/permissions/v1/types.proto

Package: cmind.permissions.v1

Enums​

SubjectType​

ValueNumberDescription
SUBJECT_TYPE_UNSPECIFIED0
SUBJECT_TYPE_USER1
SUBJECT_TYPE_GROUP2
SUBJECT_TYPE_TENANT3Every member of a tenant, as a single subject. Valid only for a tenant the resource is already in scope for: the tenant that owns it, or one it is shared with. Naming any other tenant writes a grant no check can satisfy.

DeploymentRole​

DeploymentRole is the set of user-managed roles, the same for every deployment resource. A grant stored under a relation that predates this set is reported as the role that replaced it.

ValueNumberDescription
DEPLOYMENT_ROLE_UNSPECIFIED0
DEPLOYMENT_ROLE_ADMIN1
DEPLOYMENT_ROLE_READER2

Messages​

Subject​

FieldTypeNumberDescription
typeSubjectType1
idstring2

DeploymentPermission​

FieldTypeNumberDescription
subjectSubject1
roleDeploymentRole2
metadataSubjectMetadata3metadata is populated by List responses only; writes ignore it. Absent when the referenced user or group can no longer be resolved (deleted from the identity provider) — clients should fall back to displaying the bare subject id.

SubjectMetadata​

FieldTypeNumberDescription
userUserMetadata1
groupGroupMetadata2
tenantTenantMetadata3

Oneof kind: one of user, group, tenant

UserMetadata​

FieldTypeNumberDescription
usernamestring1
emailstring2

GroupMetadata​

FieldTypeNumberDescription
namestring1

TenantMetadata​

FieldTypeNumberDescription
namestring1