cmind/permissions/v1/types.proto
Package: cmind.permissions.v1
Enums
SubjectType
| Value | Number | Description |
|---|
SUBJECT_TYPE_UNSPECIFIED | 0 | |
SUBJECT_TYPE_USER | 1 | |
SUBJECT_TYPE_GROUP | 2 | |
SUBJECT_TYPE_TENANT | 3 | Every member of a tenant, as a single subject. Valid only for a tenant the resource is already in scope for: the tenant that owns it, or one it is shared with. Naming any other tenant writes a grant no check can satisfy. |
DeploymentRole
DeploymentRole is the set of user-managed roles, the same for every deployment resource. A grant stored under a relation that predates this set is reported as the role that replaced it.
| Value | Number | Description |
|---|
DEPLOYMENT_ROLE_UNSPECIFIED | 0 | |
DEPLOYMENT_ROLE_ADMIN | 1 | |
DEPLOYMENT_ROLE_READER | 2 | |
Messages
Subject
| Field | Type | Number | Description |
|---|
type | SubjectType | 1 | |
id | string | 2 | |
DeploymentPermission
| Field | Type | Number | Description |
|---|
subject | Subject | 1 | |
role | DeploymentRole | 2 | |
metadata | SubjectMetadata | 3 | metadata is populated by List responses only; writes ignore it. Absent when the referenced user or group can no longer be resolved (deleted from the identity provider) — clients should fall back to displaying the bare subject id. |
| Field | Type | Number | Description |
|---|
user | UserMetadata | 1 | |
group | GroupMetadata | 2 | |
tenant | TenantMetadata | 3 | |
Oneof kind: one of user, group, tenant
| Field | Type | Number | Description |
|---|
username | string | 1 | |
email | string | 2 | |
| Field | Type | Number | Description |
|---|
name | string | 1 | |
| Field | Type | Number | Description |
|---|
name | string | 1 | |