Skip to main content
Version: 3.4.0-rc.1

cmind/tenants/v1/group_service.proto

Package: cmind.tenants.v1

Messages​

Group​

Group is a custom, named collection of users within a tenant — distinct from the tenant access ladder (TenantRole). Groups are usable as subjects when granting permissions on deployments (group#member in the FGA model). Managing a group — creating, deleting, adding and removing members — is a tenant-admin operation, so those RPCs gate on tenant:{tenant_id} can_admin. Reading is not: group#can_read admits the group's own members and the parent tenant's admins, so a member reads the groups it belongs to and who else is in them, and a tenant admin reads every group of the tenant. Both read RPCs gate on the model, so the rule lives with the rest of the authorization rather than in handler code.

FieldTypeNumberDescription
idstring1
tenantIdstring2
namestring3
memberCountuint324member_count is populated by List responses only.

CreateGroupRequest​

FieldTypeNumberDescription
tenantIdstring1
namestring2

CreateGroupResponse​

FieldTypeNumberDescription
groupGroup1

DeleteGroupRequest​

FieldTypeNumberDescription
tenantIdstring1
groupIdstring2

DeleteGroupResponse​

ListGroupsRequest​

FieldTypeNumberDescription
tenantIdstring1
apiKeyAttachablebool2Only the groups the caller may attach an API key to: its own groups, or every group for a tenant admin.

ListGroupsResponse​

FieldTypeNumberDescription
groupsrepeated Group1

GroupMember​

FieldTypeNumberDescription
userIdstring1
metadatacmind.permissions.v1.UserMetadata2metadata is populated by List responses only. Absent when the user can no longer be resolved (deleted from the identity provider).

ListGroupMembersRequest​

FieldTypeNumberDescription
tenantIdstring1
groupIdstring2

ListGroupMembersResponse​

FieldTypeNumberDescription
membersrepeated GroupMember1

AddGroupMemberRequest​

FieldTypeNumberDescription
tenantIdstring1
groupIdstring2
userIdstring3

AddGroupMemberResponse​

RemoveGroupMemberRequest​

FieldTypeNumberDescription
tenantIdstring1
groupIdstring2
userIdstring3

RemoveGroupMemberResponse​

Services​

GroupService​

CreateGroup​

POST /cmind.tenants.v1.GroupService/CreateGroup

Creates a custom group in the tenant.

Request: CreateGroupRequest

Response: CreateGroupResponse

ListGroups​

GET /cmind.tenants.v1.GroupService/ListGroups

Lists the custom groups the caller may read, or with api_key_attachable the ones it may attach an API key to. The gate admits any tenant member, and the handler then narrows per object on group#can_read or group#can_attach_apikey.

Request: ListGroupsRequest

Response: ListGroupsResponse

DeleteGroup​

POST /cmind.tenants.v1.GroupService/DeleteGroup

Deletes a group.

Request: DeleteGroupRequest

Response: DeleteGroupResponse

ListGroupMembers​

GET /cmind.tenants.v1.GroupService/ListGroupMembers

Lists a group's members. group#can_read admits the group's own members and the parent tenant's readers, so a group outside the caller's reach is refused before the handler runs.

Request: ListGroupMembersRequest

Response: ListGroupMembersResponse

AddGroupMember​

POST /cmind.tenants.v1.GroupService/AddGroupMember

Adds a user to a group.

Request: AddGroupMemberRequest

Response: AddGroupMemberResponse

RemoveGroupMember​

POST /cmind.tenants.v1.GroupService/RemoveGroupMember

Removes a user from a group.

Request: RemoveGroupMemberRequest

Response: RemoveGroupMemberResponse