AccessPolicyV2
A set of rules that govern how a system resource is accessed and used.
- Backends
- PostgreSQLElasticsearch
- Interactions
- CreateReadUpdatePatchDelete
- Search
- 3 of 3 parameters tested
Structure
| Element | Card. | Type | Description |
|---|---|---|---|
nameRequired | 1..1 | string | The name of the access policy. |
description | 0..1 | string | Description of the access policy. |
engineRequired | 1..1 | code | The type of evaluation that is performed to determine if access is granted or denied.Binding (required): AccessPolicyEngineV2 |
attribute | 0..15 | BackboneElement | Attributes to use for the policy evaluation. |
attributeIdRequired | 1..1 | id | The id of the attribute referenced using %attributeId in expressions. |
operation | 0..1 | BackboneElement | The operation to retrieve the attribute. |
typeRequired | 1..1 | code | The operation to retrieve the attribute.Binding (required): AccessPolicyAttributeOperationTypes |
path | 0..1 | Expression | The operation to retrieve the attribute. |
params | 0..1 | Expression | The operation to retrieve the attribute. |
rule | 0..* | BackboneElement | The rules that govern how the access policy is applied. |
nameRequired | 1..1 | string | Access Policy rule identifier. |
description | 0..1 | string | Rule description |
combineBehavior | 0..1 | code | Determine wether to use and/or to combine rules.Binding (required): AccessPolicyV2CombineBehavior |
effect | 0..1 | code | Determine whether to evaluate the rule.Binding (required): AccessPolicyV2RuleEffect |
target | 0..1 | BackboneElement | Determine whether to evaluate the rule. |
expressionRequired | 1..1 | Expression | Determine whether to evaluate the rule. |
condition | 0..1 | BackboneElement | Condition to evaluate determining whether pass/deny. |
expressionRequired | 1..1 | Expression | Condition expression to evaluate determining whether pass/deny. |
rule | 0..* | Same as AccessPolicyV2.rule | Nested rules |
target | 0..* | BackboneElement | Deprecated: use AccessPolicyV2Assignment. Who the access policy applies to. |
linkRequired | 1..1 | Reference(ClientApplication | Membership | OperationDefinition) | Deprecated: use AccessPolicyV2Assignment.link. The target reference of the access policy applies to. |
Σ in _summary results · ?! modifier element · 1.. required · inherited elements in grey
Search parameters
Query with GET [base]/AccessPolicyV2?[parameter]=[value]. Type decides which modifiers and prefixes apply, see search features.
| Parameter | Type | Description | PG | ES |
|---|---|---|---|---|
engine | token | An access policies engine. AccessPolicyV2.engine | ||
link | reference | Deprecated: search AccessPolicyV2Assignment by link instead. What/Who is associated with a given access policy through AccessPolicyV2.target. AccessPolicyV2.target.link | ||
name | string | An access policies name. AccessPolicyV2.name |
PG: PostgreSQL, ES: Elasticsearch. passes its TestScript checks, fails, not tested yet. The author of the resource Logical id of this artifact When the resource version last changed Profiles this resource claims to conform to Security Labels applied to this resource Identifies where the resource comes from Tags applied to this resource Derived from the R4B DefinitionCommon parameters on every resource (8)
_haste-health-authorreference _idtoken _lastUpdateddate _profileuri _securitytoken _sourceuri _tagtoken _typetoken