Skip to main content

rbac.proto

path sdk/rbac.proto

package m10.sdk


Messages​

Attribute​

Attribute represents custom variable that might be used in MQL expressions to evaluate them

NameTypeDescription
namestringName of the attribute (may be any valid string value)
valueAttribute.AttributeValueActual value of the attribute (may be of any type supported by AttributeValue)

Attribute.AttributeValue​

AttributeValue represents all possible types and their values to be used in attributes

NameTypeDescription
uint_valueuint64Value of unsigned integer type
int_valueint64Value of integer type
float_valuedoubleValue of float type ('double' in protobuf is analog of Rust 'f64' type)
bool_valueboolValue of bool type
string_valuestringValue of string type

Expression​

Expression represents a conditional expression that refines the scope of a RoleBinding.

NameTypeDescription
collectionstringThe collection the expression applies to.
expressionstringThe actual expression string. The syntax and semantics of this string are context-dependent.

Role​

Role defines a set of permissions.

NameTypeDescription
idbytesUnique identifier for the Role.
ownerbytesID (public key) of the owner of this Role.
namestringHuman-readable name for the Role.
rulesrepeated RuleList of rules that define the permissions granted by this role.
created_atuint64Timestamp (in milliseconds since Unix epoch) when this Role was created.
updated_atuint64Timestamp (in milliseconds since Unix epoch) when this Role was last updated.
created_bybytesPublic key of the user who created this Role.
descriptionstringOptional description of this Role (max 100 characters).
immutableboolIf true, role cannot be modified or deleted by any principal.
labelsrepeated Role.LabelsEntryOptional labels (metadata) of this Role (Key and Value must be 100 characters or less each)

Role.LabelsEntry​

NameTypeDescription
keystring
valuestring

RoleBinding​

RoleBinding represents the binding of a Role to a set of subjects.

NameTypeDescription
idbytesUnique identifier (uuid) for the RoleBinding.
namestringHuman-readable name for the RoleBinding.
rolebytesReference to the Role being bound. This is expected to be the Role's ID.
subjectsrepeated bytesList of subjects (public keys) this role binding applies to.
expressionsrepeated ExpressionList of expressions that further refine the scope of the role binding.
is_universalboolIf true, this RoleBinding applies universally, regardless of expressions or subjects.
ownerbytesID (public key) of the owner of this RoleBinding.
created_atuint64Timestamp (in milliseconds since Unix epoch) when this RoleBinding was created.
updated_atuint64Timestamp (in milliseconds since Unix epoch) when this RoleBinding was last updated.
created_bybytesPublic key of the user who created this RoleBinding.
descriptionstringOptional description of this RoleBinding (max 100 characters).
expires_atoptional uint64Optional expiry time (unix ms). If set and the current time is past expiry time, the binding is treated as if it does not exist. If absent = never expires.
labelsrepeated RoleBinding.LabelsEntryOptional labels (metadata) of this RoleBinding (Key and Value must be 100 characters or less each).
attributesrepeated AttributeList of attributes that might be used in expressions.

RoleBinding.LabelsEntry​

NameTypeDescription
keystring
valuestring

Rule​

Rule specifies permissions on a particular collection.

NameTypeDescription
effectRule.EffectEffect of this rule. Defaults to ALLOW.
collectionstringThe collection this rule applies to.
instance_keysrepeated ValueOptional list of instance keys. If provided, the rule only applies to these specific instances within the collection. Assumes a Value message is defined elsewhere.
whenoptional stringOptional MQL expression of the rule. If provided, evaluates in runtime whenever actions, that require the rule, are triggered.
typesrepeated Rule.TypesEntryTypes of variables declared in expression. All variables, that were declared in expression, must be annotated with their types here.
permissionsrepeated stringEach entry is "Verb" or "Verb:action" (e.g. "Update" or "Update:set_issuance_limit"). An unqualified verb acts as a wildcard over all actions for that verb; a qualified verb grants only the exact action.

Rule.TypesEntry​

NameTypeDescription
keystring
valueRule.Ty

Enums​

Rule.Effect​

Effect determines whether a rule grants or denies the listed permissions.

NameNumberDescription
ALLOW0
DENY1

Rule.Ty​

Ty defines the type of variables that were declared in Rule expression.

NameNumberDescription
U80Unsigned integer (8 bits)
U161Unsigned integer (16 bits)
U322Unsigned integer (32 bits)
U643Unsigned integer (64 bits)
I84Integer (8 bits)
I165Integer (16 bits)
I326Integer (32 bits)
I647Integer (64 bits)
F328Float (32 bits)
F649Float (64 bits)
BOOL10Boolean
STRING11String

Rule.Verb​

Verb defines the actions a subject can perform on a resource.

NameNumberDescription
READ0Read access
CREATE1Create access
UPDATE2Update access
DELETE3Delete access
TRANSACT4Transaction access
INITIATE5Initiate transaction
COMMIT6Commit transaction
GRANT7Allow granting this permission to others
REVOKE9Allow revoking this permission from others