path sdk/rbac.proto
package m10.sdk
Messages
Attribute
Attribute represents custom variable that might be used in MQL expressions to evaluate them
| Name | Type | Description |
|---|
name | string | Name of the attribute (may be any valid string value) |
value | Attribute.AttributeValue | Actual value of the attribute (may be of any type supported by AttributeValue) |
Attribute.AttributeValue
AttributeValue represents all possible types and their values to be used in attributes
| Name | Type | Description |
|---|
uint_value | uint64 | Value of unsigned integer type |
int_value | int64 | Value of integer type |
float_value | double | Value of float type ('double' in protobuf is analog of Rust 'f64' type) |
bool_value | bool | Value of bool type |
string_value | string | Value of string type |
Expression
Expression represents a conditional expression that refines the scope of a RoleBinding.
| Name | Type | Description |
|---|
collection | string | The collection the expression applies to. |
expression | string | The actual expression string. The syntax and semantics of this string are context-dependent. |
Role
Role defines a set of permissions.
| Name | Type | Description |
|---|
id | bytes | Unique identifier for the Role. |
owner | bytes | ID (public key) of the owner of this Role. |
name | string | Human-readable name for the Role. |
rules | repeated Rule | List of rules that define the permissions granted by this role. |
created_at | uint64 | Timestamp (in milliseconds since Unix epoch) when this Role was created. |
updated_at | uint64 | Timestamp (in milliseconds since Unix epoch) when this Role was last updated. |
created_by | bytes | Public key of the user who created this Role. |
description | string | Optional description of this Role (max 100 characters). |
immutable | bool | If true, role cannot be modified or deleted by any principal. |
labels | repeated Role.LabelsEntry | Optional labels (metadata) of this Role (Key and Value must be 100 characters or less each) |
Role.LabelsEntry
| Name | Type | Description |
|---|
key | string | |
value | string | |
RoleBinding
RoleBinding represents the binding of a Role to a set of subjects.
| Name | Type | Description |
|---|
id | bytes | Unique identifier (uuid) for the RoleBinding. |
name | string | Human-readable name for the RoleBinding. |
role | bytes | Reference to the Role being bound. This is expected to be the Role's ID. |
subjects | repeated bytes | List of subjects (public keys) this role binding applies to. |
expressions | repeated Expression | List of expressions that further refine the scope of the role binding. |
is_universal | bool | If true, this RoleBinding applies universally, regardless of expressions or subjects. |
owner | bytes | ID (public key) of the owner of this RoleBinding. |
created_at | uint64 | Timestamp (in milliseconds since Unix epoch) when this RoleBinding was created. |
updated_at | uint64 | Timestamp (in milliseconds since Unix epoch) when this RoleBinding was last updated. |
created_by | bytes | Public key of the user who created this RoleBinding. |
description | string | Optional description of this RoleBinding (max 100 characters). |
expires_at | optional uint64 | Optional expiry time (unix ms). If set and the current time is past expiry time,
the binding is treated as if it does not exist. If absent = never expires. |
labels | repeated RoleBinding.LabelsEntry | Optional labels (metadata) of this RoleBinding (Key and Value must be 100 characters or less each). |
attributes | repeated Attribute | List of attributes that might be used in expressions. |
RoleBinding.LabelsEntry
| Name | Type | Description |
|---|
key | string | |
value | string | |
Rule
Rule specifies permissions on a particular collection.
| Name | Type | Description |
|---|
effect | Rule.Effect | Effect of this rule. Defaults to ALLOW. |
collection | string | The collection this rule applies to. |
instance_keys | repeated Value | Optional list of instance keys. If provided, the rule only applies to these specific instances within the collection.
Assumes a Value message is defined elsewhere. |
when | optional string | Optional MQL expression of the rule. If provided, evaluates in runtime whenever actions, that require the rule, are triggered. |
types | repeated Rule.TypesEntry | Types of variables declared in expression. All variables, that were declared in expression, must be annotated with their types here. |
permissions | repeated string | Each entry is "Verb" or "Verb:action" (e.g. "Update" or
"Update:set_issuance_limit"). An unqualified verb acts as a wildcard
over all actions for that verb; a qualified verb grants only the exact
action. |
Rule.TypesEntry
| Name | Type | Description |
|---|
key | string | |
value | Rule.Ty | |
Enums
Rule.Effect
Effect determines whether a rule grants or denies the listed permissions.
| Name | Number | Description |
|---|
ALLOW | 0 | |
DENY | 1 | |
Rule.Ty
Ty defines the type of variables that were declared in Rule expression.
| Name | Number | Description |
|---|
U8 | 0 | Unsigned integer (8 bits) |
U16 | 1 | Unsigned integer (16 bits) |
U32 | 2 | Unsigned integer (32 bits) |
U64 | 3 | Unsigned integer (64 bits) |
I8 | 4 | Integer (8 bits) |
I16 | 5 | Integer (16 bits) |
I32 | 6 | Integer (32 bits) |
I64 | 7 | Integer (64 bits) |
F32 | 8 | Float (32 bits) |
F64 | 9 | Float (64 bits) |
BOOL | 10 | Boolean |
STRING | 11 | String |
Rule.Verb
Verb defines the actions a subject can perform on a resource.
| Name | Number | Description |
|---|
READ | 0 | Read access |
CREATE | 1 | Create access |
UPDATE | 2 | Update access |
DELETE | 3 | Delete access |
TRANSACT | 4 | Transaction access |
INITIATE | 5 | Initiate transaction |
COMMIT | 6 | Commit transaction |
GRANT | 7 | Allow granting this permission to others |
REVOKE | 9 | Allow revoking this permission from others |