Skip to content
Baack

Permission

Representation of a permission grant. Permissions are fail closed so if an object requires a permission it must be present for the subject with the given label.Permissions represent directed edges granting a subject(type) [label] to object(type). When applied to an object the permissions will be checked for an exists style relationship from the subject scope.

Browse the docs

Endpoints

  • GET/n/v1/permission/{urn}

    Endpoint for managing permission grants on the platform.

    Parameters

    urn (path, required)
    String representation of a Unique Resource Name. Typically a UUID with 36 characters.

    Responses

    200 OK
    returns PermissionREAD_SUCCESS
    404 Not found
    returns ErrorNOT_FOUND
    curl -H "Authorization: Bearer $BAACK_API_TOKEN" \
      https://api.baack.co/n/v1/permission/{urn}

Fields

Permission fields
FieldTypeDescription
urnstring (uuid)
ownerCompany

Required on create.

subjectScopestring

One of: ANY, ACCOUNT, API_CLIENT, COMPANY, EMAIL_ADDRESS, ENTITY, ENTITY_LIST, GROUP, GROUP_MEMBERSHIP, IDENTITY, ORGANISATION, PAYMENT_CARD, PERSON, PROJECT, ROLE, TASK, USER, OAUTH_TOKEN

objectUrnstring (uuid)

Required on create.

fromTimestampstring (date-time)
subjectUrnstring (uuid)

Required on create.

objectScopestring

One of: ANY, ACCOUNT, API_CLIENT, COMPANY, EMAIL_ADDRESS, ENTITY, ENTITY_LIST, GROUP, GROUP_MEMBERSHIP, IDENTITY, ORGANISATION, PAYMENT_CARD, PERSON, PROJECT, ROLE, TASK, USER, OAUTH_TOKEN

labelstring

One of: ALL, CREATE, READ, UPDATE, DELETE, ADMINISTER, MODERATE, ARCHIVE

Up to 255 characters.

toTimestampstring (date-time)