Virtru policy.actions.ActionService API

The policy.actions.ActionService API from Virtru — 5 operation(s) for policy.actions.actionservice.

OpenAPI Specification

virtru-policy-actions-actionservice-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: authorization authorization.AuthorizationService policy.actions.ActionService API
security: []
tags:
- name: policy.actions.ActionService
paths:
  /policy.actions.ActionService/GetAction:
    post:
      tags:
      - policy.actions.ActionService
      summary: GetAction
      operationId: policy.actions.ActionService.GetAction
      parameters:
      - name: Connect-Protocol-Version
        in: header
        required: true
        schema:
          $ref: '#/components/schemas/connect-protocol-version'
      - name: Connect-Timeout-Ms
        in: header
        schema:
          $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/policy.actions.GetActionRequest'
        required: true
      responses:
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/policy.actions.GetActionResponse'
  /policy.actions.ActionService/ListActions:
    post:
      tags:
      - policy.actions.ActionService
      summary: ListActions
      operationId: policy.actions.ActionService.ListActions
      parameters:
      - name: Connect-Protocol-Version
        in: header
        required: true
        schema:
          $ref: '#/components/schemas/connect-protocol-version'
      - name: Connect-Timeout-Ms
        in: header
        schema:
          $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/policy.actions.ListActionsRequest'
        required: true
      responses:
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/policy.actions.ListActionsResponse'
  /policy.actions.ActionService/CreateAction:
    post:
      tags:
      - policy.actions.ActionService
      summary: CreateAction
      operationId: policy.actions.ActionService.CreateAction
      parameters:
      - name: Connect-Protocol-Version
        in: header
        required: true
        schema:
          $ref: '#/components/schemas/connect-protocol-version'
      - name: Connect-Timeout-Ms
        in: header
        schema:
          $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/policy.actions.CreateActionRequest'
        required: true
      responses:
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/policy.actions.CreateActionResponse'
  /policy.actions.ActionService/UpdateAction:
    post:
      tags:
      - policy.actions.ActionService
      summary: UpdateAction
      operationId: policy.actions.ActionService.UpdateAction
      parameters:
      - name: Connect-Protocol-Version
        in: header
        required: true
        schema:
          $ref: '#/components/schemas/connect-protocol-version'
      - name: Connect-Timeout-Ms
        in: header
        schema:
          $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/policy.actions.UpdateActionRequest'
        required: true
      responses:
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/policy.actions.UpdateActionResponse'
  /policy.actions.ActionService/DeleteAction:
    post:
      tags:
      - policy.actions.ActionService
      summary: DeleteAction
      operationId: policy.actions.ActionService.DeleteAction
      parameters:
      - name: Connect-Protocol-Version
        in: header
        required: true
        schema:
          $ref: '#/components/schemas/connect-protocol-version'
      - name: Connect-Timeout-Ms
        in: header
        schema:
          $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/policy.actions.DeleteActionRequest'
        required: true
      responses:
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/policy.actions.DeleteActionResponse'
components:
  schemas:
    policy.PublicKey:
      type: object
      oneOf:
      - properties:
          cached:
            title: cached
            description: public key with additional information. Current preferred version
            $ref: '#/components/schemas/policy.KasPublicKeySet'
        title: cached
        required:
        - cached
      - properties:
          remote:
            type: string
            title: remote
            description: 'kas public key url - optional since can also be retrieved via public key

              URI must be a valid URL (e.g., ''https://demo.com/'') followed by additional segments. Each segment must start and end with an alphanumeric character, can contain hyphens, alphanumeric characters, and slashes.:

              ```

              this.matches(''^https://[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?)*(/.*)?$'')

              ```


              '
        title: remote
        required:
        - remote
      title: PublicKey
      additionalProperties: false
      description: Deprecated
    policy.actions.GetActionRequest:
      type: object
      oneOf:
      - properties:
          id:
            type: string
            title: id
            format: uuid
        title: id
        required:
        - id
      - properties:
          name:
            type: string
            title: name
            maxLength: 253
            description: 'Action name must be an alphanumeric string, allowing hyphens and underscores but not as the first or last character. The stored action name will be normalized to lower case.:

              ```

              this.matches(''^[a-zA-Z0-9](?:[a-zA-Z0-9_-]*[a-zA-Z0-9])?$'')

              ```


              '
        title: name
        required:
        - name
      properties:
        namespaceId:
          type: string
          title: namespace_id
          format: uuid
          description: "Optional namespace ID to scope name-based lookup.\n If omitted for name-based lookup, action search is limited to legacy (namespace_id = NULL) actions."
        namespaceFqn:
          type: string
          title: namespace_fqn
          minLength: 1
          format: uri
          description: "Optional namespace FQN to scope name-based lookup.\n If omitted for name-based lookup, action search is limited to legacy (namespace_id = NULL) actions."
      title: GetActionRequest
      additionalProperties: false
    policy.Algorithm:
      type: string
      title: Algorithm
      enum:
      - ALGORITHM_UNSPECIFIED
      - ALGORITHM_RSA_2048
      - ALGORITHM_RSA_4096
      - ALGORITHM_EC_P256
      - ALGORITHM_EC_P384
      - ALGORITHM_EC_P521
      - ALGORITHM_HPQT_XWING
      - ALGORITHM_HPQT_SECP256R1_MLKEM768
      - ALGORITHM_HPQT_SECP384R1_MLKEM1024
      - ALGORITHM_MLKEM_768
      - ALGORITHM_MLKEM_1024
      description: Supported key algorithms.
    policy.SourceType:
      type: string
      title: SourceType
      enum:
      - SOURCE_TYPE_UNSPECIFIED
      - SOURCE_TYPE_INTERNAL
      - SOURCE_TYPE_EXTERNAL
      description: "Describes whether this kas is managed by the organization or if they imported\n the kas information from an external party. These two modes are necessary in order\n to encrypt a tdf dek with an external parties kas public key."
    policy.SubjectMapping:
      type: object
      properties:
        id:
          type: string
          title: id
        attributeValue:
          title: attribute_value
          description: 'the Attribute Value mapped to; aka: "The Entity Entitlement Attribute"'
          $ref: '#/components/schemas/policy.Value'
        subjectConditionSet:
          title: subject_condition_set
          description: the reusable SubjectConditionSet mapped to the given Attribute Value
          $ref: '#/components/schemas/policy.SubjectConditionSet'
        actions:
          type: array
          items:
            $ref: '#/components/schemas/policy.Action'
          title: actions
          description: The actions permitted by subjects in this mapping
        namespace:
          title: namespace
          description: "the namespace containing this subject mapping\n possible this is empty. If so that means\n the Subject Mapping has not been migrated to a namespace."
          $ref: '#/components/schemas/policy.Namespace'
        metadata:
          title: metadata
          $ref: '#/components/schemas/common.Metadata'
      title: SubjectMapping
      additionalProperties: false
      description: 'Subject Mapping: A Policy assigning Subject Set(s) to a permitted attribute

        value + action(s) combination'
    policy.ObligationTrigger:
      type: object
      properties:
        id:
          type: string
          title: id
        obligationValue:
          title: obligation_value
          $ref: '#/components/schemas/policy.ObligationValue'
        action:
          title: action
          $ref: '#/components/schemas/policy.Action'
        attributeValue:
          title: attribute_value
          $ref: '#/components/schemas/policy.Value'
        context:
          type: array
          items:
            $ref: '#/components/schemas/policy.RequestContext'
          title: context
        namespace:
          title: namespace
          description: The source namespace for this trigger, derived from the attribute value and action.
          $ref: '#/components/schemas/policy.Namespace'
        metadata:
          title: metadata
          $ref: '#/components/schemas/common.Metadata'
      title: ObligationTrigger
      additionalProperties: false
    common.Metadata:
      type: object
      properties:
        createdAt:
          title: created_at
          description: created_at set by server (entity who created will recorded in an audit event)
          $ref: '#/components/schemas/google.protobuf.Timestamp'
        updatedAt:
          title: updated_at
          description: updated_at set by server (entity who updated will recorded in an audit event)
          $ref: '#/components/schemas/google.protobuf.Timestamp'
        labels:
          type: object
          title: labels
          additionalProperties:
            type: string
            title: value
          description: optional short description
      title: Metadata
      additionalProperties: false
      description: Struct to uniquely identify a resource with optional additional metadata
    policy.actions.CreateActionRequest:
      type: object
      properties:
        name:
          type: string
          title: name
          maxLength: 253
          description: 'Required

            Action name must be an alphanumeric string, allowing hyphens and underscores but not as the first or last character. The stored action name will be normalized to lower case.:

            ```

            this.matches(''^[a-zA-Z0-9](?:[a-zA-Z0-9_-]*[a-zA-Z0-9])?$'')

            ```


            '
        namespaceId:
          type: string
          title: namespace_id
          format: uuid
          description: "Optional namespace ID for the custom action.\n If omitted, create targets legacy (namespace_id = NULL) behavior unless enforced by server config."
        namespaceFqn:
          type: string
          title: namespace_fqn
          minLength: 1
          format: uri
          description: "Optional namespace FQN for the custom action.\n If omitted, create targets legacy (namespace_id = NULL) behavior unless enforced by server config."
        metadata:
          title: metadata
          description: Optional
          $ref: '#/components/schemas/common.MetadataMutable'
      title: CreateActionRequest
      required:
      - name
      additionalProperties: false
      description: "Create a new Custom action name with optional metadata.\n Creation of Standard actions is not supported."
    connect-protocol-version:
      type: number
      title: Connect-Protocol-Version
      enum:
      - 1
      description: Define the version of the Connect protocol
      const: 1
    policy.ResourceMappingGroup:
      type: object
      properties:
        id:
          type: string
          title: id
        namespaceId:
          type: string
          title: namespace_id
          description: the namespace containing the group of resource mappings
        name:
          type: string
          title: name
          description: "the common name for the group of resource mappings, which must be unique\n per namespace"
        fqn:
          type: string
          title: fqn
          description: the fully qualified name of the resource mapping group
        metadata:
          title: metadata
          description: Common metadata
          $ref: '#/components/schemas/common.Metadata'
      title: ResourceMappingGroup
      required:
      - namespaceId
      - name
      additionalProperties: false
      description: 'Resource Mapping Groups are namespaced collections of Resource Mappings

        associated under a common group name.'
    google.protobuf.Any:
      type: object
      properties:
        type:
          type: string
        value:
          type: string
          format: binary
        debug:
          type: object
          additionalProperties: true
      additionalProperties: true
      description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.
    policy.PolicyEnforcementPoint:
      type: object
      properties:
        clientId:
          type: string
          title: client_id
          minLength: 1
      title: PolicyEnforcementPoint
      additionalProperties: false
    policy.KasPublicKey:
      type: object
      properties:
        pem:
          type: string
          title: pem
          maxLength: 8192
          minLength: 1
          description: x509 ASN.1 content in PEM envelope, usually
        kid:
          type: string
          title: kid
          maxLength: 32
          minLength: 1
          description: A unique string identifier for this key
        alg:
          not:
            enum:
            - 0
          title: alg
          description: "A known algorithm type with any additional parameters encoded.\n To start, these may be `rsa:2048` for RSA-based wrapping and\n `ec:secp256r1` for EC-based wrapping, but more formats may be added as needed."
          $ref: '#/components/schemas/policy.KasPublicKeyAlgEnum'
      title: KasPublicKey
      additionalProperties: false
      description: "Deprecated\n A KAS public key and some associated metadata for further identifcation"
    policy.KeyAccessServer:
      type: object
      properties:
        id:
          type: string
          title: id
        uri:
          type: string
          title: uri
          description: 'Address of a KAS instance

            URI must be a valid URL (e.g., ''https://demo.com/'') followed by additional segments. Each segment must start and end with an alphanumeric character, can contain hyphens, alphanumeric characters, and slashes.:

            ```

            this.matches(''^https?://[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?)*(:[0-9]+)?(/.*)?$'')

            ```


            '
        publicKey:
          title: public_key
          description: 'Deprecated: KAS can have multiple key pairs'
          $ref: '#/components/schemas/policy.PublicKey'
        sourceType:
          title: source_type
          description: 'The source of the KAS: (INTERNAL, EXTERNAL)'
          $ref: '#/components/schemas/policy.SourceType'
        kasKeys:
          type: array
          items:
            $ref: '#/components/schemas/policy.SimpleKasKey'
          title: kas_keys
          description: Kas keys associated with this KAS
        name:
          type: string
          title: name
          description: "Optional\n Unique name of the KAS instance"
        metadata:
          title: metadata
          description: Common metadata
          $ref: '#/components/schemas/common.Metadata'
      title: KeyAccessServer
      additionalProperties: false
      description: Key Access Server Registry
    policy.SubjectSet:
      type: object
      properties:
        conditionGroups:
          type: array
          items:
            $ref: '#/components/schemas/policy.ConditionGroup'
          title: condition_groups
          minItems: 1
          description: multiple Condition Groups are evaluated with AND logic
      title: SubjectSet
      additionalProperties: false
      description: A collection of Condition Groups
    google.protobuf.Timestamp:
      type: string
      examples:
      - 1s
      - 1.000340012s
      format: date-time
      description: "A Timestamp represents a point in time independent of any time zone or local\n calendar, encoded as a count of seconds and fractions of seconds at\n nanosecond resolution. The count is relative to an epoch at UTC midnight on\n January 1, 1970, in the proleptic Gregorian calendar which extends the\n Gregorian calendar backwards to year one.\n\n All minutes are 60 seconds long. Leap seconds are \"smeared\" so that no leap\n second table is needed for interpretation, using a [24-hour linear\n smear](https://developers.google.com/time/smear).\n\n The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By\n restricting to that range, we ensure that we can convert to and from [RFC\n 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings.\n\n # Examples\n\n Example 1: Compute Timestamp from POSIX `time()`.\n\n     Timestamp timestamp;\n     timestamp.set_seconds(time(NULL));\n     timestamp.set_nanos(0);\n\n Example 2: Compute Timestamp from POSIX `gettimeofday()`.\n\n     struct timeval tv;\n     gettimeofday(&tv, NULL);\n\n     Timestamp timestamp;\n     timestamp.set_seconds(tv.tv_sec);\n     timestamp.set_nanos(tv.tv_usec * 1000);\n\n Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`.\n\n     FILETIME ft;\n     GetSystemTimeAsFileTime(&ft);\n     UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;\n\n     // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z\n     // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.\n     Timestamp timestamp;\n     timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));\n     timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));\n\n Example 4: Compute Timestamp from Java `System.currentTimeMillis()`.\n\n     long millis = System.currentTimeMillis();\n\n     Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)\n         .setNanos((int) ((millis % 1000) * 1000000)).build();\n\n Example 5: Compute Timestamp from Java `Instant.now()`.\n\n     Instant now = Instant.now();\n\n     Timestamp timestamp =\n         Timestamp.newBuilder().setSeconds(now.getEpochSecond())\n             .setNanos(now.getNano()).build();\n\n Example 6: Compute Timestamp from current time in Python.\n\n     timestamp = Timestamp()\n     timestamp.GetCurrentTime()\n\n # JSON Mapping\n\n In JSON format, the Timestamp type is encoded as a string in the\n [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the\n format is \"{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z\"\n where {year} is always expressed using four digits while {month}, {day},\n {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional\n seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution),\n are optional. The \"Z\" suffix indicates the timezone (\"UTC\"); the timezone\n is required. A proto3 JSON serializer should always use UTC (as indicated by\n \"Z\") when printing the Timestamp type and a proto3 JSON parser should be\n able to accept both UTC and other timezones (as indicated by an offset).\n\n For example, \"2017-01-15T01:30:15.01Z\" encodes 15.01 seconds past\n 01:30 UTC on January 15, 2017.\n\n In JavaScript, one can convert a Date object to this format using the\n standard\n [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString)\n method. In Python, a standard `datetime.datetime` object can be converted\n to this format using\n [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with\n the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use\n the Joda Time's [`ISODateTimeFormat.dateTime()`](\n http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime()\n ) to obtain a formatter capable of generating timestamps in this format."
    policy.Obligation:
      type: object
      properties:
        id:
          type: string
          title: id
        namespace:
          title: namespace
          $ref: '#/components/schemas/policy.Namespace'
        name:
          type: string
          title: name
        values:
          type: array
          items:
            $ref: '#/components/schemas/policy.ObligationValue'
          title: values
        fqn:
          type: string
          title: fqn
        metadata:
          title: metadata
          $ref: '#/components/schemas/common.Metadata'
      title: Obligation
      additionalProperties: false
    policy.Action.StandardAction:
      type: string
      title: StandardAction
      enum:
      - STANDARD_ACTION_UNSPECIFIED
      - STANDARD_ACTION_DECRYPT
      - STANDARD_ACTION_TRANSMIT
    policy.ResourceMapping:
      type: object
      properties:
        id:
          type: string
          title: id
        metadata:
          title: metadata
          $ref: '#/components/schemas/common.Metadata'
        attributeValue:
          title: attribute_value
          $ref: '#/components/schemas/policy.Value'
        terms:
          type: array
          items:
            type: string
          title: terms
        group:
          title: group
          $ref: '#/components/schemas/policy.ResourceMappingGroup'
        namespace:
          title: namespace
          description: "The namespace that optionally owns this resource mapping. When the mapping\n belongs to a group, this matches the group's namespace. The mapped\n attribute value may belong to a different namespace."
          $ref: '#/components/schemas/policy.Namespace'
      title: ResourceMapping
      required:
      - attributeValue
      additionalProperties: false
      description: 'Resource Mappings (aka Access Control Resource Encodings aka ACRE) are

        structures supporting the mapping of Resources and Attribute Values'
    policy.actions.CreateActionResponse:
      type: object
      properties:
        action:
          title: action
          $ref: '#/components/schemas/policy.Action'
      title: CreateActionResponse
      additionalProperties: false
    policy.KasPublicKeyAlgEnum:
      type: string
      title: KasPublicKeyAlgEnum
      enum:
      - KAS_PUBLIC_KEY_ALG_ENUM_UNSPECIFIED
      - KAS_PUBLIC_KEY_ALG_ENUM_RSA_2048
      - KAS_PUBLIC_KEY_ALG_ENUM_RSA_4096
      - KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP256R1
      - KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP384R1
      - KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP521R1
      - KAS_PUBLIC_KEY_ALG_ENUM_HPQT_XWING
      - KAS_PUBLIC_KEY_ALG_ENUM_HPQT_SECP256R1_MLKEM768
      - KAS_PUBLIC_KEY_ALG_ENUM_HPQT_SECP384R1_MLKEM1024
      - KAS_PUBLIC_KEY_ALG_ENUM_MLKEM_768
      - KAS_PUBLIC_KEY_ALG_ENUM_MLKEM_1024
    policy.PageResponse:
      type: object
      properties:
        currentOffset:
          type: integer
          title: current_offset
          format: int32
          description: Requested pagination offset
        nextOffset:
          type: integer
          title: next_offset
          format: int32
          description: "Calculated with request limit + offset or defaults\n Empty when none remain after current page"
        total:
          type: integer
          title: total
          format: int32
          description: Total count of entire list
      title: PageResponse
      additionalProperties: false
    policy.RequestContext:
      type: object
      properties:
        pep:
          title: pep
          $ref: '#/components/schemas/policy.PolicyEnforcementPoint'
      title: RequestContext
      required:
      - pep
      additionalProperties: false
      description: Holds the context needed for obligation fulfillment
    policy.Attribute:
      type: object
      properties:
        id:
          type: string
          title: id
        namespace:
          title: namespace
          description: namespace of the attribute
          $ref: '#/components/schemas/policy.Namespace'
        name:
          type: string
          title: name
          description: attribute name
        rule:
          title: rule
          description: attribute rule enum
          $ref: '#/components/schemas/policy.AttributeRuleTypeEnum'
        values:
          type: array
          items:
            $ref: '#/components/schemas/policy.Value'
          title: values
        grants:
          type: array
          items:
            $ref: '#/components/schemas/policy.KeyAccessServer'
          title: grants
          description: Deprecated KAS grants for the attribute. Use kas_keys instead.
        fqn:
          type: string
          title: fqn
        active:
          title: active
          description: active by default until explicitly deactivated
          $ref: '#/components/schemas/google.protobuf.BoolValue'
        kasKeys:
          type: array
          items:
            $ref: '#/components/schemas/policy.SimpleKasKey'
          title: kas_keys
          description: Keys associated with the attribute
        allowTraversal:
          title: allow_traversal
          description: "Whether or not we will use the attribute definition during encryption\n if the attribute value is missing."
          $ref: '#/components/schemas/google.protobuf.BoolValue'
        metadata:
          title: metadata
          description: Common metadata
          $ref: '#/components/schemas/common.Metadata'
      title: Attribute
      required:
      - rule
      additionalProperties: false
    policy.actions.GetActionResponse:
      type: object
      properties:
        action:
          title: action
          $ref: '#/components/schemas/policy.Action'
        subjectMappings:
          type: array
          items:
            $ref: '#/components/schemas/policy.SubjectMapping'
          title: subject_mappings
          description: Subject Mappings driving entitlement to the action
      title: GetActionResponse
      additionalProperties: false
    policy.SimpleKasPublicKey:
      type: object
      properties:
        algorithm:
          title: algorithm
          $ref: '#/components/schemas/policy.Algorithm'
        kid:
          type: string
          title: kid
        pem:
          type: string
          title: pem
      title: SimpleKasPublicKey
      additionalProperties: false
    policy.Condition:
      type: object
      properties:
        subjectExternalSelectorValue:
          type: string
          title: subject_external_selector_value
          description: "a selector for a field value on a flattened Entity Representation (such as\n from idP/LDAP)"
        operator:
          title: operator
          description: the evaluation operator of relation
          $ref: '#/components/schemas/policy.SubjectMappingOperatorEnum'
        subjectExternalValues:
          type: array
          items:
            type: string
            minItems: 1
          title: subject_external_values
          minItems: 1
          description: "list of comparison values for the result of applying the\n subject_external_selector_value on a flattened Entity Representation\n (Subject), evaluated by the operator"
      title: Condition
      required:
      - subjectExternalSelectorValue
      - operator
      additionalProperties: false
      description: '*

        A Condition defines a rule of <the value at the flattened ''selector value''

        location> <operator> <subject external values>'
    policy.SubjectConditionSet:
      type: object
      properties:
        id:
          type: string
          title: id
        namespace:
          title: namespace
          description: "the namespace containing this subject condition set\n possible this is empty in the case a subject condition set\n has not been migrated to a namespace."
          $ref: '#/components/schemas/policy.Namespace'
        subjectSets:
          type: array
          items:
            $ref: '#/components/schemas/policy.SubjectSet'
          title: subject_sets
          minItems: 1
        metadata:
          title: metadata
          $ref: '#/components/schemas/common.Metadata'
      title: SubjectConditionSet
      additionalProperties: false
      description: 'A container for multiple Subject Sets, each containing Condition Groups, each

        containing Conditions. Multiple Subject Sets in a SubjectConditionSet are

        evaluated with AND logic. As each Subject Mapping has only one Attribute

        Value, the SubjectConditionSet is reusable across multiple Subject Mappings /

        Attribute Values and is an independent unit.'
    policy.Value:
      type: object
      properties:
        id:
          type: string
          title: id
          description: generated uuid in database
        attribute:
          title: attribute
          $ref: '#/components/schemas/policy.Attribute'
        value:
          type: string
          title: value
        grants:
          type: array
          items:
            $ref: '#/components/schemas/policy.KeyAccessServer'
          title: grants
          description: Deprecated KAS grants for the value. Use kas_keys instead.
        fqn:
          type: string
          title: fqn
        active:
          title: active
          description: active by default until explicitly deactivated
          $ref: '#/components/schemas/google.protobuf.BoolValue'
        subjectMappings:
          type: array
          items:
            $ref: '#/components/schemas/policy.SubjectMapping'
          title: subject_mappings
          description: subject mapping
        kasKeys:
          type: array
          items:
            $ref: '#/components/schemas/policy.SimpleKasKey'
          title: kas_keys
        resourceMappings:
          type: array
          items:
            $ref: '#/components/schemas/policy.ResourceMapping'
          title: resource_mappings
        obligations:
          type: array
          items:
            $ref: '#/components/schemas/policy.Obligation'
          title: obligations
        metadata:
          title: metadata
          description: Common metadata
          $ref: '#/components/schemas/common.Metadata'
      title: Value
      additionalProperties: false
    policy.actions.DeleteActionRequest:
      type: object
      properties:
        id:
          type: string
          title: id
          format: uuid
          description: Required
      title: DeleteActionRequest
      additionalProperties: false
      descripti

# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/virtru/refs/heads/main/openapi/virtru-policy-actions-actionservice-api-openapi.yml