Virtru policy.actions.ActionService API
The policy.actions.ActionService API from Virtru — 5 operation(s) for policy.actions.actionservice.
The policy.actions.ActionService API from Virtru — 5 operation(s) for policy.actions.actionservice.
openapi: 3.1.0
info:
title: authorization authorization.AuthorizationService policy.actions.ActionService API
security: []
tags:
- name: policy.actions.ActionService
paths:
/policy.actions.ActionService/GetAction:
post:
tags:
- policy.actions.ActionService
summary: GetAction
operationId: policy.actions.ActionService.GetAction
parameters:
- name: Connect-Protocol-Version
in: header
required: true
schema:
$ref: '#/components/schemas/connect-protocol-version'
- name: Connect-Timeout-Ms
in: header
schema:
$ref: '#/components/schemas/connect-timeout-header'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.GetActionRequest'
required: true
responses:
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/connect.error'
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.GetActionResponse'
/policy.actions.ActionService/ListActions:
post:
tags:
- policy.actions.ActionService
summary: ListActions
operationId: policy.actions.ActionService.ListActions
parameters:
- name: Connect-Protocol-Version
in: header
required: true
schema:
$ref: '#/components/schemas/connect-protocol-version'
- name: Connect-Timeout-Ms
in: header
schema:
$ref: '#/components/schemas/connect-timeout-header'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.ListActionsRequest'
required: true
responses:
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/connect.error'
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.ListActionsResponse'
/policy.actions.ActionService/CreateAction:
post:
tags:
- policy.actions.ActionService
summary: CreateAction
operationId: policy.actions.ActionService.CreateAction
parameters:
- name: Connect-Protocol-Version
in: header
required: true
schema:
$ref: '#/components/schemas/connect-protocol-version'
- name: Connect-Timeout-Ms
in: header
schema:
$ref: '#/components/schemas/connect-timeout-header'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.CreateActionRequest'
required: true
responses:
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/connect.error'
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.CreateActionResponse'
/policy.actions.ActionService/UpdateAction:
post:
tags:
- policy.actions.ActionService
summary: UpdateAction
operationId: policy.actions.ActionService.UpdateAction
parameters:
- name: Connect-Protocol-Version
in: header
required: true
schema:
$ref: '#/components/schemas/connect-protocol-version'
- name: Connect-Timeout-Ms
in: header
schema:
$ref: '#/components/schemas/connect-timeout-header'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.UpdateActionRequest'
required: true
responses:
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/connect.error'
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.UpdateActionResponse'
/policy.actions.ActionService/DeleteAction:
post:
tags:
- policy.actions.ActionService
summary: DeleteAction
operationId: policy.actions.ActionService.DeleteAction
parameters:
- name: Connect-Protocol-Version
in: header
required: true
schema:
$ref: '#/components/schemas/connect-protocol-version'
- name: Connect-Timeout-Ms
in: header
schema:
$ref: '#/components/schemas/connect-timeout-header'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.DeleteActionRequest'
required: true
responses:
default:
description: Error
content:
application/json:
schema:
$ref: '#/components/schemas/connect.error'
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/policy.actions.DeleteActionResponse'
components:
schemas:
policy.PublicKey:
type: object
oneOf:
- properties:
cached:
title: cached
description: public key with additional information. Current preferred version
$ref: '#/components/schemas/policy.KasPublicKeySet'
title: cached
required:
- cached
- properties:
remote:
type: string
title: remote
description: 'kas public key url - optional since can also be retrieved via public key
URI must be a valid URL (e.g., ''https://demo.com/'') followed by additional segments. Each segment must start and end with an alphanumeric character, can contain hyphens, alphanumeric characters, and slashes.:
```
this.matches(''^https://[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?)*(/.*)?$'')
```
'
title: remote
required:
- remote
title: PublicKey
additionalProperties: false
description: Deprecated
policy.actions.GetActionRequest:
type: object
oneOf:
- properties:
id:
type: string
title: id
format: uuid
title: id
required:
- id
- properties:
name:
type: string
title: name
maxLength: 253
description: 'Action name must be an alphanumeric string, allowing hyphens and underscores but not as the first or last character. The stored action name will be normalized to lower case.:
```
this.matches(''^[a-zA-Z0-9](?:[a-zA-Z0-9_-]*[a-zA-Z0-9])?$'')
```
'
title: name
required:
- name
properties:
namespaceId:
type: string
title: namespace_id
format: uuid
description: "Optional namespace ID to scope name-based lookup.\n If omitted for name-based lookup, action search is limited to legacy (namespace_id = NULL) actions."
namespaceFqn:
type: string
title: namespace_fqn
minLength: 1
format: uri
description: "Optional namespace FQN to scope name-based lookup.\n If omitted for name-based lookup, action search is limited to legacy (namespace_id = NULL) actions."
title: GetActionRequest
additionalProperties: false
policy.Algorithm:
type: string
title: Algorithm
enum:
- ALGORITHM_UNSPECIFIED
- ALGORITHM_RSA_2048
- ALGORITHM_RSA_4096
- ALGORITHM_EC_P256
- ALGORITHM_EC_P384
- ALGORITHM_EC_P521
- ALGORITHM_HPQT_XWING
- ALGORITHM_HPQT_SECP256R1_MLKEM768
- ALGORITHM_HPQT_SECP384R1_MLKEM1024
- ALGORITHM_MLKEM_768
- ALGORITHM_MLKEM_1024
description: Supported key algorithms.
policy.SourceType:
type: string
title: SourceType
enum:
- SOURCE_TYPE_UNSPECIFIED
- SOURCE_TYPE_INTERNAL
- SOURCE_TYPE_EXTERNAL
description: "Describes whether this kas is managed by the organization or if they imported\n the kas information from an external party. These two modes are necessary in order\n to encrypt a tdf dek with an external parties kas public key."
policy.SubjectMapping:
type: object
properties:
id:
type: string
title: id
attributeValue:
title: attribute_value
description: 'the Attribute Value mapped to; aka: "The Entity Entitlement Attribute"'
$ref: '#/components/schemas/policy.Value'
subjectConditionSet:
title: subject_condition_set
description: the reusable SubjectConditionSet mapped to the given Attribute Value
$ref: '#/components/schemas/policy.SubjectConditionSet'
actions:
type: array
items:
$ref: '#/components/schemas/policy.Action'
title: actions
description: The actions permitted by subjects in this mapping
namespace:
title: namespace
description: "the namespace containing this subject mapping\n possible this is empty. If so that means\n the Subject Mapping has not been migrated to a namespace."
$ref: '#/components/schemas/policy.Namespace'
metadata:
title: metadata
$ref: '#/components/schemas/common.Metadata'
title: SubjectMapping
additionalProperties: false
description: 'Subject Mapping: A Policy assigning Subject Set(s) to a permitted attribute
value + action(s) combination'
policy.ObligationTrigger:
type: object
properties:
id:
type: string
title: id
obligationValue:
title: obligation_value
$ref: '#/components/schemas/policy.ObligationValue'
action:
title: action
$ref: '#/components/schemas/policy.Action'
attributeValue:
title: attribute_value
$ref: '#/components/schemas/policy.Value'
context:
type: array
items:
$ref: '#/components/schemas/policy.RequestContext'
title: context
namespace:
title: namespace
description: The source namespace for this trigger, derived from the attribute value and action.
$ref: '#/components/schemas/policy.Namespace'
metadata:
title: metadata
$ref: '#/components/schemas/common.Metadata'
title: ObligationTrigger
additionalProperties: false
common.Metadata:
type: object
properties:
createdAt:
title: created_at
description: created_at set by server (entity who created will recorded in an audit event)
$ref: '#/components/schemas/google.protobuf.Timestamp'
updatedAt:
title: updated_at
description: updated_at set by server (entity who updated will recorded in an audit event)
$ref: '#/components/schemas/google.protobuf.Timestamp'
labels:
type: object
title: labels
additionalProperties:
type: string
title: value
description: optional short description
title: Metadata
additionalProperties: false
description: Struct to uniquely identify a resource with optional additional metadata
policy.actions.CreateActionRequest:
type: object
properties:
name:
type: string
title: name
maxLength: 253
description: 'Required
Action name must be an alphanumeric string, allowing hyphens and underscores but not as the first or last character. The stored action name will be normalized to lower case.:
```
this.matches(''^[a-zA-Z0-9](?:[a-zA-Z0-9_-]*[a-zA-Z0-9])?$'')
```
'
namespaceId:
type: string
title: namespace_id
format: uuid
description: "Optional namespace ID for the custom action.\n If omitted, create targets legacy (namespace_id = NULL) behavior unless enforced by server config."
namespaceFqn:
type: string
title: namespace_fqn
minLength: 1
format: uri
description: "Optional namespace FQN for the custom action.\n If omitted, create targets legacy (namespace_id = NULL) behavior unless enforced by server config."
metadata:
title: metadata
description: Optional
$ref: '#/components/schemas/common.MetadataMutable'
title: CreateActionRequest
required:
- name
additionalProperties: false
description: "Create a new Custom action name with optional metadata.\n Creation of Standard actions is not supported."
connect-protocol-version:
type: number
title: Connect-Protocol-Version
enum:
- 1
description: Define the version of the Connect protocol
const: 1
policy.ResourceMappingGroup:
type: object
properties:
id:
type: string
title: id
namespaceId:
type: string
title: namespace_id
description: the namespace containing the group of resource mappings
name:
type: string
title: name
description: "the common name for the group of resource mappings, which must be unique\n per namespace"
fqn:
type: string
title: fqn
description: the fully qualified name of the resource mapping group
metadata:
title: metadata
description: Common metadata
$ref: '#/components/schemas/common.Metadata'
title: ResourceMappingGroup
required:
- namespaceId
- name
additionalProperties: false
description: 'Resource Mapping Groups are namespaced collections of Resource Mappings
associated under a common group name.'
google.protobuf.Any:
type: object
properties:
type:
type: string
value:
type: string
format: binary
debug:
type: object
additionalProperties: true
additionalProperties: true
description: Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.
policy.PolicyEnforcementPoint:
type: object
properties:
clientId:
type: string
title: client_id
minLength: 1
title: PolicyEnforcementPoint
additionalProperties: false
policy.KasPublicKey:
type: object
properties:
pem:
type: string
title: pem
maxLength: 8192
minLength: 1
description: x509 ASN.1 content in PEM envelope, usually
kid:
type: string
title: kid
maxLength: 32
minLength: 1
description: A unique string identifier for this key
alg:
not:
enum:
- 0
title: alg
description: "A known algorithm type with any additional parameters encoded.\n To start, these may be `rsa:2048` for RSA-based wrapping and\n `ec:secp256r1` for EC-based wrapping, but more formats may be added as needed."
$ref: '#/components/schemas/policy.KasPublicKeyAlgEnum'
title: KasPublicKey
additionalProperties: false
description: "Deprecated\n A KAS public key and some associated metadata for further identifcation"
policy.KeyAccessServer:
type: object
properties:
id:
type: string
title: id
uri:
type: string
title: uri
description: 'Address of a KAS instance
URI must be a valid URL (e.g., ''https://demo.com/'') followed by additional segments. Each segment must start and end with an alphanumeric character, can contain hyphens, alphanumeric characters, and slashes.:
```
this.matches(''^https?://[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]{0,61}[a-zA-Z0-9])?)*(:[0-9]+)?(/.*)?$'')
```
'
publicKey:
title: public_key
description: 'Deprecated: KAS can have multiple key pairs'
$ref: '#/components/schemas/policy.PublicKey'
sourceType:
title: source_type
description: 'The source of the KAS: (INTERNAL, EXTERNAL)'
$ref: '#/components/schemas/policy.SourceType'
kasKeys:
type: array
items:
$ref: '#/components/schemas/policy.SimpleKasKey'
title: kas_keys
description: Kas keys associated with this KAS
name:
type: string
title: name
description: "Optional\n Unique name of the KAS instance"
metadata:
title: metadata
description: Common metadata
$ref: '#/components/schemas/common.Metadata'
title: KeyAccessServer
additionalProperties: false
description: Key Access Server Registry
policy.SubjectSet:
type: object
properties:
conditionGroups:
type: array
items:
$ref: '#/components/schemas/policy.ConditionGroup'
title: condition_groups
minItems: 1
description: multiple Condition Groups are evaluated with AND logic
title: SubjectSet
additionalProperties: false
description: A collection of Condition Groups
google.protobuf.Timestamp:
type: string
examples:
- 1s
- 1.000340012s
format: date-time
description: "A Timestamp represents a point in time independent of any time zone or local\n calendar, encoded as a count of seconds and fractions of seconds at\n nanosecond resolution. The count is relative to an epoch at UTC midnight on\n January 1, 1970, in the proleptic Gregorian calendar which extends the\n Gregorian calendar backwards to year one.\n\n All minutes are 60 seconds long. Leap seconds are \"smeared\" so that no leap\n second table is needed for interpretation, using a [24-hour linear\n smear](https://developers.google.com/time/smear).\n\n The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By\n restricting to that range, we ensure that we can convert to and from [RFC\n 3339](https://www.ietf.org/rfc/rfc3339.txt) date strings.\n\n # Examples\n\n Example 1: Compute Timestamp from POSIX `time()`.\n\n Timestamp timestamp;\n timestamp.set_seconds(time(NULL));\n timestamp.set_nanos(0);\n\n Example 2: Compute Timestamp from POSIX `gettimeofday()`.\n\n struct timeval tv;\n gettimeofday(&tv, NULL);\n\n Timestamp timestamp;\n timestamp.set_seconds(tv.tv_sec);\n timestamp.set_nanos(tv.tv_usec * 1000);\n\n Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`.\n\n FILETIME ft;\n GetSystemTimeAsFileTime(&ft);\n UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;\n\n // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z\n // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.\n Timestamp timestamp;\n timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));\n timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));\n\n Example 4: Compute Timestamp from Java `System.currentTimeMillis()`.\n\n long millis = System.currentTimeMillis();\n\n Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)\n .setNanos((int) ((millis % 1000) * 1000000)).build();\n\n Example 5: Compute Timestamp from Java `Instant.now()`.\n\n Instant now = Instant.now();\n\n Timestamp timestamp =\n Timestamp.newBuilder().setSeconds(now.getEpochSecond())\n .setNanos(now.getNano()).build();\n\n Example 6: Compute Timestamp from current time in Python.\n\n timestamp = Timestamp()\n timestamp.GetCurrentTime()\n\n # JSON Mapping\n\n In JSON format, the Timestamp type is encoded as a string in the\n [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the\n format is \"{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z\"\n where {year} is always expressed using four digits while {month}, {day},\n {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional\n seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution),\n are optional. The \"Z\" suffix indicates the timezone (\"UTC\"); the timezone\n is required. A proto3 JSON serializer should always use UTC (as indicated by\n \"Z\") when printing the Timestamp type and a proto3 JSON parser should be\n able to accept both UTC and other timezones (as indicated by an offset).\n\n For example, \"2017-01-15T01:30:15.01Z\" encodes 15.01 seconds past\n 01:30 UTC on January 15, 2017.\n\n In JavaScript, one can convert a Date object to this format using the\n standard\n [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString)\n method. In Python, a standard `datetime.datetime` object can be converted\n to this format using\n [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with\n the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use\n the Joda Time's [`ISODateTimeFormat.dateTime()`](\n http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime()\n ) to obtain a formatter capable of generating timestamps in this format."
policy.Obligation:
type: object
properties:
id:
type: string
title: id
namespace:
title: namespace
$ref: '#/components/schemas/policy.Namespace'
name:
type: string
title: name
values:
type: array
items:
$ref: '#/components/schemas/policy.ObligationValue'
title: values
fqn:
type: string
title: fqn
metadata:
title: metadata
$ref: '#/components/schemas/common.Metadata'
title: Obligation
additionalProperties: false
policy.Action.StandardAction:
type: string
title: StandardAction
enum:
- STANDARD_ACTION_UNSPECIFIED
- STANDARD_ACTION_DECRYPT
- STANDARD_ACTION_TRANSMIT
policy.ResourceMapping:
type: object
properties:
id:
type: string
title: id
metadata:
title: metadata
$ref: '#/components/schemas/common.Metadata'
attributeValue:
title: attribute_value
$ref: '#/components/schemas/policy.Value'
terms:
type: array
items:
type: string
title: terms
group:
title: group
$ref: '#/components/schemas/policy.ResourceMappingGroup'
namespace:
title: namespace
description: "The namespace that optionally owns this resource mapping. When the mapping\n belongs to a group, this matches the group's namespace. The mapped\n attribute value may belong to a different namespace."
$ref: '#/components/schemas/policy.Namespace'
title: ResourceMapping
required:
- attributeValue
additionalProperties: false
description: 'Resource Mappings (aka Access Control Resource Encodings aka ACRE) are
structures supporting the mapping of Resources and Attribute Values'
policy.actions.CreateActionResponse:
type: object
properties:
action:
title: action
$ref: '#/components/schemas/policy.Action'
title: CreateActionResponse
additionalProperties: false
policy.KasPublicKeyAlgEnum:
type: string
title: KasPublicKeyAlgEnum
enum:
- KAS_PUBLIC_KEY_ALG_ENUM_UNSPECIFIED
- KAS_PUBLIC_KEY_ALG_ENUM_RSA_2048
- KAS_PUBLIC_KEY_ALG_ENUM_RSA_4096
- KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP256R1
- KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP384R1
- KAS_PUBLIC_KEY_ALG_ENUM_EC_SECP521R1
- KAS_PUBLIC_KEY_ALG_ENUM_HPQT_XWING
- KAS_PUBLIC_KEY_ALG_ENUM_HPQT_SECP256R1_MLKEM768
- KAS_PUBLIC_KEY_ALG_ENUM_HPQT_SECP384R1_MLKEM1024
- KAS_PUBLIC_KEY_ALG_ENUM_MLKEM_768
- KAS_PUBLIC_KEY_ALG_ENUM_MLKEM_1024
policy.PageResponse:
type: object
properties:
currentOffset:
type: integer
title: current_offset
format: int32
description: Requested pagination offset
nextOffset:
type: integer
title: next_offset
format: int32
description: "Calculated with request limit + offset or defaults\n Empty when none remain after current page"
total:
type: integer
title: total
format: int32
description: Total count of entire list
title: PageResponse
additionalProperties: false
policy.RequestContext:
type: object
properties:
pep:
title: pep
$ref: '#/components/schemas/policy.PolicyEnforcementPoint'
title: RequestContext
required:
- pep
additionalProperties: false
description: Holds the context needed for obligation fulfillment
policy.Attribute:
type: object
properties:
id:
type: string
title: id
namespace:
title: namespace
description: namespace of the attribute
$ref: '#/components/schemas/policy.Namespace'
name:
type: string
title: name
description: attribute name
rule:
title: rule
description: attribute rule enum
$ref: '#/components/schemas/policy.AttributeRuleTypeEnum'
values:
type: array
items:
$ref: '#/components/schemas/policy.Value'
title: values
grants:
type: array
items:
$ref: '#/components/schemas/policy.KeyAccessServer'
title: grants
description: Deprecated KAS grants for the attribute. Use kas_keys instead.
fqn:
type: string
title: fqn
active:
title: active
description: active by default until explicitly deactivated
$ref: '#/components/schemas/google.protobuf.BoolValue'
kasKeys:
type: array
items:
$ref: '#/components/schemas/policy.SimpleKasKey'
title: kas_keys
description: Keys associated with the attribute
allowTraversal:
title: allow_traversal
description: "Whether or not we will use the attribute definition during encryption\n if the attribute value is missing."
$ref: '#/components/schemas/google.protobuf.BoolValue'
metadata:
title: metadata
description: Common metadata
$ref: '#/components/schemas/common.Metadata'
title: Attribute
required:
- rule
additionalProperties: false
policy.actions.GetActionResponse:
type: object
properties:
action:
title: action
$ref: '#/components/schemas/policy.Action'
subjectMappings:
type: array
items:
$ref: '#/components/schemas/policy.SubjectMapping'
title: subject_mappings
description: Subject Mappings driving entitlement to the action
title: GetActionResponse
additionalProperties: false
policy.SimpleKasPublicKey:
type: object
properties:
algorithm:
title: algorithm
$ref: '#/components/schemas/policy.Algorithm'
kid:
type: string
title: kid
pem:
type: string
title: pem
title: SimpleKasPublicKey
additionalProperties: false
policy.Condition:
type: object
properties:
subjectExternalSelectorValue:
type: string
title: subject_external_selector_value
description: "a selector for a field value on a flattened Entity Representation (such as\n from idP/LDAP)"
operator:
title: operator
description: the evaluation operator of relation
$ref: '#/components/schemas/policy.SubjectMappingOperatorEnum'
subjectExternalValues:
type: array
items:
type: string
minItems: 1
title: subject_external_values
minItems: 1
description: "list of comparison values for the result of applying the\n subject_external_selector_value on a flattened Entity Representation\n (Subject), evaluated by the operator"
title: Condition
required:
- subjectExternalSelectorValue
- operator
additionalProperties: false
description: '*
A Condition defines a rule of <the value at the flattened ''selector value''
location> <operator> <subject external values>'
policy.SubjectConditionSet:
type: object
properties:
id:
type: string
title: id
namespace:
title: namespace
description: "the namespace containing this subject condition set\n possible this is empty in the case a subject condition set\n has not been migrated to a namespace."
$ref: '#/components/schemas/policy.Namespace'
subjectSets:
type: array
items:
$ref: '#/components/schemas/policy.SubjectSet'
title: subject_sets
minItems: 1
metadata:
title: metadata
$ref: '#/components/schemas/common.Metadata'
title: SubjectConditionSet
additionalProperties: false
description: 'A container for multiple Subject Sets, each containing Condition Groups, each
containing Conditions. Multiple Subject Sets in a SubjectConditionSet are
evaluated with AND logic. As each Subject Mapping has only one Attribute
Value, the SubjectConditionSet is reusable across multiple Subject Mappings /
Attribute Values and is an independent unit.'
policy.Value:
type: object
properties:
id:
type: string
title: id
description: generated uuid in database
attribute:
title: attribute
$ref: '#/components/schemas/policy.Attribute'
value:
type: string
title: value
grants:
type: array
items:
$ref: '#/components/schemas/policy.KeyAccessServer'
title: grants
description: Deprecated KAS grants for the value. Use kas_keys instead.
fqn:
type: string
title: fqn
active:
title: active
description: active by default until explicitly deactivated
$ref: '#/components/schemas/google.protobuf.BoolValue'
subjectMappings:
type: array
items:
$ref: '#/components/schemas/policy.SubjectMapping'
title: subject_mappings
description: subject mapping
kasKeys:
type: array
items:
$ref: '#/components/schemas/policy.SimpleKasKey'
title: kas_keys
resourceMappings:
type: array
items:
$ref: '#/components/schemas/policy.ResourceMapping'
title: resource_mappings
obligations:
type: array
items:
$ref: '#/components/schemas/policy.Obligation'
title: obligations
metadata:
title: metadata
description: Common metadata
$ref: '#/components/schemas/common.Metadata'
title: Value
additionalProperties: false
policy.actions.DeleteActionRequest:
type: object
properties:
id:
type: string
title: id
format: uuid
description: Required
title: DeleteActionRequest
additionalProperties: false
descripti
# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/virtru/refs/heads/main/openapi/virtru-policy-actions-actionservice-api-openapi.yml