AlmondTill/G3N API

EffectivePermission

object type

One operation's evaluation under the flat algorithm: permitted ⟺ at least one allow matched AND no disallow matched (default-DENY, disallow-wins; per-segment * wildcards; ONLY active roles contribute).

Fields

FieldTypeNotes
serviceString String!The logical service name (today: api).
actionString String!The service external operation name (a schema Query/Mutation field).
permittedBoolean Boolean!No further notes.
allowsDescriptorContribution [DescriptorContribution!]!The allow descriptors that matched, attributed to their carrying roles.
disallowsDescriptorContribution [DescriptorContribution!]!The disallow descriptors that matched (ANY entry here forces permitted: false), attributed to their carrying roles.