diff --git a/.generator/schemas/v2/openapi.yaml b/.generator/schemas/v2/openapi.yaml index 8307610ee5f5..419caee7342a 100644 --- a/.generator/schemas/v2/openapi.yaml +++ b/.generator/schemas/v2/openapi.yaml @@ -95624,6 +95624,12 @@ components: format: date-time readOnly: true type: string + default_permissions_opt_out: + description: |- + Whether to exclude restricted default permissions from this role. + Restricted default permissions are automatically assigned to every role by default. Set this field to `true` to exclude them. + Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization. + type: boolean modified_at: description: Time of last role modification. format: date-time @@ -95755,6 +95761,12 @@ components: format: date-time readOnly: true type: string + default_permissions_opt_out: + description: |- + Whether to exclude restricted default permissions from this role. + Restricted default permissions are automatically assigned to every role by default. Set this field to `true` to exclude them. + Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization. + type: boolean modified_at: description: Time of last role modification. format: date-time diff --git a/features/v2/roles.feature b/features/v2/roles.feature index b926c82f443a..60dc17e9644d 100644 --- a/features/v2/roles.feature +++ b/features/v2/roles.feature @@ -15,7 +15,7 @@ Feature: Roles And a valid "appKeyAuth" key in the system And an instance of "Roles" API - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Add a user to a role returns "Bad Request" response Given new "AddUserToRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -23,7 +23,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Add a user to a role returns "Not found" response Given new "AddUserToRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -31,7 +31,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Add a user to a role returns "OK" response Given there is a valid "role" in the system And there is a valid "user" in the system @@ -44,7 +44,7 @@ Feature: Roles And the response "data[0].type" is equal to "{{ user.data.type }}" And the response "data[0].relationships.roles.data" has item with field "id" with value "{{ role.data.id }}" - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Create a new role by cloning an existing role returns "Bad Request" response Given there is a valid "role" in the system And new "CloneRole" request @@ -53,7 +53,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Create a new role by cloning an existing role returns "Conflict" response Given there is a valid "role" in the system And new "CloneRole" request @@ -62,7 +62,7 @@ Feature: Roles When the request is sent Then the response status is 409 Conflict - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Create a new role by cloning an existing role returns "Not found" response Given new "CloneRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -70,7 +70,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Create a new role by cloning an existing role returns "OK" response Given there is a valid "role" in the system And new "CloneRole" request @@ -80,21 +80,21 @@ Feature: Roles Then the response status is 200 OK And the response "data.attributes.name" is equal to "{{ unique }} clone" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Create role returns "Bad Request" response Given new "CreateRole" request And body with value {"data": {"attributes": {"name": "developers", "receives_permissions_from": []}, "relationships": {"permissions": {"data": [{"type": "permissions"}]}}, "type": "roles"}} When the request is sent Then the response status is 400 Bad Request - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Create role returns "OK" response Given new "CreateRole" request And body with value {"data": {"attributes": {"name": "developers", "receives_permissions_from": []}, "relationships": {"permissions": {"data": [{"type": "permissions"}]}}, "type": "roles"}} When the request is sent Then the response status is 200 OK - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Create role with a permission returns "OK" response Given new "CreateRole" request And there is a valid "permission" in the system @@ -105,14 +105,14 @@ Feature: Roles And the response "data.type" is equal to "roles" And the response "data.relationships.permissions.data" has item with field "id" with value "{{ permission.id }}" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Delete role returns "Not found" response Given new "DeleteRole" request And request contains "role_id" parameter from "REPLACE.ME" When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Delete role returns "OK" response Given there is a valid "role" in the system And new "DeleteRole" request @@ -120,14 +120,14 @@ Feature: Roles When the request is sent Then the response status is 204 OK - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Get a role returns "Not found" response Given new "GetRole" request And request contains "role_id" parameter from "REPLACE.ME" When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Get a role returns "OK" response Given there is a valid "role" in the system And new "GetRole" request @@ -137,14 +137,14 @@ Feature: Roles And the response "data.attributes.name" has the same value as "role.data.attributes.name" And the response "data.id" has the same value as "role.data.id" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Get all users of a role returns "Not found" response Given new "ListRoleUsers" request And request contains "role_id" parameter from "REPLACE.ME" When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Get all users of a role returns "OK" response Given there is a valid "role" in the system And there is a valid "user" in the system @@ -156,7 +156,7 @@ Feature: Roles And the response "meta.page.total_count" is equal to 1 And the response "data" has item with field "id" with value "{{ user.data.id }}" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Grant permission to a role returns "Bad Request" response Given new "AddPermissionToRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -164,7 +164,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Grant permission to a role returns "Not found" response Given new "AddPermissionToRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -172,7 +172,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Grant permission to a role returns "OK" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -184,14 +184,14 @@ Feature: Roles And the response "data[0].type" is equal to "{{ permission.type }}" And the response "data" has item with field "id" with value "{{ permission.id }}" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: List permissions for a role returns "Not found" response Given new "ListRolePermissions" request And request contains "role_id" parameter from "REPLACE.ME" When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: List permissions for a role returns "OK" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -227,14 +227,14 @@ Feature: Roles And the response "data" has item with field "attributes.name" with value "admin" And the response "data" has item with field "attributes.name_aliases" with value [] - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: List role templates returns "OK" response Given operation "ListRoleTemplates" enabled And new "ListRoleTemplates" request When the request is sent Then the response status is 200 OK - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: List roles returns "OK" response Given there is a valid "role" in the system And new "ListRoles" request @@ -245,7 +245,7 @@ Feature: Roles And the response "data[0].id" has the same value as "role.data.id" And the response "data[0].attributes.name" has the same value as "role.data.attributes.name" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Remove a user from a role returns "Bad Request" response Given new "RemoveUserFromRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -253,7 +253,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Remove a user from a role returns "Not found" response Given new "RemoveUserFromRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -261,7 +261,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Remove a user from a role returns "OK" response Given there is a valid "role" in the system And there is a valid "user" in the system @@ -272,7 +272,7 @@ Feature: Roles When the request is sent Then the response status is 200 OK - @skip-validation @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @skip-validation @team:DataDog/access-policies-lifecycle Scenario: Revoke permission returns "Bad Request" response Given there is a valid "role" in the system And new "RemovePermissionFromRole" request @@ -281,7 +281,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Revoke permission returns "Not found" response Given there is a valid "permission" in the system And new "RemovePermissionFromRole" request @@ -290,7 +290,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Revoke permission returns "OK" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -302,7 +302,7 @@ Feature: Roles Then the response status is 200 OK And the response "data[0].type" is equal to "permissions" - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "Bad Request" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -312,7 +312,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "Bad Role ID" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -322,7 +322,7 @@ Feature: Roles When the request is sent Then the response status is 422 Bad Role ID in Request - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "Not found" response Given there is a valid "permission" in the system And new "UpdateRole" request @@ -331,7 +331,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @skip @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "OK" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -342,7 +342,7 @@ Feature: Roles Then the response status is 200 OK And the response "data.attributes.name" is equal to "{{ role.data.attributes.name }}-updated" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "Unprocessable Entity" response Given new "UpdateRole" request And request contains "role_id" parameter from "REPLACE.ME" diff --git a/lib/datadog_api_client/v2/models/role_create_attributes.rb b/lib/datadog_api_client/v2/models/role_create_attributes.rb index 52d3406f7fbb..55e390650338 100644 --- a/lib/datadog_api_client/v2/models/role_create_attributes.rb +++ b/lib/datadog_api_client/v2/models/role_create_attributes.rb @@ -24,6 +24,11 @@ class RoleCreateAttributes # Creation time of the role. attr_accessor :created_at + # Whether to exclude restricted default permissions from this role. + # Restricted default permissions are automatically assigned to every role by default. Set this field to `true` to exclude them. + # Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization. + attr_accessor :default_permissions_opt_out + # Time of last role modification. attr_accessor :modified_at @@ -42,6 +47,7 @@ class RoleCreateAttributes def self.attribute_map { :'created_at' => :'created_at', + :'default_permissions_opt_out' => :'default_permissions_opt_out', :'modified_at' => :'modified_at', :'name' => :'name', :'receives_permissions_from' => :'receives_permissions_from' @@ -53,6 +59,7 @@ def self.attribute_map def self.openapi_types { :'created_at' => :'Time', + :'default_permissions_opt_out' => :'Boolean', :'modified_at' => :'Time', :'name' => :'String', :'receives_permissions_from' => :'Array' @@ -81,6 +88,10 @@ def initialize(attributes = {}) self.created_at = attributes[:'created_at'] end + if attributes.key?(:'default_permissions_opt_out') + self.default_permissions_opt_out = attributes[:'default_permissions_opt_out'] + end + if attributes.key?(:'modified_at') self.modified_at = attributes[:'modified_at'] end @@ -141,6 +152,7 @@ def ==(o) return true if self.equal?(o) self.class == o.class && created_at == o.created_at && + default_permissions_opt_out == o.default_permissions_opt_out && modified_at == o.modified_at && name == o.name && receives_permissions_from == o.receives_permissions_from && @@ -151,7 +163,7 @@ def ==(o) # @return [Integer] Hash code # @!visibility private def hash - [created_at, modified_at, name, receives_permissions_from, additional_properties].hash + [created_at, default_permissions_opt_out, modified_at, name, receives_permissions_from, additional_properties].hash end end end diff --git a/lib/datadog_api_client/v2/models/role_update_attributes.rb b/lib/datadog_api_client/v2/models/role_update_attributes.rb index bfe24a2a8dc4..c8775619bb11 100644 --- a/lib/datadog_api_client/v2/models/role_update_attributes.rb +++ b/lib/datadog_api_client/v2/models/role_update_attributes.rb @@ -24,6 +24,11 @@ class RoleUpdateAttributes # Creation time of the role. attr_accessor :created_at + # Whether to exclude restricted default permissions from this role. + # Restricted default permissions are automatically assigned to every role by default. Set this field to `true` to exclude them. + # Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization. + attr_accessor :default_permissions_opt_out + # Time of last role modification. attr_accessor :modified_at @@ -45,6 +50,7 @@ class RoleUpdateAttributes def self.attribute_map { :'created_at' => :'created_at', + :'default_permissions_opt_out' => :'default_permissions_opt_out', :'modified_at' => :'modified_at', :'name' => :'name', :'receives_permissions_from' => :'receives_permissions_from', @@ -57,6 +63,7 @@ def self.attribute_map def self.openapi_types { :'created_at' => :'Time', + :'default_permissions_opt_out' => :'Boolean', :'modified_at' => :'Time', :'name' => :'String', :'receives_permissions_from' => :'Array', @@ -86,6 +93,10 @@ def initialize(attributes = {}) self.created_at = attributes[:'created_at'] end + if attributes.key?(:'default_permissions_opt_out') + self.default_permissions_opt_out = attributes[:'default_permissions_opt_out'] + end + if attributes.key?(:'modified_at') self.modified_at = attributes[:'modified_at'] end @@ -150,6 +161,7 @@ def ==(o) return true if self.equal?(o) self.class == o.class && created_at == o.created_at && + default_permissions_opt_out == o.default_permissions_opt_out && modified_at == o.modified_at && name == o.name && receives_permissions_from == o.receives_permissions_from && @@ -161,7 +173,7 @@ def ==(o) # @return [Integer] Hash code # @!visibility private def hash - [created_at, modified_at, name, receives_permissions_from, user_count, additional_properties].hash + [created_at, default_permissions_opt_out, modified_at, name, receives_permissions_from, user_count, additional_properties].hash end end end