PolicyUpsert
Data accepted by Upsert Policy. Required fields are resource_id, subject_id.
resource_idResource Id (string)required
Resource ID this policy applies to
subject_idSubject Id (string)required
Subject identifier: 'user.{uuid}' or 'group.{uuid}'
row_filters object
Structured row-filter tree, or null when no row restriction applies.
- RowFilter
- null
kindKind (string)
Possible values: [and, or]
Default value:
andconditions object[]
Nested conditions (leaf RowFilterCondition or group RowFilter)
Array [
- RowFilterCondition
- Option 2
kindKind (string)
Constant value:
conditionDefault value:
conditioncolumnColumn (string)required
Column name to filter on
operatorRowFilterOperator (string)required
Allowed Row Filter Operator values. Values: eq, ne, gt, gte, lt, lte, in, not_in, and 4 more.
Possible values: [eq, ne, gt, gte, lt, lte, in, not_in, between, like, is_null, is_not_null]
value object
Filter value. Single value for scalar operators, list for 'in'/'not_in', 2-element list for 'between'. Omit for 'is_null'/'is_not_null'.
- Option 1
- null
]
column_masks object
Column-mask rules keyed by column name, or null when no masking applies.
- object
- null
object
created_at object
anyOf
- integer
- null
integer
updated_at object
anyOf
- integer
- null
integer
PolicyUpsert
{
"resource_id": "string",
"subject_id": "string",
"row_filters": {
"kind": "and",
"conditions": [
{
"kind": "condition",
"column": "string",
"operator": "eq"
},
null
]
},
"column_masks": {},
"created_at": 0,
"updated_at": 0
}