Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

id

name

description

uuid

domain_id

removed

created

1 NORMAL

REGULAR_USER

Domain user group

d283d4f0-31f0-11e3-ad37-80f85ce25918

1

NULL

2013-10-10 14:13:34

2

ADMIN

Root admin group

d283de28-31f0-11e3-ad37-80f85ce25918

1

NULL

2013-10-10 14:13:34

3

DOMAIN_ADMIN

Domain admin group

d283e6e8-31f0-11e3-ad37-80f85ce25918

1

NULL

2013-10-10 14:13:34

acl_group_account_policymap

id

name

description

uuid

group_id

account domain_id

removed

created

rol 2 e_type

2

1

NORMAL

Domain user role

d2838dce-31f0-11e3-ad37-80f85ce25918

1

2

NULL

2013-10-10 14:13:34

Sta 3 tic

3

2 3

NULL

2013-10-11 00:14:54

4

1

4

ADMIN

Root admin role

d2839c56-31f0-11e3-ad37-80f85ce25918

1

NULL

2013-10-10 1411 00:13:34

Sta
tic

19:55

acl_policy

id

name

description

uuid

domain_id

removed

created

policy_type

1

REGULAR_USER

Domain user role

d2838dce

3

DOMAIN_ADMIN

Domain admin role

d283a7f0-31f0-11e3-ad37-80f85ce25918

1

NULL

2013-10-10 14:13:34

Sta Static tic

2

4

RESOURCE_DOMAIN_ ADMIN

Resource domain Root admin role

d283b574 d2839c56-31f0-11e3-ad37-80f85ce25918

1

NULL

2013-10-10 14:13:34

Sta Static tic

3

DOMAIN

5

READ_ONLY_ADMIN

Read only Domain admin role

d283beac d283a7f0-31f0-11e3-ad37-80f85ce25918

1

NULL

2013-10-10 14:13:34

Sta Static tic

6

RESOURCE_OWNER

Resource owner role

d283c794-31f0-11e3-ad37-80f85ce25918

1

NULL

2013-10-10 14:13:34

Dyn
amic

...

Dynamic

acl_group_policy_map;

id

group_id

policy_id

removed

created

1

1

1

NULL

2013-10-10 14:13:34

2

2

2

NULL

2013-10-10 14:13:34

3

3

3

NULL

2013-10-10 14:13:34

...

Access Check Flow

Lets consider the StartVM API is being called by a user and run through the access control usecases for various out-of-box policies.