pub enum ApiKeyScope {
WorkflowsRead,
RunsRead,
RunsWrite,
RunsManage,
StatsRead,
AccountsRead,
AccountsManage,
SignalsSend,
Admin,
}Expand description
Permission scope for an API key.
Each scope grants access to a specific set of actions. A key with no scopes has no permissions.
Variants§
WorkflowsRead
Read workflow definitions.
RunsRead
Read runs and their steps.
RunsWrite
Create new runs (trigger workflows).
RunsManage
Cancel, approve, reject, retry runs.
StatsRead
Read aggregated statistics.
AccountsRead
Read Provider Accounts and their usage.
AccountsManage
Create, update, delete and test Provider Accounts.
SignalsSend
Send signals that resume waiting runs.
Admin
Full access to all operations.
Implementations§
Source§impl ApiKeyScope
impl ApiKeyScope
Sourcepub fn permits(&self, required: &ApiKeyScope) -> bool
pub fn permits(&self, required: &ApiKeyScope) -> bool
Check whether this scope grants the required permission.
Sourcepub fn has_permission(scopes: &[ApiKeyScope], required: &ApiKeyScope) -> bool
pub fn has_permission(scopes: &[ApiKeyScope], required: &ApiKeyScope) -> bool
Check whether a set of scopes grants the required permission.
Sourcepub fn all_non_admin() -> Vec<ApiKeyScope>
pub fn all_non_admin() -> Vec<ApiKeyScope>
All available scopes (excluding admin).
Sourcepub fn member_allowed() -> &'static [ApiKeyScope]
pub fn member_allowed() -> &'static [ApiKeyScope]
Scopes a non-admin member is allowed to use.
Whitelist approach: only these scopes are permitted for members. Any scope not listed here is forbidden for non-admin users.
Sourcepub fn all_allowed_for_member(scopes: &[ApiKeyScope]) -> bool
pub fn all_allowed_for_member(scopes: &[ApiKeyScope]) -> bool
Check whether all scopes in the set are allowed for a non-admin member.