Semaphor

Create an assignment

Binds a definition to an actor and optionally provides parameter values for that actor.

The scopeType determines which actor field is required:

Scope typeRequired fieldPersisted RLS behavior
ALL_TENANTS(none)Activates the policy for all tenant actors and may supply broad values
TENANTtenantIdActivates the policy for one tenant and may supply tenant-specific values
TENANT_USERtenantUserIdActivates the policy for one tenant user and may supply user-specific values
ORG_USERorgUserIdActivates the policy directly for one organization user

You cannot assign the same definition to the same actor twice.

POST
/api/management/v1/projects/{projectId}/unified-security/assignments

Authorization

UnifiedSecurityBearerAuth
AuthorizationBearer <token>

A project-scoped access token generated for an organization Admin. Generate one with the Token API using the Admin's orgUserId. The token project must match the request path, and the user must currently be active and belong to the project organization. Dashboard tokens and tenant-user project tokens are not accepted.

In: header

Path Parameters

projectId*string

Your Semaphor project ID.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X post "https://semaphor.cloud/api/management/v1/projects/string/unified-security/assignments" \  -H "Content-Type: application/json" \  -d '{    "definitionId": "usd_123",    "scopeType": "TENANT",    "tenantId": "tenant_123",    "params": {      "region": "us"    }  }'
{
  "ok": true,
  "data": {
    "assignment": {
      "id": "string",
      "definitionId": "string",
      "scopeType": "ALL_TENANTS",
      "orgUserId": "string",
      "tenantId": "string",
      "tenantUserId": "string",
      "params": {
        "property1": "string",
        "property2": "string"
      },
      "createdAt": "2019-08-24T14:15:22Z",
      "updatedAt": "2019-08-24T14:15:22Z"
    },
    "diagnostics": [
      {
        "code": "RLS_CONFIG_SHAPE_INVALID",
        "severity": "ERROR",
        "title": "string",
        "message": "string",
        "location": {
          "resourceType": "DEFINITION",
          "resourceId": "string",
          "resourceName": "string",
          "subjectType": "RULE",
          "fieldPath": "string",
          "parameterName": "string"
        },
        "remediations": [
          {
            "code": "REAUTHOR_LEGACY_RLS",
            "label": "string",
            "target": {
              "resourceType": "DEFINITION",
              "resourceId": "string"
            }
          }
        ],
        "requiresUserDecision": true,
        "retryable": true
      }
    ],
    "impact": {
      "type": "ALL_TENANTS_BASELINE_CHANGE",
      "allOtherTenantActorsRemainActive": true,
      "parameters": [
        {
          "parameterName": "string",
          "oldValue": {
            "state": "OMITTED"
          },
          "newValue": {
            "state": "OMITTED"
          },
          "tenantOverrideAssignmentCount": 0,
          "tenantUserOverrideAssignmentCount": 0
        }
      ]
    }
  }
}
{
  "ok": false,
  "error": {
    "code": "INVALID_REQUEST",
    "message": "string",
    "requestId": "string",
    "issues": [
      {
        "code": "INVALID_JSON",
        "fieldPath": "string",
        "message": "string"
      }
    ],
    "retryable": true
  }
}
{
  "ok": false,
  "error": {
    "code": "INVALID_REQUEST",
    "message": "string",
    "details": {}
  }
}
{
  "ok": false,
  "error": {
    "code": "INVALID_REQUEST",
    "message": "string",
    "details": {}
  }
}
{
  "ok": false,
  "error": {
    "code": "INVALID_REQUEST",
    "message": "string",
    "requestId": "string",
    "issues": [
      {
        "code": "INVALID_JSON",
        "fieldPath": "string",
        "message": "string"
      }
    ],
    "retryable": true
  }
}
{
  "ok": false,
  "error": {
    "code": "INVALID_REQUEST",
    "message": "string",
    "requestId": "string",
    "issues": [
      {
        "code": "INVALID_JSON",
        "fieldPath": "string",
        "message": "string"
      }
    ],
    "retryable": true
  }
}
{
  "ok": false,
  "error": {
    "code": "RLS_CONFIGURATION_INVALID",
    "message": "string",
    "diagnostics": [
      {
        "code": "RLS_CONFIG_SHAPE_INVALID",
        "severity": "ERROR",
        "title": "string",
        "message": "string",
        "location": {
          "resourceType": "DEFINITION",
          "resourceId": "string",
          "resourceName": "string",
          "subjectType": "RULE",
          "fieldPath": "string",
          "parameterName": "string"
        },
        "remediations": [
          {
            "code": "REAUTHOR_LEGACY_RLS",
            "label": "string",
            "target": {
              "resourceType": "DEFINITION",
              "resourceId": "string"
            }
          }
        ],
        "requiresUserDecision": true,
        "retryable": true
      }
    ],
    "requestId": "string"
  }
}
{
  "ok": false,
  "error": {
    "code": "INVALID_REQUEST",
    "message": "string",
    "requestId": "string",
    "issues": [
      {
        "code": "INVALID_JSON",
        "fieldPath": "string",
        "message": "string"
      }
    ],
    "retryable": true
  }
}