diff --git a/.generator/schemas/v2/openapi.yaml b/.generator/schemas/v2/openapi.yaml index 8307610ee5..419caee734 100644 --- a/.generator/schemas/v2/openapi.yaml +++ b/.generator/schemas/v2/openapi.yaml @@ -95624,6 +95624,12 @@ components: format: date-time readOnly: true type: string + default_permissions_opt_out: + description: |- + Whether to exclude restricted default permissions from this role. + Restricted default permissions are automatically assigned to every role by default. Set this field to `true` to exclude them. + Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization. + type: boolean modified_at: description: Time of last role modification. format: date-time @@ -95755,6 +95761,12 @@ components: format: date-time readOnly: true type: string + default_permissions_opt_out: + description: |- + Whether to exclude restricted default permissions from this role. + Restricted default permissions are automatically assigned to every role by default. Set this field to `true` to exclude them. + Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization. + type: boolean modified_at: description: Time of last role modification. format: date-time diff --git a/src/datadog_api_client/v2/model/role_create_attributes.py b/src/datadog_api_client/v2/model/role_create_attributes.py index 274072d5a4..c48b26fa19 100644 --- a/src/datadog_api_client/v2/model/role_create_attributes.py +++ b/src/datadog_api_client/v2/model/role_create_attributes.py @@ -19,6 +19,7 @@ class RoleCreateAttributes(ModelNormal): def openapi_types(_): return { "created_at": (datetime,), + "default_permissions_opt_out": (bool,), "modified_at": (datetime,), "name": (str,), "receives_permissions_from": ([str],), @@ -26,6 +27,7 @@ def openapi_types(_): attribute_map = { "created_at": "created_at", + "default_permissions_opt_out": "default_permissions_opt_out", "modified_at": "modified_at", "name": "name", "receives_permissions_from": "receives_permissions_from", @@ -39,6 +41,7 @@ def __init__( self_, name: str, created_at: Union[datetime, UnsetType] = unset, + default_permissions_opt_out: Union[bool, UnsetType] = unset, modified_at: Union[datetime, UnsetType] = unset, receives_permissions_from: Union[List[str], UnsetType] = unset, **kwargs, @@ -49,6 +52,11 @@ def __init__( :param created_at: Creation time of the role. :type created_at: datetime, optional + :param default_permissions_opt_out: Whether to exclude restricted default permissions from this role. + Restricted default permissions are automatically assigned to every role by default. Set this field to ``true`` to exclude them. + Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization. + :type default_permissions_opt_out: bool, optional + :param modified_at: Time of last role modification. :type modified_at: datetime, optional @@ -62,6 +70,8 @@ def __init__( """ if created_at is not unset: kwargs["created_at"] = created_at + if default_permissions_opt_out is not unset: + kwargs["default_permissions_opt_out"] = default_permissions_opt_out if modified_at is not unset: kwargs["modified_at"] = modified_at if receives_permissions_from is not unset: diff --git a/src/datadog_api_client/v2/model/role_update_attributes.py b/src/datadog_api_client/v2/model/role_update_attributes.py index 16c22a7991..27961a0aac 100644 --- a/src/datadog_api_client/v2/model/role_update_attributes.py +++ b/src/datadog_api_client/v2/model/role_update_attributes.py @@ -25,6 +25,7 @@ class RoleUpdateAttributes(ModelNormal): def openapi_types(_): return { "created_at": (datetime,), + "default_permissions_opt_out": (bool,), "modified_at": (datetime,), "name": (str,), "receives_permissions_from": ([str],), @@ -33,6 +34,7 @@ def openapi_types(_): attribute_map = { "created_at": "created_at", + "default_permissions_opt_out": "default_permissions_opt_out", "modified_at": "modified_at", "name": "name", "receives_permissions_from": "receives_permissions_from", @@ -46,6 +48,7 @@ def openapi_types(_): def __init__( self_, created_at: Union[datetime, UnsetType] = unset, + default_permissions_opt_out: Union[bool, UnsetType] = unset, modified_at: Union[datetime, UnsetType] = unset, name: Union[str, UnsetType] = unset, receives_permissions_from: Union[List[str], UnsetType] = unset, @@ -58,6 +61,11 @@ def __init__( :param created_at: Creation time of the role. :type created_at: datetime, optional + :param default_permissions_opt_out: Whether to exclude restricted default permissions from this role. + Restricted default permissions are automatically assigned to every role by default. Set this field to ``true`` to exclude them. + Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization. + :type default_permissions_opt_out: bool, optional + :param modified_at: Time of last role modification. :type modified_at: datetime, optional @@ -74,6 +82,8 @@ def __init__( """ if created_at is not unset: kwargs["created_at"] = created_at + if default_permissions_opt_out is not unset: + kwargs["default_permissions_opt_out"] = default_permissions_opt_out if modified_at is not unset: kwargs["modified_at"] = modified_at if name is not unset: diff --git a/tests/v2/features/roles.feature b/tests/v2/features/roles.feature index b926c82f44..60dc17e964 100644 --- a/tests/v2/features/roles.feature +++ b/tests/v2/features/roles.feature @@ -15,7 +15,7 @@ Feature: Roles And a valid "appKeyAuth" key in the system And an instance of "Roles" API - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Add a user to a role returns "Bad Request" response Given new "AddUserToRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -23,7 +23,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Add a user to a role returns "Not found" response Given new "AddUserToRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -31,7 +31,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Add a user to a role returns "OK" response Given there is a valid "role" in the system And there is a valid "user" in the system @@ -44,7 +44,7 @@ Feature: Roles And the response "data[0].type" is equal to "{{ user.data.type }}" And the response "data[0].relationships.roles.data" has item with field "id" with value "{{ role.data.id }}" - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Create a new role by cloning an existing role returns "Bad Request" response Given there is a valid "role" in the system And new "CloneRole" request @@ -53,7 +53,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Create a new role by cloning an existing role returns "Conflict" response Given there is a valid "role" in the system And new "CloneRole" request @@ -62,7 +62,7 @@ Feature: Roles When the request is sent Then the response status is 409 Conflict - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Create a new role by cloning an existing role returns "Not found" response Given new "CloneRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -70,7 +70,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Create a new role by cloning an existing role returns "OK" response Given there is a valid "role" in the system And new "CloneRole" request @@ -80,21 +80,21 @@ Feature: Roles Then the response status is 200 OK And the response "data.attributes.name" is equal to "{{ unique }} clone" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Create role returns "Bad Request" response Given new "CreateRole" request And body with value {"data": {"attributes": {"name": "developers", "receives_permissions_from": []}, "relationships": {"permissions": {"data": [{"type": "permissions"}]}}, "type": "roles"}} When the request is sent Then the response status is 400 Bad Request - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Create role returns "OK" response Given new "CreateRole" request And body with value {"data": {"attributes": {"name": "developers", "receives_permissions_from": []}, "relationships": {"permissions": {"data": [{"type": "permissions"}]}}, "type": "roles"}} When the request is sent Then the response status is 200 OK - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Create role with a permission returns "OK" response Given new "CreateRole" request And there is a valid "permission" in the system @@ -105,14 +105,14 @@ Feature: Roles And the response "data.type" is equal to "roles" And the response "data.relationships.permissions.data" has item with field "id" with value "{{ permission.id }}" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Delete role returns "Not found" response Given new "DeleteRole" request And request contains "role_id" parameter from "REPLACE.ME" When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Delete role returns "OK" response Given there is a valid "role" in the system And new "DeleteRole" request @@ -120,14 +120,14 @@ Feature: Roles When the request is sent Then the response status is 204 OK - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Get a role returns "Not found" response Given new "GetRole" request And request contains "role_id" parameter from "REPLACE.ME" When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Get a role returns "OK" response Given there is a valid "role" in the system And new "GetRole" request @@ -137,14 +137,14 @@ Feature: Roles And the response "data.attributes.name" has the same value as "role.data.attributes.name" And the response "data.id" has the same value as "role.data.id" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Get all users of a role returns "Not found" response Given new "ListRoleUsers" request And request contains "role_id" parameter from "REPLACE.ME" When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Get all users of a role returns "OK" response Given there is a valid "role" in the system And there is a valid "user" in the system @@ -156,7 +156,7 @@ Feature: Roles And the response "meta.page.total_count" is equal to 1 And the response "data" has item with field "id" with value "{{ user.data.id }}" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Grant permission to a role returns "Bad Request" response Given new "AddPermissionToRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -164,7 +164,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Grant permission to a role returns "Not found" response Given new "AddPermissionToRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -172,7 +172,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Grant permission to a role returns "OK" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -184,14 +184,14 @@ Feature: Roles And the response "data[0].type" is equal to "{{ permission.type }}" And the response "data" has item with field "id" with value "{{ permission.id }}" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: List permissions for a role returns "Not found" response Given new "ListRolePermissions" request And request contains "role_id" parameter from "REPLACE.ME" When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: List permissions for a role returns "OK" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -227,14 +227,14 @@ Feature: Roles And the response "data" has item with field "attributes.name" with value "admin" And the response "data" has item with field "attributes.name_aliases" with value [] - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: List role templates returns "OK" response Given operation "ListRoleTemplates" enabled And new "ListRoleTemplates" request When the request is sent Then the response status is 200 OK - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: List roles returns "OK" response Given there is a valid "role" in the system And new "ListRoles" request @@ -245,7 +245,7 @@ Feature: Roles And the response "data[0].id" has the same value as "role.data.id" And the response "data[0].attributes.name" has the same value as "role.data.attributes.name" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Remove a user from a role returns "Bad Request" response Given new "RemoveUserFromRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -253,7 +253,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Remove a user from a role returns "Not found" response Given new "RemoveUserFromRole" request And request contains "role_id" parameter from "REPLACE.ME" @@ -261,7 +261,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Remove a user from a role returns "OK" response Given there is a valid "role" in the system And there is a valid "user" in the system @@ -272,7 +272,7 @@ Feature: Roles When the request is sent Then the response status is 200 OK - @skip-validation @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @skip-validation @team:DataDog/access-policies-lifecycle Scenario: Revoke permission returns "Bad Request" response Given there is a valid "role" in the system And new "RemovePermissionFromRole" request @@ -281,7 +281,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Revoke permission returns "Not found" response Given there is a valid "permission" in the system And new "RemovePermissionFromRole" request @@ -290,7 +290,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Revoke permission returns "OK" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -302,7 +302,7 @@ Feature: Roles Then the response status is 200 OK And the response "data[0].type" is equal to "permissions" - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "Bad Request" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -312,7 +312,7 @@ Feature: Roles When the request is sent Then the response status is 400 Bad Request - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "Bad Role ID" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -322,7 +322,7 @@ Feature: Roles When the request is sent Then the response status is 422 Bad Role ID in Request - @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "Not found" response Given there is a valid "permission" in the system And new "UpdateRole" request @@ -331,7 +331,7 @@ Feature: Roles When the request is sent Then the response status is 404 Not found - @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @skip @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "OK" response Given there is a valid "role" in the system And there is a valid "permission" in the system @@ -342,7 +342,7 @@ Feature: Roles Then the response status is 200 OK And the response "data.attributes.name" is equal to "{{ role.data.attributes.name }}-updated" - @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle + @generated @skip @team:DataDog/access-policies-lifecycle Scenario: Update a role returns "Unprocessable Entity" response Given new "UpdateRole" request And request contains "role_id" parameter from "REPLACE.ME"