统一身份认证服务 IAM-授权项:权限管理

时间:2023-11-01 16:23:05

权限管理

权限

对应API接口

授权项

IAM项目

(Project)

企业项目

(Enterprise Project)

查询权限列表

GET /v3/roles

iam:roles:listRoles

-

-

查询权限详情

GET /v3/roles/{role_id}

iam:roles:getRole

-

-

查询租户授权信息

GET /v3.0/OS-PERMISSION/role-assignments

iam:permissions:listRoleAssignments

查询全局服务中的用户组权限

GET /v3/domains/{domain_id}/groups/{group_id}/roles

iam:permissions:listRolesForGroupOnDomain

-

-

查询项目服务中的用户组权限

GET /v3/projects/{project_id}/groups/{group_id}/roles

iam:permissions:listRolesForGroupOnProject

-

-

为用户组授予全局服务权限

PUT /v3/domains/{domain_id}/groups/{group_id}/roles/{role_id}

iam:permissions:grantRoleToGroupOnDomain

-

-

为用户组授予项目服务权限

PUT /v3/projects/{project_id}/groups/{group_id}/roles/{role_id}

iam:permissions:grantRoleToGroupOnProject

-

-

移除用户组的项目服务权限

DELETE /v3/projects/{project_id}/groups/{group_id}/roles/{role_id}

iam:permissions:revokeRoleFromGroupOnProject

-

-

移除用户组的全局服务权限

DELETE /v3/domains/{domain_id}/groups/{group_id}/roles/{role_id}

iam:permissions:revokeRoleFromGroupOnDomain

-

-

查询用户组是否拥有全局服务权限

HEAD /v3/domains/{domain_id}/groups/{group_id}/roles/{role_id}

iam:permissions:checkRoleForGroupOnDomain

-

-

查询用户组是否拥有项目服务权限

HEAD /v3/projects/{project_id}/groups/{group_id}/roles/{role_id}

iam:permissions:checkRoleForGroupOnProject

-

-

为用户组授予所有项目服务权限

PUT /v3/OS-INHERIT/domains/{domain_id}/groups/{group_id}/roles/{role_id}/inherited_to_projects

iam:permissions:grantRoleToGroup

-

-

查询用户在指定项目上拥有的权限

×

iam:permissions:listRolesForUserOnProject

-

-

查询用户组的所有权限

×

iam:permissions:listRolesForGroup

-

-

查询用户组是否拥有指定权限

×

iam:permissions:checkRoleForGroup

-

-

移除用户组的指定权限

×

iam:permissions:revokeRoleFromGroup

-

-

查询帐号授权记录

×

iam:permissions:listRoleAssignments

-

-

support.huaweicloud.com/api-iam/iam_19_0001.html