diff --git a/.openapi-generator/FILES b/.openapi-generator/FILES
index 1d586f4..451a335 100644
--- a/.openapi-generator/FILES
+++ b/.openapi-generator/FILES
@@ -31,10 +31,25 @@ docs/Bundle.md
docs/BundleGroup.md
docs/BundleResource.md
docs/BundlesApi.md
+docs/Campaign.md
+docs/CampaignConfiguration.md
+docs/CampaignGroupAssetVisibilityPolicyEnum.md
+docs/CampaignItem.md
+docs/CampaignItemAdminOverride.md
+docs/CampaignItemReview.md
+docs/CampaignItemReviewDecisionEnum.md
+docs/CampaignItemReviewerAssignmentSourceEnum.md
+docs/CampaignItemStatusEnum.md
+docs/CampaignItemTargetTypeEnum.md
+docs/CampaignRevokeOnEnum.md
+docs/CampaignStatusEnum.md
+docs/CampaignsApi.md
docs/Condition.md
docs/ConfigurationTemplate.md
docs/ConfigurationTemplatesApi.md
docs/CreateBundleInfo.md
+docs/CreateCampaignConfigurationInfo.md
+docs/CreateCampaignInfo.md
docs/CreateConfigurationTemplateInfo.md
docs/CreateDelegationRequest.md
docs/CreateEventStreamInfo.md
@@ -45,6 +60,8 @@ docs/CreateIdpGroupMappingRequest.md
docs/CreateMessageChannelInfo.md
docs/CreateOnCallScheduleInfo.md
docs/CreateOwnerInfo.md
+docs/CreatePaladinContextSourceInfo.md
+docs/CreatePaladinInfo.md
docs/CreateRequest200Response.md
docs/CreateRequestCommentRequest.md
docs/CreateRequestConfigurationInfoList.md
@@ -53,12 +70,15 @@ docs/CreateRequestInfoCustomMetadataInner.md
docs/CreateRequestInfoGroupsInner.md
docs/CreateRequestInfoResourcesInner.md
docs/CreateRequestInfoSupportTicket.md
+docs/CreateRequestTemplateInfo.md
+docs/CreateResourceCustomAccessLevelInfo.md
docs/CreateResourceInfo.md
docs/CreateTagInfo.md
docs/CreateUARInfo.md
docs/Delegation.md
docs/DelegationsApi.md
docs/DenyRequestRequest.md
+docs/EntityAdminFilter.md
docs/EntityItemTypeEnum.md
docs/EntityNameFilter.md
docs/EntityTagFilter.md
@@ -73,6 +93,7 @@ docs/EventsApi.md
docs/GetResourceUser200Response.md
docs/Group.md
docs/GroupAccessLevel.md
+docs/GroupAccessLevelList.md
docs/GroupBinding.md
docs/GroupBindingGroup.md
docs/GroupBindingsApi.md
@@ -84,9 +105,12 @@ docs/GroupRemoteInfoAwsSsoGroup.md
docs/GroupRemoteInfoAzureAdMicrosoft365Group.md
docs/GroupRemoteInfoAzureAdSecurityGroup.md
docs/GroupRemoteInfoClickhouseRole.md
+docs/GroupRemoteInfoConfluenceGroup.md
docs/GroupRemoteInfoConnectorGroup.md
docs/GroupRemoteInfoDatabricksAccountGroup.md
docs/GroupRemoteInfoDevinGroup.md
+docs/GroupRemoteInfoDocusignGroup.md
+docs/GroupRemoteInfoDocusignSigningGroup.md
docs/GroupRemoteInfoDuoGroup.md
docs/GroupRemoteInfoGithubEnterpriseTeam.md
docs/GroupRemoteInfoGithubTeam.md
@@ -95,19 +119,23 @@ docs/GroupRemoteInfoGoogleGroup.md
docs/GroupRemoteInfoGrafanaTeam.md
docs/GroupRemoteInfoHubspotTeam.md
docs/GroupRemoteInfoIncidentioOnCallSchedule.md
+docs/GroupRemoteInfoJiraGroup.md
docs/GroupRemoteInfoLdapGroup.md
+docs/GroupRemoteInfoLinearTeam.md
docs/GroupRemoteInfoOktaGroup.md
docs/GroupRemoteInfoOktaGroupRule.md
docs/GroupRemoteInfoPagerdutyOnCallSchedule.md
docs/GroupRemoteInfoRootlyOnCallSchedule.md
docs/GroupRemoteInfoSlackUserGroup.md
docs/GroupRemoteInfoSnowflakeRole.md
+docs/GroupRemoteInfoTableauGroup.md
docs/GroupRemoteInfoTailscaleGroup.md
docs/GroupRemoteInfoTwingateGroup.md
docs/GroupRemoteInfoTwingateGroupSynced.md
docs/GroupRemoteInfoWorkdayUserSecurityGroup.md
docs/GroupRemoteInfoZendeskGroup.md
docs/GroupRemoteInfoZendeskOrganization.md
+docs/GroupRemoteInfoZoomGroup.md
docs/GroupResource.md
docs/GroupResourceList.md
docs/GroupTypeEnum.md
@@ -118,6 +146,8 @@ docs/GroupsApi.md
docs/IdpGroupMapping.md
docs/IdpGroupMappingList.md
docs/IdpGroupMappingsApi.md
+docs/IdpStatusFilter.md
+docs/InviteUserInfo.md
docs/MessageChannel.md
docs/MessageChannelIDList.md
docs/MessageChannelList.md
@@ -129,12 +159,19 @@ docs/OnCallScheduleIDList.md
docs/OnCallScheduleList.md
docs/OnCallScheduleProviderEnum.md
docs/OnCallSchedulesApi.md
+docs/OpalAccessPathEdgeFilter.md
+docs/OpalAccessPathQuery.md
+docs/OpalAccessPathQueryBody.md
+docs/OpalAccessPathQueryResults.md
+docs/OpalAccessPathResultEdge.md
+docs/OpalAccessPathResultNode.md
docs/OpalNodeQuery.md
docs/OpalNodeQueryBody.md
docs/OpalNodeQueryResults.md
docs/OpalQueriesApi.md
docs/OpalQueryResultEdge.md
docs/OpalQueryResultNode.md
+docs/OpalQueryResults.md
docs/Owner.md
docs/OwnersApi.md
docs/PageInfo.md
@@ -143,6 +180,8 @@ docs/PaginatedAssignedRequestList.md
docs/PaginatedBundleGroupList.md
docs/PaginatedBundleList.md
docs/PaginatedBundleResourceList.md
+docs/PaginatedCampaignItemsList.md
+docs/PaginatedCampaignsList.md
docs/PaginatedConfigurationTemplateList.md
docs/PaginatedDelegationsList.md
docs/PaginatedEventList.md
@@ -150,14 +189,25 @@ docs/PaginatedGroupBindingsList.md
docs/PaginatedGroupsList.md
docs/PaginatedOwnersList.md
docs/PaginatedRemoteUsersList.md
+docs/PaginatedRequestTemplateList.md
docs/PaginatedResourcesList.md
docs/PaginatedTagsList.md
docs/PaginatedTokensList.md
docs/PaginatedUARsList.md
docs/PaginatedUsersList.md
+docs/PaginatedViewerCampaignItemsList.md
+docs/Paladin.md
+docs/PaladinApi.md
+docs/PaladinConnector.md
+docs/PaladinContextSource.md
+docs/PaladinContextSourceKind.md
+docs/PaladinContextSourceList.md
+docs/PaladinContextSourceProvider.md
+docs/PaladinList.md
docs/PropagationStatus.md
docs/PropagationStatusEnum.md
docs/RDSEngineEnum.md
+docs/RemindRequest200Response.md
docs/RemoteUser.md
docs/Request.md
docs/RequestApprovalEnum.md
@@ -174,15 +224,27 @@ docs/RequestReviewer.md
docs/RequestReviewerStages.md
docs/RequestStage.md
docs/RequestStatusEnum.md
+docs/RequestTemplate.md
+docs/RequestTemplateCustomField.md
+docs/RequestTemplateCustomFieldCalloutMetadata.md
+docs/RequestTemplateCustomFieldInput.md
+docs/RequestTemplateCustomFieldMetadata.md
+docs/RequestTemplateCustomFieldMultiChoiceMetadata.md
docs/RequestTemplateCustomFieldTypeEnum.md
+docs/RequestTemplatesApi.md
docs/RequestedItem.md
docs/RequestsApi.md
docs/Resource.md
docs/ResourceAccessLevel.md
+docs/ResourceAccessLevelList.md
docs/ResourceAccessUser.md
docs/ResourceAccessUserList.md
+docs/ResourceCustomAccessLevelList.md
+docs/ResourceCustomAccessLevelResponse.md
docs/ResourceNHI.md
docs/ResourceRemoteInfo.md
+docs/ResourceRemoteInfoAlicloudEcsInstance.md
+docs/ResourceRemoteInfoAlicloudRamRole.md
docs/ResourceRemoteInfoAnthropicWorkspace.md
docs/ResourceRemoteInfoAwsAccount.md
docs/ResourceRemoteInfoAwsEc2Instance.md
@@ -215,8 +277,10 @@ docs/ResourceRemoteInfoDatadogRole.md
docs/ResourceRemoteInfoDatastaxAstraRole.md
docs/ResourceRemoteInfoDevinOrganization.md
docs/ResourceRemoteInfoDevinRole.md
+docs/ResourceRemoteInfoDocusignPermissionProfile.md
docs/ResourceRemoteInfoGcpBigQueryDataset.md
docs/ResourceRemoteInfoGcpBigQueryTable.md
+docs/ResourceRemoteInfoGcpBillingAccount.md
docs/ResourceRemoteInfoGcpBucket.md
docs/ResourceRemoteInfoGcpComputeInstance.md
docs/ResourceRemoteInfoGcpFolder.md
@@ -236,6 +300,8 @@ docs/ResourceRemoteInfoGrafanaFolder.md
docs/ResourceRemoteInfoGrafanaRole.md
docs/ResourceRemoteInfoHubspotRole.md
docs/ResourceRemoteInfoIlevelAdvancedRole.md
+docs/ResourceRemoteInfoLinearOrganization.md
+docs/ResourceRemoteInfoLinearProject.md
docs/ResourceRemoteInfoNetsuiteRole.md
docs/ResourceRemoteInfoOktaApp.md
docs/ResourceRemoteInfoOktaCustomRole.md
@@ -255,6 +321,8 @@ docs/ResourceRemoteInfoTeleportRole.md
docs/ResourceRemoteInfoTwingateResource.md
docs/ResourceRemoteInfoWorkdayRole.md
docs/ResourceRemoteInfoZendeskRole.md
+docs/ResourceRemoteInfoZoomLicense.md
+docs/ResourceRemoteInfoZoomRole.md
docs/ResourceTypeEnum.md
docs/ResourceUser.md
docs/ResourceUserAccessStatus.md
@@ -271,11 +339,14 @@ docs/RolePermissionTargetTypeEnum.md
docs/RuleClauses.md
docs/RuleConjunction.md
docs/RuleDisjunction.md
+docs/RunOpalQueryRequest.md
docs/ScopedRolePermission.md
docs/ScopedRolePermissionList.md
docs/Session.md
docs/SessionsApi.md
docs/SessionsList.md
+docs/SortDirectionEnum.md
+docs/StopCampaignRequest.md
docs/StringMatchType.md
docs/SubEvent.md
docs/SyncError.md
@@ -296,6 +367,8 @@ docs/UARReviewerAssignmentPolicyEnum.md
docs/UARScope.md
docs/UarsApi.md
docs/UpdateAccessRuleInfo.md
+docs/UpdateCampaignConfigurationInfo.md
+docs/UpdateCampaignInfo.md
docs/UpdateConfigurationTemplateInfo.md
docs/UpdateEventStreamInfo.md
docs/UpdateGroupBindingInfo.md
@@ -308,15 +381,24 @@ docs/UpdateIdpGroupMappingsRequest.md
docs/UpdateIdpGroupMappingsRequestMappingsInner.md
docs/UpdateOwnerInfo.md
docs/UpdateOwnerInfoList.md
+docs/UpdatePaladinInfo.md
+docs/UpdateRequestTemplateInfo.md
+docs/UpdateResourceCustomAccessLevelInfo.md
docs/UpdateResourceInfo.md
docs/UpdateResourceInfoList.md
docs/UpdateResourceUserRequest.md
+docs/UpdateUserInfo.md
docs/User.md
docs/UserAttributeSelector.md
docs/UserHrIdpStatusEnum.md
docs/UserIDList.md
docs/UserList.md
+docs/UserProductRoleEnum.md
docs/UsersApi.md
+docs/ViewerCampaignItem.md
+docs/ViewerCampaignItemReviewDecisionEnum.md
+docs/ViewerCampaignItemSortFieldEnum.md
+docs/ViewerCampaignItemStatusEnum.md
docs/VisibilityInfo.md
docs/VisibilityTypeEnum.md
docs/WebhookApiKeyCredential.md
@@ -330,6 +412,7 @@ opal_security/api/__init__.py
opal_security/api/access_rules_api.py
opal_security/api/apps_api.py
opal_security/api/bundles_api.py
+opal_security/api/campaigns_api.py
opal_security/api/configuration_templates_api.py
opal_security/api/delegations_api.py
opal_security/api/event_streams_api.py
@@ -342,6 +425,8 @@ opal_security/api/non_human_identities_api.py
opal_security/api/on_call_schedules_api.py
opal_security/api/opal_queries_api.py
opal_security/api/owners_api.py
+opal_security/api/paladin_api.py
+opal_security/api/request_templates_api.py
opal_security/api/requests_api.py
opal_security/api/resources_api.py
opal_security/api/sessions_api.py
@@ -379,9 +464,23 @@ opal_security/models/aws_permission_set_metadata_aws_permission_set.py
opal_security/models/bundle.py
opal_security/models/bundle_group.py
opal_security/models/bundle_resource.py
+opal_security/models/campaign.py
+opal_security/models/campaign_configuration.py
+opal_security/models/campaign_group_asset_visibility_policy_enum.py
+opal_security/models/campaign_item.py
+opal_security/models/campaign_item_admin_override.py
+opal_security/models/campaign_item_review.py
+opal_security/models/campaign_item_review_decision_enum.py
+opal_security/models/campaign_item_reviewer_assignment_source_enum.py
+opal_security/models/campaign_item_status_enum.py
+opal_security/models/campaign_item_target_type_enum.py
+opal_security/models/campaign_revoke_on_enum.py
+opal_security/models/campaign_status_enum.py
opal_security/models/condition.py
opal_security/models/configuration_template.py
opal_security/models/create_bundle_info.py
+opal_security/models/create_campaign_configuration_info.py
+opal_security/models/create_campaign_info.py
opal_security/models/create_configuration_template_info.py
opal_security/models/create_delegation_request.py
opal_security/models/create_event_stream_info.py
@@ -392,6 +491,8 @@ opal_security/models/create_idp_group_mapping_request.py
opal_security/models/create_message_channel_info.py
opal_security/models/create_on_call_schedule_info.py
opal_security/models/create_owner_info.py
+opal_security/models/create_paladin_context_source_info.py
+opal_security/models/create_paladin_info.py
opal_security/models/create_request200_response.py
opal_security/models/create_request_comment_request.py
opal_security/models/create_request_configuration_info_list.py
@@ -400,11 +501,14 @@ opal_security/models/create_request_info_custom_metadata_inner.py
opal_security/models/create_request_info_groups_inner.py
opal_security/models/create_request_info_resources_inner.py
opal_security/models/create_request_info_support_ticket.py
+opal_security/models/create_request_template_info.py
+opal_security/models/create_resource_custom_access_level_info.py
opal_security/models/create_resource_info.py
opal_security/models/create_tag_info.py
opal_security/models/create_uar_info.py
opal_security/models/delegation.py
opal_security/models/deny_request_request.py
+opal_security/models/entity_admin_filter.py
opal_security/models/entity_item_type_enum.py
opal_security/models/entity_name_filter.py
opal_security/models/entity_tag_filter.py
@@ -417,6 +521,7 @@ opal_security/models/event_stream_list.py
opal_security/models/get_resource_user200_response.py
opal_security/models/group.py
opal_security/models/group_access_level.py
+opal_security/models/group_access_level_list.py
opal_security/models/group_binding.py
opal_security/models/group_binding_group.py
opal_security/models/group_containing_group.py
@@ -427,9 +532,12 @@ opal_security/models/group_remote_info_aws_sso_group.py
opal_security/models/group_remote_info_azure_ad_microsoft365_group.py
opal_security/models/group_remote_info_azure_ad_security_group.py
opal_security/models/group_remote_info_clickhouse_role.py
+opal_security/models/group_remote_info_confluence_group.py
opal_security/models/group_remote_info_connector_group.py
opal_security/models/group_remote_info_databricks_account_group.py
opal_security/models/group_remote_info_devin_group.py
+opal_security/models/group_remote_info_docusign_group.py
+opal_security/models/group_remote_info_docusign_signing_group.py
opal_security/models/group_remote_info_duo_group.py
opal_security/models/group_remote_info_github_enterprise_team.py
opal_security/models/group_remote_info_github_team.py
@@ -438,19 +546,23 @@ opal_security/models/group_remote_info_google_group.py
opal_security/models/group_remote_info_grafana_team.py
opal_security/models/group_remote_info_hubspot_team.py
opal_security/models/group_remote_info_incidentio_on_call_schedule.py
+opal_security/models/group_remote_info_jira_group.py
opal_security/models/group_remote_info_ldap_group.py
+opal_security/models/group_remote_info_linear_team.py
opal_security/models/group_remote_info_okta_group.py
opal_security/models/group_remote_info_okta_group_rule.py
opal_security/models/group_remote_info_pagerduty_on_call_schedule.py
opal_security/models/group_remote_info_rootly_on_call_schedule.py
opal_security/models/group_remote_info_slack_user_group.py
opal_security/models/group_remote_info_snowflake_role.py
+opal_security/models/group_remote_info_tableau_group.py
opal_security/models/group_remote_info_tailscale_group.py
opal_security/models/group_remote_info_twingate_group.py
opal_security/models/group_remote_info_twingate_group_synced.py
opal_security/models/group_remote_info_workday_user_security_group.py
opal_security/models/group_remote_info_zendesk_group.py
opal_security/models/group_remote_info_zendesk_organization.py
+opal_security/models/group_remote_info_zoom_group.py
opal_security/models/group_resource.py
opal_security/models/group_resource_list.py
opal_security/models/group_type_enum.py
@@ -459,6 +571,8 @@ opal_security/models/group_user_list.py
opal_security/models/group_with_access_level.py
opal_security/models/idp_group_mapping.py
opal_security/models/idp_group_mapping_list.py
+opal_security/models/idp_status_filter.py
+opal_security/models/invite_user_info.py
opal_security/models/message_channel.py
opal_security/models/message_channel_id_list.py
opal_security/models/message_channel_list.py
@@ -467,11 +581,18 @@ opal_security/models/on_call_schedule.py
opal_security/models/on_call_schedule_id_list.py
opal_security/models/on_call_schedule_list.py
opal_security/models/on_call_schedule_provider_enum.py
+opal_security/models/opal_access_path_edge_filter.py
+opal_security/models/opal_access_path_query.py
+opal_security/models/opal_access_path_query_body.py
+opal_security/models/opal_access_path_query_results.py
+opal_security/models/opal_access_path_result_edge.py
+opal_security/models/opal_access_path_result_node.py
opal_security/models/opal_node_query.py
opal_security/models/opal_node_query_body.py
opal_security/models/opal_node_query_results.py
opal_security/models/opal_query_result_edge.py
opal_security/models/opal_query_result_node.py
+opal_security/models/opal_query_results.py
opal_security/models/owner.py
opal_security/models/page_info.py
opal_security/models/paginated_access_rules_list.py
@@ -479,6 +600,8 @@ opal_security/models/paginated_assigned_request_list.py
opal_security/models/paginated_bundle_group_list.py
opal_security/models/paginated_bundle_list.py
opal_security/models/paginated_bundle_resource_list.py
+opal_security/models/paginated_campaign_items_list.py
+opal_security/models/paginated_campaigns_list.py
opal_security/models/paginated_configuration_template_list.py
opal_security/models/paginated_delegations_list.py
opal_security/models/paginated_event_list.py
@@ -486,14 +609,24 @@ opal_security/models/paginated_group_bindings_list.py
opal_security/models/paginated_groups_list.py
opal_security/models/paginated_owners_list.py
opal_security/models/paginated_remote_users_list.py
+opal_security/models/paginated_request_template_list.py
opal_security/models/paginated_resources_list.py
opal_security/models/paginated_tags_list.py
opal_security/models/paginated_tokens_list.py
opal_security/models/paginated_uars_list.py
opal_security/models/paginated_users_list.py
+opal_security/models/paginated_viewer_campaign_items_list.py
+opal_security/models/paladin.py
+opal_security/models/paladin_connector.py
+opal_security/models/paladin_context_source.py
+opal_security/models/paladin_context_source_kind.py
+opal_security/models/paladin_context_source_list.py
+opal_security/models/paladin_context_source_provider.py
+opal_security/models/paladin_list.py
opal_security/models/propagation_status.py
opal_security/models/propagation_status_enum.py
opal_security/models/rds_engine_enum.py
+opal_security/models/remind_request200_response.py
opal_security/models/remote_user.py
opal_security/models/request.py
opal_security/models/request_approval_enum.py
@@ -510,14 +643,25 @@ opal_security/models/request_reviewer.py
opal_security/models/request_reviewer_stages.py
opal_security/models/request_stage.py
opal_security/models/request_status_enum.py
+opal_security/models/request_template.py
+opal_security/models/request_template_custom_field.py
+opal_security/models/request_template_custom_field_callout_metadata.py
+opal_security/models/request_template_custom_field_input.py
+opal_security/models/request_template_custom_field_metadata.py
+opal_security/models/request_template_custom_field_multi_choice_metadata.py
opal_security/models/request_template_custom_field_type_enum.py
opal_security/models/requested_item.py
opal_security/models/resource.py
opal_security/models/resource_access_level.py
+opal_security/models/resource_access_level_list.py
opal_security/models/resource_access_user.py
opal_security/models/resource_access_user_list.py
+opal_security/models/resource_custom_access_level_list.py
+opal_security/models/resource_custom_access_level_response.py
opal_security/models/resource_nhi.py
opal_security/models/resource_remote_info.py
+opal_security/models/resource_remote_info_alicloud_ecs_instance.py
+opal_security/models/resource_remote_info_alicloud_ram_role.py
opal_security/models/resource_remote_info_anthropic_workspace.py
opal_security/models/resource_remote_info_aws_account.py
opal_security/models/resource_remote_info_aws_ec2_instance.py
@@ -550,8 +694,10 @@ opal_security/models/resource_remote_info_datadog_role.py
opal_security/models/resource_remote_info_datastax_astra_role.py
opal_security/models/resource_remote_info_devin_organization.py
opal_security/models/resource_remote_info_devin_role.py
+opal_security/models/resource_remote_info_docusign_permission_profile.py
opal_security/models/resource_remote_info_gcp_big_query_dataset.py
opal_security/models/resource_remote_info_gcp_big_query_table.py
+opal_security/models/resource_remote_info_gcp_billing_account.py
opal_security/models/resource_remote_info_gcp_bucket.py
opal_security/models/resource_remote_info_gcp_compute_instance.py
opal_security/models/resource_remote_info_gcp_folder.py
@@ -571,6 +717,8 @@ opal_security/models/resource_remote_info_grafana_folder.py
opal_security/models/resource_remote_info_grafana_role.py
opal_security/models/resource_remote_info_hubspot_role.py
opal_security/models/resource_remote_info_ilevel_advanced_role.py
+opal_security/models/resource_remote_info_linear_organization.py
+opal_security/models/resource_remote_info_linear_project.py
opal_security/models/resource_remote_info_netsuite_role.py
opal_security/models/resource_remote_info_okta_app.py
opal_security/models/resource_remote_info_okta_custom_role.py
@@ -590,6 +738,8 @@ opal_security/models/resource_remote_info_teleport_role.py
opal_security/models/resource_remote_info_twingate_resource.py
opal_security/models/resource_remote_info_workday_role.py
opal_security/models/resource_remote_info_zendesk_role.py
+opal_security/models/resource_remote_info_zoom_license.py
+opal_security/models/resource_remote_info_zoom_role.py
opal_security/models/resource_type_enum.py
opal_security/models/resource_user.py
opal_security/models/resource_user_access_status.py
@@ -605,10 +755,13 @@ opal_security/models/role_permission_target_type_enum.py
opal_security/models/rule_clauses.py
opal_security/models/rule_conjunction.py
opal_security/models/rule_disjunction.py
+opal_security/models/run_opal_query_request.py
opal_security/models/scoped_role_permission.py
opal_security/models/scoped_role_permission_list.py
opal_security/models/session.py
opal_security/models/sessions_list.py
+opal_security/models/sort_direction_enum.py
+opal_security/models/stop_campaign_request.py
opal_security/models/string_match_type.py
opal_security/models/sub_event.py
opal_security/models/sync_error.py
@@ -626,6 +779,8 @@ opal_security/models/uar.py
opal_security/models/uar_reviewer_assignment_policy_enum.py
opal_security/models/uar_scope.py
opal_security/models/update_access_rule_info.py
+opal_security/models/update_campaign_configuration_info.py
+opal_security/models/update_campaign_info.py
opal_security/models/update_configuration_template_info.py
opal_security/models/update_event_stream_info.py
opal_security/models/update_group_binding_info.py
@@ -638,14 +793,23 @@ opal_security/models/update_idp_group_mappings_request.py
opal_security/models/update_idp_group_mappings_request_mappings_inner.py
opal_security/models/update_owner_info.py
opal_security/models/update_owner_info_list.py
+opal_security/models/update_paladin_info.py
+opal_security/models/update_request_template_info.py
+opal_security/models/update_resource_custom_access_level_info.py
opal_security/models/update_resource_info.py
opal_security/models/update_resource_info_list.py
opal_security/models/update_resource_user_request.py
+opal_security/models/update_user_info.py
opal_security/models/user.py
opal_security/models/user_attribute_selector.py
opal_security/models/user_hr_idp_status_enum.py
opal_security/models/user_id_list.py
opal_security/models/user_list.py
+opal_security/models/user_product_role_enum.py
+opal_security/models/viewer_campaign_item.py
+opal_security/models/viewer_campaign_item_review_decision_enum.py
+opal_security/models/viewer_campaign_item_sort_field_enum.py
+opal_security/models/viewer_campaign_item_status_enum.py
opal_security/models/visibility_info.py
opal_security/models/visibility_type_enum.py
opal_security/models/webhook_api_key_credential.py
@@ -655,47 +819,91 @@ opal_security/models/webhook_credentials.py
opal_security/models/webhook_hmac_credential.py
opal_security/py.typed
opal_security/rest.py
-pyproject.toml
requirements.txt
setup.cfg
setup.py
test-requirements.txt
test/__init__.py
-test/test_access_entity_filters.py
-test/test_access_relationship_filters.py
-test/test_create_event_stream_info.py
-test/test_entity_item_type_enum.py
-test/test_entity_name_filter.py
-test/test_entity_tag_filter.py
-test/test_event_stream.py
-test/test_event_stream_connection.py
-test/test_event_stream_connection_type_enum.py
-test/test_event_stream_list.py
-test/test_event_streams_api.py
-test/test_group_remote_info_grafana_team.py
-test/test_group_remote_info_hubspot_team.py
-test/test_group_remote_info_slack_user_group.py
-test/test_group_remote_info_twingate_group_synced.py
-test/test_group_remote_info_zendesk_group.py
-test/test_group_remote_info_zendesk_organization.py
-test/test_opal_node_query.py
-test/test_opal_node_query_body.py
-test/test_opal_node_query_results.py
-test/test_opal_queries_api.py
-test/test_opal_query_result_edge.py
-test/test_opal_query_result_node.py
-test/test_paginated_access_rules_list.py
-test/test_resource_remote_info_grafana_dashboard.py
-test/test_resource_remote_info_grafana_folder.py
-test/test_resource_remote_info_grafana_role.py
-test/test_resource_remote_info_hubspot_role.py
-test/test_resource_remote_info_zendesk_role.py
-test/test_string_match_type.py
-test/test_update_event_stream_info.py
-test/test_user_attribute_selector.py
-test/test_webhook_api_key_credential.py
-test/test_webhook_api_key_location_enum.py
-test/test_webhook_auth_type_enum.py
-test/test_webhook_credentials.py
-test/test_webhook_hmac_credential.py
+test/test_campaign.py
+test/test_campaign_configuration.py
+test/test_campaign_group_asset_visibility_policy_enum.py
+test/test_campaign_item.py
+test/test_campaign_item_admin_override.py
+test/test_campaign_item_review.py
+test/test_campaign_item_review_decision_enum.py
+test/test_campaign_item_reviewer_assignment_source_enum.py
+test/test_campaign_item_status_enum.py
+test/test_campaign_item_target_type_enum.py
+test/test_campaign_revoke_on_enum.py
+test/test_campaign_status_enum.py
+test/test_campaigns_api.py
+test/test_create_campaign_configuration_info.py
+test/test_create_campaign_info.py
+test/test_create_paladin_context_source_info.py
+test/test_create_paladin_info.py
+test/test_create_request_template_info.py
+test/test_create_resource_custom_access_level_info.py
+test/test_entity_admin_filter.py
+test/test_group_access_level_list.py
+test/test_group_remote_info_confluence_group.py
+test/test_group_remote_info_docusign_group.py
+test/test_group_remote_info_docusign_signing_group.py
+test/test_group_remote_info_jira_group.py
+test/test_group_remote_info_linear_team.py
+test/test_group_remote_info_tableau_group.py
+test/test_group_remote_info_zoom_group.py
+test/test_idp_status_filter.py
+test/test_invite_user_info.py
+test/test_opal_access_path_edge_filter.py
+test/test_opal_access_path_query.py
+test/test_opal_access_path_query_body.py
+test/test_opal_access_path_query_results.py
+test/test_opal_access_path_result_edge.py
+test/test_opal_access_path_result_node.py
+test/test_opal_query_results.py
+test/test_paginated_campaign_items_list.py
+test/test_paginated_campaigns_list.py
+test/test_paginated_request_template_list.py
+test/test_paginated_viewer_campaign_items_list.py
+test/test_paladin.py
+test/test_paladin_api.py
+test/test_paladin_connector.py
+test/test_paladin_context_source.py
+test/test_paladin_context_source_kind.py
+test/test_paladin_context_source_list.py
+test/test_paladin_context_source_provider.py
+test/test_paladin_list.py
+test/test_remind_request200_response.py
+test/test_request_template.py
+test/test_request_template_custom_field.py
+test/test_request_template_custom_field_callout_metadata.py
+test/test_request_template_custom_field_input.py
+test/test_request_template_custom_field_metadata.py
+test/test_request_template_custom_field_multi_choice_metadata.py
+test/test_request_templates_api.py
+test/test_resource_access_level_list.py
+test/test_resource_custom_access_level_list.py
+test/test_resource_custom_access_level_response.py
+test/test_resource_remote_info_alicloud_ecs_instance.py
+test/test_resource_remote_info_alicloud_ram_role.py
+test/test_resource_remote_info_docusign_permission_profile.py
+test/test_resource_remote_info_gcp_billing_account.py
+test/test_resource_remote_info_linear_organization.py
+test/test_resource_remote_info_linear_project.py
+test/test_resource_remote_info_zoom_license.py
+test/test_resource_remote_info_zoom_role.py
+test/test_run_opal_query_request.py
+test/test_sort_direction_enum.py
+test/test_stop_campaign_request.py
+test/test_update_campaign_configuration_info.py
+test/test_update_campaign_info.py
+test/test_update_paladin_info.py
+test/test_update_request_template_info.py
+test/test_update_resource_custom_access_level_info.py
+test/test_update_user_info.py
+test/test_user_product_role_enum.py
+test/test_viewer_campaign_item.py
+test/test_viewer_campaign_item_review_decision_enum.py
+test/test_viewer_campaign_item_sort_field_enum.py
+test/test_viewer_campaign_item_status_enum.py
tox.ini
diff --git a/README.md b/README.md
index 81688b4..d3c2e31 100644
--- a/README.md
+++ b/README.md
@@ -160,6 +160,15 @@ Class | Method | HTTP request | Description
*BundlesApi* | [**remove_bundle_resource**](docs/BundlesApi.md#remove_bundle_resource) | **DELETE** /bundles/{bundle_id}/resources/{resource_id} |
*BundlesApi* | [**set_bundle_visibility**](docs/BundlesApi.md#set_bundle_visibility) | **PUT** /bundles/{bundle_id}/visibility |
*BundlesApi* | [**update_bundle**](docs/BundlesApi.md#update_bundle) | **PUT** /bundles/{bundle_id} |
+*CampaignsApi* | [**create_campaign**](docs/CampaignsApi.md#create_campaign) | **POST** /campaigns |
+*CampaignsApi* | [**end_campaign**](docs/CampaignsApi.md#end_campaign) | **POST** /campaigns/{campaign_id}/end | End campaign
+*CampaignsApi* | [**get_campaign**](docs/CampaignsApi.md#get_campaign) | **GET** /campaigns/{campaign_id} | Get campaign by ID
+*CampaignsApi* | [**get_campaign_items**](docs/CampaignsApi.md#get_campaign_items) | **GET** /campaigns/{campaign_id}/items | List campaign items
+*CampaignsApi* | [**get_campaign_viewer_items**](docs/CampaignsApi.md#get_campaign_viewer_items) | **GET** /campaigns/{campaign_id}/viewer-items | List viewer campaign items
+*CampaignsApi* | [**get_campaigns**](docs/CampaignsApi.md#get_campaigns) | **GET** /campaigns |
+*CampaignsApi* | [**start_campaign**](docs/CampaignsApi.md#start_campaign) | **POST** /campaigns/{campaign_id}/start | Start campaign
+*CampaignsApi* | [**stop_campaign**](docs/CampaignsApi.md#stop_campaign) | **POST** /campaigns/{campaign_id}/stop | Stop campaign
+*CampaignsApi* | [**update_campaign**](docs/CampaignsApi.md#update_campaign) | **PUT** /campaigns/{campaign_id} | Update campaign
*ConfigurationTemplatesApi* | [**create_configuration_template**](docs/ConfigurationTemplatesApi.md#create_configuration_template) | **POST** /configuration-templates |
*ConfigurationTemplatesApi* | [**delete_configuration_template**](docs/ConfigurationTemplatesApi.md#delete_configuration_template) | **DELETE** /configuration-templates/{configuration_template_id} |
*ConfigurationTemplatesApi* | [**get_configuration_templates**](docs/ConfigurationTemplatesApi.md#get_configuration_templates) | **GET** /configuration-templates |
@@ -186,6 +195,7 @@ Class | Method | HTTP request | Description
*GroupsApi* | [**delete_group**](docs/GroupsApi.md#delete_group) | **DELETE** /groups/{group_id} |
*GroupsApi* | [**delete_group_user**](docs/GroupsApi.md#delete_group_user) | **DELETE** /groups/{group_id}/users/{user_id} |
*GroupsApi* | [**get_group**](docs/GroupsApi.md#get_group) | **GET** /groups/{group_id} | Get group by ID
+*GroupsApi* | [**get_group_access_levels**](docs/GroupsApi.md#get_group_access_levels) | **GET** /groups/{group_id}/access_levels | Get group access levels
*GroupsApi* | [**get_group_containing_group**](docs/GroupsApi.md#get_group_containing_group) | **GET** /groups/{group_id}/containing-groups/{containing_group_id} | Get nested group by ID
*GroupsApi* | [**get_group_containing_groups**](docs/GroupsApi.md#get_group_containing_groups) | **GET** /groups/{group_id}/containing-groups | Get nested groups
*GroupsApi* | [**get_group_message_channels**](docs/GroupsApi.md#get_group_message_channels) | **GET** /groups/{group_id}/message-channels |
@@ -228,7 +238,21 @@ Class | Method | HTTP request | Description
*OwnersApi* | [**get_owners**](docs/OwnersApi.md#get_owners) | **GET** /owners | Get owners
*OwnersApi* | [**set_owner_users**](docs/OwnersApi.md#set_owner_users) | **PUT** /owners/{owner_id}/users |
*OwnersApi* | [**update_owners**](docs/OwnersApi.md#update_owners) | **PUT** /owners |
+*PaladinApi* | [**create_paladin**](docs/PaladinApi.md#create_paladin) | **POST** /paladin | Create Paladin
+*PaladinApi* | [**create_paladin_context_source**](docs/PaladinApi.md#create_paladin_context_source) | **POST** /paladin/{paladin_id}/context-sources | Add a Paladin context source
+*PaladinApi* | [**delete_paladin**](docs/PaladinApi.md#delete_paladin) | **DELETE** /paladin/{paladin_id} | Delete Paladin
+*PaladinApi* | [**delete_paladin_context_source**](docs/PaladinApi.md#delete_paladin_context_source) | **DELETE** /paladin/{paladin_id}/context-sources/{context_source_id} | Remove a Paladin context source
+*PaladinApi* | [**get_paladin**](docs/PaladinApi.md#get_paladin) | **GET** /paladin/{paladin_id} | Get Paladin by ID
+*PaladinApi* | [**get_paladin_from_name**](docs/PaladinApi.md#get_paladin_from_name) | **GET** /paladin/name/{paladin_name} | Get Paladins by name
+*PaladinApi* | [**list_paladin_context_sources**](docs/PaladinApi.md#list_paladin_context_sources) | **GET** /paladin/{paladin_id}/context-sources | List Paladin context sources
+*PaladinApi* | [**update_paladin**](docs/PaladinApi.md#update_paladin) | **PUT** /paladin/{paladin_id} | Update Paladin
+*RequestTemplatesApi* | [**create_request_template**](docs/RequestTemplatesApi.md#create_request_template) | **POST** /request-templates |
+*RequestTemplatesApi* | [**delete_request_template**](docs/RequestTemplatesApi.md#delete_request_template) | **DELETE** /request-templates/{request_template_id} |
+*RequestTemplatesApi* | [**get_request_template**](docs/RequestTemplatesApi.md#get_request_template) | **GET** /request-templates/{request_template_id} |
+*RequestTemplatesApi* | [**get_request_templates**](docs/RequestTemplatesApi.md#get_request_templates) | **GET** /request-templates |
+*RequestTemplatesApi* | [**update_request_template**](docs/RequestTemplatesApi.md#update_request_template) | **PUT** /request-templates |
*RequestsApi* | [**approve_request**](docs/RequestsApi.md#approve_request) | **POST** /requests/{id}/approve |
+*RequestsApi* | [**cancel_request**](docs/RequestsApi.md#cancel_request) | **POST** /requests/{id}/cancel | Cancel request
*RequestsApi* | [**create_request**](docs/RequestsApi.md#create_request) | **POST** /requests |
*RequestsApi* | [**create_request_comment**](docs/RequestsApi.md#create_request_comment) | **POST** /requests/{id}/comments |
*RequestsApi* | [**deny_request**](docs/RequestsApi.md#deny_request) | **POST** /requests/{id}/deny |
@@ -236,13 +260,19 @@ Class | Method | HTTP request | Description
*RequestsApi* | [**get_request_comments**](docs/RequestsApi.md#get_request_comments) | **GET** /requests/{id}/comments |
*RequestsApi* | [**get_requests**](docs/RequestsApi.md#get_requests) | **GET** /requests | Get requests
*RequestsApi* | [**get_requests_relay**](docs/RequestsApi.md#get_requests_relay) | **GET** /requests/relay | Get requests via Relay
+*RequestsApi* | [**remind_request**](docs/RequestsApi.md#remind_request) | **POST** /requests/{id}/remind | Send request reminder
+*RequestsApi* | [**remind_request_reviewer**](docs/RequestsApi.md#remind_request_reviewer) | **POST** /requests/{id}/reviewers/{reviewer_id}/remind | Send reminder to a reviewer
*ResourcesApi* | [**add_resource_nhi**](docs/ResourcesApi.md#add_resource_nhi) | **POST** /resources/{resource_id}/non-human-identities/{non_human_identity_id} |
*ResourcesApi* | [**add_resource_user**](docs/ResourcesApi.md#add_resource_user) | **POST** /resources/{resource_id}/users/{user_id} |
*ResourcesApi* | [**create_resource**](docs/ResourcesApi.md#create_resource) | **POST** /resources |
+*ResourcesApi* | [**create_resource_custom_access_level**](docs/ResourcesApi.md#create_resource_custom_access_level) | **POST** /resources/{resource_id}/custom-access-levels |
*ResourcesApi* | [**delete_resource**](docs/ResourcesApi.md#delete_resource) | **DELETE** /resources/{resource_id} |
+*ResourcesApi* | [**delete_resource_custom_access_level**](docs/ResourcesApi.md#delete_resource_custom_access_level) | **DELETE** /resources/{resource_id}/custom-access-levels/{access_level_remote_id} |
*ResourcesApi* | [**delete_resource_nhi**](docs/ResourcesApi.md#delete_resource_nhi) | **DELETE** /resources/{resource_id}/non-human-identities/{non_human_identity_id} |
*ResourcesApi* | [**delete_resource_user**](docs/ResourcesApi.md#delete_resource_user) | **DELETE** /resources/{resource_id}/users/{user_id} |
*ResourcesApi* | [**get_resource**](docs/ResourcesApi.md#get_resource) | **GET** /resources/{resource_id} | Get resource by ID
+*ResourcesApi* | [**get_resource_access_levels**](docs/ResourcesApi.md#get_resource_access_levels) | **GET** /resources/{resource_id}/access_levels | Get resource access levels
+*ResourcesApi* | [**get_resource_custom_access_levels**](docs/ResourcesApi.md#get_resource_custom_access_levels) | **GET** /resources/{resource_id}/custom-access-levels |
*ResourcesApi* | [**get_resource_groups**](docs/ResourcesApi.md#get_resource_groups) | **GET** /resources/{resource_id}/groups |
*ResourcesApi* | [**get_resource_message_channels**](docs/ResourcesApi.md#get_resource_message_channels) | **GET** /resources/{resource_id}/message-channels |
*ResourcesApi* | [**get_resource_nhis**](docs/ResourcesApi.md#get_resource_nhis) | **GET** /resources/{resource_id}/non-human-identities |
@@ -261,6 +291,7 @@ Class | Method | HTTP request | Description
*ResourcesApi* | [**set_resource_reviewers**](docs/ResourcesApi.md#set_resource_reviewers) | **PUT** /resources/{resource_id}/reviewers |
*ResourcesApi* | [**set_resource_scoped_role_permissions**](docs/ResourcesApi.md#set_resource_scoped_role_permissions) | **PUT** /resources/{resource_id}/scoped-role-permissions |
*ResourcesApi* | [**set_resource_visibility**](docs/ResourcesApi.md#set_resource_visibility) | **PUT** /resources/{resource_id}/visibility |
+*ResourcesApi* | [**update_resource_custom_access_level**](docs/ResourcesApi.md#update_resource_custom_access_level) | **PATCH** /resources/{resource_id}/custom-access-levels/{access_level_remote_id} |
*ResourcesApi* | [**update_resource_user**](docs/ResourcesApi.md#update_resource_user) | **PUT** /resources/{resource_id}/users/{user_id} |
*ResourcesApi* | [**update_resources**](docs/ResourcesApi.md#update_resources) | **PUT** /resources |
*SessionsApi* | [**sessions**](docs/SessionsApi.md#sessions) | **GET** /sessions |
@@ -280,9 +311,13 @@ Class | Method | HTTP request | Description
*UarsApi* | [**create_uar**](docs/UarsApi.md#create_uar) | **POST** /uar |
*UarsApi* | [**get_uar**](docs/UarsApi.md#get_uar) | **GET** /uar/{uar_id} |
*UarsApi* | [**get_uars**](docs/UarsApi.md#get_uars) | **GET** /uars |
+*UsersApi* | [**delete_user**](docs/UsersApi.md#delete_user) | **DELETE** /users/{user_id} |
*UsersApi* | [**get_remote_users**](docs/UsersApi.md#get_remote_users) | **GET** /users/remote_users |
*UsersApi* | [**get_user_tags**](docs/UsersApi.md#get_user_tags) | **GET** /users/{user_id}/tags |
+*UsersApi* | [**get_user_whoami**](docs/UsersApi.md#get_user_whoami) | **GET** /users/whoami |
*UsersApi* | [**get_users**](docs/UsersApi.md#get_users) | **GET** /users |
+*UsersApi* | [**invite_user**](docs/UsersApi.md#invite_user) | **POST** /users |
+*UsersApi* | [**update_user**](docs/UsersApi.md#update_user) | **PATCH** /users/{user_id} |
*UsersApi* | [**user**](docs/UsersApi.md#user) | **GET** /user |
@@ -313,9 +348,23 @@ Class | Method | HTTP request | Description
- [Bundle](docs/Bundle.md)
- [BundleGroup](docs/BundleGroup.md)
- [BundleResource](docs/BundleResource.md)
+ - [Campaign](docs/Campaign.md)
+ - [CampaignConfiguration](docs/CampaignConfiguration.md)
+ - [CampaignGroupAssetVisibilityPolicyEnum](docs/CampaignGroupAssetVisibilityPolicyEnum.md)
+ - [CampaignItem](docs/CampaignItem.md)
+ - [CampaignItemAdminOverride](docs/CampaignItemAdminOverride.md)
+ - [CampaignItemReview](docs/CampaignItemReview.md)
+ - [CampaignItemReviewDecisionEnum](docs/CampaignItemReviewDecisionEnum.md)
+ - [CampaignItemReviewerAssignmentSourceEnum](docs/CampaignItemReviewerAssignmentSourceEnum.md)
+ - [CampaignItemStatusEnum](docs/CampaignItemStatusEnum.md)
+ - [CampaignItemTargetTypeEnum](docs/CampaignItemTargetTypeEnum.md)
+ - [CampaignRevokeOnEnum](docs/CampaignRevokeOnEnum.md)
+ - [CampaignStatusEnum](docs/CampaignStatusEnum.md)
- [Condition](docs/Condition.md)
- [ConfigurationTemplate](docs/ConfigurationTemplate.md)
- [CreateBundleInfo](docs/CreateBundleInfo.md)
+ - [CreateCampaignConfigurationInfo](docs/CreateCampaignConfigurationInfo.md)
+ - [CreateCampaignInfo](docs/CreateCampaignInfo.md)
- [CreateConfigurationTemplateInfo](docs/CreateConfigurationTemplateInfo.md)
- [CreateDelegationRequest](docs/CreateDelegationRequest.md)
- [CreateEventStreamInfo](docs/CreateEventStreamInfo.md)
@@ -326,6 +375,8 @@ Class | Method | HTTP request | Description
- [CreateMessageChannelInfo](docs/CreateMessageChannelInfo.md)
- [CreateOnCallScheduleInfo](docs/CreateOnCallScheduleInfo.md)
- [CreateOwnerInfo](docs/CreateOwnerInfo.md)
+ - [CreatePaladinContextSourceInfo](docs/CreatePaladinContextSourceInfo.md)
+ - [CreatePaladinInfo](docs/CreatePaladinInfo.md)
- [CreateRequest200Response](docs/CreateRequest200Response.md)
- [CreateRequestCommentRequest](docs/CreateRequestCommentRequest.md)
- [CreateRequestConfigurationInfoList](docs/CreateRequestConfigurationInfoList.md)
@@ -334,11 +385,14 @@ Class | Method | HTTP request | Description
- [CreateRequestInfoGroupsInner](docs/CreateRequestInfoGroupsInner.md)
- [CreateRequestInfoResourcesInner](docs/CreateRequestInfoResourcesInner.md)
- [CreateRequestInfoSupportTicket](docs/CreateRequestInfoSupportTicket.md)
+ - [CreateRequestTemplateInfo](docs/CreateRequestTemplateInfo.md)
+ - [CreateResourceCustomAccessLevelInfo](docs/CreateResourceCustomAccessLevelInfo.md)
- [CreateResourceInfo](docs/CreateResourceInfo.md)
- [CreateTagInfo](docs/CreateTagInfo.md)
- [CreateUARInfo](docs/CreateUARInfo.md)
- [Delegation](docs/Delegation.md)
- [DenyRequestRequest](docs/DenyRequestRequest.md)
+ - [EntityAdminFilter](docs/EntityAdminFilter.md)
- [EntityItemTypeEnum](docs/EntityItemTypeEnum.md)
- [EntityNameFilter](docs/EntityNameFilter.md)
- [EntityTagFilter](docs/EntityTagFilter.md)
@@ -351,6 +405,7 @@ Class | Method | HTTP request | Description
- [GetResourceUser200Response](docs/GetResourceUser200Response.md)
- [Group](docs/Group.md)
- [GroupAccessLevel](docs/GroupAccessLevel.md)
+ - [GroupAccessLevelList](docs/GroupAccessLevelList.md)
- [GroupBinding](docs/GroupBinding.md)
- [GroupBindingGroup](docs/GroupBindingGroup.md)
- [GroupContainingGroup](docs/GroupContainingGroup.md)
@@ -361,9 +416,12 @@ Class | Method | HTTP request | Description
- [GroupRemoteInfoAzureAdMicrosoft365Group](docs/GroupRemoteInfoAzureAdMicrosoft365Group.md)
- [GroupRemoteInfoAzureAdSecurityGroup](docs/GroupRemoteInfoAzureAdSecurityGroup.md)
- [GroupRemoteInfoClickhouseRole](docs/GroupRemoteInfoClickhouseRole.md)
+ - [GroupRemoteInfoConfluenceGroup](docs/GroupRemoteInfoConfluenceGroup.md)
- [GroupRemoteInfoConnectorGroup](docs/GroupRemoteInfoConnectorGroup.md)
- [GroupRemoteInfoDatabricksAccountGroup](docs/GroupRemoteInfoDatabricksAccountGroup.md)
- [GroupRemoteInfoDevinGroup](docs/GroupRemoteInfoDevinGroup.md)
+ - [GroupRemoteInfoDocusignGroup](docs/GroupRemoteInfoDocusignGroup.md)
+ - [GroupRemoteInfoDocusignSigningGroup](docs/GroupRemoteInfoDocusignSigningGroup.md)
- [GroupRemoteInfoDuoGroup](docs/GroupRemoteInfoDuoGroup.md)
- [GroupRemoteInfoGithubEnterpriseTeam](docs/GroupRemoteInfoGithubEnterpriseTeam.md)
- [GroupRemoteInfoGithubTeam](docs/GroupRemoteInfoGithubTeam.md)
@@ -372,19 +430,23 @@ Class | Method | HTTP request | Description
- [GroupRemoteInfoGrafanaTeam](docs/GroupRemoteInfoGrafanaTeam.md)
- [GroupRemoteInfoHubspotTeam](docs/GroupRemoteInfoHubspotTeam.md)
- [GroupRemoteInfoIncidentioOnCallSchedule](docs/GroupRemoteInfoIncidentioOnCallSchedule.md)
+ - [GroupRemoteInfoJiraGroup](docs/GroupRemoteInfoJiraGroup.md)
- [GroupRemoteInfoLdapGroup](docs/GroupRemoteInfoLdapGroup.md)
+ - [GroupRemoteInfoLinearTeam](docs/GroupRemoteInfoLinearTeam.md)
- [GroupRemoteInfoOktaGroup](docs/GroupRemoteInfoOktaGroup.md)
- [GroupRemoteInfoOktaGroupRule](docs/GroupRemoteInfoOktaGroupRule.md)
- [GroupRemoteInfoPagerdutyOnCallSchedule](docs/GroupRemoteInfoPagerdutyOnCallSchedule.md)
- [GroupRemoteInfoRootlyOnCallSchedule](docs/GroupRemoteInfoRootlyOnCallSchedule.md)
- [GroupRemoteInfoSlackUserGroup](docs/GroupRemoteInfoSlackUserGroup.md)
- [GroupRemoteInfoSnowflakeRole](docs/GroupRemoteInfoSnowflakeRole.md)
+ - [GroupRemoteInfoTableauGroup](docs/GroupRemoteInfoTableauGroup.md)
- [GroupRemoteInfoTailscaleGroup](docs/GroupRemoteInfoTailscaleGroup.md)
- [GroupRemoteInfoTwingateGroup](docs/GroupRemoteInfoTwingateGroup.md)
- [GroupRemoteInfoTwingateGroupSynced](docs/GroupRemoteInfoTwingateGroupSynced.md)
- [GroupRemoteInfoWorkdayUserSecurityGroup](docs/GroupRemoteInfoWorkdayUserSecurityGroup.md)
- [GroupRemoteInfoZendeskGroup](docs/GroupRemoteInfoZendeskGroup.md)
- [GroupRemoteInfoZendeskOrganization](docs/GroupRemoteInfoZendeskOrganization.md)
+ - [GroupRemoteInfoZoomGroup](docs/GroupRemoteInfoZoomGroup.md)
- [GroupResource](docs/GroupResource.md)
- [GroupResourceList](docs/GroupResourceList.md)
- [GroupTypeEnum](docs/GroupTypeEnum.md)
@@ -393,6 +455,8 @@ Class | Method | HTTP request | Description
- [GroupWithAccessLevel](docs/GroupWithAccessLevel.md)
- [IdpGroupMapping](docs/IdpGroupMapping.md)
- [IdpGroupMappingList](docs/IdpGroupMappingList.md)
+ - [IdpStatusFilter](docs/IdpStatusFilter.md)
+ - [InviteUserInfo](docs/InviteUserInfo.md)
- [MessageChannel](docs/MessageChannel.md)
- [MessageChannelIDList](docs/MessageChannelIDList.md)
- [MessageChannelList](docs/MessageChannelList.md)
@@ -401,11 +465,18 @@ Class | Method | HTTP request | Description
- [OnCallScheduleIDList](docs/OnCallScheduleIDList.md)
- [OnCallScheduleList](docs/OnCallScheduleList.md)
- [OnCallScheduleProviderEnum](docs/OnCallScheduleProviderEnum.md)
+ - [OpalAccessPathEdgeFilter](docs/OpalAccessPathEdgeFilter.md)
+ - [OpalAccessPathQuery](docs/OpalAccessPathQuery.md)
+ - [OpalAccessPathQueryBody](docs/OpalAccessPathQueryBody.md)
+ - [OpalAccessPathQueryResults](docs/OpalAccessPathQueryResults.md)
+ - [OpalAccessPathResultEdge](docs/OpalAccessPathResultEdge.md)
+ - [OpalAccessPathResultNode](docs/OpalAccessPathResultNode.md)
- [OpalNodeQuery](docs/OpalNodeQuery.md)
- [OpalNodeQueryBody](docs/OpalNodeQueryBody.md)
- [OpalNodeQueryResults](docs/OpalNodeQueryResults.md)
- [OpalQueryResultEdge](docs/OpalQueryResultEdge.md)
- [OpalQueryResultNode](docs/OpalQueryResultNode.md)
+ - [OpalQueryResults](docs/OpalQueryResults.md)
- [Owner](docs/Owner.md)
- [PageInfo](docs/PageInfo.md)
- [PaginatedAccessRulesList](docs/PaginatedAccessRulesList.md)
@@ -413,6 +484,8 @@ Class | Method | HTTP request | Description
- [PaginatedBundleGroupList](docs/PaginatedBundleGroupList.md)
- [PaginatedBundleList](docs/PaginatedBundleList.md)
- [PaginatedBundleResourceList](docs/PaginatedBundleResourceList.md)
+ - [PaginatedCampaignItemsList](docs/PaginatedCampaignItemsList.md)
+ - [PaginatedCampaignsList](docs/PaginatedCampaignsList.md)
- [PaginatedConfigurationTemplateList](docs/PaginatedConfigurationTemplateList.md)
- [PaginatedDelegationsList](docs/PaginatedDelegationsList.md)
- [PaginatedEventList](docs/PaginatedEventList.md)
@@ -420,14 +493,24 @@ Class | Method | HTTP request | Description
- [PaginatedGroupsList](docs/PaginatedGroupsList.md)
- [PaginatedOwnersList](docs/PaginatedOwnersList.md)
- [PaginatedRemoteUsersList](docs/PaginatedRemoteUsersList.md)
+ - [PaginatedRequestTemplateList](docs/PaginatedRequestTemplateList.md)
- [PaginatedResourcesList](docs/PaginatedResourcesList.md)
- [PaginatedTagsList](docs/PaginatedTagsList.md)
- [PaginatedTokensList](docs/PaginatedTokensList.md)
- [PaginatedUARsList](docs/PaginatedUARsList.md)
- [PaginatedUsersList](docs/PaginatedUsersList.md)
+ - [PaginatedViewerCampaignItemsList](docs/PaginatedViewerCampaignItemsList.md)
+ - [Paladin](docs/Paladin.md)
+ - [PaladinConnector](docs/PaladinConnector.md)
+ - [PaladinContextSource](docs/PaladinContextSource.md)
+ - [PaladinContextSourceKind](docs/PaladinContextSourceKind.md)
+ - [PaladinContextSourceList](docs/PaladinContextSourceList.md)
+ - [PaladinContextSourceProvider](docs/PaladinContextSourceProvider.md)
+ - [PaladinList](docs/PaladinList.md)
- [PropagationStatus](docs/PropagationStatus.md)
- [PropagationStatusEnum](docs/PropagationStatusEnum.md)
- [RDSEngineEnum](docs/RDSEngineEnum.md)
+ - [RemindRequest200Response](docs/RemindRequest200Response.md)
- [RemoteUser](docs/RemoteUser.md)
- [Request](docs/Request.md)
- [RequestApprovalEnum](docs/RequestApprovalEnum.md)
@@ -444,14 +527,25 @@ Class | Method | HTTP request | Description
- [RequestReviewerStages](docs/RequestReviewerStages.md)
- [RequestStage](docs/RequestStage.md)
- [RequestStatusEnum](docs/RequestStatusEnum.md)
+ - [RequestTemplate](docs/RequestTemplate.md)
+ - [RequestTemplateCustomField](docs/RequestTemplateCustomField.md)
+ - [RequestTemplateCustomFieldCalloutMetadata](docs/RequestTemplateCustomFieldCalloutMetadata.md)
+ - [RequestTemplateCustomFieldInput](docs/RequestTemplateCustomFieldInput.md)
+ - [RequestTemplateCustomFieldMetadata](docs/RequestTemplateCustomFieldMetadata.md)
+ - [RequestTemplateCustomFieldMultiChoiceMetadata](docs/RequestTemplateCustomFieldMultiChoiceMetadata.md)
- [RequestTemplateCustomFieldTypeEnum](docs/RequestTemplateCustomFieldTypeEnum.md)
- [RequestedItem](docs/RequestedItem.md)
- [Resource](docs/Resource.md)
- [ResourceAccessLevel](docs/ResourceAccessLevel.md)
+ - [ResourceAccessLevelList](docs/ResourceAccessLevelList.md)
- [ResourceAccessUser](docs/ResourceAccessUser.md)
- [ResourceAccessUserList](docs/ResourceAccessUserList.md)
+ - [ResourceCustomAccessLevelList](docs/ResourceCustomAccessLevelList.md)
+ - [ResourceCustomAccessLevelResponse](docs/ResourceCustomAccessLevelResponse.md)
- [ResourceNHI](docs/ResourceNHI.md)
- [ResourceRemoteInfo](docs/ResourceRemoteInfo.md)
+ - [ResourceRemoteInfoAlicloudEcsInstance](docs/ResourceRemoteInfoAlicloudEcsInstance.md)
+ - [ResourceRemoteInfoAlicloudRamRole](docs/ResourceRemoteInfoAlicloudRamRole.md)
- [ResourceRemoteInfoAnthropicWorkspace](docs/ResourceRemoteInfoAnthropicWorkspace.md)
- [ResourceRemoteInfoAwsAccount](docs/ResourceRemoteInfoAwsAccount.md)
- [ResourceRemoteInfoAwsEc2Instance](docs/ResourceRemoteInfoAwsEc2Instance.md)
@@ -484,8 +578,10 @@ Class | Method | HTTP request | Description
- [ResourceRemoteInfoDatastaxAstraRole](docs/ResourceRemoteInfoDatastaxAstraRole.md)
- [ResourceRemoteInfoDevinOrganization](docs/ResourceRemoteInfoDevinOrganization.md)
- [ResourceRemoteInfoDevinRole](docs/ResourceRemoteInfoDevinRole.md)
+ - [ResourceRemoteInfoDocusignPermissionProfile](docs/ResourceRemoteInfoDocusignPermissionProfile.md)
- [ResourceRemoteInfoGcpBigQueryDataset](docs/ResourceRemoteInfoGcpBigQueryDataset.md)
- [ResourceRemoteInfoGcpBigQueryTable](docs/ResourceRemoteInfoGcpBigQueryTable.md)
+ - [ResourceRemoteInfoGcpBillingAccount](docs/ResourceRemoteInfoGcpBillingAccount.md)
- [ResourceRemoteInfoGcpBucket](docs/ResourceRemoteInfoGcpBucket.md)
- [ResourceRemoteInfoGcpComputeInstance](docs/ResourceRemoteInfoGcpComputeInstance.md)
- [ResourceRemoteInfoGcpFolder](docs/ResourceRemoteInfoGcpFolder.md)
@@ -505,6 +601,8 @@ Class | Method | HTTP request | Description
- [ResourceRemoteInfoGrafanaRole](docs/ResourceRemoteInfoGrafanaRole.md)
- [ResourceRemoteInfoHubspotRole](docs/ResourceRemoteInfoHubspotRole.md)
- [ResourceRemoteInfoIlevelAdvancedRole](docs/ResourceRemoteInfoIlevelAdvancedRole.md)
+ - [ResourceRemoteInfoLinearOrganization](docs/ResourceRemoteInfoLinearOrganization.md)
+ - [ResourceRemoteInfoLinearProject](docs/ResourceRemoteInfoLinearProject.md)
- [ResourceRemoteInfoNetsuiteRole](docs/ResourceRemoteInfoNetsuiteRole.md)
- [ResourceRemoteInfoOktaApp](docs/ResourceRemoteInfoOktaApp.md)
- [ResourceRemoteInfoOktaCustomRole](docs/ResourceRemoteInfoOktaCustomRole.md)
@@ -524,6 +622,8 @@ Class | Method | HTTP request | Description
- [ResourceRemoteInfoTwingateResource](docs/ResourceRemoteInfoTwingateResource.md)
- [ResourceRemoteInfoWorkdayRole](docs/ResourceRemoteInfoWorkdayRole.md)
- [ResourceRemoteInfoZendeskRole](docs/ResourceRemoteInfoZendeskRole.md)
+ - [ResourceRemoteInfoZoomLicense](docs/ResourceRemoteInfoZoomLicense.md)
+ - [ResourceRemoteInfoZoomRole](docs/ResourceRemoteInfoZoomRole.md)
- [ResourceTypeEnum](docs/ResourceTypeEnum.md)
- [ResourceUser](docs/ResourceUser.md)
- [ResourceUserAccessStatus](docs/ResourceUserAccessStatus.md)
@@ -539,10 +639,13 @@ Class | Method | HTTP request | Description
- [RuleClauses](docs/RuleClauses.md)
- [RuleConjunction](docs/RuleConjunction.md)
- [RuleDisjunction](docs/RuleDisjunction.md)
+ - [RunOpalQueryRequest](docs/RunOpalQueryRequest.md)
- [ScopedRolePermission](docs/ScopedRolePermission.md)
- [ScopedRolePermissionList](docs/ScopedRolePermissionList.md)
- [Session](docs/Session.md)
- [SessionsList](docs/SessionsList.md)
+ - [SortDirectionEnum](docs/SortDirectionEnum.md)
+ - [StopCampaignRequest](docs/StopCampaignRequest.md)
- [StringMatchType](docs/StringMatchType.md)
- [SubEvent](docs/SubEvent.md)
- [SyncError](docs/SyncError.md)
@@ -560,6 +663,8 @@ Class | Method | HTTP request | Description
- [UARReviewerAssignmentPolicyEnum](docs/UARReviewerAssignmentPolicyEnum.md)
- [UARScope](docs/UARScope.md)
- [UpdateAccessRuleInfo](docs/UpdateAccessRuleInfo.md)
+ - [UpdateCampaignConfigurationInfo](docs/UpdateCampaignConfigurationInfo.md)
+ - [UpdateCampaignInfo](docs/UpdateCampaignInfo.md)
- [UpdateConfigurationTemplateInfo](docs/UpdateConfigurationTemplateInfo.md)
- [UpdateEventStreamInfo](docs/UpdateEventStreamInfo.md)
- [UpdateGroupBindingInfo](docs/UpdateGroupBindingInfo.md)
@@ -572,14 +677,23 @@ Class | Method | HTTP request | Description
- [UpdateIdpGroupMappingsRequestMappingsInner](docs/UpdateIdpGroupMappingsRequestMappingsInner.md)
- [UpdateOwnerInfo](docs/UpdateOwnerInfo.md)
- [UpdateOwnerInfoList](docs/UpdateOwnerInfoList.md)
+ - [UpdatePaladinInfo](docs/UpdatePaladinInfo.md)
+ - [UpdateRequestTemplateInfo](docs/UpdateRequestTemplateInfo.md)
+ - [UpdateResourceCustomAccessLevelInfo](docs/UpdateResourceCustomAccessLevelInfo.md)
- [UpdateResourceInfo](docs/UpdateResourceInfo.md)
- [UpdateResourceInfoList](docs/UpdateResourceInfoList.md)
- [UpdateResourceUserRequest](docs/UpdateResourceUserRequest.md)
+ - [UpdateUserInfo](docs/UpdateUserInfo.md)
- [User](docs/User.md)
- [UserAttributeSelector](docs/UserAttributeSelector.md)
- [UserHrIdpStatusEnum](docs/UserHrIdpStatusEnum.md)
- [UserIDList](docs/UserIDList.md)
- [UserList](docs/UserList.md)
+ - [UserProductRoleEnum](docs/UserProductRoleEnum.md)
+ - [ViewerCampaignItem](docs/ViewerCampaignItem.md)
+ - [ViewerCampaignItemReviewDecisionEnum](docs/ViewerCampaignItemReviewDecisionEnum.md)
+ - [ViewerCampaignItemSortFieldEnum](docs/ViewerCampaignItemSortFieldEnum.md)
+ - [ViewerCampaignItemStatusEnum](docs/ViewerCampaignItemStatusEnum.md)
- [VisibilityInfo](docs/VisibilityInfo.md)
- [VisibilityTypeEnum](docs/VisibilityTypeEnum.md)
- [WebhookApiKeyCredential](docs/WebhookApiKeyCredential.md)
diff --git a/api/openapi.yaml b/api/openapi.yaml
index b1418bc..2055a7f 100644
--- a/api/openapi.yaml
+++ b/api/openapi.yaml
@@ -20,6 +20,8 @@ tags:
description: Operations related to apps
- name: bundles
description: Operations related to bundles
+ - name: campaigns
+ description: Operations related to access review campaigns
- name: configuration-templates
description: Operations related to configuration templates
- name: delegations
@@ -48,6 +50,9 @@ tags:
description: Operations related to requests
- name: resources
description: Operations related to resources
+ - name: paladin
+ description: Operations related to Paladin
+
- name: sessions
description: Operations related to sessions
- name: tags
@@ -55,7 +60,8 @@ tags:
- name: tokens
description: Operations related to API tokens
- name: uars
- description: Operations related to UARs
+ description:
+ Operations related to UARs. Deprecated in favor of the `campaigns` API.
- name: users
description: Operations related to users
paths:
@@ -598,164 +604,313 @@ paths:
- BearerAuth: []
tags:
- bundles
- /configuration-templates:
+ /campaigns:
get:
- description: Returns a list of `ConfigurationTemplate` objects.
- operationId: getConfigurationTemplates
+ description: Returns a list of `Campaign` objects.
+ operationId: getCampaigns
+ parameters:
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
+ - description: Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive).
+ example: Q3 Access Review
+ explode: true
+ in: query
+ name: name
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Filter by campaign status. Status is derived from lifecycle timestamps and review progress.
+ example: ONGOING
+ explode: true
+ in: query
+ name: status
+ required: false
+ schema:
+ $ref: "#/components/schemas/CampaignStatusEnum"
+ style: form
+ - description: Include campaigns created after this timestamp (exclusive). ISO 8601 format.
+ example: 2026-01-01T00:00:00Z
+ explode: true
+ in: query
+ name: created_at_after
+ required: false
+ schema:
+ type: string
+ format: date-time
+ style: form
+ - description: Include campaigns created before this timestamp (exclusive). ISO 8601 format.
+ example: 2026-12-31T23:59:59Z
+ explode: true
+ in: query
+ name: created_at_before
+ required: false
+ schema:
+ type: string
+ format: date-time
+ style: form
+ - description: Include campaigns started after this timestamp (exclusive). ISO 8601 format.
+ example: 2026-01-01T00:00:00Z
+ explode: true
+ in: query
+ name: started_at_after
+ required: false
+ schema:
+ type: string
+ format: date-time
+ style: form
+ - description: Include campaigns started before this timestamp (exclusive). ISO 8601 format.
+ example: 2026-12-31T23:59:59Z
+ explode: true
+ in: query
+ name: started_at_before
+ required: false
+ schema:
+ type: string
+ format: date-time
+ style: form
+ - description: Include campaigns ended after this timestamp (exclusive). ISO 8601 format.
+ example: 2026-01-01T00:00:00Z
+ explode: true
+ in: query
+ name: ended_at_after
+ required: false
+ schema:
+ type: string
+ format: date-time
+ style: form
+ - description: Include campaigns ended before this timestamp (exclusive). ISO 8601 format.
+ example: 2026-12-31T23:59:59Z
+ explode: true
+ in: query
+ name: ended_at_before
+ required: false
+ schema:
+ type: string
+ format: date-time
+ style: form
+ - description: Include campaigns stopped after this timestamp (exclusive). ISO 8601 format.
+ example: 2026-01-01T00:00:00Z
+ explode: true
+ in: query
+ name: stopped_at_after
+ required: false
+ schema:
+ type: string
+ format: date-time
+ style: form
+ - description: Include campaigns stopped before this timestamp (exclusive). ISO 8601 format.
+ example: 2026-12-31T23:59:59Z
+ explode: true
+ in: query
+ name: stopped_at_before
+ required: false
+ schema:
+ type: string
+ format: date-time
+ style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedConfigurationTemplateList"
- description: One page worth of configuration templates for your organization.
+ $ref: "#/components/schemas/PaginatedCampaignsList"
+ description: A list of campaigns for your organization.
security:
- BearerAuth: []
tags:
- - configuration-templates
+ - campaigns
post:
- description: Creates a configuration template.
- operationId: createConfigurationTemplate
+ description: |
+ Creates a campaign. Campaign scope only supports direct access edges:
+ `configuration.query.edgeFilter.directOnly` defaults to `true`, is
+ always stored as `true`, and passing `false` returns 400.
+ operationId: createCampaign
requestBody:
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateConfigurationTemplateInfo"
+ $ref: "#/components/schemas/CreateCampaignInfo"
responses:
- "200":
+ "201":
+ description: The campaign successfully created.
content:
application/json:
schema:
- $ref: "#/components/schemas/ConfigurationTemplate"
- description: The configuration template just created.
+ $ref: "#/components/schemas/Campaign"
security:
- BearerAuth: []
tags:
- - configuration-templates
- put:
- description: Update a configuration template.
- operationId: updateConfigurationTemplate
+ - campaigns
+ /campaigns/{campaign_id}:
+ get:
+ summary: Get campaign by ID
+ description: Returns a `Campaign` object.
+ operationId: getCampaign
+ parameters:
+ - description: The ID of the campaign.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
+ explode: true
+ in: path
+ name: campaign_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/ConfigurationTemplate"
- description: The configuration template just updated.
- requestBody:
- description: Configuration template to be updated
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UpdateConfigurationTemplateInfo"
+ $ref: "#/components/schemas/Campaign"
+ description: The requested `Campaign`.
security:
- BearerAuth: []
tags:
- - configuration-templates
- /configuration-templates/{configuration_template_id}:
- delete:
- description: Deletes a configuration template.
- operationId: deleteConfigurationTemplate
+ - campaigns
+ put:
+ summary: Update campaign
+ description: |
+ Partially updates a campaign. Omitted fields are left unchanged.
+ `configuration.query` and `configuration.reviewer_assignment_policy`
+ cannot be updated after create; including either field returns 400.
+ `configuration.cron_expression` and
+ `configuration.recurring_duration_days` may only be set on template
+ campaigns; setting them on a one-off campaign returns 400.
+ `configuration.is_template` is immutable and not accepted on update.
+ Configuration updates on a stopped or ended (non-template) campaign
+ return 400. Name-only updates are still allowed.
+ operationId: updateCampaign
parameters:
- - description: The ID of the configuration template.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the campaign.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
+ explode: true
in: path
- name: configuration_template_id
+ name: campaign_id
required: true
schema:
format: uuid
type: string
style: simple
- responses:
- "200":
- description: The configuration template was successfully deleted.
- security:
- - BearerAuth: []
- tags:
- - configuration-templates
- /event-streams:
- get:
- summary: Get event streams
- description: Returns a list of configured event streaming connections for your organization.
- operationId: getEventStreams
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdateCampaignInfo"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/EventStreamList"
- description: A list of event streams for your organization.
+ $ref: "#/components/schemas/Campaign"
+ description: The updated `Campaign`.
security:
- BearerAuth: []
tags:
- - event-streams
+ - campaigns
+ /campaigns/{campaign_id}/start:
post:
- summary: Create event stream
- description: Creates a new event streaming connection.
- operationId: createEventStream
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/CreateEventStreamInfo"
+ summary: Start campaign
+ description: |
+ Starts a draft campaign immediately, setting `started_at` and
+ `started_by_user_id`. Returns 400 if the campaign is not in draft
+ state, or if it is a recurring template (`is_template: true`) —
+ templates spawn draft campaigns on their schedule and cannot be
+ started directly.
+ operationId: startCampaign
+ parameters:
+ - description: The ID of the campaign.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
+ explode: true
+ in: path
+ name: campaign_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/EventStream"
- description: The event stream just created. Credentials are returned in clear text only on creation.
+ $ref: "#/components/schemas/Campaign"
+ description: The started `Campaign`.
security:
- BearerAuth: []
tags:
- - event-streams
- /event-streams/{event_stream_id}:
- put:
- summary: Update event stream
- description: Updates an existing event streaming connection.
- operationId: updateEventStream
+ - campaigns
+ /campaigns/{campaign_id}/stop:
+ post:
+ summary: Stop campaign
+ description: |
+ Stops an ongoing campaign immediately, setting `stopped_at` and
+ `stopped_by_user_id`. Returns 400 if the campaign has not started or
+ has already stopped.
+ operationId: stopCampaign
parameters:
- - description: The ID of the event stream.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the campaign.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
+ explode: true
in: path
- name: event_stream_id
+ name: campaign_id
required: true
schema:
format: uuid
type: string
style: simple
requestBody:
- required: true
+ required: false
content:
application/json:
schema:
- $ref: "#/components/schemas/UpdateEventStreamInfo"
+ $ref: "#/components/schemas/StopCampaignRequest"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/EventStream"
- description: The updated event stream.
+ $ref: "#/components/schemas/Campaign"
+ description: The stopped `Campaign`.
security:
- BearerAuth: []
tags:
- - event-streams
- delete:
- summary: Delete event stream
- description: Deletes an event streaming connection.
- operationId: deleteEventStream
+ - campaigns
+ /campaigns/{campaign_id}/end:
+ post:
+ summary: End campaign
+ description: |
+ Ends a stopped campaign, setting `ended_at` and `ended_by_user_id`,
+ applying pending access changes, and queuing report generation.
+ Returns 400 unless the campaign is started and stopped and not already
+ ended.
+ operationId: endCampaign
parameters:
- - description: The ID of the event stream.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the campaign.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
+ explode: true
in: path
- name: event_stream_id
+ name: campaign_id
required: true
schema:
format: uuid
@@ -763,151 +918,133 @@ paths:
style: simple
responses:
"200":
- description: The event stream was successfully deleted.
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Campaign"
+ description: The ended `Campaign`.
security:
- BearerAuth: []
tags:
- - event-streams
- /events:
+ - campaigns
+ /campaigns/{campaign_id}/items:
get:
- description: Returns a list of `Event` objects.
- operationId: events
+ summary: List campaign items
+ description: |
+ Returns a paginated list of review items for a campaign — the same rows
+ shown on the admin Reviews tab. Status is derived using the same rules
+ as the UI Status column. Soft-deleted role assignments are still
+ returned with `is_target_deleted: true`.
+ operationId: getCampaignItems
parameters:
- - description: A start date filter for the events.
- examples:
- withDate:
- summary: Example with date
- value: 2021-11-01
- withDatetime:
- summary: Example with date and time in ISO 8601 datetime format.
- value: 2025-01-01T00:00:00Z
+ - description: The ID of the campaign.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
explode: true
- in: query
- name: start_date_filter
- required: false
+ in: path
+ name: campaign_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
- - description: An end date filter for the events.
- examples:
- withDate:
- summary: Example with date
- value: 2021-11-12
- withDatetime:
- summary: Example with date and time in ISO 8601 datetime format.
- value: 2025-01-01T00:00:00Z
+ style: simple
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
explode: true
in: query
- name: end_date_filter
+ name: cursor
required: false
schema:
type: string
style: form
- - description: An actor filter for the events. Supply the ID of the actor.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ - description: |
+ Number of results to return per page. Default is 200; maximum is
+ 500 (the campaign-items list cap).
+ example: 200
explode: true
in: query
- name: actor_filter
+ name: page_size
required: false
schema:
- format: uuid
- type: string
+ type: integer
+ maximum: 500
style: form
- - description: An object filter for the events. Supply the ID of the object.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ - description: |
+ Filter by derived item status. When multiple values are provided,
+ items matching any status are returned (OR).
explode: true
in: query
- name: object_filter
+ name: statuses
required: false
schema:
- format: uuid
- type: string
+ items:
+ $ref: "#/components/schemas/CampaignItemStatusEnum"
+ type: array
style: form
- - description: An event type filter for the events.
- example: USER_MFA_RESET
+ - description: Restrict to items assigned to this reviewer user ID.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
explode: true
in: query
- name: event_type_filter
+ name: reviewer_user_id
required: false
schema:
+ format: uuid
type: string
style: form
- - description:
- An API filter for the events. Supply the name and preview of the
- API token.
- example: fullaccess:**************************M_g==
+ - description: When true, restrict to items with no reviewer assigned.
explode: true
in: query
- name: api_token_filter
+ name: unassigned
required: false
schema:
- type: string
+ type: boolean
style: form
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ - description: |
+ Case-insensitive search over principal name, asset name, and
+ reviewer name.
explode: true
in: query
- name: cursor
+ name: search
required: false
schema:
type: string
style: form
- - description: Number of results to return per page. Default is 200.
- example: 200
- explode: true
- in: query
- name: page_size
- required: false
- schema:
- type: integer
- maximum: 1000
- style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedEventList"
- description: One page worth of events with the appropriate filters applied.
+ $ref: "#/components/schemas/PaginatedCampaignItemsList"
+ description: A page of campaign items.
+ "404":
+ description: Campaign not found.
security:
- BearerAuth: []
tags:
- - events
- /events/{event_id}:
+ - campaigns
+ /campaigns/{campaign_id}/viewer-items:
get:
- summary: Get event by ID
- description: Returns an `Event` object.
- operationId: getEvent
+ summary: List viewer campaign items
+ description: |
+ Returns a paginated list of campaign review items assigned to the
+ current authenticated viewer. Matches GraphQL `Campaign.viewerItems`.
+
+ Campaign access matches `GET /campaigns/{campaign_id}` and GraphQL
+ `campaign(id)`: the caller must have access-review read permission or
+ be a reviewer on the campaign. Otherwise the request fails with 403
+ (same as get-by-id). Item rows are still scoped to the caller's own
+ reviews (empty page when the caller is an admin but not a reviewer).
+ operationId: getCampaignViewerItems
parameters:
- - description: The ID of the event.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ - description: The ID of the campaign.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
explode: true
in: path
- name: event_id
+ name: campaign_id
required: true
schema:
format: uuid
type: string
style: simple
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/Event"
- description: The requested `Event`.
- "404":
- description: Event not found.
- security:
- - BearerAuth: []
- tags:
- - events
- /groups:
- get:
- summary: Get groups
- description: Returns a list of groups for your organization.
- operationId: getGroups
- parameters:
- description: The pagination cursor value.
example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
explode: true
@@ -917,7 +1054,9 @@ paths:
schema:
type: string
style: form
- - description: Number of results to return per page. Default is 200.
+ - description: |
+ Number of results to return per page. Default is 200; maximum is
+ 500.
example: 200
explode: true
in: query
@@ -925,141 +1064,166 @@ paths:
required: false
schema:
type: integer
- maximum: 1000
+ maximum: 500
style: form
- - description: The group type to filter by.
- example: OPAL_GROUP
+ - description: |
+ Sort by. Omit to sort by created_at.
explode: true
in: query
- name: group_type_filter
+ name: sort_field
required: false
schema:
- $ref: "#/components/schemas/GroupTypeEnum"
+ $ref: "#/components/schemas/ViewerCampaignItemSortFieldEnum"
style: form
- - description: The group ids to filter by.
- example:
- - 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- - 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
+ - description: Sort direction.
+ explode: true
in: query
- name: group_ids
+ name: sort_direction
+ required: false
+ schema:
+ $ref: "#/components/schemas/SortDirectionEnum"
+ style: form
+ - description: |
+ Filter by review status. When multiple values are provided,
+ items matching any status are returned (OR).
+ explode: true
+ in: query
+ name: statuses
+ required: false
+ schema:
+ items:
+ $ref: "#/components/schemas/ViewerCampaignItemStatusEnum"
+ type: array
+ style: form
+ - description: Filter by access level name.
+ explode: true
+ in: query
+ name: access_level_names
required: false
schema:
items:
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- format: uuid
type: string
type: array
style: form
- - description: Group name.
- example: example-name
+ - description: Filter by principal ID.
explode: true
in: query
- name: group_name
+ name: principal_ids
required: false
schema:
- type: string
+ items:
+ format: uuid
+ type: string
+ type: array
style: form
- - description:
- The IDs of the tags to filter by. Returns only groups that have any
- of these tags applied.
+ - description: Filter by entity ID.
+ explode: true
in: query
- name: tag_ids
+ name: entity_ids
required: false
schema:
+ items:
+ format: uuid
+ type: string
type: array
+ style: form
+ - description: Filter to specific campaign item review IDs.
+ explode: true
+ in: query
+ name: item_ids
+ required: false
+ schema:
items:
format: uuid
type: string
+ type: array
+ style: form
+ - description: Restrict to items in this AI-suggestion bucket.
+ explode: true
+ in: query
+ name: ai_bucket_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedGroupsList"
- description: One page worth groups associated with your organization.
+ $ref: "#/components/schemas/PaginatedViewerCampaignItemsList"
+ description: A page of viewer campaign items.
security:
- BearerAuth: []
tags:
- - groups
- put:
- description: Bulk updates a list of groups.
- operationId: updateGroups
- requestBody:
- description: Groups to be updated
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UpdateGroupInfoList"
+ - campaigns
+ /configuration-templates:
+ get:
+ description: Returns a list of `ConfigurationTemplate` objects.
+ operationId: getConfigurationTemplates
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/UpdateGroupInfoList"
- description: The resulting updated group infos.
+ $ref: "#/components/schemas/PaginatedConfigurationTemplateList"
+ description: One page worth of configuration templates for your organization.
security:
- BearerAuth: []
tags:
- - groups
+ - configuration-templates
post:
- description: Creates an Opal group or [imports a remote
- group](https://docs.opal.dev/reference/end-system-objects).
- operationId: createGroup
+ description: Creates a configuration template.
+ operationId: createConfigurationTemplate
requestBody:
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateGroupInfo"
+ $ref: "#/components/schemas/CreateConfigurationTemplateInfo"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/Group"
- description: The group just created.
+ $ref: "#/components/schemas/ConfigurationTemplate"
+ description: The configuration template just created.
security:
- BearerAuth: []
tags:
- - groups
- /groups/{group_id}:
- get:
- summary: Get group by ID
- description: Returns a `Group` object.
- operationId: getGroup
- parameters:
- - description: The ID of the group.
- example: 32acc112-21ff-4669-91c2-21e27683eaa1
- explode: true
- in: path
- name: group_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
+ - configuration-templates
+ put:
+ description: Update a configuration template.
+ operationId: updateConfigurationTemplate
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/Group"
- description: The requested `Group`.
+ $ref: "#/components/schemas/ConfigurationTemplate"
+ description: The configuration template just updated.
+ requestBody:
+ description: Configuration template to be updated
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdateConfigurationTemplateInfo"
security:
- BearerAuth: []
tags:
- - groups
+ - configuration-templates
+ /configuration-templates/{configuration_template_id}:
delete:
- description: Deletes a group.
- operationId: delete_group
+ description: Deletes a configuration template.
+ operationId: deleteConfigurationTemplate
parameters:
- - description: The ID of the group.
+ - description: The ID of the configuration template.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: group_id
+ name: configuration_template_id
required: true
schema:
format: uuid
@@ -1067,46 +1231,59 @@ paths:
style: simple
responses:
"200":
- description: The group was successfully deleted.
+ description: The configuration template was successfully deleted.
security:
- BearerAuth: []
tags:
- - groups
- /groups/{group_id}/message-channels:
+ - configuration-templates
+ /event-streams:
get:
- description: Gets the list of audit and reviewer message channels attached to a group.
- operationId: get_group_message_channels
- parameters:
- - description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: group_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
+ summary: Get event streams
+ description: Returns a list of configured event streaming connections for your organization.
+ operationId: getEventStreams
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/MessageChannelList"
- description: The audit and reviewer message channels attached to the group.
+ $ref: "#/components/schemas/EventStreamList"
+ description: A list of event streams for your organization.
security:
- BearerAuth: []
tags:
- - groups
+ - event-streams
+ post:
+ summary: Create event stream
+ description: Creates a new event streaming connection.
+ operationId: createEventStream
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateEventStreamInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/EventStream"
+ description: The event stream just created. Credentials are returned in clear text only on creation.
+ security:
+ - BearerAuth: []
+ tags:
+ - event-streams
+ /event-streams/{event_stream_id}:
put:
- description: Sets the list of audit message channels attached to a group.
- operationId: set_group_message_channels
+ summary: Update event stream
+ description: Updates an existing event streaming connection.
+ operationId: updateEventStream
parameters:
- - description: The ID of the group.
+ - description: The ID of the event stream.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: group_id
+ name: event_stream_id
required: true
schema:
format: uuid
@@ -1117,32 +1294,28 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/MessageChannelIDList"
+ $ref: "#/components/schemas/UpdateEventStreamInfo"
responses:
"200":
content:
application/json:
schema:
- items:
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- format: uuid
- type: string
- type: array
- description: The updated audit message channel IDs for the group.
+ $ref: "#/components/schemas/EventStream"
+ description: The updated event stream.
security:
- BearerAuth: []
tags:
- - groups
- /groups/{group_id}/on-call-schedules:
- get:
- description: Gets the list of on call schedules attached to a group.
- operationId: get_group_on_call_schedules
+ - event-streams
+ delete:
+ summary: Delete event stream
+ description: Deletes an event streaming connection.
+ operationId: deleteEventStream
parameters:
- - description: The ID of the group.
+ - description: The ID of the event stream.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: group_id
+ name: event_stream_id
required: true
schema:
format: uuid
@@ -1150,331 +1323,287 @@ paths:
style: simple
responses:
"200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/OnCallScheduleList"
- description: The on call schedules attached to the group.
+ description: The event stream was successfully deleted.
security:
- BearerAuth: []
tags:
- - groups
- put:
- description: Sets the list of on call schedules attached to a group.
- operationId: set_group_on_call_schedules
+ - event-streams
+ /events:
+ get:
+ description: Returns a list of `Event` objects.
+ operationId: events
parameters:
- - description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: group_id
- required: true
+ - description: A start date filter for the events.
+ examples:
+ withDate:
+ summary: Example with date
+ value: 2021-11-01
+ withDatetime:
+ summary: Example with date and time in ISO 8601 datetime format.
+ value: 2025-01-01T00:00:00Z
+ explode: true
+ in: query
+ name: start_date_filter
+ required: false
schema:
- format: uuid
type: string
- style: simple
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/OnCallScheduleIDList"
- responses:
- "200":
- content:
- application/json:
- schema:
- items:
- example: bb0197c0-5ea5-45d9-b3b7-b6c439be6435
- format: uuid
- type: string
- type: array
- description: The updated on call schedule IDs for the group.
- security:
- - BearerAuth: []
- tags:
- - groups
- /groups/{group_id}/resources:
- get:
- description: Gets the list of resources that the group gives access to.
- operationId: get_group_resources
- parameters:
- - description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: group_id
- required: true
+ style: form
+ - description: An end date filter for the events.
+ examples:
+ withDate:
+ summary: Example with date
+ value: 2021-11-12
+ withDatetime:
+ summary: Example with date and time in ISO 8601 datetime format.
+ value: 2025-01-01T00:00:00Z
+ explode: true
+ in: query
+ name: end_date_filter
+ required: false
schema:
- format: uuid
type: string
- style: simple
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/GroupResourceList"
- description: The resources that the group gives access to.
- security:
- - BearerAuth: []
- tags:
- - groups
- put:
- description: Sets the list of resources that the group gives access to.
- operationId: set_group_resources
- parameters:
- - description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: group_id
- required: true
+ style: form
+ - description: An actor filter for the events. Supply the ID of the actor.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ explode: true
+ in: query
+ name: actor_filter
+ required: false
schema:
format: uuid
type: string
- style: simple
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UpdateGroupResourcesInfo"
- responses:
- "200":
- description: The group resource were successfully set.
- security:
- - BearerAuth: []
- tags:
- - groups
- /groups/{group_id}/containing-groups:
- get:
- summary: Get nested groups
- description: Gets the list of groups that the group gives access to.
- operationId: get_group_containing_groups
- parameters:
- - description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: group_id
- required: true
+ style: form
+ - description: An object filter for the events. Supply the ID of the object.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ explode: true
+ in: query
+ name: object_filter
+ required: false
schema:
format: uuid
type: string
- style: simple
- - description: The access level's remote ID to filter by.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
+ style: form
+ - description: An event type filter for the events.
+ example: USER_MFA_RESET
explode: true
in: query
- name: access_level_remote_id
+ name: event_type_filter
required: false
schema:
type: string
style: form
-
+ - description:
+ An API filter for the events. Supply the name and preview of the
+ API token.
+ example: fullaccess:**************************M_g==
+ explode: true
+ in: query
+ name: api_token_filter
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/GroupContainingGroupList"
- description: The groups that the group gives access to.
+ $ref: "#/components/schemas/PaginatedEventList"
+ description: One page worth of events with the appropriate filters applied.
security:
- BearerAuth: []
tags:
- - groups
- post:
- description: Creates a new containing group.
- operationId: add_group_containing_group
+ - events
+ /events/{event_id}:
+ get:
+ summary: Get event by ID
+ description: Returns an `Event` object.
+ operationId: getEvent
parameters:
- - description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the event.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ explode: true
in: path
- name: group_id
+ name: event_id
required: true
schema:
format: uuid
type: string
style: simple
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/GroupContainingGroup"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/GroupContainingGroup"
- description: The created `GroupContainingGroup` object.
+ $ref: "#/components/schemas/Event"
+ description: The requested `Event`.
+ "404":
+ description: Event not found.
security:
- BearerAuth: []
tags:
- - groups
- /groups/{group_id}/containing-groups/{containing_group_id}:
+ - events
+ /groups:
get:
- summary: Get nested group by ID
- description: Gets a specific containing group for a group.
- operationId: get_group_containing_group
+ summary: Get groups
+ description: Returns a list of groups for your organization.
+ operationId: getGroups
parameters:
- - description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: group_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- - description: The ID of the containing group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: containing_group_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/GroupContainingGroup"
- description: The created `GroupContainingGroup` object.
- security:
- - BearerAuth: []
- tags:
- - groups
- delete:
- description: Removes a containing group from a group.
- operationId: remove_group_containing_group
- parameters:
- - description: The ID of the member group to remove.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: group_id
- required: true
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
schema:
- format: uuid
type: string
- style: simple
- - description: The ID of the containing group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: containing_group_id
- required: true
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
schema:
- format: uuid
- type: string
- style: simple
- - description: The remote ID of the member group's access level to filter by.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
+ type: integer
+ maximum: 1000
+ style: form
+ - description: The group type to filter by.
+ example: OPAL_GROUP
explode: true
in: query
- name: access_level_remote_id
+ name: group_type_filter
required: false
schema:
- type: string
+ $ref: "#/components/schemas/GroupTypeEnum"
style: form
-
- responses:
- "204":
- description: The member group was successfully removed from the containing group.
- security:
- - BearerAuth: []
- tags:
- - groups
- /groups/{group_id}/resources/{resource_id}:
- post:
- description: Adds a resource to a group.
- operationId: add_group_resource
- parameters:
- - description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ - description: The group ids to filter by.
+ example:
+ - 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ - 1b978423-db0a-4037-a4cf-f79c60cb67b3
explode: false
- in: path
- name: group_id
- required: true
+ in: query
+ name: group_ids
+ required: false
schema:
- format: uuid
- type: string
- style: simple
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: resource_id
- required: true
+ items:
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ format: uuid
+ type: string
+ type: array
+ style: form
+ - description: Group name.
+ example: example-name
+ explode: true
+ in: query
+ name: group_name
+ required: false
schema:
- format: uuid
type: string
- style: simple
+ style: form
- description:
- The remote ID of the access level to grant to this user. If
- omitted, the default access level remote ID value (empty string) is
- used.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
+ The IDs of the tags to filter by. Returns only groups that have any
+ of these tags applied.
+ in: query
+ name: tag_ids
+ required: false
+ schema:
+ type: array
+ items:
+ format: uuid
+ type: string
+ - description:
+ If true, only return groups that allow access requests. Does not check
+ whether the caller is permitted to request the group.
+ example: true
explode: true
in: query
- name: access_level_remote_id
+ name: requestable
required: false
schema:
- type: string
+ type: boolean
style: form
- deprecated: true
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/PaginatedGroupsList"
+ description: One page worth groups associated with your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - groups
+ put:
+ description: Bulk updates a list of groups.
+ operationId: updateGroups
requestBody:
- required: false
+ description: Groups to be updated
+ required: true
content:
application/json:
schema:
- example:
- access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
- duration_minutes: 60
- properties:
- access_level_remote_id:
- description:
- The remote ID of the access level to grant to this user. If
- omitted, the default access level remote ID value (empty
- string) is used.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
- type: string
- duration_minutes:
- description:
- The duration for which the resource can be accessed (in minutes).
- Use 0 to set to indefinite.
- example: 60
- type: integer
- maximum: 525960 # One year
- minimum: 0
- type: object
+ $ref: "#/components/schemas/UpdateGroupInfoList"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/GroupResource"
- description: The created `GroupResource` object.
+ $ref: "#/components/schemas/UpdateGroupInfoList"
+ description: The resulting updated group infos.
security:
- BearerAuth: []
tags:
- groups
- /groups/{group_id}/visibility:
+ post:
+ description: Creates an Opal group or [imports a remote
+ group](https://docs.opal.dev/reference/end-system-objects).
+ operationId: createGroup
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateGroupInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Group"
+ description: The group just created.
+ security:
+ - BearerAuth: []
+ tags:
+ - groups
+ /groups/{group_id}:
get:
- description: Gets the visibility of this group.
- operationId: get_group_visibility
+ summary: Get group by ID
+ description: Returns a `Group` object.
+ operationId: getGroup
parameters:
- description: The ID of the group.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
in: path
name: group_id
required: true
@@ -1487,15 +1616,15 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/VisibilityInfo"
- description: The visibility info of this group.
+ $ref: "#/components/schemas/Group"
+ description: The requested `Group`.
security:
- BearerAuth: []
tags:
- groups
- put:
- description: Sets the visibility of this group.
- operationId: set_group_visibility
+ delete:
+ description: Deletes a group.
+ operationId: delete_group
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
@@ -1507,28 +1636,17 @@ paths:
format: uuid
type: string
style: simple
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/VisibilityInfo"
responses:
"200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/VisibilityInfo"
- description: The visibility info of this group.
+ description: The group was successfully deleted.
security:
- BearerAuth: []
tags:
- groups
- /groups/{group_id}/reviewers:
+ /groups/{group_id}/message-channels:
get:
- deprecated: true
- description: Gets the list of owner IDs of the reviewers for a group.
- operationId: get_group_reviewers
+ description: Gets the list of audit and reviewer message channels attached to a group.
+ operationId: get_group_message_channels
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
@@ -1545,20 +1663,15 @@ paths:
content:
application/json:
schema:
- items:
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- format: uuid
- type: string
- type: array
- description: The IDs of owners that are reviewers for this group.
+ $ref: "#/components/schemas/MessageChannelList"
+ description: The audit and reviewer message channels attached to the group.
security:
- BearerAuth: []
tags:
- groups
put:
- deprecated: true
- description: Sets the list of reviewers for a group.
- operationId: set_group_reviewers
+ description: Sets the list of audit message channels attached to a group.
+ operationId: set_group_message_channels
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
@@ -1575,7 +1688,7 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/ReviewerIDList"
+ $ref: "#/components/schemas/MessageChannelIDList"
responses:
"200":
content:
@@ -1586,16 +1699,15 @@ paths:
format: uuid
type: string
type: array
- description: The updated IDs of owners that are reviewers for this group
+ description: The updated audit message channel IDs for the group.
security:
- BearerAuth: []
tags:
- groups
- /groups/{group_id}/reviewer-stages:
+ /groups/{group_id}/on-call-schedules:
get:
- deprecated: true
- description: Gets the list of reviewer stages for a group.
- operationId: get_group_reviewer_stages
+ description: Gets the list of on call schedules attached to a group.
+ operationId: get_group_on_call_schedules
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
@@ -1612,19 +1724,15 @@ paths:
content:
application/json:
schema:
- description: A list of reviewer stages.
- items:
- $ref: "#/components/schemas/ReviewerStage"
- type: array
- description: The reviewer stages for this group.
+ $ref: "#/components/schemas/OnCallScheduleList"
+ description: The on call schedules attached to the group.
security:
- BearerAuth: []
tags:
- groups
put:
- deprecated: true
- description: Sets the list of reviewer stages for a group.
- operationId: set_group_reviewer_stages
+ description: Sets the list of on call schedules attached to a group.
+ operationId: set_group_on_call_schedules
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
@@ -1641,29 +1749,33 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/ReviewerStageList"
+ $ref: "#/components/schemas/OnCallScheduleIDList"
responses:
"200":
content:
application/json:
schema:
- description: A list of reviewer stages.
items:
- $ref: "#/components/schemas/ReviewerStage"
+ example: bb0197c0-5ea5-45d9-b3b7-b6c439be6435
+ format: uuid
+ type: string
type: array
- description: The updated reviewer stages for this group.
+ description: The updated on call schedule IDs for the group.
security:
- BearerAuth: []
tags:
- groups
- /groups/{group_id}/tags:
+ /groups/{group_id}/access_levels:
get:
- description: Returns all tags applied to the group.
- operationId: get_group_tags
+ summary: Get group access levels
+ description:
+ Returns the list of access levels defined for the group. Groups that
+ only offer default (unnamed) access return an empty list.
+ operationId: get_group_access_levels
parameters:
- - description: The ID of the group whose tags to return.
+ - description: The ID of the group whose access levels to return.
name: group_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
required: true
@@ -1676,16 +1788,18 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/TagsList"
- description: The tags applied to the group.
+ $ref: "#/components/schemas/GroupAccessLevelList"
+ description: The access levels defined for the group.
+ "404":
+ description: Group not found.
security:
- BearerAuth: []
tags:
- groups
- /groups/{group_id}/users:
+ /groups/{group_id}/resources:
get:
- description: Gets the list of users for this group.
- operationId: get_group_users
+ description: Gets the list of resources that the group gives access to.
+ operationId: get_group_resources
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
@@ -1697,43 +1811,24 @@ paths:
format: uuid
type: string
style: simple
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
- explode: true
- in: query
- name: cursor
- required: false
- schema:
- type: string
- style: form
- - description: Number of results to return per page. Default is 200.
- example: 200
- explode: true
- in: query
- name: page_size
- required: false
- schema:
- type: integer
- maximum: 1000
- style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/GroupUserList"
- description: List of users with access to this group.
+ $ref: "#/components/schemas/GroupResourceList"
+ description: The resources that the group gives access to.
security:
- BearerAuth: []
tags:
- groups
- /groups/{group_id}/users/{user_id}:
put:
- description: Updates a user's access level or duration in this group.
- operationId: update_group_user
+ description: Sets the list of resources that the group gives access to.
+ operationId: set_group_resources
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
in: path
name: group_id
required: true
@@ -1741,53 +1836,24 @@ paths:
format: uuid
type: string
style: simple
- - description: The ID of the user whose access is being updated.
- example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
- in: path
- name: user_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
requestBody:
required: true
content:
application/json:
schema:
- type: object
- example:
- duration_minutes: 60
- access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
- properties:
- duration_minutes:
- description:
- The updated duration for which the group can be accessed (in
- minutes). Use 0 for indefinite, or a negative value to
- revoke access.
- type: integer
- maximum: 525960 # One year
- example: 120
- access_level_remote_id:
- description: The updated remote ID of the access level granted to this user.
- type: string
- example: arn:aws:iam::590304332660:role/ReadOnlyAccess
- required:
- - duration_minutes
+ $ref: "#/components/schemas/UpdateGroupResourcesInfo"
responses:
"200":
- description: The GroupUser was successfully updated.
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/GroupUser"
+ description: The group resource were successfully set.
security:
- BearerAuth: []
tags:
- groups
- post:
- description: Adds a user to this group.
- operationId: add_group_user
+ /groups/{group_id}/containing-groups:
+ get:
+ summary: Get nested groups
+ description: Gets the list of groups that the group gives access to.
+ operationId: get_group_containing_groups
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
@@ -1799,33 +1865,7 @@ paths:
format: uuid
type: string
style: simple
- - description: The ID of the user to add.
- example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
- explode: false
- in: path
- name: user_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- - description:
- The duration for which the group can be accessed (in minutes). Use
- 0 to set to indefinite.
- example: 60
- explode: true
- in: query
- name: duration_minutes
- required: false
- schema:
- type: integer
- maximum: 525960 # One year
- style: form
- deprecated: true
- - description:
- The remote ID of the access level to grant to this user. If
- omitted, the default access level remote ID value (empty string) is
- used.
+ - description: The access level's remote ID to filter by.
example: arn:aws:iam::590304332660:role/AdministratorAccess
explode: true
in: query
@@ -1834,46 +1874,54 @@ paths:
schema:
type: string
style: form
- deprecated: true
+
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/GroupContainingGroupList"
+ description: The groups that the group gives access to.
+ security:
+ - BearerAuth: []
+ tags:
+ - groups
+ post:
+ description: Creates a new containing group.
+ operationId: add_group_containing_group
+ parameters:
+ - description: The ID of the group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: group_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
requestBody:
- required: false
+ required: true
content:
application/json:
schema:
- example:
- duration_minutes: 60
- access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
- properties:
- duration_minutes:
- description:
- The duration for which the group can be accessed (in minutes). Use
- 0 to set to indefinite.
- example: 60
- type: integer
- access_level_remote_id:
- description:
- The remote ID of the access level to grant to this user. If
- omitted, the default access level remote ID value (empty
- string) is used.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
- type: string
- required:
- - duration_minutes
- type: object
+ $ref: "#/components/schemas/GroupContainingGroup"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/GroupUser"
- description: The GroupUser that was created.
+ $ref: "#/components/schemas/GroupContainingGroup"
+ description: The created `GroupContainingGroup` object.
security:
- BearerAuth: []
tags:
- groups
- delete:
- description: Removes a user's access from this group.
- operationId: delete_group_user
+ /groups/{group_id}/containing-groups/{containing_group_id}:
+ get:
+ summary: Get nested group by ID
+ description: Gets a specific containing group for a group.
+ operationId: get_group_containing_group
parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
@@ -1885,163 +1933,152 @@ paths:
format: uuid
type: string
style: simple
- - description: The ID of a user to remove from this group.
- example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
+ - description: The ID of the containing group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: user_id
+ name: containing_group_id
required: true
schema:
format: uuid
type: string
style: simple
- - description:
- The remote ID of the access level for which this user has direct
- access. If omitted, the default access level remote ID value (empty
- string) is assumed.
- example: 30
- explode: true
- in: query
- name: access_level_remote_id
- required: false
- schema:
- type: string
- style: form
responses:
"200":
- description: This user's access was successfully removed from this group.
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/GroupContainingGroup"
+ description: The created `GroupContainingGroup` object.
security:
- BearerAuth: []
tags:
- groups
- /groups/users/{user_id}:
- get:
- description: Returns all groups that the user is a member of.
- operationId: get_user_groups
+ delete:
+ description: Removes a containing group from a group.
+ operationId: remove_group_containing_group
parameters:
- - description: The ID of the user whose groups to return.
- name: user_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the member group to remove.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: group_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the containing group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
+ name: containing_group_id
required: true
schema:
format: uuid
type: string
style: simple
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ - description: The remote ID of the member group's access level to filter by.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
explode: true
in: query
- name: cursor
+ name: access_level_remote_id
required: false
schema:
type: string
style: form
- - description: Number of results to return per page. Default is 200.
- example: 200
- explode: true
- in: query
- name: page_size
- required: false
- schema:
- type: integer
- maximum: 1000
- style: form
+
responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/GroupUserList"
- description: The groups that the user is a member of.
+ "204":
+ description: The member group was successfully removed from the containing group.
security:
- BearerAuth: []
tags:
- groups
- /group-bindings:
- get:
- summary: Get group bindings
- description: Returns a list of `GroupBinding` objects.
- operationId: getGroupBindings
+ /groups/{group_id}/resources/{resource_id}:
+ post:
+ description: Adds a resource to a group.
+ operationId: add_group_resource
parameters:
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
- explode: true
- in: query
- name: cursor
- required: false
+ - description: The ID of the group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: group_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
- - description: Number of results to return per page. Default is 200.
- example: 200
+ style: simple
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: resource_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description:
+ The remote ID of the access level to grant to this user. If
+ omitted, the default access level remote ID value (empty string) is
+ used.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
explode: true
in: query
- name: page_size
+ name: access_level_remote_id
+ required: false
schema:
- type: integer
- maximum: 1000
+ type: string
style: form
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/PaginatedGroupBindingsList"
- description: One page worth of group bindings for your organization.
- security:
- - BearerAuth: []
- tags:
- - group-bindings
- post:
- description: Creates a group binding.
- operationId: createGroupBinding
+ deprecated: true
requestBody:
- required: true
+ required: false
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateGroupBindingInfo"
+ example:
+ access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
+ duration_minutes: 60
+ properties:
+ access_level_remote_id:
+ description:
+ The remote ID of the access level to grant to this user. If
+ omitted, the default access level remote ID value (empty
+ string) is used.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
+ type: string
+ duration_minutes:
+ description:
+ The duration for which the resource can be accessed (in minutes).
+ Use 0 to set to indefinite.
+ example: 60
+ type: integer
+ maximum: 153722867 # Largest duration Opal can represent (~292 years)
+ minimum: 0
+ type: object
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/GroupBinding"
- description: The group binding just created.
- security:
- - BearerAuth: []
- tags:
- - group-bindings
- put:
- description: Bulk updates a list of group bindings.
- operationId: updateGroupBindings
- requestBody:
- description: Group bindings to be updated
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UpdateGroupBindingInfoList"
- responses:
- "200":
- description: The group bindings were successfully updated.
+ $ref: "#/components/schemas/GroupResource"
+ description: The created `GroupResource` object.
security:
- BearerAuth: []
tags:
- - group-bindings
- /group-bindings/{group_binding_id}:
+ - groups
+ /groups/{group_id}/visibility:
get:
- summary: Get group binding by ID
- description: Returns a `GroupBinding` object.
- operationId: getGroupBinding
+ description: Gets the visibility of this group.
+ operationId: get_group_visibility
parameters:
- - description: The ID of the group binding.
- example: 32acc112-21ff-4669-91c2-21e27683eaa1
- explode: true
+ - description: The ID of the group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
in: path
- name: group_binding_id
+ name: group_id
required: true
schema:
format: uuid
@@ -2052,45 +2089,56 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/GroupBinding"
- description: The requested `GroupBinding`.
+ $ref: "#/components/schemas/VisibilityInfo"
+ description: The visibility info of this group.
+ "403":
+ description: The caller is not authorized to view this group's visibility.
security:
- BearerAuth: []
tags:
- - group-bindings
- delete:
- description: Deletes a group binding.
- operationId: deleteGroupBinding
+ - groups
+ put:
+ description: Sets the visibility of this group.
+ operationId: set_group_visibility
parameters:
- - description: The ID of the group binding.
+ - description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: group_binding_id
+ name: group_id
required: true
schema:
format: uuid
type: string
style: simple
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/VisibilityInfo"
responses:
"200":
- description: The group binding was successfully deleted.
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/VisibilityInfo"
+ description: The visibility info of this group.
security:
- BearerAuth: []
tags:
- - group-bindings
- /idp-group-mappings/{app_resource_id}:
+ - groups
+ /groups/{group_id}/reviewers:
get:
- description:
- Returns the configured set of available `IdpGroupMapping` objects
- for an Okta app.
- operationId: getIdpGroupMappings
+ deprecated: true
+ description: Gets the list of owner IDs of the reviewers for a group.
+ operationId: get_group_reviewers
parameters:
- - description: The ID of the Okta app.
+ - description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: app_resource_id
+ name: group_id
required: true
schema:
format: uuid
@@ -2101,23 +2149,26 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/IdpGroupMappingList"
- description:
- The configured set of available `IdpGroupMapping` objects for an
- Okta app.
+ items:
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ format: uuid
+ type: string
+ type: array
+ description: The IDs of owners that are reviewers for this group.
security:
- BearerAuth: []
tags:
- - idp-group-mappings
+ - groups
put:
- description: Updates the list of available `IdpGroupMapping` objects for an Okta app.
- operationId: updateIdpGroupMappings
+ deprecated: true
+ description: Sets the list of reviewers for a group.
+ operationId: set_group_reviewers
parameters:
- - description: The ID of the Okta app.
+ - description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: app_resource_id
+ name: group_id
required: true
schema:
format: uuid
@@ -2128,46 +2179,28 @@ paths:
content:
application/json:
schema:
- properties:
- mappings:
- type: array
- items:
- properties:
- group_id:
- type: string
- format: uuid
- alias:
- type: string
- hidden_from_end_user:
- type: boolean
- type: object
- required:
- - mappings
- type: object
+ $ref: "#/components/schemas/ReviewerIDList"
responses:
"200":
- description:
- The updated set of available `IdpGroupMapping` objects for an Okta
- app.
+ content:
+ application/json:
+ schema:
+ items:
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ format: uuid
+ type: string
+ type: array
+ description: The updated IDs of owners that are reviewers for this group
security:
- BearerAuth: []
tags:
- - idp-group-mappings
- /idp-group-mappings/{app_resource_id}/groups/{group_id}:
+ - groups
+ /groups/{group_id}/reviewer-stages:
get:
- description: Gets an `IdpGroupMapping` object for an Okta app and group.
- operationId: getIdpGroupMapping
+ deprecated: true
+ description: Gets the list of reviewer stages for a group.
+ operationId: get_group_reviewer_stages
parameters:
- - description: The ID of the Okta app.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: app_resource_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
@@ -2183,31 +2216,20 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/IdpGroupMapping"
- description: The `IdpGroupMapping` object for the Okta app and group.
+ description: A list of reviewer stages.
+ items:
+ $ref: "#/components/schemas/ReviewerStage"
+ type: array
+ description: The reviewer stages for this group.
security:
- BearerAuth: []
tags:
- - idp-group-mappings
- post:
- description: |
- Creates or updates an individual `IdpGroupMapping` object (upsert operation).
-
- **Behavior:**
- - If the mapping doesn't exist, it will be created with the provided values
- - If the mapping exists, only the fields provided in the request will be updated
- operationId: createIdpGroupMapping
+ - groups
+ put:
+ deprecated: true
+ description: Sets the list of reviewer stages for a group.
+ operationId: set_group_reviewer_stages
parameters:
- - description: The ID of the Okta app.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: app_resource_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
@@ -2219,49 +2241,56 @@ paths:
type: string
style: simple
requestBody:
- required: false
+ required: true
content:
application/json:
schema:
- properties:
- alias:
- description: Optional alias for the group mapping
- type: string
- nullable: true
- hidden_from_end_user:
- description: |
- Whether this mapping should be hidden from end users.
- - **New mappings**: If not provided, defaults to `false`
- - **Existing mappings**: If not provided, existing value is preserved (no change)
- - **Explicit values**: If provided, value is updated to the specified boolean
- type: boolean
- nullable: true
- type: object
+ $ref: "#/components/schemas/ReviewerStageList"
responses:
"200":
- description: The IDP group mapping was successfully created or updated.
content:
application/json:
schema:
- $ref: "#/components/schemas/IdpGroupMapping"
+ description: A list of reviewer stages.
+ items:
+ $ref: "#/components/schemas/ReviewerStage"
+ type: array
+ description: The updated reviewer stages for this group.
security:
- BearerAuth: []
tags:
- - idp-group-mappings
- delete:
- description: Deletes an `IdpGroupMapping` object.
- operationId: delete_idp_group_mappings
+ - groups
+ /groups/{group_id}/tags:
+ get:
+ description: Returns all tags applied to the group.
+ operationId: get_group_tags
parameters:
- - description: The ID of the Okta app.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ - description: The ID of the group whose tags to return.
+ name: group_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
explode: false
in: path
- name: app_resource_id
required: true
schema:
format: uuid
type: string
style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/TagsList"
+ description: The tags applied to the group.
+ security:
+ - BearerAuth: []
+ tags:
+ - groups
+ /groups/{group_id}/users:
+ get:
+ description: Gets the list of users for this group.
+ operationId: get_group_users
+ parameters:
- description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
@@ -2272,19 +2301,6 @@ paths:
format: uuid
type: string
style: simple
- responses:
- "200":
- description: The IDP group mapping was successfully deleted.
- security:
- - BearerAuth: []
- tags:
- - idp-group-mappings
- /owners:
- get:
- summary: Get owners
- description: Returns a list of `Owner` objects.
- operationId: get_owners
- parameters:
- description: The pagination cursor value.
example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
explode: true
@@ -2294,7 +2310,13 @@ paths:
schema:
type: string
style: form
- - description: Number of results to return per page. Default is 200.
+ - description:
+ Number of results to return per page, up to 1000. When set (or when a
+ cursor is provided), the response contains a single page of results and
+ a `next` cursor; the default page size is 200. When both page_size and
+ cursor are omitted, the entire group membership is returned in one
+ response with no `next` cursor. For large groups, prefer setting
+ page_size and following `next`.
example: 200
explode: true
in: query
@@ -2304,279 +2326,255 @@ paths:
type: integer
maximum: 1000
style: form
- - description: Owner name to filter by.
- example: 200
- explode: true
- in: query
- name: name
- required: false
- schema:
- type: string
- style: form
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/PaginatedOwnersList"
- description: One page worth of owners in your organization.
- security:
- - BearerAuth: []
- tags:
- - owners
- post:
- description: Creates an owner.
- operationId: createOwner
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/CreateOwnerInfo"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/Owner"
- description: The owner just created.
+ $ref: "#/components/schemas/GroupUserList"
+ description: List of users with access to this group.
security:
- BearerAuth: []
tags:
- - owners
+ - groups
+ /groups/{group_id}/users/{user_id}:
put:
- description: Bulk updates a list of owners.
- operationId: updateOwners
- requestBody:
- description: Owners to be updated
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UpdateOwnerInfoList"
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UpdateOwnerInfoList"
- description: The resulting updated owner infos.
- security:
- - BearerAuth: []
- tags:
- - owners
- /owners/{owner_id}:
- get:
- summary: Get owner by ID
- description: Returns an `Owner` object.
- operationId: getOwner
- parameters:
- - description: The ID of the owner.
- example: 32acc112-21ff-4669-91c2-21e27683eaa1
- explode: true
- in: path
- name: owner_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/Owner"
- description: The owner object associated with the passed-in ID.
- security:
- - BearerAuth: []
- tags:
- - owners
- delete:
- description: Deletes an owner.
- operationId: delete_owner
+ description: Updates a user's access level or duration in this group.
+ operationId: update_group_user
parameters:
- - description: The ID of the owner.
+ - description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
in: path
- name: owner_id
+ name: group_id
required: true
schema:
format: uuid
type: string
style: simple
- responses:
- "200":
- description: The owner was successfully deleted.
- security:
- - BearerAuth: []
- tags:
- - owners
- /owners/name/{owner_name}:
- get:
- description:
- Returns an `Owner` object. Does not support owners with `/` in
- their name, use /owners?name=... instead.
- operationId: getOwnerFromName
- parameters:
- - description: The name of the owner.
- example: MyOwner
- explode: true
+ - description: The ID of the user whose access is being updated.
+ example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
in: path
- name: owner_name
+ name: user_id
required: true
schema:
+ format: uuid
type: string
style: simple
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ type: object
+ example:
+ duration_minutes: 60
+ access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
+ properties:
+ duration_minutes:
+ description:
+ The updated duration for which the group can be accessed (in
+ minutes). Use 0 for indefinite, or a negative value to
+ revoke access.
+ type: integer
+ maximum: 153722867 # Largest duration Opal can represent (~292 years)
+ example: 120
+ access_level_remote_id:
+ description: The updated remote ID of the access level granted to this user.
+ type: string
+ example: arn:aws:iam::590304332660:role/ReadOnlyAccess
+ required:
+ - duration_minutes
responses:
"200":
+ description: The GroupUser was successfully updated.
content:
application/json:
schema:
- $ref: "#/components/schemas/Owner"
- description: The owner object associated with the passed-in name.
+ $ref: "#/components/schemas/GroupUser"
security:
- BearerAuth: []
tags:
- - owners
- /owners/{owner_id}/users:
- get:
- description:
- Gets the list of users for this owner, in escalation priority order
- if applicable.
- operationId: get_owner_users
+ - groups
+ post:
+ description: Adds a user to this group.
+ operationId: add_group_user
parameters:
- - description: The ID of the owner.
+ - description: The ID of the group.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: owner_id
+ name: group_id
required: true
schema:
format: uuid
type: string
style: simple
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UserList"
- description: The users for this owner.
- security:
- - BearerAuth: []
- tags:
- - owners
- put:
- description:
- Sets the list of users for this owner. If escalation is enabled,
- the order of this list is the escalation priority order of the users. If
- the owner has a source group, adding or removing users from this list
- won't be possible.
- operationId: set_owner_users
- parameters:
- - description: The ID of the owner.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ - description: The ID of the user to add.
+ example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
explode: false
in: path
- name: owner_id
+ name: user_id
required: true
schema:
format: uuid
type: string
style: simple
+ - description:
+ The duration for which the group can be accessed (in minutes). Use
+ 0 to set to indefinite.
+ example: 60
+ explode: true
+ in: query
+ name: duration_minutes
+ required: false
+ schema:
+ type: integer
+ maximum: 153722867 # Largest duration Opal can represent (~292 years)
+ style: form
+ deprecated: true
+ - description:
+ The remote ID of the access level to grant to this user. If
+ omitted, the default access level remote ID value (empty string) is
+ used.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
+ explode: true
+ in: query
+ name: access_level_remote_id
+ required: false
+ schema:
+ type: string
+ style: form
+ deprecated: true
requestBody:
- required: true
+ required: false
content:
application/json:
schema:
- $ref: "#/components/schemas/UserIDList"
+ example:
+ duration_minutes: 60
+ access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
+ properties:
+ duration_minutes:
+ description:
+ The duration for which the group can be accessed (in minutes). Use
+ 0 to set to indefinite.
+ example: 60
+ type: integer
+ access_level_remote_id:
+ description:
+ The remote ID of the access level to grant to this user. If
+ omitted, the default access level remote ID value (empty
+ string) is used.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
+ type: string
+ required:
+ - duration_minutes
+ type: object
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/UserList"
- description: The updated users for the owner.
+ $ref: "#/components/schemas/GroupUser"
+ description: The GroupUser that was created.
security:
- BearerAuth: []
tags:
- - owners
- /requests:
- get:
- summary: Get requests
- description:
- Returns a list of requests for your organization that is visible by
- the admin.
- operationId: getRequests
+ - groups
+ delete:
+ description: Removes a user's access from this group.
+ operationId: delete_group_user
parameters:
- - description: A start date filter for the events.
- examples:
- withDate:
- summary: Example with date
- value: 2021-11-01
- withDatetime:
- summary: Example with date and time in ISO 8601 datetime format.
- value: 2025-01-01T00:00:00Z
- explode: true
- in: query
- name: start_date_filter
- required: false
+ - description: The ID of the group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: group_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
- - description: An end date filter for the events.
- examples:
- withDate:
- summary: Example with date
- value: 2021-11-12
- withDatetime:
- summary: Example with date and time in ISO 8601 datetime format.
- value: 2025-01-01T00:00:00Z
- explode: true
- in: query
- name: end_date_filter
- required: false
+ style: simple
+ - description: The ID of a user to remove from this group.
+ example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
+ explode: false
+ in: path
+ name: user_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
- - description: Filter requests by their requester ID.
- example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ style: simple
+ - description:
+ The remote ID of the access level for which this user has direct
+ access. If omitted, the default access level remote ID value (empty
+ string) is assumed.
+ example: 30
+ explode: true
in: query
- name: requester_id
+ name: access_level_remote_id
required: false
schema:
- format: uuid
type: string
style: form
- - description: Filter requests by their target user ID.
- example: 37cb7e41-12ba-46da-92ff-030abe0450b1
- in: query
- name: target_user_id
- required: false
+ responses:
+ "200":
+ description: This user's access was successfully removed from this group.
+ security:
+ - BearerAuth: []
+ tags:
+ - groups
+ /groups/users/{user_id}:
+ get:
+ description: Returns all groups that the user is a member of.
+ operationId: get_user_groups
+ parameters:
+ - description: The ID of the user whose groups to return.
+ name: user_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
schema:
format: uuid
type: string
- style: form
- - description: Filter requests by the resource ID that was requested.
- example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ style: simple
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
in: query
- name: resource_id
+ name: cursor
required: false
schema:
- format: uuid
type: string
style: form
- - description: Filter requests by the group ID that was requested.
- example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
in: query
- name: group_id
+ name: page_size
required: false
schema:
- format: uuid
- type: string
+ type: integer
+ maximum: 1000
style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/GroupUserList"
+ description: The groups that the user is a member of.
+ security:
+ - BearerAuth: []
+ tags:
+ - groups
+ /group-bindings:
+ get:
+ summary: Get group bindings
+ description: Returns a list of `GroupBinding` objects.
+ operationId: getGroupBindings
+ parameters:
- description: The pagination cursor value.
example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
explode: true
@@ -2591,149 +2589,94 @@ paths:
explode: true
in: query
name: page_size
- required: false
schema:
type: integer
maximum: 1000
style: form
- - description: Boolean toggle for if it should only show pending requests.
- explode: true
- in: query
- name: show_pending_only
- required: false
- schema:
- type: boolean
- style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/RequestList"
- description: The list of requests.
+ $ref: "#/components/schemas/PaginatedGroupBindingsList"
+ description: One page worth of group bindings for your organization.
security:
- BearerAuth: []
tags:
- - requests
+ - group-bindings
post:
- description: "Create an access request"
- operationId: "createRequest"
+ description: Creates a group binding.
+ operationId: createGroupBinding
requestBody:
- description: Resources to be updated
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateRequestInfo"
+ $ref: "#/components/schemas/CreateGroupBindingInfo"
responses:
"200":
content:
application/json:
schema:
- properties:
- id:
- format: uuid
- type: string
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- description: The resulting request.
+ $ref: "#/components/schemas/GroupBinding"
+ description: The group binding just created.
security:
- BearerAuth: []
tags:
- - requests
- /requests/relay:
+ - group-bindings
+ put:
+ description: Bulk updates a list of group bindings.
+ operationId: updateGroupBindings
+ requestBody:
+ description: Group bindings to be updated
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdateGroupBindingInfoList"
+ responses:
+ "200":
+ description: The group bindings were successfully updated.
+ security:
+ - BearerAuth: []
+ tags:
+ - group-bindings
+ /group-bindings/{group_binding_id}:
get:
- summary: Get requests via Relay
- description: Returns a paginated list of requests using Relay-style cursor pagination.
- operationId: getRequestsRelay
- deprecated: true
+ summary: Get group binding by ID
+ description: Returns a `GroupBinding` object.
+ operationId: getGroupBinding
parameters:
- - description: Number of results to return after the cursor. Use either
- first/after or last/before, not both.
- example: 10
- in: query
- name: first
- required: false
- schema:
- type: integer
- minimum: 1
- maximum: 100
- - description:
- Cursor to fetch results after. Used with 'first' for forward
- pagination.
- example:
- "Y3Vyc29yOnYyOpK5MjAyMS0wMS0wN1QwNzo0MToyNy4xMTlaFjYwZmM2YmJlZjk4YzE1N\
- 2ZhNjFhYjk4Nw=="
- in: query
- name: after
- required: false
- schema:
- type: string
- - description: Number of results to return before the cursor. Use either
- first/after or last/before, not both.
- example: 10
- in: query
- name: last
- required: false
- schema:
- type: integer
- minimum: 1
- maximum: 100
- - description:
- Cursor to fetch results before. Used with 'last' for backward
- pagination.
- example:
- "Y3Vyc29yOnYyOpK5MjAyMS0wMS0wN1QwNzo0MToyNy4xMTlaFjYwZmM2YmJlZjk4YzE1N\
- 2ZhNjFhYjk4Nw=="
- in: query
- name: before
- required: false
- schema:
- type: string
- - description: Filter requests by their status.
- example: PENDING
- in: query
- name: status
- required: false
- schema:
- $ref: "#/components/schemas/RequestStatusEnum"
- - description: Filter requests assigned to a specific user ID.
- example: 37cb7e41-12ba-46da-92ff-030abe0450b1
- in: query
- name: to
- required: false
- schema:
- format: uuid
- type: string
- - description: Filter requests made by a specific user ID.
- example: 37cb7e41-12ba-46da-92ff-030abe0450b1
- in: query
- name: from
- required: false
+ - description: The ID of the group binding.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
+ in: path
+ name: group_binding_id
+ required: true
schema:
format: uuid
type: string
+ style: simple
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/RequestConnection"
- description: A paginated list of requests using Relay-style cursor pagination.
+ $ref: "#/components/schemas/GroupBinding"
+ description: The requested `GroupBinding`.
security:
- BearerAuth: []
tags:
- - requests
- /requests/{id}:
- get:
- summary: Get request by ID
- description: Returns a request by ID.
- operationId: getRequest
+ - group-bindings
+ delete:
+ description: Deletes a group binding.
+ operationId: deleteGroupBinding
parameters:
- - description: The ID of the request.
+ - description: The ID of the group binding.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: id
+ name: group_binding_id
required: true
schema:
format: uuid
@@ -2741,165 +2684,216 @@ paths:
style: simple
responses:
"200":
- description: The requested request object.
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/Request"
+ description: The group binding was successfully deleted.
security:
- BearerAuth: []
tags:
- - requests
- /requests/{id}/approve:
- post:
- description: "Approve an access request"
- operationId: "approveRequest"
+ - group-bindings
+ /idp-group-mappings/{app_resource_id}:
+ get:
+ description:
+ Returns the configured set of available `IdpGroupMapping` objects
+ for an Okta app.
+ operationId: getIdpGroupMappings
parameters:
- - description: "The ID of the request to approve"
+ - description: The ID of the Okta app.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
in: path
- name: id
+ name: app_resource_id
required: true
schema:
- type: string
format: uuid
- requestBody:
- description: Approval parameters
- required: true
- content:
- application/json:
- schema:
- type: object
- properties:
- level:
- $ref: "#/components/schemas/RequestApprovalEnum"
- comment:
- type: string
- description: "Optional comment for the approval"
- example: "Approved after security review"
- required:
- - level
+ type: string
+ style: simple
responses:
"200":
- description: "Request successfully approved"
content:
application/json:
schema:
- type: object
- properties:
- request:
- $ref: "#/components/schemas/Request"
+ $ref: "#/components/schemas/IdpGroupMappingList"
+ description:
+ The configured set of available `IdpGroupMapping` objects for an
+ Okta app.
security:
- BearerAuth: []
tags:
- - requests
- /requests/{id}/deny:
- post:
- description: "Deny an access request"
- operationId: "denyRequest"
+ - idp-group-mappings
+ put:
+ description: Updates the list of available `IdpGroupMapping` objects for an Okta app.
+ operationId: updateIdpGroupMappings
parameters:
- - description: "The ID of the request to deny"
+ - description: The ID of the Okta app.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
in: path
- name: id
+ name: app_resource_id
required: true
schema:
- type: string
format: uuid
+ type: string
+ style: simple
requestBody:
- description: Denial parameters
required: true
content:
application/json:
schema:
- type: object
properties:
- comment:
- type: string
- description: "Comment for the denial"
- example: "Denied due to insufficient justification"
- level:
- $ref: "#/components/schemas/RequestApprovalEnum"
+ mappings:
+ type: array
+ items:
+ properties:
+ group_id:
+ type: string
+ format: uuid
+ alias:
+ type: string
+ hidden_from_end_user:
+ type: boolean
+ type: object
required:
- - comment
+ - mappings
+ type: object
responses:
"200":
- description: "Request successfully denied"
- content:
- application/json:
- schema:
- type: object
- properties:
- request:
- $ref: "#/components/schemas/Request"
+ description:
+ The updated set of available `IdpGroupMapping` objects for an Okta
+ app.
security:
- BearerAuth: []
tags:
- - requests
- /requests/{id}/comments:
+ - idp-group-mappings
+ /idp-group-mappings/{app_resource_id}/groups/{group_id}:
get:
- description: Returns a list of comments for a specific request.
- operationId: getRequestComments
+ description: Gets an `IdpGroupMapping` object for an Okta app and group.
+ operationId: getIdpGroupMapping
parameters:
- - description: "The ID of the request to get comments for"
+ - description: The ID of the Okta app.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
in: path
- name: id
+ name: app_resource_id
required: true
schema:
+ format: uuid
type: string
+ style: simple
+ - description: The ID of the group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: group_id
+ required: true
+ schema:
format: uuid
+ type: string
+ style: simple
responses:
"200":
- description: A list of comments associated with the specified request.
content:
application/json:
schema:
- $ref: "#/components/schemas/RequestCommentList"
+ $ref: "#/components/schemas/IdpGroupMapping"
+ description: The `IdpGroupMapping` object for the Okta app and group.
security:
- BearerAuth: []
tags:
- - requests
+ - idp-group-mappings
post:
- description: "Comment on an access request"
- operationId: "createRequestComment"
+ description: |
+ Creates or updates an individual `IdpGroupMapping` object (upsert operation).
+
+ **Behavior:**
+ - If the mapping doesn't exist, it will be created with the provided values
+ - If the mapping exists, only the fields provided in the request will be updated
+ operationId: createIdpGroupMapping
parameters:
- - description: "The ID of the request to comment on"
+ - description: The ID of the Okta app.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
in: path
- name: id
+ name: app_resource_id
required: true
schema:
+ format: uuid
type: string
+ style: simple
+ - description: The ID of the group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: group_id
+ required: true
+ schema:
format: uuid
+ type: string
+ style: simple
requestBody:
- description: Comment parameters
- required: true
+ required: false
content:
application/json:
schema:
- type: object
properties:
- comment:
+ alias:
+ description: Optional alias for the group mapping
type: string
- description: "comment"
- required:
- - comment
+ nullable: true
+ hidden_from_end_user:
+ description: |
+ Whether this mapping should be hidden from end users.
+ - **New mappings**: If not provided, defaults to `false`
+ - **Existing mappings**: If not provided, existing value is preserved (no change)
+ - **Explicit values**: If provided, value is updated to the specified boolean
+ type: boolean
+ nullable: true
+ type: object
responses:
"200":
- description: "Request successfully commented"
+ description: The IDP group mapping was successfully created or updated.
content:
application/json:
schema:
- type: object
- properties:
- request:
- $ref: "#/components/schemas/Request"
+ $ref: "#/components/schemas/IdpGroupMapping"
security:
- BearerAuth: []
tags:
- - requests
- /resources:
+ - idp-group-mappings
+ delete:
+ description: Deletes an `IdpGroupMapping` object.
+ operationId: delete_idp_group_mappings
+ parameters:
+ - description: The ID of the Okta app.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: app_resource_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the group.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: group_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: The IDP group mapping was successfully deleted.
+ security:
+ - BearerAuth: []
+ tags:
+ - idp-group-mappings
+ /owners:
get:
- summary: Get resources
- description: Returns a list of resources for your organization.
- operationId: getResources
+ summary: Get owners
+ description: Returns a list of `Owner` objects.
+ operationId: get_owners
parameters:
- description: The pagination cursor value.
example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
@@ -2920,150 +2914,78 @@ paths:
type: integer
maximum: 1000
style: form
- - description: The resource type to filter by. Required when remote_id is provided.
- example: AWS_IAM_ROLE
- explode: true
- in: query
- name: resource_type_filter
- required: false
- schema:
- $ref: "#/components/schemas/ResourceTypeEnum"
- style: form
- - description: The resource ids to filter by.
- example:
- - 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- - 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
- in: query
- name: resource_ids
- required: false
- schema:
- items:
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- format: uuid
- type: string
- type: array
- style: form
- - description: Resource name.
- example: example-name
+ - description: Owner name to filter by.
+ example: 200
explode: true
in: query
- name: resource_name
- required: false
- schema:
- type: string
- style: form
- - description: The parent resource id to filter by.
- example:
- - 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: query
- name: parent_resource_id
- required: false
- schema:
- format: uuid
- type: string
- style: form
- - description:
- The ancestor resource id to filter by. Returns all resources that
- are descendants of the specified resource.
- example:
- - 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: query
- name: ancestor_resource_id
- required: false
- schema:
- format: uuid
- type: string
- style: form
- - description:
- Filter resources by their remote id. This will return all resources
- that have a remote id that matches the provided remote id. Note that
- this requires resource_type_filter to be provided.
- in: query
- name: remote_id
+ name: name
required: false
schema:
type: string
style: form
- - description:
- The IDs of the tags to filter by. Returns only resources that have
- any of these tags applied.
- in: query
- name: tag_ids
- required: false
- schema:
- type: array
- items:
- format: uuid
- type: string
- style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedResourcesList"
- description: One page worth resources associated with your organization.
+ $ref: "#/components/schemas/PaginatedOwnersList"
+ description: One page worth of owners in your organization.
security:
- BearerAuth: []
tags:
- - resources
- put:
- description: Bulk updates a list of resources.
- operationId: updateResources
+ - owners
+ post:
+ description: Creates an owner.
+ operationId: createOwner
requestBody:
- description: Resources to be updated
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/UpdateResourceInfoList"
+ $ref: "#/components/schemas/CreateOwnerInfo"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/UpdateResourceInfoList"
- description: The resulting updated resource infos.
+ $ref: "#/components/schemas/Owner"
+ description: The owner just created.
security:
- BearerAuth: []
tags:
- - resources
- post:
- description: Creates a resource. See
- [here](https://docs.opal.dev/reference/end-system-objects) for details
- about importing resources.
- operationId: createResource
+ - owners
+ put:
+ description: Bulk updates a list of owners.
+ operationId: updateOwners
requestBody:
+ description: Owners to be updated
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateResourceInfo"
+ $ref: "#/components/schemas/UpdateOwnerInfoList"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/Resource"
- description: The resource just created.
+ $ref: "#/components/schemas/UpdateOwnerInfoList"
+ description: The resulting updated owner infos.
security:
- BearerAuth: []
tags:
- - resources
- /resources/{resource_id}:
+ - owners
+ /owners/{owner_id}:
get:
- summary: Get resource by ID
- description: Retrieves a resource.
- operationId: get_resource
+ summary: Get owner by ID
+ description: Returns an `Owner` object.
+ operationId: getOwner
parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the owner.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
in: path
- name: resource_id
+ name: owner_id
required: true
schema:
format: uuid
@@ -3071,24 +2993,24 @@ paths:
style: simple
responses:
"200":
- description: The requested resource.
content:
application/json:
schema:
- $ref: "#/components/schemas/Resource"
+ $ref: "#/components/schemas/Owner"
+ description: The owner object associated with the passed-in ID.
security:
- BearerAuth: []
tags:
- - resources
+ - owners
delete:
- description: Deletes a resource.
- operationId: delete_resource
+ description: Deletes an owner.
+ operationId: delete_owner
parameters:
- - description: The ID of the resource.
+ - description: The ID of the owner.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: resource_id
+ name: owner_id
required: true
schema:
format: uuid
@@ -3096,24 +3018,25 @@ paths:
style: simple
responses:
"200":
- description: The resource was successfully deleted.
+ description: The owner was successfully deleted.
security:
- BearerAuth: []
tags:
- - resources
- /resources/{resource_id}/message-channels:
+ - owners
+ /owners/name/{owner_name}:
get:
- description: Gets the list of audit message channels attached to a resource.
- operationId: get_resource_message_channels
+ description:
+ Returns an `Owner` object. Does not support owners with `/` in
+ their name, use /owners?name=... instead.
+ operationId: getOwnerFromName
parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The name of the owner.
+ example: MyOwner
+ explode: true
in: path
- name: resource_id
+ name: owner_name
required: true
schema:
- format: uuid
type: string
style: simple
responses:
@@ -3121,179 +3044,141 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/MessageChannelList"
- description: The audit message channels attached to the resource.
+ $ref: "#/components/schemas/Owner"
+ description: The owner object associated with the passed-in name.
security:
- BearerAuth: []
tags:
- - resources
- put:
- description: Sets the list of audit message channels attached to a resource.
- operationId: set_resource_message_channels
+ - owners
+ /owners/{owner_id}/users:
+ get:
+ description:
+ Gets the list of users for this owner, in escalation priority order
+ if applicable.
+ operationId: get_owner_users
parameters:
- - description: The ID of the resource.
+ - description: The ID of the owner.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: resource_id
+ name: owner_id
required: true
schema:
format: uuid
type: string
style: simple
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/MessageChannelIDList"
responses:
"200":
content:
application/json:
schema:
- items:
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- format: uuid
- type: string
- type: array
- description: The updated audit message channel IDs for the resource.
+ $ref: "#/components/schemas/UserList"
+ description: The users for this owner.
security:
- BearerAuth: []
tags:
- - resources
- /resources/{resource_id}/visibility:
- get:
- description: Gets the visibility of this resource.
- operationId: get_resource_visibility
+ - owners
+ put:
+ description:
+ Sets the list of users for this owner. If escalation is enabled,
+ the order of this list is the escalation priority order of the users. If
+ the owner has a source group, adding or removing users from this list
+ won't be possible.
+ operationId: set_owner_users
parameters:
- - description: The ID of the resource.
+ - description: The ID of the owner.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: resource_id
+ name: owner_id
required: true
schema:
format: uuid
type: string
style: simple
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UserIDList"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/VisibilityInfo"
- description: The visibility info of this resource.
+ $ref: "#/components/schemas/UserList"
+ description: The updated users for the owner.
security:
- BearerAuth: []
tags:
- - resources
- put:
- description: Sets the visibility of this resource.
- operationId: set_resource_visibility
- parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: resource_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/VisibilityInfo"
+ - owners
+ /request-templates:
+ get:
+ description: Returns a list of `RequestTemplate` objects.
+ operationId: getRequestTemplates
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/VisibilityInfo"
- description: The visibility info of this resource.
+ $ref: "#/components/schemas/PaginatedRequestTemplateList"
+ description: One page worth of request templates for your organization.
security:
- BearerAuth: []
tags:
- - resources
- /resources/{resource_id}/reviewers:
- get:
- description: Gets the list of owner IDs of the reviewers for a resource.
- operationId: get_resource_reviewers
- parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: resource_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
+ - request-templates
+ post:
+ description: Creates a request template.
+ operationId: createRequestTemplate
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateRequestTemplateInfo"
responses:
"200":
content:
application/json:
schema:
- items:
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- format: uuid
- type: string
- type: array
- description: The IDs of owners that are reviewers for this resource.
+ $ref: "#/components/schemas/RequestTemplate"
+ description: The request template just created.
security:
- BearerAuth: []
tags:
- - resources
+ - request-templates
put:
- description: Sets the list of reviewers for a resource.
- operationId: set_resource_reviewers
- parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: resource_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
+ description: Updates a request template.
+ operationId: updateRequestTemplate
requestBody:
+ description: Request template to be updated
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/ReviewerIDList"
+ $ref: "#/components/schemas/UpdateRequestTemplateInfo"
responses:
"200":
content:
application/json:
schema:
- items:
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- format: uuid
- type: string
- type: array
- description: The updated IDs of owners that are reviewers for this resource
+ $ref: "#/components/schemas/RequestTemplate"
+ description: The request template just updated.
security:
- BearerAuth: []
tags:
- - resources
- /resources/{resource_id}/reviewer-stages:
+ - request-templates
+ /request-templates/{request_template_id}:
get:
- description: Gets the list reviewer stages for a resource.
- operationId: get_resource_reviewer_stages
+ description: Returns a `RequestTemplate` object.
+ operationId: getRequestTemplate
parameters:
- - description: The ID of the resource.
+ - description: The ID of the request template.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: resource_id
+ name: request_template_id
required: true
schema:
format: uuid
@@ -3304,54 +3189,107 @@ paths:
content:
application/json:
schema:
- description: A list of reviewer stages.
- items:
- $ref: "#/components/schemas/ReviewerStage"
- type: array
- description: The reviewer stages for this resource.
+ $ref: "#/components/schemas/RequestTemplate"
+ description: The requested request template.
security:
- BearerAuth: []
tags:
- - resources
- put:
- description: Sets the list of reviewer stages for a resource.
- operationId: set_resource_reviewer_stages
+ - request-templates
+ delete:
+ description: Deletes a request template.
+ operationId: deleteRequestTemplate
parameters:
- - description: The ID of the resource.
+ - description: The ID of the request template.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: resource_id
+ name: request_template_id
required: true
schema:
format: uuid
type: string
style: simple
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/ReviewerStageList"
responses:
"200":
- content:
- application/json:
- schema:
- description: A list of reviewer stages.
- items:
- $ref: "#/components/schemas/ReviewerStage"
- type: array
- description: The updated reviewer stages for this resource.
+ description: The request template was successfully deleted.
security:
- BearerAuth: []
tags:
- - resources
- /non-human-identities:
+ - request-templates
+ /requests:
get:
- description: Returns a list of non-human identities for your organization.
- operationId: get_nhis
+ summary: Get requests
+ description:
+ Returns a list of requests for your organization that is visible by
+ the admin.
+ operationId: getRequests
parameters:
+ - description: A start date filter for the events.
+ examples:
+ withDate:
+ summary: Example with date
+ value: 2021-11-01
+ withDatetime:
+ summary: Example with date and time in ISO 8601 datetime format.
+ value: 2025-01-01T00:00:00Z
+ explode: true
+ in: query
+ name: start_date_filter
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: An end date filter for the events.
+ examples:
+ withDate:
+ summary: Example with date
+ value: 2021-11-12
+ withDatetime:
+ summary: Example with date and time in ISO 8601 datetime format.
+ value: 2025-01-01T00:00:00Z
+ explode: true
+ in: query
+ name: end_date_filter
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Filter requests by their requester ID.
+ example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ in: query
+ name: requester_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ - description: Filter requests by their target user ID.
+ example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ in: query
+ name: target_user_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ - description: Filter requests by the resource ID that was requested.
+ example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ in: query
+ name: resource_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ - description: Filter requests by the group ID that was requested.
+ example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ in: query
+ name: group_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
- description: The pagination cursor value.
example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
explode: true
@@ -3371,523 +3309,581 @@ paths:
type: integer
maximum: 1000
style: form
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/PaginatedResourcesList"
- description: One page worth non-human identities in your organization.
- security:
- - BearerAuth: []
- tags:
- - non-human-identities
- /resources/{resource_id}/non-human-identities:
- get:
- description: Gets the list of non-human identities with access to this resource.
- operationId: get_resource_nhis
- parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: resource_id
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- - description: Limit the number of results returned.
- example: 200
+ - description: Boolean toggle for if it should only show pending requests.
explode: true
in: query
- name: limit
+ name: show_pending_only
required: false
schema:
- type: integer
+ type: boolean
style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/AccessList"
- description: List of non-human identities with access to this resource.
+ $ref: "#/components/schemas/RequestList"
+ description: The list of requests.
security:
- BearerAuth: []
tags:
- - resources
- /resources/{resource_id}/users:
- get:
- summary: Get resource users
- description: Gets the list of users for this resource.
- operationId: get_resource_users
+ - requests
+ post:
+ description: "Create an access request"
+ operationId: "createRequest"
+ requestBody:
+ description: Resources to be updated
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateRequestInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ properties:
+ id:
+ format: uuid
+ type: string
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ description: The resulting request.
+ security:
+ - BearerAuth: []
+ tags:
+ - requests
+ /requests/relay:
+ get:
+ summary: Get requests via Relay
+ description: Returns a paginated list of requests using Relay-style cursor pagination.
+ operationId: getRequestsRelay
+ deprecated: true
parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
- in: path
- name: resource_id
- required: true
+ - description: Number of results to return after the cursor. Use either
+ first/after or last/before, not both.
+ example: 10
+ in: query
+ name: first
+ required: false
+ schema:
+ type: integer
+ minimum: 1
+ maximum: 100
+ - description:
+ Cursor to fetch results after. Used with 'first' for forward
+ pagination.
+ example:
+ "Y3Vyc29yOnYyOpK5MjAyMS0wMS0wN1QwNzo0MToyNy4xMTlaFjYwZmM2YmJlZjk4YzE1N\
+ 2ZhNjFhYjk4Nw=="
+ in: query
+ name: after
+ required: false
schema:
- format: uuid
type: string
- style: simple
- - description: Limit the number of results returned.
- example: 200
- explode: true
+ - description: Number of results to return before the cursor. Use either
+ first/after or last/before, not both.
+ example: 10
in: query
- name: limit
+ name: last
required: false
schema:
type: integer
- style: form
+ minimum: 1
+ maximum: 100
+ - description:
+ Cursor to fetch results before. Used with 'last' for backward
+ pagination.
+ example:
+ "Y3Vyc29yOnYyOpK5MjAyMS0wMS0wN1QwNzo0MToyNy4xMTlaFjYwZmM2YmJlZjk4YzE1N\
+ 2ZhNjFhYjk4Nw=="
+ in: query
+ name: before
+ required: false
+ schema:
+ type: string
+ - description: Filter requests by their status.
+ example: PENDING
+ in: query
+ name: status
+ required: false
+ schema:
+ $ref: "#/components/schemas/RequestStatusEnum"
+ - description: Filter requests assigned to a specific user ID.
+ example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ in: query
+ name: to
+ required: false
+ schema:
+ format: uuid
+ type: string
+ - description: Filter requests made by a specific user ID.
+ example: 37cb7e41-12ba-46da-92ff-030abe0450b1
+ in: query
+ name: from
+ required: false
+ schema:
+ format: uuid
+ type: string
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/ResourceAccessUserList"
- description: List of users with access to this resource.
+ $ref: "#/components/schemas/RequestConnection"
+ description: A paginated list of requests using Relay-style cursor pagination.
security:
- BearerAuth: []
tags:
- - resources
- /resources/{resource_id}/non-human-identities/{non_human_identity_id}:
- post:
- description: Gives a non-human identity access to this resource.
- operationId: add_resource_nhi
+ - requests
+ /requests/{id}:
+ get:
+ summary: Get request by ID
+ description: Returns a request by ID.
+ operationId: getRequest
parameters:
- - description: The ID of the resource.
+ - description: The ID of the request.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: resource_id
+ name: id
required: true
schema:
format: uuid
type: string
style: simple
- - description: The resource ID of the non-human identity to add.
- example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
- explode: false
+ responses:
+ "200":
+ description: The requested request object.
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Request"
+ security:
+ - BearerAuth: []
+ tags:
+ - requests
+ /requests/{id}/approve:
+ post:
+ description: "Approve an access request"
+ operationId: "approveRequest"
+ parameters:
+ - description: "The ID of the request to approve"
in: path
- name: non_human_identity_id
+ name: id
required: true
schema:
- format: uuid
type: string
- style: simple
+ format: uuid
requestBody:
- required: false
+ description: Approval parameters
+ required: true
content:
application/json:
schema:
- example:
- duration_minutes: 60
- access_level_remote_id: roles/cloudsql.instanceUser
+ type: object
properties:
- duration_minutes:
- description:
- The duration for which the resource can be accessed (in minutes).
- Use 0 to set to indefinite.
- example: 60
- type: integer
- maximum: 525960 # One year
- access_level_remote_id:
- description:
- The remote ID of the access level to grant. If omitted, the default
- access level remote ID value (empty string) is used.
- example: roles/cloudsql.instanceUser
+ level:
+ $ref: "#/components/schemas/RequestApprovalEnum"
+ comment:
type: string
+ description: "Optional comment for the approval"
+ example: "Approved after security review"
required:
- - duration_minutes
- type: object
+ - level
responses:
"200":
+ description: "Request successfully approved"
content:
application/json:
schema:
- $ref: "#/components/schemas/ResourceNHI"
- description:
- Details about the access that the non-human identity was granted to
- the resource.
+ type: object
+ properties:
+ request:
+ $ref: "#/components/schemas/Request"
security:
- BearerAuth: []
tags:
- - resources
- delete:
- description: Removes a non-human identity's direct access from this resource.
- operationId: delete_resource_nhi
+ - requests
+ /requests/{id}/deny:
+ post:
+ description: "Deny an access request"
+ operationId: "denyRequest"
parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: "The ID of the request to deny"
in: path
- name: resource_id
+ name: id
required: true
schema:
- format: uuid
type: string
- style: simple
- - description:
- The resource ID of the non-human identity to remove from this
- resource.
- example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
- explode: false
- in: path
- name: non_human_identity_id
- required: true
- schema:
format: uuid
- type: string
- style: simple
- - description:
- The remote ID of the access level for which this non-human identity
- has direct access. If omitted, the default access level remote ID
- value (empty string) is assumed.
- example: roles/cloudsql.instanceUser
- explode: true
- in: query
- name: access_level_remote_id
- required: false
- schema:
- type: string
- style: form
+ requestBody:
+ description: Denial parameters
+ required: true
+ content:
+ application/json:
+ schema:
+ type: object
+ properties:
+ comment:
+ type: string
+ description: "Comment for the denial"
+ example: "Denied due to insufficient justification"
+ level:
+ $ref: "#/components/schemas/RequestApprovalEnum"
+ required:
+ - comment
responses:
"200":
- description:
- This non-human identity's access was successfully removed from this
- resource.
+ description: "Request successfully denied"
+ content:
+ application/json:
+ schema:
+ type: object
+ properties:
+ request:
+ $ref: "#/components/schemas/Request"
security:
- BearerAuth: []
tags:
- - resources
- /resources/{resource_id}/users/{user_id}:
+ - requests
+ /requests/{id}/cancel:
post:
- description: Adds a user to this resource.
- operationId: add_resource_user
+ summary: Cancel request
+ description: Cancels a pending access request.
+ operationId: cancelRequest
parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the request to cancel.
in: path
- name: resource_id
+ name: id
required: true
schema:
- format: uuid
type: string
- style: simple
- - description: The ID of the user to add.
- example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
- explode: false
- in: path
- name: user_id
- required: true
- schema:
format: uuid
- type: string
- style: simple
- - description:
- The duration for which the resource can be accessed (in minutes).
- Use 0 to set to indefinite.
- example: 60
- explode: true
- in: query
- name: duration_minutes
- required: false
- schema:
- type: integer
- maximum: 525960 # One year
- style: form
- deprecated: true
- - description:
- The remote ID of the access level to grant to this user. If
- omitted, the default access level remote ID value (empty string) is
- used.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
- explode: true
- in: query
- name: access_level_remote_id
- required: false
- schema:
- type: string
- style: form
- deprecated: true
- requestBody:
- required: false
- content:
- application/json:
- schema:
- example:
- duration_minutes: 60
- access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
- properties:
- duration_minutes:
- description:
- The duration for which the resource can be accessed (in minutes).
- Use 0 to set to indefinite.
- example: 60
- type: integer
- maximum: 525960 # One year
- access_level_remote_id:
- description:
- The remote ID of the access level to grant to this user. If
- omitted, the default access level remote ID value (empty
- string) is used.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
- type: string
- required:
- - duration_minutes
- type: object
responses:
"200":
+ description: The canceled request.
content:
application/json:
schema:
- $ref: "#/components/schemas/ResourceUser"
- description: The ResourceUser that was created.
+ $ref: "#/components/schemas/Request"
+ "403":
+ description: The authenticated user cannot cancel this request.
+ "404":
+ description: The request was not found.
+ "409":
+ description: The request has already been actioned.
security:
- BearerAuth: []
tags:
- - resources
- put:
- description: Updates a user's access level or duration on this resource.
- operationId: update_resource_user
+ - requests
+ /requests/{id}/remind:
+ post:
+ summary: Send request reminder
+ description: Sends a reminder to all pending reviewers of the request.
+ operationId: remindRequest
parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ - description: The ID of the request whose reviewers should be reminded.
in: path
- name: resource_id
+ name: id
required: true
schema:
- format: uuid
type: string
- style: simple
- - description: The ID of the user whose access is being updated.
- example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
- in: path
- name: user_id
- required: true
- schema:
format: uuid
- type: string
- style: simple
- requestBody:
- required: true
- content:
- application/json:
- schema:
- type: object
- example:
- duration_minutes: 60
- access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
- properties:
- duration_minutes:
- description:
- The updated duration for which the resource can be accessed (in
- minutes). Use 0 for indefinite.
- type: integer
- maximum: 525960 # One year
- example: 120
- access_level_remote_id:
- description: The updated remote ID of the access level granted to this user.
- type: string
- example: arn:aws:iam::590304332660:role/ReadOnlyAccess
- required:
- - duration_minutes
responses:
"200":
- description: The ResourceUser was successfully updated.
+ description: The reminder was sent, or the request was already resolved.
content:
application/json:
schema:
- $ref: "#/components/schemas/ResourceUser"
+ type: object
+ properties:
+ success:
+ type: boolean
+ required:
+ - success
+ "400":
+ description: Unknown JSON fields in the request body.
+ "404":
+ description: The request was not found.
+ "429":
+ description: The reviewer reminder cooldown has not elapsed.
security:
- BearerAuth: []
tags:
- - resources
- delete:
- description: Removes a user's direct access from this resource.
- operationId: delete_resource_user
+ - requests
+ /requests/{id}/reviewers/{reviewer_id}/remind:
+ post:
+ summary: Send reminder to a reviewer
+ description: Sends a reminder to one pending reviewer of the request.
+ operationId: remindRequestReviewer
parameters:
- - description: The ID of the resource.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the request whose reviewer should be reminded.
in: path
- name: resource_id
+ name: id
required: true
schema:
- format: uuid
type: string
- style: simple
- - description: The ID of a user to remove from this resource.
- example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
- explode: false
+ format: uuid
+ - description: The ID of the pending reviewer to remind.
in: path
- name: user_id
+ name: reviewer_id
required: true
- schema:
- format: uuid
- type: string
- style: simple
- - description:
- The remote ID of the access level for which this user has direct
- access. If omitted, the default access level remote ID value (empty
- string) is assumed.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
- explode: true
- in: query
- name: access_level_remote_id
- required: false
schema:
type: string
- style: form
+ format: uuid
responses:
"200":
- description: This user's access was successfully removed from this resource.
+ description: The reminder was sent, or the request was already resolved.
+ content:
+ application/json:
+ schema:
+ type: object
+ properties:
+ success:
+ type: boolean
+ required:
+ - success
+ "400":
+ description: Unknown JSON fields, or the user is not a pending reviewer of the request.
+ "404":
+ description: The request was not found.
+ "429":
+ description: The reviewer reminder cooldown has not elapsed.
security:
- BearerAuth: []
tags:
- - resources
+ - requests
+ /requests/{id}/comments:
get:
- summary: Get resource user
- description: Returns information about a specific user's access to a resource.
- operationId: getResourceUser
+ description: Returns a list of comments for a specific request.
+ operationId: getRequestComments
parameters:
- - description: The ID of the resource.
- example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ - description: "The ID of the request to get comments for"
in: path
- name: resource_id
+ name: id
required: true
schema:
- format: uuid
type: string
- style: simple
- - description: The ID of the user.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ format: uuid
+ responses:
+ "200":
+ description: A list of comments associated with the specified request.
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/RequestCommentList"
+ security:
+ - BearerAuth: []
+ tags:
+ - requests
+ post:
+ description: "Comment on an access request"
+ operationId: "createRequestComment"
+ parameters:
+ - description: "The ID of the request to comment on"
in: path
- name: user_id
+ name: id
required: true
- schema:
- format: uuid
- type: string
- style: simple
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
- explode: true
- in: query
- name: cursor
- required: false
schema:
type: string
- style: form
+ format: uuid
+ requestBody:
+ description: Comment parameters
+ required: true
+ content:
+ application/json:
+ schema:
+ type: object
+ properties:
+ comment:
+ type: string
+ description: "comment"
+ required:
+ - comment
responses:
"200":
+ description: "Request successfully commented"
content:
application/json:
schema:
type: object
properties:
- data:
- type: array
- items:
- $ref: "#/components/schemas/ResourceUser"
- cursor:
- type: string
- description: Pagination cursor for the next page of results
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
- total_count:
- type: integer
- description: Total number of results
- example: 120
- required:
- - data
- description: List of ResourceUser records for the user's access to the resource.
- "404":
- description: Resource or user not found.
+ request:
+ $ref: "#/components/schemas/Request"
security:
- BearerAuth: []
tags:
- - resources
- /resource-user-access-status/{resource_id}/{user_id}:
+ - requests
+ /resources:
get:
- deprecated: true
- description: Get user's access status to a resource.
- operationId: resource_user_access_status_retrieve
+ summary: Get resources
+ description: Returns a list of resources for your organization.
+ operationId: getResources
parameters:
- - description: The ID of the resource.
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
- in: path
- name: resource_id
- required: true
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
schema:
- format: uuid
type: string
- style: simple
- - description: The ID of the user.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
+ - description: The resource type to filter by. Required when remote_id is provided.
+ example: AWS_IAM_ROLE
+ explode: true
+ in: query
+ name: resource_type_filter
+ required: false
+ schema:
+ $ref: "#/components/schemas/ResourceTypeEnum"
+ style: form
+ - description: The resource ids to filter by.
+ example:
+ - 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ - 1b978423-db0a-4037-a4cf-f79c60cb67b3
explode: false
- in: path
- name: user_id
- required: true
+ in: query
+ name: resource_ids
+ required: false
+ schema:
+ items:
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ format: uuid
+ type: string
+ type: array
+ style: form
+ - description: Resource name.
+ example: example-name
+ explode: true
+ in: query
+ name: resource_name
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: The parent resource id to filter by.
+ example:
+ - 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: query
+ name: parent_resource_id
+ required: false
schema:
format: uuid
type: string
- style: simple
+ style: form
- description:
- The remote ID of the access level that you wish to query for the
- resource. If omitted, the default access level remote ID value
- (empty string) is used.
- example: arn:aws:iam::590304332660:role/AdministratorAccess
- explode: true
+ The ancestor resource id to filter by. Returns all resources that
+ are descendants of the specified resource.
+ example:
+ - 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
in: query
- name: access_level_remote_id
+ name: ancestor_resource_id
required: false
schema:
+ format: uuid
type: string
style: form
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
- explode: true
+ - description:
+ Filter resources by their remote id. This will return all resources
+ that have a remote id that matches the provided remote id. Note that
+ this requires resource_type_filter to be provided.
in: query
- name: cursor
+ name: remote_id
required: false
schema:
type: string
style: form
- - description: Number of results to return per page. Default is 200.
- example: 200
- explode: true
+ - description:
+ The IDs of the tags to filter by. Returns only resources that have
+ any of these tags applied.
in: query
- name: page_size
+ name: tag_ids
required: false
schema:
- type: integer
- maximum: 1000
+ type: array
+ items:
+ format: uuid
+ type: string
style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/ResourceUserAccessStatus"
- description: The access status reflecting the user's access to the resource.
+ $ref: "#/components/schemas/PaginatedResourcesList"
+ description: One page worth resources associated with your organization.
security:
- BearerAuth: []
tags:
- resources
- /resources/{resource_id}/tags:
+ put:
+ description: Bulk updates a list of resources.
+ operationId: updateResources
+ requestBody:
+ description: Resources to be updated
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdateResourceInfoList"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdateResourceInfoList"
+ description: The resulting updated resource infos.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ post:
+ description: Creates a resource. See
+ [here](https://docs.opal.dev/reference/end-system-objects) for details
+ about importing resources.
+ operationId: createResource
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateResourceInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Resource"
+ description: The resource just created.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ /resources/{resource_id}:
get:
- description: Returns all tags applied to the resource.
- operationId: get_resource_tags
+ summary: Get resource by ID
+ description: Retrieves a resource.
+ operationId: get_resource
parameters:
- - description: The ID of the resource whose tags to return.
- name: resource_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
+ name: resource_id
required: true
schema:
format: uuid
@@ -3895,27 +3891,46 @@ paths:
style: simple
responses:
"200":
+ description: The requested resource.
content:
application/json:
schema:
- $ref: "#/components/schemas/TagsList"
- description: The tags applied to the resource.
+ $ref: "#/components/schemas/Resource"
security:
- BearerAuth: []
tags:
- resources
- /resources/{resource_id}/scoped-role-permissions:
- get:
- description:
- Returns all the scoped role permissions that apply to the given
- resource. Only OPAL_SCOPED_ROLE resource type supports this field.
- operationId: get_resource_scoped_role_permissions
+ delete:
+ description: Deletes a resource.
+ operationId: delete_resource
parameters:
- - description: The ID of the resource whose scoped role permissions belong to.
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
name: resource_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: The resource was successfully deleted.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ /resources/{resource_id}/message-channels:
+ get:
+ description: Gets the list of audit message channels attached to a resource.
+ operationId: get_resource_message_channels
+ parameters:
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
+ name: resource_id
required: true
schema:
format: uuid
@@ -3926,23 +3941,21 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/ScopedRolePermissionList"
- description: The role permissions that this Opal Scoped Role has.
+ $ref: "#/components/schemas/MessageChannelList"
+ description: The audit message channels attached to the resource.
security:
- BearerAuth: []
tags:
- resources
put:
- description: Sets all the scoped role permissions on an OPAL_SCOPED_ROLE resource.
- operationId: set_resource_scoped_role_permissions
+ description: Sets the list of audit message channels attached to a resource.
+ operationId: set_resource_message_channels
parameters:
- - description:
- The ID of the resource whose scoped role permissions belong to.
- Must be of OPAL_SCOPED_ROLE resource type.
- name: resource_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
+ name: resource_id
required: true
schema:
format: uuid
@@ -3953,174 +3966,213 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/ScopedRolePermissionList"
+ $ref: "#/components/schemas/MessageChannelIDList"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/ScopedRolePermissionList"
- description: The role permissions that this Opal Scoped Role has.
+ items:
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ format: uuid
+ type: string
+ type: array
+ description: The updated audit message channel IDs for the resource.
security:
- BearerAuth: []
tags:
- resources
- /resources/users/{user_id}:
+ /resources/{resource_id}/visibility:
get:
- description: Gets the list of resources for this user.
- operationId: get_user_resources
+ description: Gets the visibility of this resource.
+ operationId: get_resource_visibility
parameters:
- - description: The ID of the user.
+ - description: The ID of the resource.
example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: user_id
+ name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
- - description: Limit the number of results returned.
- example: 200
- explode: true
- in: query
- name: limit
- required: false
- schema:
- type: integer
- style: form
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
- explode: true
- in: query
- name: cursor
- required: false
- schema:
- type: string
- style: form
- - description: Include user's access to unmanaged resources.
- example: false
- explode: true
- in: query
- name: include_unmanaged
- required: false
- schema:
- type: boolean
- style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/ResourceAccessUserList"
- description: List of resources user has access to.
+ $ref: "#/components/schemas/VisibilityInfo"
+ description: The visibility info of this resource.
+ "403":
+ description: The caller is not authorized to view this resource's visibility.
security:
- BearerAuth: []
tags:
- resources
- /resources/{resource_id}/groups:
- get:
- description: Returns a list of groups that grant access to the resource
- operationId: get_resource_groups
+ put:
+ description: Sets the visibility of this resource.
+ operationId: set_resource_visibility
parameters:
- - description: The ID of the resource that the groups grant access to.
- name: resource_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
+ name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/VisibilityInfo"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/GroupResourceList"
- description: The groups that grant access to the resource.
+ $ref: "#/components/schemas/VisibilityInfo"
+ description: The visibility info of this resource.
security:
- BearerAuth: []
tags:
- resources
- /sessions:
+ /resources/{resource_id}/reviewers:
get:
- description: Returns a list of `Session` objects.
- operationId: sessions
+ description: Gets the list of owner IDs of the reviewers for a resource.
+ operationId: get_resource_reviewers
parameters:
- description: The ID of the resource.
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: true
- in: query
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
name: resource_id
required: true
schema:
format: uuid
type: string
- style: form
- - description: The ID of the user you wish to query sessions for.
- example: 32acc112-21ff-4669-91c2-21e27683eaa1
- explode: true
- in: query
- name: user_id
- required: false
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ items:
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ format: uuid
+ type: string
+ type: array
+ description: The IDs of owners that are reviewers for this resource.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ put:
+ description: Sets the list of reviewers for a resource.
+ operationId: set_resource_reviewers
+ parameters:
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: resource_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
+ style: simple
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/ReviewerIDList"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/SessionsList"
- description: The sessions associated with a resource.
+ items:
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ format: uuid
+ type: string
+ type: array
+ description: The updated IDs of owners that are reviewers for this resource
security:
- BearerAuth: []
tags:
- - sessions
- /user:
+ - resources
+ /resources/{resource_id}/reviewer-stages:
get:
- description: Returns a `User` object.
- operationId: user
+ description: Gets the list reviewer stages for a resource.
+ operationId: get_resource_reviewer_stages
parameters:
- - description: The user ID of the user.
- example: 32acc112-21ff-4669-91c2-21e27683eaa1
- explode: true
- in: query
- name: user_id
- required: false
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: resource_id
+ required: true
schema:
format: uuid
type: string
- style: form
- - description:
- The email of the user. If both user ID and email are provided, user
- ID will take precedence. If neither are provided, an error will
- occur.
- example: johndoe@domain.org
- explode: true
- in: query
- name: email
- required: false
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ description: A list of reviewer stages.
+ items:
+ $ref: "#/components/schemas/ReviewerStage"
+ type: array
+ description: The reviewer stages for this resource.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ put:
+ description: Sets the list of reviewer stages for a resource.
+ operationId: set_resource_reviewer_stages
+ parameters:
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: resource_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
+ style: simple
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/ReviewerStageList"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/User"
- description: The user object associated with the passed-in email or ID.
+ description: A list of reviewer stages.
+ items:
+ $ref: "#/components/schemas/ReviewerStage"
+ type: array
+ description: The updated reviewer stages for this resource.
security:
- BearerAuth: []
tags:
- - users
- /users:
+ - resources
+ /non-human-identities:
get:
- description: Returns a list of users for your organization.
- operationId: getUsers
+ description: Returns a list of non-human identities for your organization.
+ operationId: get_nhis
parameters:
- description: The pagination cursor value.
example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
@@ -4141,140 +4193,73 @@ paths:
type: integer
maximum: 1000
style: form
- - description:
- The IDs of the tags to filter by. Returns only users that have any
- of these tags applied.
- in: query
- name: tag_ids
- required: false
- schema:
- type: array
- items:
- format: uuid
- type: string
- style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedUsersList"
- description: One page worth users in your organization.
+ $ref: "#/components/schemas/PaginatedResourcesList"
+ description: One page worth non-human identities in your organization.
security:
- BearerAuth: []
tags:
- - users
- /users/remote_users:
+ - non-human-identities
+ /resources/{resource_id}/non-human-identities:
get:
- description: Returns a list of remote users for your organization.
- operationId: getRemoteUsers
+ description: Gets the list of non-human identities with access to this resource.
+ operationId: get_resource_nhis
parameters:
- - description: Filter remote users by their third party provider.
- example: [GIT_HUB]
- in: query
- name: third_party_provider
- required: false
- schema:
- type: array
- items:
- $ref: "#/components/schemas/ThirdPartyProviderEnum"
- style: form
- - description: Filter remote users by their user ID.
- example: [32acc112-21ff-4669-91c2-21e27683eaa1]
- in: query
- name: user_id
- required: false
- schema:
- type: array
- items:
- type: string
- format: uuid
- style: form
- - description: Filter remote users by their remote ID.
- example: [1234567890]
- in: query
- name: remote_id
- required: false
- schema:
- type: array
- items:
- type: string
- style: form
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
- explode: true
- in: query
- name: cursor
- required: false
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: resource_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
- - description: Number of results to return per page. Default is 200.
+ style: simple
+ - description: Limit the number of results returned.
example: 200
explode: true
in: query
- name: page_size
+ name: limit
required: false
schema:
type: integer
- maximum: 1000
style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedRemoteUsersList"
- description: One page worth users in your organization.
+ $ref: "#/components/schemas/AccessList"
+ description: List of non-human identities with access to this resource.
security:
- BearerAuth: []
tags:
- - users
- /users/{user_id}/tags:
+ - resources
+ /resources/{resource_id}/users:
get:
- description: Returns all tags applied to the user.
- operationId: get_user_tags
+ summary: Get resource users
+ description: Gets the list of users for this resource.
+ operationId: get_resource_users
parameters:
- - description: The ID of the user whose tags to return.
- name: user_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
+ name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/TagsList"
- description: The tags applied to the user.
- security:
- - BearerAuth: []
- tags:
- - users
- /access-rules:
- get:
- description: Returns a list of access rules for your organization.
- operationId: get_access_rules
- parameters:
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
- explode: true
- in: query
- name: cursor
- required: false
- schema:
- type: string
- style: form
- - description: Number of results to return per page. Default is 200.
+ - description: Limit the number of results returned.
example: 200
explode: true
in: query
- name: page_size
+ name: limit
required: false
schema:
type: integer
@@ -4284,314 +4269,282 @@ paths:
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedAccessRulesList"
- description: One page of access rules for your organization.
+ $ref: "#/components/schemas/ResourceAccessUserList"
+ description: List of users with access to this resource.
security:
- BearerAuth: []
tags:
- - access-rules
+ - resources
+ /resources/{resource_id}/non-human-identities/{non_human_identity_id}:
post:
- description: Creates a new access rule config for the given group_id.
- operationId: create_access_rule
- requestBody:
- required: true
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UpdateAccessRuleInfo"
- responses:
- "201":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/AccessRule"
- description: The created access rule config for the group.
- security:
- - BearerAuth: []
- tags:
- - access-rules
- /access-rules/{access_rule_id}:
- get:
- description:
- Returns a list of access rule config given the group_id of the
- access rule.
- operationId: get_access_rule
+ description: Gives a non-human identity access to this resource.
+ operationId: add_resource_nhi
parameters:
- - description: The access rule ID (group ID) of the access rule.
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: access_rule_id
+ name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/AccessRule"
- description: The access rules for the group.
- security:
- - BearerAuth: []
- tags:
- - access-rules
- put:
- description: Updates the access rule config for the given group_id.
- operationId: update_access_rule
- parameters:
- - description: The access rule ID (group ID) of the access rule.
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The resource ID of the non-human identity to add.
+ example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
explode: false
in: path
- name: access_rule_id
+ name: non_human_identity_id
required: true
schema:
format: uuid
type: string
style: simple
requestBody:
- required: true
+ required: false
content:
application/json:
schema:
- $ref: "#/components/schemas/UpdateAccessRuleInfo"
+ example:
+ duration_minutes: 60
+ access_level_remote_id: roles/cloudsql.instanceUser
+ properties:
+ duration_minutes:
+ description:
+ The duration for which the resource can be accessed (in minutes).
+ Use 0 to set to indefinite.
+ example: 60
+ type: integer
+ maximum: 153722867 # Largest duration Opal can represent (~292 years)
+ access_level_remote_id:
+ description:
+ The remote ID of the access level to grant. If omitted, the default
+ access level remote ID value (empty string) is used.
+ example: roles/cloudsql.instanceUser
+ type: string
+ required:
+ - duration_minutes
+ type: object
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/AccessRule"
- description: The updated access rule config for the group.
+ $ref: "#/components/schemas/ResourceNHI"
+ description:
+ Details about the access that the non-human identity was granted to
+ the resource.
security:
- BearerAuth: []
tags:
- - access-rules
- /tag/{tag_id}:
- get:
- summary: Get tag by ID
- description: UNSTABLE. May be removed at any time. Gets a tag with the given id.
- operationId: get_tag_by_ID
+ - resources
+ delete:
+ description: Removes a non-human identity's direct access from this resource.
+ operationId: delete_resource_nhi
parameters:
- - description: The tag ID
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: tag_id
+ name: resource_id
required: true
schema:
- type: string
format: uuid
+ type: string
style: simple
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/Tag"
- description: The tag requested.
- security:
- - BearerAuth: []
- tags:
- - tags
- delete:
- description: UNSTABLE. May be removed at any time. Deletes a tag with the given id.
- operationId: delete_tag_by_ID
- parameters:
- - description: The tag ID
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description:
+ The resource ID of the non-human identity to remove from this
+ resource.
+ example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
explode: false
in: path
- name: tag_id
+ name: non_human_identity_id
required: true
schema:
- type: string
format: uuid
- style: simple
- responses:
- "200":
- description: Tag was deleted.
- security:
- - BearerAuth: []
- tags:
- - tags
- /tag:
- get:
- description: Gets a tag with the given key and value.
- operationId: get_tag
- parameters:
- - description: The key of the tag to get.
- example: api-scope
- explode: false
- in: query
- name: tag_key
- required: true
- schema:
type: string
- style: form
- - description: The value of the tag to get.
- example: production
- explode: false
+ style: simple
+ - description:
+ The remote ID of the access level for which this non-human identity
+ has direct access. If omitted, the default access level remote ID
+ value (empty string) is assumed.
+ example: roles/cloudsql.instanceUser
+ explode: true
in: query
- name: tag_value
+ name: access_level_remote_id
required: false
schema:
type: string
style: form
responses:
"200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/Tag"
- description: The tag requested.
+ description:
+ This non-human identity's access was successfully removed from this
+ resource.
security:
- BearerAuth: []
tags:
- - tags
+ - resources
+ /resources/{resource_id}/users/{user_id}:
post:
- description: Creates a tag with the given key and value.
- operationId: create_tag
+ description: Adds a user to this resource.
+ operationId: add_resource_user
parameters:
- - description: The key of the tag to create.
- example: api-scope
- explode: false
- in: query
- name: tag_key
- required: false
- schema:
- type: string
- style: form
- deprecated: true
- - description: The value of the tag to create.
- example: production
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
- in: query
- name: tag_value
- required: false
+ in: path
+ name: resource_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
- deprecated: true
- - description: The ID of the owner that manages the tag.
+ style: simple
+ - description: The ID of the user to add.
example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
explode: false
- in: query
- name: admin_owner_id
+ in: path
+ name: user_id
+ required: true
schema:
format: uuid
type: string
- style: form
- deprecated: true
- requestBody:
- required: false
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/CreateTagInfo"
- responses:
- "200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/Tag"
- description: The tag that was created.
- security:
- - BearerAuth: []
- tags:
- - tags
- /tags:
- get:
- summary: Get tags
- description: Returns a list of tags created by your organization.
- operationId: getTags
- parameters:
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ style: simple
+ - description:
+ The duration for which the resource can be accessed (in minutes).
+ Use 0 to set to indefinite.
+ example: 60
explode: true
in: query
- name: cursor
+ name: duration_minutes
required: false
schema:
- type: string
+ type: integer
+ maximum: 153722867 # Largest duration Opal can represent (~292 years)
style: form
- - description: Number of results to return per page. Default is 200.
- example: 200
+ deprecated: true
+ - description:
+ The remote ID of the access level to grant to this user. If
+ omitted, the default access level remote ID value (empty string) is
+ used.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
explode: true
in: query
- name: page_size
+ name: access_level_remote_id
required: false
schema:
- type: integer
- maximum: 1000
+ type: string
style: form
+ deprecated: true
+ requestBody:
+ required: false
+ content:
+ application/json:
+ schema:
+ example:
+ duration_minutes: 60
+ access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
+ properties:
+ duration_minutes:
+ description:
+ The duration for which the resource can be accessed (in minutes).
+ Use 0 to set to indefinite.
+ example: 60
+ type: integer
+ maximum: 153722867 # Largest duration Opal can represent (~292 years)
+ access_level_remote_id:
+ description:
+ The remote ID of the access level to grant to this user. If
+ omitted, the default access level remote ID value (empty
+ string) is used.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
+ type: string
+ required:
+ - duration_minutes
+ type: object
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedTagsList"
- description: A list of tags created by your organization.
+ $ref: "#/components/schemas/ResourceUser"
+ description: The ResourceUser that was created.
security:
- BearerAuth: []
tags:
- - tags
- /tags/{tag_id}/users/{user_id}:
- post:
- description: Applies a tag to a user.
- operationId: add_user_tag
+ - resources
+ put:
+ description: Updates a user's access level or duration on this resource.
+ operationId: update_resource_user
parameters:
- - description: The ID of the tag to apply.
- name: tag_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
in: path
+ name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
- - description: The ID of the user to apply the tag to.
- name: user_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
+ - description: The ID of the user whose access is being updated.
+ example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
in: path
+ name: user_id
required: true
schema:
format: uuid
type: string
style: simple
requestBody:
- required: false
+ required: true
content:
application/json:
schema:
type: object
+ example:
+ duration_minutes: 60
+ access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
+ properties:
+ duration_minutes:
+ description:
+ The updated duration for which the resource can be accessed (in
+ minutes). Use 0 for indefinite.
+ type: integer
+ maximum: 153722867 # Largest duration Opal can represent (~292 years)
+ example: 120
+ access_level_remote_id:
+ description: The updated remote ID of the access level granted to this user.
+ type: string
+ example: arn:aws:iam::590304332660:role/ReadOnlyAccess
+ required:
+ - duration_minutes
responses:
"200":
- description: Tag applied to user successfully.
+ description: The ResourceUser was successfully updated.
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/ResourceUser"
security:
- BearerAuth: []
tags:
- - tags
+ - resources
delete:
- description: Removes a tag from a user.
- operationId: remove_user_tag
+ description: Removes a user's direct access from this resource.
+ operationId: delete_resource_user
parameters:
- - description: The ID of the tag to remove.
- name: tag_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the resource.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
+ name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
- - description: The ID of the user to remove the tag from.
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of a user to remove from this resource.
+ example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
explode: false
in: path
name: user_id
@@ -4600,114 +4553,160 @@ paths:
format: uuid
type: string
style: simple
+ - description:
+ The remote ID of the access level for which this user has direct
+ access. If omitted, the default access level remote ID value (empty
+ string) is assumed.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
+ explode: true
+ in: query
+ name: access_level_remote_id
+ required: false
+ schema:
+ type: string
+ style: form
responses:
"200":
- description: Tag removed from user successfully.
+ description: This user's access was successfully removed from this resource.
security:
- BearerAuth: []
tags:
- - tags
- /tags/{tag_id}/groups/{group_id}:
- post:
- description: Applies a tag to a group.
- operationId: add_group_tag
+ - resources
+ get:
+ summary: Get resource user
+ description: Returns information about a specific user's access to a resource.
+ operationId: getResourceUser
parameters:
- - description: The ID of the tag to apply.
- name: tag_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
+ - description: The ID of the resource.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
in: path
+ name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
- - description: The ID of the group to apply the tag to.
- name: group_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
+ - description: The ID of the user.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
in: path
+ name: user_id
required: true
schema:
format: uuid
type: string
style: simple
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
responses:
"200":
- description: Tag applied to group successfully.
+ content:
+ application/json:
+ schema:
+ type: object
+ properties:
+ data:
+ type: array
+ items:
+ $ref: "#/components/schemas/ResourceUser"
+ cursor:
+ type: string
+ description: Pagination cursor for the next page of results
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ total_count:
+ type: integer
+ description: Total number of results
+ example: 120
+ required:
+ - data
+ description: List of ResourceUser records for the user's access to the resource.
+ "404":
+ description: Resource or user not found.
security:
- BearerAuth: []
tags:
- - tags
- delete:
- description: Removes a tag from a group.
- operationId: remove_group_tag
+ - resources
+ /resource-user-access-status/{resource_id}/{user_id}:
+ get:
+ deprecated: true
+ description: Get user's access status to a resource.
+ operationId: resource_user_access_status_retrieve
parameters:
- - description: The ID of the tag to remove.
- name: tag_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
- in: path
- required: true
- schema:
- format: uuid
- type: string
- style: simple
- - description: The ID of the group to remove the tag from.
+ - description: The ID of the resource.
example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
explode: false
in: path
- name: group_id
+ name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
- responses:
- "200":
- description: Tag removed from group successfully.
- security:
- - BearerAuth: []
- tags:
- - tags
- /tags/{tag_id}/resources/{resource_id}:
- post:
- description: Applies a tag to a resource.
- operationId: add_resource_tag
- parameters:
- - description: The ID of the tag to apply.
- name: tag_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ - description: The ID of the user.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
explode: false
in: path
+ name: user_id
required: true
schema:
format: uuid
type: string
style: simple
- - description: The ID of the resource to apply the tag to.
- name: resource_id
- example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
- explode: false
- in: path
- required: true
+ - description:
+ The remote ID of the access level that you wish to query for the
+ resource. If omitted, the default access level remote ID value
+ (empty string) is used.
+ example: arn:aws:iam::590304332660:role/AdministratorAccess
+ explode: true
+ in: query
+ name: access_level_remote_id
+ required: false
schema:
- format: uuid
type: string
- style: simple
+ style: form
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
responses:
"200":
- description: Tag applied to resource successfully.
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/ResourceUserAccessStatus"
+ description: The access status reflecting the user's access to the resource.
security:
- BearerAuth: []
tags:
- - tags
- delete:
- description: Removes a tag from a resource.
- operationId: remove_resource_tag
+ - resources
+ /resources/{resource_id}/tags:
+ get:
+ description: Returns all tags applied to the resource.
+ operationId: get_resource_tags
parameters:
- - description: The ID of the tag to remove.
- name: tag_id
+ - description: The ID of the resource whose tags to return.
+ name: resource_id
example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
explode: false
in: path
@@ -4716,248 +4715,413 @@ paths:
format: uuid
type: string
style: simple
- - description: The ID of the resource to remove the tag from.
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/TagsList"
+ description: The tags applied to the resource.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ /resources/{resource_id}/scoped-role-permissions:
+ get:
+ description:
+ Returns all the scoped role permissions that apply to the given
+ resource. Only OPAL_SCOPED_ROLE resource type supports this field.
+ operationId: get_resource_scoped_role_permissions
+ parameters:
+ - description: The ID of the resource whose scoped role permissions belong to.
+ name: resource_id
example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
explode: false
in: path
- name: resource_id
required: true
schema:
format: uuid
type: string
style: simple
- responses:
- "200":
- description: Tag removed from resource successfully.
- security:
- - BearerAuth: []
- tags:
- - tags
- /message-channels:
- get:
- summary: Get message channels
- description: Returns a list of `MessageChannel` objects.
- operationId: get_message_channels
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/MessageChannelList"
- description: A list of message channels for your organization.
+ $ref: "#/components/schemas/ScopedRolePermissionList"
+ description: The role permissions that this Opal Scoped Role has.
security:
- BearerAuth: []
tags:
- - message-channels
- post:
- description: Creates a `MessageChannel` objects.
- operationId: create_message_channel
+ - resources
+ put:
+ description: Sets all the scoped role permissions on an OPAL_SCOPED_ROLE resource.
+ operationId: set_resource_scoped_role_permissions
+ parameters:
+ - description:
+ The ID of the resource whose scoped role permissions belong to.
+ Must be of OPAL_SCOPED_ROLE resource type.
+ name: resource_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
requestBody:
- description: The `MessageChannel` object to be created.
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateMessageChannelInfo"
+ $ref: "#/components/schemas/ScopedRolePermissionList"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/MessageChannel"
- description: The message channel that was created.
+ $ref: "#/components/schemas/ScopedRolePermissionList"
+ description: The role permissions that this Opal Scoped Role has.
security:
- BearerAuth: []
tags:
- - message-channels
- /message-channels/{message_channel_id}:
+ - resources
+ /resources/{resource_id}/custom-access-levels:
get:
- summary: Get message channel by ID
- description: Gets a `MessageChannel` object.
- operationId: get_message_channel
+ description: Returns all custom access levels for a resource. If the resource is a parent type (e.g. GitHubOrg), returns aggregated roles across child resources.
+ operationId: get_resource_custom_access_levels
parameters:
- - description: The ID of the message_channel.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the resource.
+ name: resource_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
in: path
- name: message_channel_id
required: true
schema:
format: uuid
type: string
- style: simple
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/MessageChannel"
- description: The requested message channel.
+ $ref: "#/components/schemas/ResourceCustomAccessLevelList"
+ description: The custom access levels for the resource.
+ "400":
+ description: Unsupported resource type.
+ "404":
+ description: Resource not found or access denied.
security:
- BearerAuth: []
tags:
- - message-channels
- /on-call-schedules:
- get:
- summary: Get on call schedules
- description: Returns a list of `OnCallSchedule` objects.
- operationId: get_on_call_schedules
+ - resources
+ post:
+ description: Creates a custom access level on a resource. If the resource is a parent type, the role is created on all child resources.
+ operationId: create_resource_custom_access_level
+ parameters:
+ - description: The ID of the resource.
+ name: resource_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateResourceCustomAccessLevelInfo"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/OnCallScheduleList"
- description: A list of on call schedules for your organization.
+ $ref: "#/components/schemas/ResourceCustomAccessLevelResponse"
+ description: The created custom access level.
+ "400":
+ description: Unsupported resource type.
+ "404":
+ description: Resource not found or access denied.
+ "409":
+ description: A custom access level with this remote ID already exists.
security:
- BearerAuth: []
tags:
- - on-call-schedules
- post:
- description: Creates a `OnCallSchedule` objects.
- operationId: create_on_call_schedule
+ - resources
+ /resources/{resource_id}/custom-access-levels/{access_level_remote_id}:
+ patch:
+ description: Updates a custom access level identified by its remote ID. If the resource is a parent type, the update fans out to all child resources.
+ operationId: update_resource_custom_access_level
+ parameters:
+ - description: The ID of the resource.
+ name: resource_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ - description: The remote ID of the access level.
+ name: access_level_remote_id
+ example: admin
+ in: path
+ required: true
+ schema:
+ type: string
requestBody:
- description: The `OnCallSchedule` object to be created.
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateOnCallScheduleInfo"
+ $ref: "#/components/schemas/UpdateResourceCustomAccessLevelInfo"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/OnCallSchedule"
- description: The on call schedule that was created.
+ $ref: "#/components/schemas/ResourceCustomAccessLevelResponse"
+ description: The updated custom access level.
+ "400":
+ description: Unsupported resource type.
+ "404":
+ description: Resource or access level not found, or access denied.
security:
- BearerAuth: []
tags:
- - on-call-schedules
- /on-call-schedules/{on_call_schedule_id}:
+ - resources
+ delete:
+ description: Deletes a custom access level identified by its remote ID. If the resource is a parent type, the deletion fans out to all child resources.
+ operationId: delete_resource_custom_access_level
+ parameters:
+ - description: The ID of the resource.
+ name: resource_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ - description: The remote ID of the access level.
+ name: access_level_remote_id
+ example: admin
+ in: path
+ required: true
+ schema:
+ type: string
+ responses:
+ "200":
+ description: Successfully deleted.
+ "400":
+ description: Unsupported resource type.
+ "404":
+ description: Resource or access level not found, or access denied.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ /resources/users/{user_id}:
get:
- summary: Get on call schedule by ID
- description: Gets a `OnCallSchedule` object.
- operationId: get_on_call_schedule
+ description: Gets the list of resources for this user.
+ operationId: get_user_resources
parameters:
- - description: The ID of the on_call_schedule.
- example: 9546209c-42c2-4801-96d7-9ec42df0f59c
+ - description: The ID of the user.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
explode: false
in: path
- name: on_call_schedule_id
+ name: user_id
required: true
schema:
format: uuid
type: string
style: simple
+ - description: Limit the number of results returned.
+ example: 200
+ explode: true
+ in: query
+ name: limit
+ required: false
+ schema:
+ type: integer
+ style: form
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Include user's access to unmanaged resources.
+ example: false
+ explode: true
+ in: query
+ name: include_unmanaged
+ required: false
+ schema:
+ type: boolean
+ style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/OnCallSchedule"
- description: The requested on call schedule.
+ $ref: "#/components/schemas/ResourceAccessUserList"
+ description: List of resources user has access to.
security:
- BearerAuth: []
tags:
- - on-call-schedules
- /queries/run:
+ - resources
+ /resources/{resource_id}/groups:
+ get:
+ description: Returns a list of groups that grant access to the resource
+ operationId: get_resource_groups
+ parameters:
+ - description: The ID of the resource that the groups grant access to.
+ name: resource_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/GroupResourceList"
+ description: The groups that grant access to the resource.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ /resources/{resource_id}/access_levels:
+ get:
+ summary: Get resource access levels
+ description:
+ Returns the list of access levels defined for the resource. Resources
+ that only offer default (unnamed) access return an empty list.
+ operationId: get_resource_access_levels
+ parameters:
+ - description: The ID of the resource whose access levels to return.
+ name: resource_id
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/ResourceAccessLevelList"
+ description: The access levels defined for the resource.
+ "404":
+ description: Resource not found.
+ security:
+ - BearerAuth: []
+ tags:
+ - resources
+ /paladin:
post:
- summary: Run an ad-hoc OpalQuery
- description: Runs an ad-hoc OpalQuery and returns the results. Currently
- supports NODE queries (users, resources, groups). This endpoint is only
- available to our OpalQuery beta group. Please contact Opal support if
- you'd like to be added to the beta.
- operationId: runOpalQuery
+ summary: Create Paladin
+ description: Creates a new `Paladin`.
+ operationId: createPaladin
requestBody:
- required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/RunOpalQueryRequest"
+ $ref: "#/components/schemas/CreatePaladinInfo"
+ required: true
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/OpalQueryResults"
- description: The results of the OpalQuery.
+ $ref: "#/components/schemas/Paladin"
+ description: The created Paladin.
security:
- BearerAuth: []
tags:
- - opal-queries
- /tokens:
+ - paladin
+ /paladin/{paladin_id}:
get:
- summary: Get tokens
- description:
- Returns a list of first-party API tokens for your organization.
- Requires admin access.
- operationId: getTokens
+ summary: Get Paladin by ID
+ description: Returns a `Paladin` object.
+ operationId: getPaladin
parameters:
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ - description: The ID of the Paladin.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
explode: true
- in: query
- name: cursor
- required: false
+ in: path
+ name: paladin_id
+ required: true
schema:
+ format: uuid
type: string
- style: form
- - description: Number of results to return per page. Default is 200.
- example: 200
- explode: true
- in: query
- name: page_size
- required: false
- schema:
- type: integer
- maximum: 1000
- style: form
- - description: Filter by token IDs.
- explode: false
- in: query
- name: token_ids
- required: false
- schema:
- items:
- format: uuid
- type: string
- type: array
- style: form
- - description: Filter by user ID.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Paladin"
+ description: The Paladin associated with the passed-in ID.
+ security:
+ - BearerAuth: []
+ tags:
+ - paladin
+ put:
+ summary: Update Paladin
+ description: Updates a `Paladin` object.
+ operationId: updatePaladin
+ parameters:
+ - description: The ID of the Paladin.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
explode: true
- in: query
- name: user_id
- required: false
+ in: path
+ name: paladin_id
+ required: true
schema:
format: uuid
type: string
- style: form
+ style: simple
+ requestBody:
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdatePaladinInfo"
+ required: true
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedTokensList"
- description: A list of API tokens for your organization.
+ $ref: "#/components/schemas/Paladin"
+ description: The updated Paladin.
security:
- BearerAuth: []
tags:
- - tokens
- /tokens/{token_id}:
+ - paladin
delete:
- summary: Delete token
- description: Deletes a first-party API token. Admins can delete any token.
- Non-admins can only delete their own tokens when the organization allows
- all users to create API tokens.
- operationId: deleteToken
+ summary: Delete Paladin
+ description: Deletes a Paladin, removing the underlying service user.
+ operationId: deletePaladin
parameters:
- - description: The ID of the token to delete.
- example: f454d283-ca87-4a8a-bdbb-df212eca5353
- explode: false
+ - description: The ID of the Paladin.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
in: path
- name: token_id
+ name: paladin_id
required: true
schema:
format: uuid
@@ -4965,82 +5129,123 @@ paths:
style: simple
responses:
"200":
- description: The token was successfully deleted.
- "403":
- description: Not authorized to delete this token.
- "404":
- description: Token not found.
+ description: The Paladin was deleted.
security:
- BearerAuth: []
tags:
- - tokens
- /uars:
+ - paladin
+ /paladin/name/{paladin_name}:
get:
- description: Returns a list of `UAR` objects.
- operationId: getUARs
+ summary: Get Paladins by name
+ description:
+ Returns all Paladins whose name exactly matches the given name. Names
+ are not unique, so the result is a list and may be empty.
+ operationId: getPaladinFromName
parameters:
- - description: The pagination cursor value.
- example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ - description: The name of the Paladin.
+ example: paladin-agent-1
explode: true
- in: query
- name: cursor
- required: false
+ in: path
+ name: paladin_name
+ required: true
schema:
type: string
- style: form
- - description: Number of results to return per page. Default is 200.
- example: 200
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/PaladinList"
+ description: The list of Paladins matching the passed-in name.
+ security:
+ - BearerAuth: []
+ tags:
+ - paladin
+ /paladin/{paladin_id}/context-sources:
+ get:
+ summary: List Paladin context sources
+ description:
+ Returns the context sources (Slack channels and documents) configured
+ for a Paladin.
+ operationId: listPaladinContextSources
+ parameters:
+ - description: The ID of the Paladin.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
explode: true
- in: query
- name: page_size
- required: false
+ in: path
+ name: paladin_id
+ required: true
schema:
- type: integer
- maximum: 1000
- style: form
+ format: uuid
+ type: string
+ style: simple
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedUARsList"
- description: A list of UARs for your organization.
+ $ref: "#/components/schemas/PaladinContextSourceList"
+ description: The context sources configured for the Paladin.
security:
- BearerAuth: []
tags:
- - uars
- /uar:
+ - paladin
post:
- description: Starts a User Access Review.
- operationId: create_uar
+ summary: Add a Paladin context source
+ description:
+ Configures a context source (a Slack channel or a document) for a
+ Paladin to read. Idempotent, so re-adding an existing source returns it.
+ operationId: createPaladinContextSource
+ parameters:
+ - description: The ID of the Paladin.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
+ in: path
+ name: paladin_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
requestBody:
- description: The settings of the UAR.
- required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateUARInfo"
+ $ref: "#/components/schemas/CreatePaladinContextSourceInfo"
+ required: true
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/UAR"
- description: The UAR that was started.
+ $ref: "#/components/schemas/PaladinContextSource"
+ description: The configured context source.
security:
- BearerAuth: []
tags:
- - uars
- /uar/{uar_id}:
- get:
- description: Retrieves a specific UAR.
- operationId: get_uar
+ - paladin
+ /paladin/{paladin_id}/context-sources/{context_source_id}:
+ delete:
+ summary: Remove a Paladin context source
+ description: Removes a context source from a Paladin.
+ operationId: deletePaladinContextSource
parameters:
- - description: The ID of the UAR.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the Paladin.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
in: path
- name: uar_id
+ name: paladin_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the context source.
+ example: 8a1f2c3d-4b5e-6f70-8192-a3b4c5d6e7f8
+ explode: true
+ in: path
+ name: context_source_id
required: true
schema:
format: uuid
@@ -5048,50 +5253,33 @@ paths:
style: simple
responses:
"200":
- content:
- application/json:
- schema:
- $ref: "#/components/schemas/UAR"
- description: The UAR that was requested.
+ description: The context source was removed.
security:
- BearerAuth: []
tags:
- - uars
- /sync_errors:
+ - paladin
+ /sessions:
get:
- description:
- Returns a list of recent sync errors that have occurred since the
- last successful sync.
- operationId: getSyncErrors
+ description: Returns a list of `Session` objects.
+ operationId: sessions
parameters:
- - description: The ID of the app to list sync errors for.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
- explode: false
+ - description: The ID of the resource.
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: true
in: query
- name: app_id
- required: false
+ name: resource_id
+ required: true
schema:
format: uuid
type: string
style: form
- - description: The ID of the resource to list sync errors for.
- example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
- explode: false
+ - description: The ID of the user you wish to query sessions for.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
in: query
- name: resource_id
+ name: user_id
required: false
schema:
- format: uuid
- type: string
- style: form
- - description: The ID of the group to list sync errors for.
- example: 9546209c-42c2-4801-96d7-9ec42df0f59c
- explode: false
- in: query
- name: group_id
- required: false
- schema:
- format: uuid
type: string
style: form
responses:
@@ -5099,47 +5287,56 @@ paths:
content:
application/json:
schema:
- items:
- $ref: "#/components/schemas/SyncErrorList"
- type: array
- description: A list of sync errors.
+ $ref: "#/components/schemas/SessionsList"
+ description: The sessions associated with a resource.
security:
- BearerAuth: []
tags:
- - apps
- /delegations:
+ - sessions
+ /user:
get:
- summary: Get delegations
- description:
- Returns a list of request reviewer delegations configured for your
- organization.
- operationId: getDelegations
+ description: Returns a `User` object.
+ operationId: user
parameters:
- - description:
- The delegator user ID to filter delegations by the user delegating
- their access review requests.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ - description: The user ID of the user.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
explode: true
in: query
- name: delegator_user_id
+ name: user_id
required: false
schema:
format: uuid
type: string
style: form
- description:
- The delegate user ID to filter delegations by the user being
- delegated to.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ The email of the user. If both user ID and email are provided, user
+ ID will take precedence. If neither are provided, an error will
+ occur.
+ example: johndoe@domain.org
explode: true
in: query
- name: delegate_user_id
+ name: email
required: false
schema:
- format: uuid
type: string
style: form
- - description: A cursor to indicate where to start fetching results.
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/User"
+ description: The user object associated with the passed-in email or ID.
+ security:
+ - BearerAuth: []
+ tags:
+ - users
+ /users:
+ get:
+ description: Returns a list of users for your organization.
+ operationId: getUsers
+ parameters:
+ - description: The pagination cursor value.
example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
explode: true
in: query
@@ -5148,7 +5345,7 @@ paths:
schema:
type: string
style: form
- - description: The maximum number of results to return per page. The default is 200.
+ - description: Number of results to return per page. Default is 200.
example: 200
explode: true
in: query
@@ -5158,539 +5355,2717 @@ paths:
type: integer
maximum: 1000
style: form
+ - description:
+ The IDs of the tags to filter by. Returns only users that have any
+ of these tags applied.
+ in: query
+ name: tag_ids
+ required: false
+ schema:
+ type: array
+ items:
+ format: uuid
+ type: string
+ style: form
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/PaginatedDelegationsList"
- description: A list of delegations for your organization.
+ $ref: "#/components/schemas/PaginatedUsersList"
+ description: One page worth users in your organization.
security:
- BearerAuth: []
tags:
- - delegations
+ - users
post:
- description:
- Creates a new request reviewer delegation to delegate access review
- requests from one user to another.
- operationId: createDelegation
+ description: Invites a user to your organization.
+ operationId: inviteUser
requestBody:
required: true
content:
application/json:
schema:
- $ref: "#/components/schemas/CreateDelegationRequest"
+ $ref: "#/components/schemas/InviteUserInfo"
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/Delegation"
- description: Delegation created successfully.
+ $ref: "#/components/schemas/User"
+ description: The invited user.
+ "400":
+ description: The invite input is invalid.
+ "403":
+ description: The caller is not authorized to invite users.
+ "409":
+ description: The user already belongs to another organization.
security:
- BearerAuth: []
tags:
- - delegations
- /delegations/{delegation_id}:
- get:
- summary: Get delegation by ID
- description: Returns a specific delegation by its ID.
- operationId: getDelegation
+ - users
+ /users/{user_id}:
+ delete:
+ description: Deletes a user from your organization.
+ operationId: deleteUser
parameters:
- - description: The ID of the delegation to retrieve.
- example: 32acc112-21ff-4669-91c2-21e27683eaa1
- explode: true
+ - description: The ID of the user to delete.
in: path
- name: delegation_id
+ name: user_id
required: true
schema:
format: uuid
type: string
- style: simple
responses:
"200":
content:
application/json:
schema:
- $ref: "#/components/schemas/Delegation"
- description: The requested delegation.
+ $ref: "#/components/schemas/User"
+ description: The deleted user.
+ "403":
+ description: The caller is not authorized to delete the user.
+ "404":
+ description: The user was not found.
+ "409":
+ description: The user cannot be deleted in its current state.
security:
- BearerAuth: []
tags:
- - delegations
- delete:
- description: Deletes a delegation by its ID.
- operationId: deleteDelegation
+ - users
+ patch:
+ description: Updates a user's position or manager.
+ operationId: updateUser
parameters:
- - description: The ID of the delegation to remove.
- example: 32acc112-21ff-4669-91c2-21e27683eaa1
- explode: true
+ - description: The ID of the user to update.
in: path
- name: delegation_id
+ name: user_id
required: true
schema:
format: uuid
type: string
- style: simple
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdateUserInfo"
responses:
"200":
- description: Delegation removed successfully
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/User"
+ description: The updated user.
+ "400":
+ description: The update input is invalid.
+ "403":
+ description: The caller is not authorized to update the user.
+ "404":
+ description: The user was not found.
+ "409":
+ description: The user is managed by an identity provider or is immutable.
security:
- BearerAuth: []
tags:
- - delegations
-
-components:
- schemas:
- AccessEntityFilters:
- type: object
- description:
- Filters for matching entities by type, name, tag, IDs, connections,
- or access levels. Supports recursive logical composition via
- allOf/anyOf.
- properties:
- entityTypes:
- type: array
- description: Filter by entity type. Only RESOURCE, GROUP, and USER are
- queryable via OpalQuery.
- items:
- type: string
- enum: [RESOURCE, GROUP, USER]
- entityItemTypes:
- type: array
- description: Filter by entity item types.
- items:
- $ref: "#/components/schemas/EntityItemTypeEnum"
- entityName:
- $ref: "#/components/schemas/EntityNameFilter"
- entityTag:
- $ref: "#/components/schemas/EntityTagFilter"
- entityIDs:
- type: array
- description: Filter by specific entity UUIDs.
- items:
+ - users
+ /users/remote_users:
+ get:
+ description: Returns a list of remote users for your organization.
+ operationId: getRemoteUsers
+ parameters:
+ - description: Filter remote users by their third party provider.
+ example: [GIT_HUB]
+ in: query
+ name: third_party_provider
+ required: false
+ schema:
+ type: array
+ items:
+ $ref: "#/components/schemas/ThirdPartyProviderEnum"
+ style: form
+ - description: Filter remote users by their user ID.
+ example: [32acc112-21ff-4669-91c2-21e27683eaa1]
+ in: query
+ name: user_id
+ required: false
+ schema:
+ type: array
+ items:
+ type: string
+ format: uuid
+ style: form
+ - description: Filter remote users by their remote ID.
+ example: [1234567890]
+ in: query
+ name: remote_id
+ required: false
+ schema:
+ type: array
+ items:
+ type: string
+ style: form
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
type: string
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/PaginatedRemoteUsersList"
+ description: One page worth users in your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - users
+ /users/whoami:
+ get:
+ description:
+ Returns the user that the provided API token authenticates as.
+ operationId: getUserWhoami
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/User"
+ description: The user that the API token authenticates as.
+ security:
+ - BearerAuth: []
+ tags:
+ - users
+ /users/{user_id}/tags:
+ get:
+ description: Returns all tags applied to the user.
+ operationId: get_user_tags
+ parameters:
+ - description: The ID of the user whose tags to return.
+ name: user_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
format: uuid
- importedFromApp:
- type: array
- description: Filter by app IDs from which returned nodes will be imported from.
- items:
type: string
- format: uuid
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/TagsList"
+ description: The tags applied to the user.
+ security:
+ - BearerAuth: []
+ tags:
+ - users
+ /access-rules:
+ get:
+ description: Returns a list of access rules for your organization.
+ operationId: get_access_rules
+ parameters:
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/PaginatedAccessRulesList"
+ description: One page of access rules for your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - access-rules
+ post:
+ description: Creates a new access rule config for the given group_id.
+ operationId: create_access_rule
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdateAccessRuleInfo"
+ responses:
+ "201":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/AccessRule"
+ description: The created access rule config for the group.
+ security:
+ - BearerAuth: []
+ tags:
+ - access-rules
+ /access-rules/{access_rule_id}:
+ get:
+ description:
+ Returns a list of access rule config given the group_id of the
+ access rule.
+ operationId: get_access_rule
+ parameters:
+ - description: The access rule ID (group ID) of the access rule.
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ name: access_rule_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/AccessRule"
+ description: The access rules for the group.
+ security:
+ - BearerAuth: []
+ tags:
+ - access-rules
+ put:
+ description: Updates the access rule config for the given group_id.
+ operationId: update_access_rule
+ parameters:
+ - description: The access rule ID (group ID) of the access rule.
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ name: access_rule_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UpdateAccessRuleInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/AccessRule"
+ description: The updated access rule config for the group.
+ security:
+ - BearerAuth: []
+ tags:
+ - access-rules
+ /tag/{tag_id}:
+ get:
+ summary: Get tag by ID
+ description: UNSTABLE. May be removed at any time. Gets a tag with the given id.
+ operationId: get_tag_by_ID
+ parameters:
+ - description: The tag ID
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ name: tag_id
+ required: true
+ schema:
+ type: string
+ format: uuid
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Tag"
+ description: The tag requested.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ delete:
+ description: UNSTABLE. May be removed at any time. Deletes a tag with the given id.
+ operationId: delete_tag_by_ID
+ parameters:
+ - description: The tag ID
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ name: tag_id
+ required: true
+ schema:
+ type: string
+ format: uuid
+ style: simple
+ responses:
+ "200":
+ description: Tag was deleted.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ /tag:
+ get:
+ description: Gets a tag with the given key and value.
+ operationId: get_tag
+ parameters:
+ - description: The key of the tag to get.
+ example: api-scope
+ explode: false
+ in: query
+ name: tag_key
+ required: true
+ schema:
+ type: string
+ style: form
+ - description: The value of the tag to get.
+ example: production
+ explode: false
+ in: query
+ name: tag_value
+ required: false
+ schema:
+ type: string
+ style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Tag"
+ description: The tag requested.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ post:
+ description: Creates a tag with the given key and value.
+ operationId: create_tag
+ parameters:
+ - description: The key of the tag to create.
+ example: api-scope
+ explode: false
+ in: query
+ name: tag_key
+ required: false
+ schema:
+ type: string
+ style: form
+ deprecated: true
+ - description: The value of the tag to create.
+ example: production
+ explode: false
+ in: query
+ name: tag_value
+ required: false
+ schema:
+ type: string
+ style: form
+ deprecated: true
+ - description: The ID of the owner that manages the tag.
+ example: f92aa855-cea9-4814-b9d8-f2a60d3e4a06
+ explode: false
+ in: query
+ name: admin_owner_id
+ schema:
+ format: uuid
+ type: string
+ style: form
+ deprecated: true
+ requestBody:
+ required: false
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateTagInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Tag"
+ description: The tag that was created.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ /tags:
+ get:
+ summary: Get tags
+ description: Returns a list of tags created by your organization.
+ operationId: getTags
+ parameters:
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/PaginatedTagsList"
+ description: A list of tags created by your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ /tags/{tag_id}/users/{user_id}:
+ post:
+ description: Applies a tag to a user.
+ operationId: add_user_tag
+ parameters:
+ - description: The ID of the tag to apply.
+ name: tag_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the user to apply the tag to.
+ name: user_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ requestBody:
+ required: false
+ content:
+ application/json:
+ schema:
+ type: object
+ responses:
+ "200":
+ description: Tag applied to user successfully.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ delete:
+ description: Removes a tag from a user.
+ operationId: remove_user_tag
+ parameters:
+ - description: The ID of the tag to remove.
+ name: tag_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the user to remove the tag from.
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ name: user_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: Tag removed from user successfully.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ /tags/{tag_id}/groups/{group_id}:
+ post:
+ description: Applies a tag to a group.
+ operationId: add_group_tag
+ parameters:
+ - description: The ID of the tag to apply.
+ name: tag_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the group to apply the tag to.
+ name: group_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: Tag applied to group successfully.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ delete:
+ description: Removes a tag from a group.
+ operationId: remove_group_tag
+ parameters:
+ - description: The ID of the tag to remove.
+ name: tag_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the group to remove the tag from.
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ name: group_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: Tag removed from group successfully.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ /tags/{tag_id}/resources/{resource_id}:
+ post:
+ description: Applies a tag to a resource.
+ operationId: add_resource_tag
+ parameters:
+ - description: The ID of the tag to apply.
+ name: tag_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the resource to apply the tag to.
+ name: resource_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: Tag applied to resource successfully.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ delete:
+ description: Removes a tag from a resource.
+ operationId: remove_resource_tag
+ parameters:
+ - description: The ID of the tag to remove.
+ name: tag_id
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ - description: The ID of the resource to remove the tag from.
+ example: 1b978423-db0a-4037-a4cf-f79c60cb67b3
+ explode: false
+ in: path
+ name: resource_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: Tag removed from resource successfully.
+ security:
+ - BearerAuth: []
+ tags:
+ - tags
+ /message-channels:
+ get:
+ summary: Get message channels
+ description: Returns a list of `MessageChannel` objects.
+ operationId: get_message_channels
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/MessageChannelList"
+ description: A list of message channels for your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - message-channels
+ post:
+ description: Creates a `MessageChannel` objects.
+ operationId: create_message_channel
+ requestBody:
+ description: The `MessageChannel` object to be created.
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateMessageChannelInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/MessageChannel"
+ description: The message channel that was created.
+ security:
+ - BearerAuth: []
+ tags:
+ - message-channels
+ /message-channels/{message_channel_id}:
+ get:
+ summary: Get message channel by ID
+ description: Gets a `MessageChannel` object.
+ operationId: get_message_channel
+ parameters:
+ - description: The ID of the message_channel.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: message_channel_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/MessageChannel"
+ description: The requested message channel.
+ security:
+ - BearerAuth: []
+ tags:
+ - message-channels
+ /on-call-schedules:
+ get:
+ summary: Get on call schedules
+ description: Returns a list of `OnCallSchedule` objects.
+ operationId: get_on_call_schedules
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/OnCallScheduleList"
+ description: A list of on call schedules for your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - on-call-schedules
+ post:
+ description: Creates a `OnCallSchedule` objects.
+ operationId: create_on_call_schedule
+ requestBody:
+ description: The `OnCallSchedule` object to be created.
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateOnCallScheduleInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/OnCallSchedule"
+ description: The on call schedule that was created.
+ security:
+ - BearerAuth: []
+ tags:
+ - on-call-schedules
+ /on-call-schedules/{on_call_schedule_id}:
+ get:
+ summary: Get on call schedule by ID
+ description: Gets a `OnCallSchedule` object.
+ operationId: get_on_call_schedule
+ parameters:
+ - description: The ID of the on_call_schedule.
+ example: 9546209c-42c2-4801-96d7-9ec42df0f59c
+ explode: false
+ in: path
+ name: on_call_schedule_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/OnCallSchedule"
+ description: The requested on call schedule.
+ security:
+ - BearerAuth: []
+ tags:
+ - on-call-schedules
+ /queries/run:
+ post:
+ summary: Run an ad-hoc OpalQuery
+ description: >
+ Executes an ad-hoc OpalQuery and returns paginated results. Two query
+ types are supported: a **Node** query filters and returns entities
+ (users, resources, or groups); an **Access Path** query returns the
+ access edges between principals and their entitlements. Set `type` to
+ `NODE` or `ACCESS_PATH` in the request body to select the query type.
+
+
+ This endpoint is available to OpalQuery beta participants. To request
+ access, contact Opal support.
+ operationId: runOpalQuery
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/RunOpalQueryRequest"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/OpalQueryResults"
+ description: The results of the OpalQuery.
+ security:
+ - BearerAuth: []
+ tags:
+ - opal-queries
+ /tokens:
+ get:
+ summary: Get tokens
+ description:
+ Returns a list of first-party API tokens for your organization.
+ Requires admin access.
+ operationId: getTokens
+ parameters:
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
+ - description: Filter by token IDs.
+ explode: false
+ in: query
+ name: token_ids
+ required: false
+ schema:
+ items:
+ format: uuid
+ type: string
+ type: array
+ style: form
+ - description: Filter by user ID.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ explode: true
+ in: query
+ name: user_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/PaginatedTokensList"
+ description: A list of API tokens for your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - tokens
+ /tokens/{token_id}:
+ delete:
+ summary: Delete token
+ description: Deletes a first-party API token. Admins can delete any token.
+ Non-admins can only delete their own tokens when the organization allows
+ all users to create API tokens.
+ operationId: deleteToken
+ parameters:
+ - description: The ID of the token to delete.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
+ explode: false
+ in: path
+ name: token_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: The token was successfully deleted.
+ "403":
+ description: Not authorized to delete this token.
+ "404":
+ description: Token not found.
+ security:
+ - BearerAuth: []
+ tags:
+ - tokens
+ /uars:
+ get:
+ deprecated: true
+ description:
+ Returns a list of `UAR` objects. Deprecated in favor of `GET /campaigns`.
+ operationId: getUARs
+ parameters:
+ - description: The pagination cursor value.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: Number of results to return per page. Default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/PaginatedUARsList"
+ description: A list of UARs for your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - uars
+ /uar:
+ post:
+ deprecated: true
+ description:
+ Starts a User Access Review. Deprecated in favor of `POST /campaigns`.
+ operationId: create_uar
+ requestBody:
+ description: The settings of the UAR.
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateUARInfo"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UAR"
+ description: The UAR that was started.
+ security:
+ - BearerAuth: []
+ tags:
+ - uars
+ /uar/{uar_id}:
+ get:
+ deprecated: true
+ description:
+ Retrieves a specific UAR. Deprecated in favor of
+ `GET /campaigns/{campaign_id}`.
+ operationId: get_uar
+ parameters:
+ - description: The ID of the UAR.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: path
+ name: uar_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/UAR"
+ description: The UAR that was requested.
+ security:
+ - BearerAuth: []
+ tags:
+ - uars
+ /sync_errors:
+ get:
+ description:
+ Returns a list of recent sync errors that have occurred since the
+ last successful sync.
+ operationId: getSyncErrors
+ parameters:
+ - description: The ID of the app to list sync errors for.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ explode: false
+ in: query
+ name: app_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ - description: The ID of the resource to list sync errors for.
+ example: 4baf8423-db0a-4037-a4cf-f79c60cb67a5
+ explode: false
+ in: query
+ name: resource_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ - description: The ID of the group to list sync errors for.
+ example: 9546209c-42c2-4801-96d7-9ec42df0f59c
+ explode: false
+ in: query
+ name: group_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ items:
+ $ref: "#/components/schemas/SyncErrorList"
+ type: array
+ description: A list of sync errors.
+ security:
+ - BearerAuth: []
+ tags:
+ - apps
+ /delegations:
+ get:
+ summary: Get delegations
+ description:
+ Returns a list of request reviewer delegations configured for your
+ organization.
+ operationId: getDelegations
+ parameters:
+ - description:
+ The delegator user ID to filter delegations by the user delegating
+ their access review requests.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ explode: true
+ in: query
+ name: delegator_user_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ - description:
+ The delegate user ID to filter delegations by the user being
+ delegated to.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+ explode: true
+ in: query
+ name: delegate_user_id
+ required: false
+ schema:
+ format: uuid
+ type: string
+ style: form
+ - description: A cursor to indicate where to start fetching results.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ explode: true
+ in: query
+ name: cursor
+ required: false
+ schema:
+ type: string
+ style: form
+ - description: The maximum number of results to return per page. The default is 200.
+ example: 200
+ explode: true
+ in: query
+ name: page_size
+ required: false
+ schema:
+ type: integer
+ maximum: 1000
+ style: form
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/PaginatedDelegationsList"
+ description: A list of delegations for your organization.
+ security:
+ - BearerAuth: []
+ tags:
+ - delegations
+ post:
+ description:
+ Creates a new request reviewer delegation to delegate access review
+ requests from one user to another.
+ operationId: createDelegation
+ requestBody:
+ required: true
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/CreateDelegationRequest"
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Delegation"
+ description: Delegation created successfully.
+ security:
+ - BearerAuth: []
+ tags:
+ - delegations
+ /delegations/{delegation_id}:
+ get:
+ summary: Get delegation by ID
+ description: Returns a specific delegation by its ID.
+ operationId: getDelegation
+ parameters:
+ - description: The ID of the delegation to retrieve.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
+ in: path
+ name: delegation_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ content:
+ application/json:
+ schema:
+ $ref: "#/components/schemas/Delegation"
+ description: The requested delegation.
+ security:
+ - BearerAuth: []
+ tags:
+ - delegations
+ delete:
+ description: Deletes a delegation by its ID.
+ operationId: deleteDelegation
+ parameters:
+ - description: The ID of the delegation to remove.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ explode: true
+ in: path
+ name: delegation_id
+ required: true
+ schema:
+ format: uuid
+ type: string
+ style: simple
+ responses:
+ "200":
+ description: Delegation removed successfully
+ security:
+ - BearerAuth: []
+ tags:
+ - delegations
+
+components:
+ schemas:
+ AccessEntityFilters:
+ type: object
+ description:
+ Filters for matching entities by type, name, tag, IDs, connections,
+ or access levels. Supports recursive logical composition via
+ allOf/anyOf.
+ properties:
+ entityTypes:
+ type: array
+ description: Filter by entity type. Only RESOURCE, GROUP, and USER are
+ queryable via OpalQuery.
+ items:
+ type: string
+ enum: [RESOURCE, GROUP, USER]
+ entityItemTypes:
+ type: array
+ description: Filter by entity item types.
+ items:
+ $ref: "#/components/schemas/EntityItemTypeEnum"
+ entityName:
+ $ref: "#/components/schemas/EntityNameFilter"
+ entityTag:
+ $ref: "#/components/schemas/EntityTagFilter"
+ hrIdpStatus:
+ $ref: "#/components/schemas/IdpStatusFilter"
+ entityAdminOwner:
+ $ref: "#/components/schemas/EntityAdminFilter"
+ entityIDs:
+ type: array
+ description: Filter by specific entity UUIDs.
+ items:
+ type: string
+ format: uuid
+ importedFromApp:
+ type: array
+ description: Filter by app IDs from which returned nodes will be imported from.
+ items:
+ type: string
+ format: uuid
roleRemoteIds:
type: array
- description: Filter by role remote IDs. Can only be applied within a hasAccessTo clause.
+ description: Filter by role remote IDs. Can only be applied within a hasAccessTo clause.
+ items:
+ type: string
+ roleNames:
+ type: array
+ description: Filter by role display names (e.g. "Admin", "Read"). Can only be applied within a hasAccessTo clause.
+ items:
+ type: string
+ allOf:
+ type: array
+ description: >
+ A list of nested filters that must all match (logical AND). Each
+ item has the same shape as this object — scalar fields like
+ `entityTypes` or `entityTag`, and can further nest `allOf`,
+ `anyOf`, or `not`.
+ items:
+ $ref: "#/components/schemas/AccessEntityFilters"
+ anyOf:
+ type: array
+ description: >
+ A list of nested filters where at least one must match (logical
+ OR). Each item has the same shape as this object.
+ items:
+ $ref: "#/components/schemas/AccessEntityFilters"
+ not:
+ description: >
+ Excludes entities matching the embedded filter (logical NOT). Pass
+ a filter object with the same shape as this one — typically a
+ single scalar field, like `{not: {entityTypes: ["RESOURCE"]}}` to
+ exclude resources.
+ type: object
+ x-go-type: AccessEntityFilters
+
+ RunOpalQueryRequest:
+ description: >
+ Request body for an ad-hoc OpalQuery. Set `type` to `NODE` to query
+ entities, or `ACCESS_PATH` to query access edges. The fields available
+ in `query` differ by type — refer to each tab for the full schema.
+ oneOf:
+ - $ref: "#/components/schemas/OpalNodeQuery"
+ - $ref: "#/components/schemas/OpalAccessPathQuery"
+ discriminator:
+ propertyName: type
+ mapping:
+ NODE: "#/components/schemas/OpalNodeQuery"
+ ACCESS_PATH: "#/components/schemas/OpalAccessPathQuery"
+ # example:
+ # type: NODE
+ # query:
+ # nodeFilters:
+ # entityTypes: [RESOURCE]
+ # allOf:
+ # - entityTag:
+ # key: env
+ # value: prod
+ # - entityTag:
+ # key: team
+ # value: platform
+ # not:
+ # entityItemTypes: [AWS_IAM_ROLE]
+ # accessFilters:
+ # isAccessibleBy:
+ # entityTypes: [USER]
+ # entityTag:
+ # key: contractor
+ # first: 50
+
+ OpalNodeQuery:
+ title: Node
+ type: object
+ required:
+ - type
+ description: >
+ Use a Node query to retrieve entities — users, resources, or groups —
+ that match a set of filters. You can filter by entity type, tags, and
+ access relationships. Results are paginated and returned as a list of
+ entity edges.
+ example:
+ type: NODE
+ query:
+ nodeFilters:
+ entityTypes: [RESOURCE]
+ entityTag:
+ key: env
+ value: prod
+ accessFilters:
+ isAccessibleBy:
+ entityTypes: [USER]
+ entityTag:
+ key: contractor
+ first: 50
+ properties:
+ type:
+ type: string
+ enum:
+ - NODE
+ query:
+ $ref: "#/components/schemas/OpalNodeQueryBody"
+ first:
+ type: integer
+ description: Maximum number of results to return. Defaults to 200.
+ example: 200
+ after:
+ type: string
+ description: Cursor from a previous response to fetch the next page of results.
+ example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
+
+ OpalNodeQueryBody:
+ type: object
+ description: The filter body for a NODE-type OpalQuery.
+ properties:
+ nodeFilters:
+ $ref: "#/components/schemas/AccessEntityFilters"
+ accessFilters:
+ $ref: "#/components/schemas/AccessRelationshipFilters"
+
+ OpalQueryResultNode:
+ type: object
+ required:
+ - id
+ - name
+ - entityType
+ - entityItemType
+ description: A matched entity from an OpalQuery result.
+ properties:
+ id:
+ type: string
+ format: uuid
+ description: The entity's unique identifier.
+ name:
+ type: string
+ description: The display name of the entity.
+ entityType:
+ type: string
+ enum:
+ - USER
+ - GROUP
+ - RESOURCE
+ description: The top-level entity type.
+ entityItemType:
+ $ref: "#/components/schemas/EntityItemTypeEnum"
+
+ OpalQueryResultEdge:
+ type: object
+ required:
+ - node
+ - cursor
+ description:
+ A single result edge from an OpalQuery, containing the matched
+ entity and its pagination cursor.
+ properties:
+ node:
+ $ref: "#/components/schemas/OpalQueryResultNode"
+ cursor:
+ type: string
+ description: Opaque cursor for this entity, used for pagination.
+
+ OpalQueryResults:
+ description:
+ Paginated results of an OpalQuery. The `type` field discriminates
+ which result schema applies and mirrors the `type` field on the request.
+ oneOf:
+ - $ref: "#/components/schemas/OpalNodeQueryResults"
+ - $ref: "#/components/schemas/OpalAccessPathQueryResults"
+ discriminator:
+ propertyName: type
+ mapping:
+ NODE: "#/components/schemas/OpalNodeQueryResults"
+ ACCESS_PATH: "#/components/schemas/OpalAccessPathQueryResults"
+
+ OpalNodeQueryResults:
+ type: object
+ required:
+ - type
+ - edges
+ - pageInfo
+ description:
+ Paginated results of a NODE-type OpalQuery — one edge per matched
+ entity (user, resource, or group).
+ properties:
+ type:
+ type: string
+ enum:
+ - NODE
+ edges:
+ type: array
+ description: List of matched entities.
+ items:
+ $ref: "#/components/schemas/OpalQueryResultEdge"
+ pageInfo:
+ $ref: "#/components/schemas/PageInfo"
+
+ OpalAccessPathQuery:
+ title: Access Path
+ type: object
+ required:
+ - type
+ description: >
+ Use an Access Path query to retrieve the access edges between principals
+ (users or groups) and their entitlements (resources or groups). You can
+ filter by principal type, entitlement type, access level, and edge
+ characteristics such as depth or expiration. Results are paginated and
+ returned as a list of access path edges.
+ example:
+ type: ACCESS_PATH
+ query:
+ principalFilter:
+ entityTypes: [USER]
+ entitlementFilter:
+ entityItemTypes: [AWS_IAM_ROLE]
+ edgeFilter:
+ directOnly: true
+ first: 50
+ properties:
+ type:
+ type: string
+ enum:
+ - ACCESS_PATH
+ query:
+ $ref: "#/components/schemas/OpalAccessPathQueryBody"
+ first:
+ type: integer
+ description: Maximum number of results to return. Defaults to 200.
+ example: 200
+ after:
+ type: string
+ description:
+ Opaque cursor from a previous ACCESS_PATH response to fetch the
+ next page of results.
+ includeCount:
+ type: boolean
+ description:
+ When true, populate totalCount in the response. Defaults to false.
+ example: false
+
+ OpalAccessPathQueryBody:
+ type: object
+ description:
+ Edge-query filters for an ACCESS_PATH OpalQuery. At least one of
+ principalFilter or entitlementFilter is required.
+ properties:
+ principalFilter:
+ $ref: "#/components/schemas/AccessEntityFilters"
+ entitlementFilter:
+ $ref: "#/components/schemas/AccessEntityFilters"
+ principalAccessFilters:
+ description: >
+ Advanced access filter on the principal side of each path. Restricts
+ results to principals that additionally satisfy these access-edge
+ constraints: `hasAccessTo` keeps only principals that also have
+ access to a matching entity; `isAccessibleBy` keeps only principals
+ that are also accessible by a matching entity. Only takes effect when
+ `principalFilter` is also supplied (it refines that filter); on its
+ own it has no effect.
+ $ref: "#/components/schemas/AccessRelationshipFilters"
+ entitlementAccessFilters:
+ description: >
+ Advanced access filter on the entitlement side of each path.
+ Restricts results to entitlements that additionally satisfy these
+ access-edge constraints: `hasAccessTo` keeps only entitlements that
+ also have access to a matching entity; `isAccessibleBy` keeps only
+ entitlements that are also accessible by a matching entity. Only
+ takes effect when `entitlementFilter` is also supplied (it refines
+ that filter); on its own it has no effect.
+ $ref: "#/components/schemas/AccessRelationshipFilters"
+ accessLevelRemoteIds:
+ type: array
+ description: Filter by access-level remote IDs on the terminal edge.
+ items:
+ type: string
+ accessLevelNames:
+ type: array
+ description: Filter by access-level display names on the terminal edge.
+ items:
+ type: string
+ edgeFilter:
+ $ref: "#/components/schemas/OpalAccessPathEdgeFilter"
+
+ OpalAccessPathEdgeFilter:
+ type: object
+ description: Constraints on the access path edges themselves.
+ properties:
+ directOnly:
+ type: boolean
+ description:
+ When true, only return direct (depth-1) principal-to-entitlement
+ edges.
+ example: true
+ accessDurationType:
+ type: string
+ description: Constrain results by whether the terminal access expires.
+ enum:
+ - EXPIRING_ONLY
+ - PERMANENT_ONLY
+ example: EXPIRING_ONLY
+
+ OpalAccessPathResultNode:
+ type: object
+ required:
+ - principalId
+ - entitlementId
+ - depth
+ - path
+ description: A matched access path from an ACCESS_PATH OpalQuery.
+ properties:
+ principalId:
+ type: string
+ format: uuid
+ description: The principal entity ID.
+ entitlementId:
+ type: string
+ format: uuid
+ description: The entitlement entity ID.
+ accessLevelRemoteId:
+ type: string
+ nullable: true
+ description: Remote ID of the terminal access level.
+ accessLevelName:
+ type: string
+ nullable: true
+ description: Display name of the terminal access level.
+ expiration:
+ type: string
+ format: date-time
+ nullable: true
+ description: Expiration of the terminal access, if any.
+ depth:
+ type: integer
+ description: Number of hops from principal to entitlement (path length - 1).
+ path:
+ type: array
+ description: Entity IDs along the path from principal to entitlement.
+ items:
+ type: string
+ format: uuid
+
+ OpalAccessPathResultEdge:
+ type: object
+ required:
+ - node
+ - cursor
+ description:
+ A single ACCESS_PATH result edge containing the matched path and its
+ pagination cursor.
+ properties:
+ node:
+ $ref: "#/components/schemas/OpalAccessPathResultNode"
+ cursor:
+ type: string
+ description: Opaque cursor for this path, used for pagination.
+
+ OpalAccessPathQueryResults:
+ type: object
+ required:
+ - type
+ - edges
+ - pageInfo
+ description:
+ Paginated results of an ACCESS_PATH-type OpalQuery — one edge per
+ matched principal-to-entitlement access path.
+ properties:
+ type:
+ type: string
+ enum:
+ - ACCESS_PATH
+ edges:
+ type: array
+ description: List of matched access paths.
+ items:
+ $ref: "#/components/schemas/OpalAccessPathResultEdge"
+ pageInfo:
+ $ref: "#/components/schemas/PageInfo"
+ totalCount:
+ type: integer
+ nullable: true
+ description:
+ Exact total number of matching paths when includeCount was true on
+ the request; otherwise null.
+
+ AccessRelationshipFilters:
+ type: object
+ description: >
+ Filters the returned nodes by the access edges connected to them.
+ When `isAccessibleBy` and `hasAccessTo` are provided, the returned nodes
+ must satisfy both edge constraints simultaneously.
+ properties:
+ isAccessibleBy:
+ description:
+ Inbound-edge filter. The returned node must be accessible by at
+ least one entity matching this filter.
+ $ref: "#/components/schemas/AccessEntityFilters"
+ hasAccessTo:
+ description:
+ Outbound-edge filter. The returned node must have access to at
+ least one entity matching this filter.
+ $ref: "#/components/schemas/AccessEntityFilters"
+
+ EntityNameFilter:
+ type: object
+ required:
+ - stringMatchType
+ - string
+ description: Filters entities by name using a string match strategy.
+ properties:
+ stringMatchType:
+ $ref: "#/components/schemas/StringMatchType"
+ string:
+ type: string
+ description: The string value to match against the entity name.
+ example: engineering
+
+ EntityTagFilter:
+ type: object
+ required:
+ - key
+ description:
+ Filters entities by a tag key/value pair, optionally scoped to a
+ connection.
+ properties:
+ key:
+ type: string
+ description: The tag key to filter by.
+ example: team
+ value:
+ type: string
+ description:
+ The tag value to filter by. If omitted, matches any value for the
+ given key.
+ example: platform
+ connectionId:
+ type: string
+ format: uuid
+ description: If specified, filters by tags associated with this connection.
+
+ IdpStatusFilter:
+ type: object
+ description: >
+ Filters USER entities by their HR/IDP lifecycle status. Only applies to
+ USER entities; GROUP and RESOURCE entities never match, in either
+ polarity. `statuses` combine with OR. `not` inverts the match within the
+ user domain (e.g. "IDP status is NOT active"), so it still returns only
+ users rather than sweeping in groups/resources.
+ properties:
+ statuses:
+ type: array
+ description: Match users whose HR/IDP status is one of these values.
+ items:
+ $ref: "#/components/schemas/UserHrIdpStatusEnum"
+ not:
+ type: boolean
+ description:
+ Invert the match within the user domain (e.g. "IDP status is NOT
+ active").
+
+ EntityAdminFilter:
+ type: object
+ required:
+ - ownerIDs
+ description: >
+ Filters GROUP and RESOURCE entities by their admin owner. USER entities
+ never match, in either polarity. `not` inverts the match within the
+ resource/group domain (self-negating, like IdpStatusFilter): omit it (or
+ false) to include entities owned by the given owners, set it true to
+ exclude them.
+ properties:
+ ownerIDs:
+ type: array
+ description: The owner (group) UUIDs to match entities against.
+ items:
+ type: string
+ format: uuid
+ not:
+ type: boolean
+ description:
+ Invert the match — return resources/groups NOT owned by the given
+ owners.
+
+ StringMatchType:
+ type: string
+ description: >-
+ How to match a string value against entity names. REGEX matches the
+ value as a case-insensitive regular expression.
+ enum:
+ - CONTAINS
+ - EQUALS
+ - STARTS_WITH
+ - ENDS_WITH
+ - REGEX
+
+ PaginatedAssignedRequestList:
+ type: object
+ required:
+ - requests
+ - cursor
+ properties:
+ requests:
+ type: array
+ items:
+ $ref: "#/components/schemas/Request"
+ cursor:
+ type: string
+ description: The cursor to continue pagination
+ PageInfo:
+ type: object
+ required:
+ - hasNextPage
+ - endCursor
+ - hasPreviousPage
+ - startCursor
+ properties:
+ hasNextPage:
+ type: boolean
+ description: Whether there are more items after the end cursor
+ endCursor:
+ type: string
+ description: The cursor to continue pagination forwards
+ hasPreviousPage:
+ type: boolean
+ description: Whether there are more items before the start cursor
+ startCursor:
+ type: string
+ description: The cursor to continue pagination backwards
+
+ RequestEdge:
+ type: object
+ required:
+ - node
+ - cursor
+ properties:
+ node:
+ $ref: "#/components/schemas/Request"
+ cursor:
+ type: string
+ description: The cursor for this request edge
+
+ RequestConnection:
+ type: object
+ required:
+ - edges
+ - pageInfo
+ - totalCount
+ properties:
+ edges:
+ type: array
+ items:
+ $ref: "#/components/schemas/RequestEdge"
+ pageInfo:
+ $ref: "#/components/schemas/PageInfo"
+ totalCount:
+ type: integer
+ description: The total number of items available
+ UARScope:
+ description:
+ If set, the access review will only contain resources and groups
+ that match at least one of the filters in scope.
+ example:
+ filter_operator: ANY
+ users:
+ - userd283-ca87-4a8a-bdbb-df212eca5353
+ include_group_bindings: True
+ tags:
+ - key: uar_scope
+ value: high_priority
+ names:
+ - demo
+ - api
+ admins:
+ - f454d283-ca87-4a8a-bdbb-df212eca5353
+ - 8763d283-ca87-4a8a-bdbb-df212ecab139
+ resource_types:
+ - GCP_CLOUD_SQL_POSTGRES_INSTANCE
+ group_types:
+ - AWS_SSO_GROUP
+ apps:
+ - pas2d283-ca87-4a8a-bdbb-df212eca5353
+ - apss2d283-ca87-4a8a-bdbb-df212eca5353
+ entities:
+ - f454d283-as87-4a8a-bdbb-df212eca5353
+ - f454d283-as87-4a8a-bdbb-df212eca5329
+ properties:
+ group_visibility:
+ description: Specifies what users can see during an Access Review
+ type: string
+ enum: [STRICT, VIEW_VISIBLE_AND_ASSIGNED, VIEW_ALL]
+ users:
+ description:
+ The access review will only include the following users. If any
+ users are selected, any entity filters will be applied to only the
+ entities that the selected users have access to.
+ items:
+ example: userd283-ca87-4a8a-bdbb-df212eca5353
+ type: string
+ format: uuid
+ type: array
+ filter_operator:
+ description:
+ Specifies whether entities must match all (AND) or any (OR) of the
+ filters.
+ type: string
+ enum: [ANY, ALL]
+ entities:
+ description:
+ This access review will include resources and groups with ids in
+ the given strings.
+ items:
+ example: f454d283-as87-4a8a-bdbb-df212eca5353
+ type: string
+ format: uuid
+ type: array
+ apps:
+ description: This access review will include items in the specified applications
items:
+ example: pas2d283-ca87-4a8a-bdbb-df212eca5353
type: string
- roleNames:
+ format: uuid
type: array
- description: Filter by role display names (e.g. "Admin", "Read"). Can only be applied within a hasAccessTo clause.
+ admins:
+ description:
+ This access review will include resources and groups who are owned
+ by one of the owners corresponding to the given IDs.
items:
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
type: string
- allOf:
+ format: uuid
+ type: array
+ group_types:
+ description: This access review will include items of the specified group types
type: array
- description: >
- A list of nested filters that must all match (logical AND). Each
- item has the same shape as this object — scalar fields like
- `entityTypes` or `entityTag`, and can further nest `allOf`,
- `anyOf`, or `not`.
items:
- $ref: "#/components/schemas/AccessEntityFilters"
- anyOf:
+ $ref: "#/components/schemas/GroupTypeEnum"
+ resource_types:
+ description: This access review will include items of the specified resource types
type: array
- description: >
- A list of nested filters where at least one must match (logical
- OR). Each item has the same shape as this object.
items:
- $ref: "#/components/schemas/AccessEntityFilters"
- not:
- description: >
- Excludes entities matching the embedded filter (logical NOT). Pass
- a filter object with the same shape as this one — typically a
- single scalar field, like `{not: {entityTypes: ["RESOURCE"]}}` to
- exclude resources.
- type: object
- x-go-type: AccessEntityFilters
-
- RunOpalQueryRequest:
- description:
- Request body for running an ad-hoc OpalQuery. The `type` field
- determines which query schema applies.
- oneOf:
- - $ref: "#/components/schemas/OpalNodeQuery"
- discriminator:
- propertyName: type
- mapping:
- NODE: "#/components/schemas/OpalNodeQuery"
- # example:
- # type: NODE
- # query:
- # nodeFilters:
- # entityTypes: [RESOURCE]
- # allOf:
- # - entityTag:
- # key: env
- # value: prod
- # - entityTag:
- # key: team
- # value: platform
- # not:
- # entityItemTypes: [AWS_IAM_ROLE]
- # accessFilters:
- # isAccessibleBy:
- # entityTypes: [USER]
- # entityTag:
- # key: contractor
- # first: 50
-
- OpalNodeQuery:
+ $ref: "#/components/schemas/ResourceTypeEnum"
+ include_group_bindings:
+ type: boolean
+ example: False
+ tags:
+ description:
+ This access review will include resources and groups who are tagged
+ with one of the given tags.
+ items:
+ $ref: "#/components/schemas/TagFilter"
+ type: array
+ names:
+ description:
+ This access review will include resources and groups whose name
+ contains one of the given strings.
+ items:
+ example: demo
+ type: string
+ type: array
type: object
- required:
- - type
- description:
- Request body for a NODE-type OpalQuery. Returns entities (users,
- resources, groups) matching the given filters.
+ CampaignStatusEnum:
+ description: The current status of a campaign.
+ enum:
+ - DRAFT
+ - ONGOING
+ - COMPLETED
+ - STOPPED
+ - ENDED
+ example: ONGOING
+ type: string
+ CampaignRevokeOnEnum:
+ description: When access decisions take effect during a campaign.
+ enum:
+ - ACTION
+ - END
+ - NONE
+ example: END
+ type: string
+ CampaignGroupAssetVisibilityPolicyEnum:
+ description: Controls what group assets reviewers can see during the campaign.
+ enum:
+ - STRICT
+ - VIEW_VISIBLE_AND_ASSIGNED
+ - VIEW_ALL
+ example: STRICT
+ type: string
+ CampaignConfiguration:
+ description: Configuration for an access review campaign.
example:
- type: NODE
- query:
- nodeFilters:
- entityTypes: [RESOURCE]
- entityTag:
- key: env
- value: prod
- accessFilters:
- isAccessibleBy:
- entityTypes: [USER]
- entityTag:
- key: contractor
- first: 50
+ configuration_id: 39a4d283-ca87-4a8a-bdbb-df212eca5fdb
+ created_at: 2026-07-01T00:00:00Z
+ updated_at: 2026-07-01T00:00:00Z
+ query: null
+ reviewer_assignment_policy: MANUALLY
+ allow_self_review: false
+ send_reviewer_assignment_notification: true
+ allow_reviewer_reassignment: false
+ start_date: null
+ end_date: 2026-09-30T00:00:00Z
+ timezone: America/Los_Angeles
+ revoke_on: END
+ reminder_schedule: [7, 3, 1]
+ reminder_include_manager: true
+ require_reason_on_denial: false
+ hide_ai_suggestions: false
+ custom_start_message: null
+ group_asset_visibility_policy: STRICT
+ is_template: false
+ cron_expression: null
+ next_scheduled_run: null
+ last_scheduled_run: null
+ recurring_duration_days: null
properties:
- type:
+ configuration_id:
+ description: The ID of the campaign configuration.
+ example: 39a4d283-ca87-4a8a-bdbb-df212eca5fdb
+ format: uuid
+ type: string
+ created_at:
+ description: The creation time of the configuration.
+ example: 2026-07-01T00:00:00Z
+ format: date-time
+ type: string
+ updated_at:
+ description: The last updated time of the configuration.
+ example: 2026-07-01T00:00:00Z
+ format: date-time
type: string
- enum:
- - NODE
query:
- $ref: "#/components/schemas/OpalNodeQueryBody"
- first:
- type: integer
- description: Maximum number of results to return. Defaults to 200.
- example: 200
- after:
+ description:
+ Access-path query defining the scope of access to review. Uses the
+ same principalFilter / entitlementFilter shape as ACCESS_PATH
+ OpalQuery.
+ allOf:
+ - $ref: "#/components/schemas/OpalAccessPathQueryBody"
+ nullable: true
+ reviewer_assignment_policy:
+ $ref: "#/components/schemas/UARReviewerAssignmentPolicyEnum"
+ allow_self_review:
+ description: Whether reviewers can review their own access.
+ example: false
+ type: boolean
+ send_reviewer_assignment_notification:
+ description: Whether to notify reviewers upon assignment.
+ example: true
+ type: boolean
+ allow_reviewer_reassignment:
+ description: Whether reviewers may reassign their reviews to another user.
+ example: false
+ type: boolean
+ start_date:
+ description: Scheduled start date of the campaign.
+ example: 2026-07-02T00:00:00Z
+ format: date-time
+ nullable: true
type: string
- description: Cursor from a previous response to fetch the next page of results.
- example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
-
- OpalNodeQueryBody:
+ end_date:
+ description: Scheduled end date of the campaign.
+ example: 2026-09-30T00:00:00Z
+ format: date-time
+ nullable: true
+ type: string
+ timezone:
+ description:
+ IANA timezone used to interpret campaign deadlines (e.g.
+ America/Los_Angeles).
+ example: America/Los_Angeles
+ type: string
+ revoke_on:
+ $ref: "#/components/schemas/CampaignRevokeOnEnum"
+ reminder_schedule:
+ description: Days before end date to send reminder notifications.
+ example: [7, 3, 1]
+ items:
+ type: integer
+ type: array
+ reminder_include_manager:
+ description: Whether to include the reviewer's manager in reminders.
+ example: true
+ type: boolean
+ require_reason_on_denial:
+ description:
+ Whether reviewers must provide a reason when denying (revoking)
+ access.
+ example: false
+ type: boolean
+ hide_ai_suggestions:
+ description: Whether AI suggestions are hidden from reviewers.
+ example: false
+ type: boolean
+ custom_start_message:
+ description:
+ Optional custom message included when notifying reviewers that the
+ campaign started.
+ example: Please complete your reviews by Friday.
+ nullable: true
+ type: string
+ group_asset_visibility_policy:
+ $ref: "#/components/schemas/CampaignGroupAssetVisibilityPolicyEnum"
+ is_template:
+ description:
+ Whether this configuration is a recurring schedule template.
+ example: false
+ type: boolean
+ cron_expression:
+ description:
+ Cron expression driving the recurring schedule. Null for one-off
+ campaigns.
+ example: 0 9 1 * *
+ nullable: true
+ type: string
+ next_scheduled_run:
+ description: Next time a draft will be generated from this template.
+ example: 2026-08-01T16:00:00Z
+ format: date-time
+ nullable: true
+ type: string
+ last_scheduled_run:
+ description: Most recent time a draft was generated from this template.
+ example: 2026-07-01T16:00:00Z
+ format: date-time
+ nullable: true
+ type: string
+ recurring_duration_days:
+ description:
+ Deadline window in days applied to each draft generated from this
+ template.
+ example: 14
+ nullable: true
+ type: integer
+ required:
+ - configuration_id
+ - created_at
+ - updated_at
+ - reviewer_assignment_policy
+ - allow_self_review
+ - send_reviewer_assignment_notification
+ - allow_reviewer_reassignment
+ - timezone
+ - revoke_on
+ - reminder_include_manager
+ - require_reason_on_denial
+ - hide_ai_suggestions
+ - group_asset_visibility_policy
+ - is_template
type: object
- description: The filter body for a NODE-type OpalQuery.
+ CreateCampaignConfigurationInfo:
+ description:
+ Configuration to apply when creating a campaign. `query` is required;
+ other omitted fields use defaults.
+ example:
+ query:
+ principalFilter:
+ entityTypes: [USER]
+ end_date: 2026-09-30T00:00:00Z
+ timezone: America/Los_Angeles
+ allow_self_review: false
properties:
- nodeFilters:
- $ref: "#/components/schemas/AccessEntityFilters"
- accessFilters:
- $ref: "#/components/schemas/AccessRelationshipFilters"
+ query:
+ description: |
+ Access-path query defining the scope of access to review. Required.
+ Uses the same principalFilter / entitlementFilter shape as
+ ACCESS_PATH OpalQuery. Must include at least one of
+ principalFilter or entitlementFilter.
- OpalQueryResultNode:
- type: object
- required:
- - id
- - name
- - entityType
- - entityItemType
- description: A matched entity from an OpalQuery result.
- properties:
- id:
+ Campaign scope only supports direct access edges:
+ `edgeFilter.directOnly` defaults to `true`, is always stored as
+ `true`, and passing `false` returns 400.
+ allOf:
+ - $ref: "#/components/schemas/OpalAccessPathQueryBody"
+ reviewer_assignment_policy:
+ $ref: "#/components/schemas/UARReviewerAssignmentPolicyEnum"
+ allow_self_review:
+ description: Whether reviewers can review their own access.
+ example: false
+ type: boolean
+ send_reviewer_assignment_notification:
+ description: Whether to notify reviewers upon assignment.
+ example: true
+ type: boolean
+ allow_reviewer_reassignment:
+ description: Whether reviewers may reassign their reviews to another user.
+ example: false
+ type: boolean
+ start_date:
+ description: Scheduled start date of the campaign.
+ example: 2026-07-02T00:00:00Z
+ format: date-time
+ nullable: true
type: string
- format: uuid
- description: The entity's unique identifier.
- name:
+ end_date:
+ description: Scheduled end date of the campaign.
+ example: 2026-09-30T00:00:00Z
+ format: date-time
+ nullable: true
+ type: string
+ timezone:
+ description:
+ IANA timezone used to interpret campaign deadlines (e.g.
+ America/Los_Angeles).
+ example: America/Los_Angeles
+ type: string
+ revoke_on:
+ $ref: "#/components/schemas/CampaignRevokeOnEnum"
+ reminder_schedule:
+ description: Days before end date to send reminder notifications.
+ example: [7, 3, 1]
+ items:
+ type: integer
+ type: array
+ reminder_include_manager:
+ description: Whether to include the reviewer's manager in reminders.
+ example: true
+ type: boolean
+ require_reason_on_denial:
+ description:
+ Whether reviewers must provide a reason when denying (revoking)
+ access.
+ example: false
+ type: boolean
+ hide_ai_suggestions:
+ description: Whether AI suggestions are hidden from reviewers.
+ example: false
+ type: boolean
+ custom_start_message:
+ description:
+ Optional custom message included when notifying reviewers that the
+ campaign started.
+ example: Please complete your reviews by Friday.
+ nullable: true
type: string
- description: The display name of the entity.
- entityType:
+ group_asset_visibility_policy:
+ $ref: "#/components/schemas/CampaignGroupAssetVisibilityPolicyEnum"
+ is_template:
+ description:
+ Whether this configuration is a recurring schedule template.
+ example: false
+ type: boolean
+ cron_expression:
+ description:
+ Cron expression driving the recurring schedule. Null for one-off
+ campaigns.
+ example: 0 9 1 * *
+ nullable: true
type: string
- enum:
- - USER
- - GROUP
- - RESOURCE
- description: The top-level entity type.
- entityItemType:
- $ref: "#/components/schemas/EntityItemTypeEnum"
-
- OpalQueryResultEdge:
- type: object
+ recurring_duration_days:
+ description:
+ Deadline window in days applied to each draft generated from this
+ template.
+ example: 14
+ nullable: true
+ type: integer
+ excluded_role_assignment_ids:
+ description:
+ Role assignment IDs to exclude from the campaign scope during
+ population.
+ items:
+ format: uuid
+ type: string
+ type: array
required:
- - node
- - cursor
- description:
- A single result edge from an OpalQuery, containing the matched
- entity and its pagination cursor.
+ - query
+ type: object
+ CreateCampaignInfo:
+ description: |-
+ # CreateCampaignInfo Object
+ ### Description
+ The `CreateCampaignInfo` object is used to create a campaign.
+
+ ### Usage Example
+ Use in the `POST Campaigns` endpoint.
+ example:
+ name: Q3 Access Review
+ configuration:
+ query:
+ principalFilter:
+ entityTypes: [USER]
+ end_date: 2026-09-30T00:00:00Z
+ timezone: America/Los_Angeles
properties:
- node:
- $ref: "#/components/schemas/OpalQueryResultNode"
- cursor:
+ name:
+ description: The name of the campaign.
+ example: Q3 Access Review
type: string
- description: Opaque cursor for this entity, used for pagination.
-
- OpalQueryResults:
- description:
- Paginated results of an OpalQuery. The `type` field discriminates
- which result schema applies and mirrors the `type` field on the request.
- oneOf:
- - $ref: "#/components/schemas/OpalNodeQueryResults"
- discriminator:
- propertyName: type
- mapping:
- NODE: "#/components/schemas/OpalNodeQueryResults"
-
- OpalNodeQueryResults:
- type: object
+ configuration:
+ description:
+ Configuration for the campaign. Required; must include a query.
+ Other omitted fields use defaults.
+ allOf:
+ - $ref: "#/components/schemas/CreateCampaignConfigurationInfo"
required:
- - type
- - edges
- - pageInfo
- description:
- Paginated results of a NODE-type OpalQuery — one edge per matched
- entity (user, resource, or group).
+ - name
+ - configuration
+ type: object
+ UpdateCampaignConfigurationInfo:
+ description: |
+ Configuration fields to update on a campaign. All fields are optional;
+ omitted fields are left unchanged. `query` and
+ `reviewer_assignment_policy` are set at create time and cannot be
+ updated here; including either field returns 400.
+ `cron_expression` and `recurring_duration_days` may only be set when
+ the campaign is a template; setting them on a one-off campaign returns
+ 400. `is_template` is immutable and not accepted on update.
+ example:
+ end_date: 2026-09-30T00:00:00Z
+ timezone: America/Los_Angeles
+ allow_self_review: false
properties:
- type:
+ allow_self_review:
+ description: Whether reviewers can review their own access.
+ example: false
+ type: boolean
+ send_reviewer_assignment_notification:
+ description: Whether to notify reviewers upon assignment.
+ example: true
+ type: boolean
+ allow_reviewer_reassignment:
+ description: Whether reviewers may reassign their reviews to another user.
+ example: false
+ type: boolean
+ start_date:
+ description: |
+ Scheduled start date of the campaign. May only be updated while the
+ campaign has not started (started_at is null). When set, the date's
+ calendar day in the campaign timezone must be at least tomorrow.
+ example: 2026-07-02T00:00:00Z
+ format: date-time
+ nullable: true
type: string
- enum:
- - NODE
- edges:
- type: array
- description: List of matched entities.
+ end_date:
+ description: |
+ Scheduled end date of the campaign. When set, the date's calendar
+ day in the campaign timezone must be at least tomorrow.
+ example: 2026-09-30T00:00:00Z
+ format: date-time
+ nullable: true
+ type: string
+ timezone:
+ description:
+ IANA timezone used to interpret campaign deadlines (e.g.
+ America/Los_Angeles).
+ example: America/Los_Angeles
+ type: string
+ revoke_on:
+ $ref: "#/components/schemas/CampaignRevokeOnEnum"
+ reminder_schedule:
+ description: Days before end date to send reminder notifications.
+ example: [7, 3, 1]
items:
- $ref: "#/components/schemas/OpalQueryResultEdge"
- pageInfo:
- $ref: "#/components/schemas/PageInfo"
-
- AccessRelationshipFilters:
- type: object
- description: >
- Filters the returned nodes by the access edges connected to them.
- When `isAccessibleBy` and `hasAccessTo` are provided, the returned nodes
- must satisfy both edge constraints simultaneously.
- properties:
- isAccessibleBy:
+ type: integer
+ type: array
+ reminder_include_manager:
+ description: Whether to include the reviewer's manager in reminders.
+ example: true
+ type: boolean
+ require_reason_on_denial:
description:
- Inbound-edge filter. The returned node must be accessible by at
- least one entity matching this filter.
- $ref: "#/components/schemas/AccessEntityFilters"
- hasAccessTo:
+ Whether reviewers must provide a reason when denying (revoking)
+ access.
+ example: false
+ type: boolean
+ hide_ai_suggestions:
+ description: Whether AI suggestions are hidden from reviewers.
+ example: false
+ type: boolean
+ custom_start_message:
description:
- Outbound-edge filter. The returned node must have access to at
- least one entity matching this filter.
- $ref: "#/components/schemas/AccessEntityFilters"
-
- EntityNameFilter:
+ Optional custom message included when notifying reviewers that the
+ campaign started.
+ example: Please complete your reviews by Friday.
+ nullable: true
+ type: string
+ group_asset_visibility_policy:
+ $ref: "#/components/schemas/CampaignGroupAssetVisibilityPolicyEnum"
+ cron_expression:
+ description:
+ Cron expression driving the recurring schedule. Only valid on
+ template campaigns. Pass an empty string to clear the active months
+ (next_scheduled_run is cleared); the campaign remains a template.
+ example: 0 9 1 * *
+ nullable: true
+ type: string
+ recurring_duration_days:
+ description:
+ Deadline window in days applied to each draft generated from this
+ template. Only valid on template campaigns.
+ example: 14
+ nullable: true
+ type: integer
type: object
- required:
- - stringMatchType
- - string
- description: Filters entities by name using a string match strategy.
+ UpdateCampaignInfo:
+ description: |-
+ # UpdateCampaignInfo Object
+ ### Description
+ The `UpdateCampaignInfo` object is used to partially update a campaign.
+ Omitted fields are left unchanged.
+
+ ### Usage Example
+ Use in the `PUT Campaign` endpoint.
+ example:
+ name: Q3 Access Review (Updated)
+ configuration:
+ end_date: 2026-09-30T00:00:00Z
+ timezone: America/Los_Angeles
properties:
- stringMatchType:
- $ref: "#/components/schemas/StringMatchType"
- string:
+ name:
+ description: The name of the campaign.
+ example: Q3 Access Review (Updated)
type: string
- description: The string value to match against the entity name.
- example: engineering
-
- EntityTagFilter:
+ configuration:
+ description: Configuration fields to create or update.
+ allOf:
+ - $ref: "#/components/schemas/UpdateCampaignConfigurationInfo"
type: object
- required:
- - key
- description:
- Filters entities by a tag key/value pair, optionally scoped to a
- connection.
+ Campaign:
+ description: An access review campaign.
+ example:
+ campaign_id: f454d283-ca87-4a8a-bdbb-df212eca5353
+ name: Q3 Access Review
+ status: DRAFT
+ is_template: false
+ created_at: 2026-07-01T00:00:00Z
+ updated_at: 2026-07-01T00:00:00Z
+ created_by_user_id: 32acc112-21ff-4669-91c2-21e27683eaa1
+ configuration: null
+ started_at: null
+ started_by_user_id: null
+ stopped_at: null
+ stopped_by_user_id: null
+ ended_at: null
+ ended_by_user_id: null
properties:
- key:
+ campaign_id:
+ description: The ID of the campaign.
+ example: f454d283-ca87-4a8a-bdbb-df212eca5353
+ format: uuid
type: string
- description: The tag key to filter by.
- example: team
- value:
+ name:
+ description: The name of the campaign.
+ example: Q3 Access Review
type: string
+ status:
+ $ref: "#/components/schemas/CampaignStatusEnum"
+ is_template:
description:
- The tag value to filter by. If omitted, matches any value for the
- given key.
- example: platform
- connectionId:
+ Whether this campaign is a recurring schedule template. Templates
+ spawn draft campaigns on schedule rather than being reviewed directly.
+ example: false
+ type: boolean
+ created_at:
+ description: The creation time of the campaign.
+ example: 2026-07-01T00:00:00Z
+ format: date-time
+ type: string
+ updated_at:
+ description: The last updated time of the campaign.
+ example: 2026-07-01T00:00:00Z
+ format: date-time
type: string
+ created_by_user_id:
+ description: The ID of the user who created the campaign.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
format: uuid
- description: If specified, filters by tags associated with this connection.
-
- StringMatchType:
- type: string
- description: How to match a string value against entity names.
- enum:
- - CONTAINS
- - EQUALS
- - STARTS_WITH
- - ENDS_WITH
-
- PaginatedAssignedRequestList:
- type: object
+ type: string
+ configuration:
+ description: The campaign's configuration, if set.
+ allOf:
+ - $ref: "#/components/schemas/CampaignConfiguration"
+ nullable: true
+ started_at:
+ description: The time the campaign was started, if started.
+ example: 2026-07-02T00:00:00Z
+ format: date-time
+ nullable: true
+ type: string
+ started_by_user_id:
+ description: The ID of the user who started the campaign, if started.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ format: uuid
+ nullable: true
+ type: string
+ stopped_at:
+ description: The time the campaign was manually stopped, if stopped.
+ example: 2026-07-10T00:00:00Z
+ format: date-time
+ nullable: true
+ type: string
+ stopped_by_user_id:
+ description: The ID of the user who stopped the campaign, if stopped.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ format: uuid
+ nullable: true
+ type: string
+ ended_at:
+ description: The time the campaign reached its scheduled end, if ended.
+ example: 2026-07-14T00:00:00Z
+ format: date-time
+ nullable: true
+ type: string
+ ended_by_user_id:
+ description: The ID of the user who ended the campaign, if ended.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ format: uuid
+ nullable: true
+ type: string
required:
- - requests
- - cursor
+ - campaign_id
+ - name
+ - status
+ - is_template
+ - created_at
+ - updated_at
+ - created_by_user_id
+ type: object
+ PaginatedCampaignsList:
+ description: A list of campaigns.
+ example:
+ next: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ previous: cj1sZXdwd2VycWVtY29zZnNkc2NzUWxNMEUxTXk0ME16UXpNallsTWtJ
+ results:
+ - campaign_id: f454d283-ca87-4a8a-bdbb-df212eca5353
+ name: Q3 Access Review
+ status: DRAFT
+ is_template: false
+ created_at: 2026-07-01T00:00:00Z
+ updated_at: 2026-07-01T00:00:00Z
+ created_by_user_id: 32acc112-21ff-4669-91c2-21e27683eaa1
properties:
- requests:
- type: array
- items:
- $ref: "#/components/schemas/Request"
- cursor:
+ next:
+ description:
+ The cursor with which to continue pagination if additional result
+ pages exist.
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw
+ nullable: true
type: string
- description: The cursor to continue pagination
- PageInfo:
- type: object
+ previous:
+ description: The cursor used to obtain the current result page.
+ example: cj1sZXdwd2VycWVtY29zZnNkc2NzUWxNMEUxTXk0ME16UXpNallsTWtJ
+ nullable: true
+ type: string
+ results:
+ items:
+ $ref: "#/components/schemas/Campaign"
+ type: array
required:
- - hasNextPage
- - endCursor
- - hasPreviousPage
- - startCursor
+ - results
+ type: object
+ CampaignItemStatusEnum:
+ description: |
+ Derived aggregate status for a campaign item. Matches the admin Reviews
+ tab Status column labels (undecided items on a stopped campaign are
+ PENDING, not a separate stopped status).
+ enum:
+ - PENDING
+ - COMPLETED
+ - APPROVED
+ - REVOKED
+ - NO_ACTION
+ - CHANGED_ROLE
+ - ADMIN_REVOKED
+ example: PENDING
+ type: string
+ CampaignItemReviewDecisionEnum:
+ description: Decision recorded on a campaign item review row.
+ enum:
+ - APPROVED
+ - REVOKED
+ - CHANGE_ROLE
+ - ADMIN_REVOKED
+ - NO_ACTION
+ - REASSIGNED
+ - ADMIN_OVERRIDE_APPROVED
+ - ADMIN_OVERRIDE_REVOKED
+ example: APPROVED
+ type: string
+ CampaignItemReviewerAssignmentSourceEnum:
+ description: How a reviewer was assigned to a campaign item.
+ enum:
+ - MANUAL
+ - PRINCIPAL_MANAGER
+ - ASSET_ADMIN_OWNER
+ example: MANUAL
+ type: string
+ CampaignItemTargetTypeEnum:
+ description: Type of access edge the campaign item reviews.
+ enum:
+ - ROLE_ASSIGNMENT
+ example: ROLE_ASSIGNMENT
+ type: string
+ CampaignItemReview:
+ description: A single reviewer's assignment and decision for a campaign item.
properties:
- hasNextPage:
- type: boolean
- description: Whether there are more items after the end cursor
- endCursor:
+ campaign_item_review_id:
+ description: The ID of the campaign item review.
+ format: uuid
type: string
- description: The cursor to continue pagination forwards
- hasPreviousPage:
- type: boolean
- description: Whether there are more items before the start cursor
- startCursor:
+ campaign_item_id:
+ description: The ID of the campaign item.
+ format: uuid
+ type: string
+ reviewer_user_id:
+ description: The ID of the assigned reviewer.
+ format: uuid
+ type: string
+ assignment_source:
+ $ref: "#/components/schemas/CampaignItemReviewerAssignmentSourceEnum"
+ decision:
+ description: |
+ The reviewer's decision. Null when the reviewer has not yet
+ submitted.
+ allOf:
+ - $ref: "#/components/schemas/CampaignItemReviewDecisionEnum"
+ nullable: true
+ note:
+ description: Optional note from the reviewer.
+ nullable: true
+ type: string
+ updated_access_level_remote_id:
+ description: Target access level remote ID when decision is CHANGE_ROLE.
+ nullable: true
+ type: string
+ decided_at:
+ description: When the decision was finalized.
+ format: date-time
+ nullable: true
type: string
- description: The cursor to continue pagination backwards
-
- RequestEdge:
- type: object
required:
- - node
- - cursor
+ - campaign_item_review_id
+ - campaign_item_id
+ - reviewer_user_id
+ - assignment_source
+ type: object
+ CampaignItemAdminOverride:
+ description: |
+ Admin override applied to a campaign item. When set, it takes precedence
+ over reviewer decisions for status and end-campaign remediations.
properties:
- node:
- $ref: "#/components/schemas/Request"
- cursor:
+ actor_user_id:
+ description: The admin who applied the override.
+ format: uuid
+ type: string
+ decision:
+ $ref: "#/components/schemas/CampaignItemReviewDecisionEnum"
+ decided_at:
+ description: When the override was applied.
+ format: date-time
type: string
- description: The cursor for this request edge
-
- RequestConnection:
- type: object
required:
- - edges
- - pageInfo
- - totalCount
- properties:
- edges:
- type: array
- items:
- $ref: "#/components/schemas/RequestEdge"
- pageInfo:
- $ref: "#/components/schemas/PageInfo"
- totalCount:
- type: integer
- description: The total number of items available
- UARScope:
- description:
- If set, the access review will only contain resources and groups
- that match at least one of the filters in scope.
- example:
- filter_operator: ANY
- users:
- - userd283-ca87-4a8a-bdbb-df212eca5353
- include_group_bindings: True
- tags:
- - key: uar_scope
- value: high_priority
- names:
- - demo
- - api
- admins:
- - f454d283-ca87-4a8a-bdbb-df212eca5353
- - 8763d283-ca87-4a8a-bdbb-df212ecab139
- resource_types:
- - GCP_CLOUD_SQL_POSTGRES_INSTANCE
- group_types:
- - AWS_SSO_GROUP
- apps:
- - pas2d283-ca87-4a8a-bdbb-df212eca5353
- - apss2d283-ca87-4a8a-bdbb-df212eca5353
- entities:
- - f454d283-as87-4a8a-bdbb-df212eca5353
- - f454d283-as87-4a8a-bdbb-df212eca5329
+ - actor_user_id
+ - decision
+ - decided_at
+ type: object
+ CampaignItem:
+ description: |
+ A campaign review item — one direct access edge under review, matching
+ a row on the admin Reviews tab.
properties:
- group_visibility:
- description: Specifies what users can see during an Access Review
+ campaign_item_id:
+ description: The ID of the campaign item.
+ format: uuid
type: string
- enum: [STRICT, VIEW_VISIBLE_AND_ASSIGNED, VIEW_ALL]
- users:
- description:
- The access review will only include the following users. If any
- users are selected, any entity filters will be applied to only the
- entities that the selected users have access to.
- items:
- example: userd283-ca87-4a8a-bdbb-df212eca5353
- type: string
- format: uuid
- type: array
- filter_operator:
- description:
- Specifies whether entities must match all (AND) or any (OR) of the
- filters.
+ campaign_id:
+ description: The ID of the parent campaign.
+ format: uuid
type: string
- enum: [ANY, ALL]
- entities:
- description:
- This access review will include resources and groups with ids in
- the given strings.
- items:
- example: f454d283-as87-4a8a-bdbb-df212eca5353
- type: string
- format: uuid
- type: array
- apps:
- description: This access review will include items in the specified applications
- items:
- example: pas2d283-ca87-4a8a-bdbb-df212eca5353
- type: string
- format: uuid
- type: array
- admins:
- description:
- This access review will include resources and groups who are owned
- by one of the owners corresponding to the given IDs.
- items:
- example: f454d283-ca87-4a8a-bdbb-df212eca5353
- type: string
- format: uuid
- type: array
- group_types:
- description: This access review will include items of the specified group types
- type: array
- items:
- $ref: "#/components/schemas/GroupTypeEnum"
- resource_types:
- description: This access review will include items of the specified resource types
- type: array
- items:
- $ref: "#/components/schemas/ResourceTypeEnum"
- include_group_bindings:
+ target_type:
+ $ref: "#/components/schemas/CampaignItemTargetTypeEnum"
+ role_assignment_id:
+ description: |
+ The role assignment ID this item reviews (`target_id` when
+ `target_type` is ROLE_ASSIGNMENT).
+ format: uuid
+ type: string
+ status:
+ $ref: "#/components/schemas/CampaignItemStatusEnum"
+ created_at:
+ description: When the item was created (snapshotted into the campaign).
+ format: date-time
+ type: string
+ is_target_deleted:
+ description: True when the underlying role assignment is soft-deleted.
type: boolean
- example: False
- tags:
- description:
- This access review will include resources and groups who are tagged
- with one of the given tags.
+ principal_id:
+ description: Principal ID from the role assignment. Null if the RA is missing.
+ format: uuid
+ nullable: true
+ type: string
+ principal_type:
+ description: Principal entity type. Null if the RA is missing.
+ allOf:
+ - $ref: "#/components/schemas/EntityTypeEnum"
+ nullable: true
+ entity_id:
+ description: Entitlement entity ID. Null if the RA is missing.
+ format: uuid
+ nullable: true
+ type: string
+ entity_type:
+ description: Entitlement entity type. Null if the RA is missing.
+ allOf:
+ - $ref: "#/components/schemas/EntityTypeEnum"
+ nullable: true
+ access_level:
+ description: Access level on the role assignment, if any.
+ allOf:
+ - $ref: "#/components/schemas/ResourceAccessLevel"
+ nullable: true
+ access_level_name:
+ description: Denormalized access level name stored on the campaign item.
+ nullable: true
+ type: string
+ reviews:
+ description: Reviewer assignments and decisions for this item.
items:
- $ref: "#/components/schemas/TagFilter"
+ $ref: "#/components/schemas/CampaignItemReview"
type: array
- names:
+ admin_override:
+ description: Admin override, if any.
+ allOf:
+ - $ref: "#/components/schemas/CampaignItemAdminOverride"
+ nullable: true
+ required:
+ - campaign_item_id
+ - campaign_id
+ - target_type
+ - role_assignment_id
+ - status
+ - created_at
+ - is_target_deleted
+ - reviews
+ type: object
+ PaginatedCampaignItemsList:
+ description: A paginated list of campaign items.
+ properties:
+ next:
description:
- This access review will include resources and groups whose name
- contains one of the given strings.
+ The cursor with which to continue pagination if additional result
+ pages exist.
+ nullable: true
+ type: string
+ previous:
+ description: The cursor used to obtain the current result page.
+ nullable: true
+ type: string
+ results:
items:
- example: demo
- type: string
+ $ref: "#/components/schemas/CampaignItem"
type: array
+ total_count:
+ description: Total number of items matching the filter (across all pages).
+ type: integer
+ format: int64
+ required:
+ - results
+ - total_count
type: object
PaginatedUARsList:
description: A list of UARs.
@@ -6013,10 +8388,13 @@ components:
- COUPA
- CURSOR
- CUSTOM
+ - CONFLUENCE
- CUSTOM_CONNECTOR
- DATABRICKS
- DATASTAX_ASTRA
+ - ALICLOUD
- DEVIN
+ - DOCUSIGN
- DUO
- GCP
- GIT_HUB
@@ -6027,7 +8405,9 @@ components:
- HUBSPOT
- ILEVEL
- INCIDENTIO
+ - JIRA
- LDAP
+ - LINEAR
- MARIADB
- MONGO
- MONGO_ATLAS
@@ -6045,12 +8425,14 @@ components:
- SALESFORCE
- SNOWFLAKE
- SLACK
+ - TABLEAU
- TAILSCALE
- TELEPORT
- TWINGATE
- VAULT
- WORKDAY
- ZENDESK
+ - ZOOM
example: OKTA_DIRECTORY
type: string
EntityTypeEnum:
@@ -6061,6 +8443,157 @@ components:
- USER
example: GROUP
type: string
+ ViewerCampaignItemSortFieldEnum:
+ description: Sort field for viewer campaign items.
+ enum:
+ - PRINCIPAL_NAME
+ - ENTITY_NAME
+ - EXPIRATION
+ - LAST_USED
+ example: PRINCIPAL_NAME
+ type: string
+ SortDirectionEnum:
+ description: Sort direction for viewer campaign items.
+ enum:
+ - ASC
+ - DESC
+ example: ASC
+ type: string
+ ViewerCampaignItemStatusEnum:
+ description: Decision status for a viewer campaign item.
+ enum:
+ - APPROVED
+ - REVOKED
+ - CHANGE_ROLE
+ - NO_ACTION
+ - PENDING
+ - REASSIGNED
+ example: PENDING
+ type: string
+ ViewerCampaignItemReviewDecisionEnum:
+ description: Decision recorded on a campaign item review row.
+ enum:
+ - APPROVED
+ - REVOKED
+ - CHANGE_ROLE
+ - ADMIN_REVOKED
+ - NO_ACTION
+ - REASSIGNED
+ example: APPROVED
+ type: string
+ ViewerCampaignItem:
+ description: |
+ A campaign review item assigned to the current viewer, matching
+ GraphQL `ViewerCampaignItem`.
+ properties:
+ campaign_item_review_id:
+ description: The ID of the campaign item review.
+ format: uuid
+ type: string
+ decision:
+ description: The reviewer's decision. Null when undecided.
+ allOf:
+ - $ref: "#/components/schemas/ViewerCampaignItemReviewDecisionEnum"
+ nullable: true
+ note:
+ description: Optional note from the reviewer.
+ nullable: true
+ type: string
+ decided_at:
+ description: When the decision was finalized.
+ format: date-time
+ nullable: true
+ type: string
+ pending_decision:
+ description: Pending decision staged by the viewer, if any.
+ allOf:
+ - $ref: "#/components/schemas/ViewerCampaignItemReviewDecisionEnum"
+ nullable: true
+ pending_note:
+ description: Pending note attached to the reviewer's pending decision.
+ nullable: true
+ type: string
+ updated_access_level_remote_id:
+ description: Target access level remote ID when decision is CHANGE_ROLE.
+ nullable: true
+ type: string
+ pending_updated_access_level_remote_id:
+ description: Pending target access level remote ID when decision is CHANGE_ROLE.
+ nullable: true
+ type: string
+ reassigned_to_reviewer_ids:
+ description: User IDs this review was reassigned to.
+ items:
+ format: uuid
+ type: string
+ type: array
+ principal_id:
+ description: Principal ID from the role assignment.
+ format: uuid
+ type: string
+ principal_type:
+ $ref: "#/components/schemas/EntityTypeEnum"
+ entity_id:
+ description: Entity ID from the role assignment.
+ format: uuid
+ type: string
+ entity_type:
+ $ref: "#/components/schemas/EntityTypeEnum"
+ access_level_name:
+ description: Denormalized access level name.
+ nullable: true
+ type: string
+ access_level_remote_id:
+ description: Access level remote ID from the role assignment.
+ nullable: true
+ type: string
+ granted_at:
+ description: When the access was originally granted.
+ format: date-time
+ type: string
+ expires_at:
+ description: When the access expires, if set.
+ format: date-time
+ nullable: true
+ type: string
+ role_assignment_id:
+ description: ID of the underlying role assignment.
+ format: uuid
+ type: string
+ required:
+ - campaign_item_review_id
+ - principal_id
+ - principal_type
+ - entity_id
+ - entity_type
+ - granted_at
+ - role_assignment_id
+ type: object
+ PaginatedViewerCampaignItemsList:
+ description: A paginated list of viewer campaign items.
+ properties:
+ next:
+ description: |
+ The cursor with which to continue pagination if additional result
+ pages exist.
+ nullable: true
+ type: string
+ previous:
+ description: The cursor used to obtain the current result page.
+ nullable: true
+ type: string
+ results:
+ items:
+ $ref: "#/components/schemas/ViewerCampaignItem"
+ type: array
+ total_count:
+ description: Total number of items matching the filter (across all pages).
+ type: integer
+ format: int64
+ required:
+ - results
+ - total_count
+ type: object
Event:
description: |-
# Event Object
@@ -6285,6 +8818,99 @@ components:
$ref: "#/components/schemas/ResourceAccessUser"
type: array
type: object
+ ResourceCustomAccessLevelResponse:
+ description: A custom access level for a resource.
+ properties:
+ resource_custom_access_level_id:
+ description: The unique ID of the custom access level.
+ type: string
+ format: uuid
+ resource_id:
+ description: The resource this access level belongs to.
+ type: string
+ format: uuid
+ access_level:
+ $ref: "#/components/schemas/ResourceAccessLevel"
+ policy:
+ description: The policy document for this access level.
+ type: string
+ nullable: true
+ requestable_by_default:
+ description: Whether this role is requestable.
+ type: boolean
+ stackable_sensitivity_index:
+ description: The sensitivity index in the access hierarchy. Null if unranked.
+ type: integer
+ nullable: true
+ member_resource_ids:
+ description: When addressed via a parent resource, lists the child resource IDs that back this aggregated entry.
+ type: array
+ items:
+ type: string
+ format: uuid
+ nullable: true
+ created_at:
+ type: string
+ format: date-time
+ updated_at:
+ type: string
+ format: date-time
+ required:
+ - resource_custom_access_level_id
+ - resource_id
+ - access_level
+ - requestable_by_default
+ type: object
+ ResourceCustomAccessLevelList:
+ description: A list of custom access levels.
+ properties:
+ custom_access_levels:
+ type: array
+ items:
+ $ref: "#/components/schemas/ResourceCustomAccessLevelResponse"
+ required:
+ - custom_access_levels
+ type: object
+ CreateResourceCustomAccessLevelInfo:
+ description: Info for creating a custom access level.
+ properties:
+ access_level:
+ $ref: "#/components/schemas/ResourceAccessLevel"
+ policy:
+ description: The policy document.
+ type: string
+ nullable: true
+ requestable_by_default:
+ description: Whether the role is requestable. Defaults to false.
+ type: boolean
+ stackable_sensitivity_index:
+ description: The sensitivity index. Null to leave unranked.
+ type: integer
+ nullable: true
+ required:
+ - access_level
+ type: object
+ UpdateResourceCustomAccessLevelInfo:
+ description: Info for updating a custom access level.
+ properties:
+ access_level_name:
+ description: The new human-readable name.
+ type: string
+ policy:
+ description: The new policy document.
+ type: string
+ nullable: true
+ requestable_by_default:
+ description: Whether the role is requestable.
+ type: boolean
+ stackable_sensitivity_index:
+ description: The new sensitivity index.
+ type: integer
+ nullable: true
+ clear_stackable_sensitivity_index:
+ description: Set to true to remove from the hierarchy.
+ type: boolean
+ type: object
ResourceAccessLevel:
description: |-
# Access Level Object
@@ -6310,6 +8936,20 @@ components:
- access_level_name
- access_level_remote_id
type: object
+ ResourceAccessLevelList:
+ description: A list of access levels defined for a resource.
+ example:
+ results:
+ - access_level_name: AdminRole
+ access_level_remote_id: arn:aws:iam::590304332660:role/AdministratorAccess
+ - access_level_name: ReadOnly
+ access_level_remote_id: arn:aws:iam::590304332660:role/ReadOnlyAccess
+ properties:
+ results:
+ items:
+ $ref: "#/components/schemas/ResourceAccessLevel"
+ type: array
+ type: object
ResourceUserAccessStatus:
description: |-
# AccessStatus Object
@@ -6621,6 +9261,273 @@ components:
$ref: "#/components/schemas/Session"
type: array
type: object
+ Paladin:
+ description: |-
+ # Paladin Object
+ ### Description
+ The `Paladin` object represents a Paladin, Opal's AI access-request
+ reviewer.
+ example:
+ paladin_id: 32acc112-21ff-4669-91c2-21e27683eaa1
+ name: paladin-agent-1
+ owner_id: 7c86c85d-0651-43e2-a748-d69d658418e8
+ monitor_mode: true
+ admin_view_only: false
+ enabled_connectors:
+ - SLACK
+ properties:
+ paladin_id:
+ description:
+ The ID of the Paladin. Use this value as a reviewer in a request
+ configuration's service_user_ids.
+ example: 32acc112-21ff-4669-91c2-21e27683eaa1
+ format: uuid
+ type: string
+ name:
+ description: The name of the Paladin.
+ example: paladin-agent-1
+ type: string
+ owner_id:
+ description: The ID of the owner of the Paladin.
+ example: 7c86c85d-0651-43e2-a748-d69d658418e8
+ format: uuid
+ type: string
+ monitor_mode:
+ description:
+ When true, the Paladin reasons about requests but takes no action.
+ Shown as "Monitor mode" in the UI.
+ type: boolean
+ admin_view_only:
+ description:
+ When true, the Paladin's recommendations are visible only to admins.
+ Only meaningful when monitor_mode is true.
+ type: boolean
+ enabled_connectors:
+ description: The connectors the Paladin is allowed to use.
+ type: array
+ items:
+ $ref: "#/components/schemas/PaladinConnector"
+ instructions:
+ description:
+ The free-form instructions that guide the Paladin's decisions.
+ example: Approve read-only access; escalate anything that grants write access.
+ type: string
+ required:
+ - paladin_id
+ - name
+ - owner_id
+ - monitor_mode
+ - admin_view_only
+ - enabled_connectors
+ - instructions
+ type: object
+ PaladinList:
+ description: |-
+ # PaladinList Object
+ ### Description
+ A list of `Paladin` objects.
+ properties:
+ results:
+ items:
+ $ref: "#/components/schemas/Paladin"
+ type: array
+ required:
+ - results
+ type: object
+ PaladinConnector:
+ description: A connector a Paladin is allowed to use.
+ enum:
+ - NOTION
+ - JIRA
+ - LINEAR
+ - SERVICE_NOW
+ - NOTION_TICKETS
+ - FRESH_SERVICE
+ - SHORTCUT
+ - SLACK
+ - PAGER_DUTY
+ - CONFLUENCE
+ - FLEET_DM
+ type: string
+ PaladinContextSourceKind:
+ description:
+ The kind of source a Paladin can read. A SLACK_CHANNEL is a Slack
+ channel; a DOCUMENT is a Notion or Confluence page.
+ enum:
+ - SLACK_CHANNEL
+ - DOCUMENT
+ type: string
+ PaladinContextSourceProvider:
+ description: The integration a Paladin context source comes from.
+ enum:
+ - SLACK
+ - NOTION
+ - CONFLUENCE
+ type: string
+ PaladinContextSource:
+ description: |-
+ # PaladinContextSource Object
+ ### Description
+ A context source (a Slack channel or a document) that a Paladin is
+ configured to read during access-request review.
+ example:
+ id: 8a1f2c3d-4b5e-6f70-8192-a3b4c5d6e7f8
+ paladin_id: 32acc112-21ff-4669-91c2-21e27683eaa1
+ source_kind: SLACK_CHANNEL
+ third_party_provider: SLACK
+ remote_id: C0123456789
+ name: "#access-requests"
+ url: https://example.slack.com/archives/C0123456789
+ properties:
+ id:
+ description: The ID of the context source.
+ format: uuid
+ type: string
+ paladin_id:
+ description: The ID of the Paladin this source belongs to.
+ format: uuid
+ type: string
+ source_kind:
+ $ref: "#/components/schemas/PaladinContextSourceKind"
+ third_party_provider:
+ $ref: "#/components/schemas/PaladinContextSourceProvider"
+ remote_id:
+ description:
+ The provider's identifier for the source. The Slack channel ID for
+ a channel, or the Notion/Confluence page ID for a document.
+ type: string
+ name:
+ description: A human-readable name for the source.
+ type: string
+ url:
+ description: A link to the source.
+ type: string
+ required:
+ - id
+ - paladin_id
+ - source_kind
+ - third_party_provider
+ - remote_id
+ - name
+ - url
+ type: object
+ PaladinContextSourceList:
+ description: |-
+ # PaladinContextSourceList Object
+ ### Description
+ A list of `PaladinContextSource` objects.
+ properties:
+ results:
+ items:
+ $ref: "#/components/schemas/PaladinContextSource"
+ type: array
+ required:
+ - results
+ type: object
+ CreatePaladinContextSourceInfo:
+ description: Information for adding a context source to a Paladin.
+ example:
+ source_kind: SLACK_CHANNEL
+ third_party_provider: SLACK
+ remote_id: C0123456789
+ name: "#access-requests"
+ properties:
+ source_kind:
+ $ref: "#/components/schemas/PaladinContextSourceKind"
+ third_party_provider:
+ $ref: "#/components/schemas/PaladinContextSourceProvider"
+ remote_id:
+ description:
+ The provider's identifier for the source. The Slack channel ID for
+ a channel, or the Notion/Confluence page ID for a document.
+ type: string
+ name:
+ description: An optional human-readable name for the source.
+ type: string
+ url:
+ description: An optional link to the source.
+ type: string
+ required:
+ - source_kind
+ - third_party_provider
+ - remote_id
+ type: object
+ CreatePaladinInfo:
+ description: Information for creating a Paladin.
+ example:
+ name: paladin-agent-1
+ owner_id: 7c86c85d-0651-43e2-a748-d69d658418e8
+ properties:
+ name:
+ description: The name of the Paladin.
+ example: paladin-agent-1
+ type: string
+ owner_id:
+ description: The ID of the owner of the Paladin.
+ example: 7c86c85d-0651-43e2-a748-d69d658418e8
+ format: uuid
+ type: string
+ monitor_mode:
+ description:
+ When true, the Paladin reasons about requests but takes no action.
+ Defaults to true.
+ type: boolean
+ default: true
+ admin_view_only:
+ description:
+ When true, recommendations are visible only to admins. Only
+ meaningful when monitor_mode is true. Defaults to false.
+ type: boolean
+ default: false
+ enabled_connectors:
+ description: The connectors the Paladin is allowed to use.
+ type: array
+ items:
+ $ref: "#/components/schemas/PaladinConnector"
+ instructions:
+ description:
+ The free-form instructions that guide the Paladin's decisions.
+ Optional; if omitted the Paladin is created without instructions.
+ type: string
+ required:
+ - name
+ - owner_id
+ type: object
+ UpdatePaladinInfo:
+ description: Information for updating a Paladin.
+ example:
+ name: paladin-agent-1
+ properties:
+ name:
+ description: The name of the Paladin.
+ example: paladin-agent-1
+ type: string
+ monitor_mode:
+ description:
+ When true, the Paladin reasons about requests but takes no action.
+ If omitted, the existing value is preserved.
+ type: boolean
+ admin_view_only:
+ description:
+ When true, recommendations are visible only to admins. Only
+ meaningful when monitor_mode is true. If omitted, the existing value
+ is preserved.
+ type: boolean
+ enabled_connectors:
+ description:
+ The connectors the Paladin is allowed to use. If omitted, the
+ existing connectors are preserved.
+ type: array
+ items:
+ $ref: "#/components/schemas/PaladinConnector"
+ instructions:
+ description:
+ The free-form instructions that guide the Paladin's decisions. If
+ omitted, the existing instructions are preserved.
+ type: string
+ required:
+ - name
+ type: object
Session:
description: |-
# Session Object
@@ -6744,20 +9651,51 @@ components:
example: 29827fb8-f2dd-4e80-9576-28e31e9934ac
format: uuid
type: string
- remote_id:
- description: The ID of the remote user.
- example: 1234567890
+ remote_id:
+ description: The ID of the remote user.
+ example: 1234567890
+ type: string
+ third_party_provider:
+ description: The third party provider of the remote user.
+ example: GIT_HUB
+ $ref: "#/components/schemas/ThirdPartyProviderEnum"
+ required:
+ - user_id
+ - remote_id
+ - third_party_provider
+ type: object
+
+ InviteUserInfo:
+ description: The information required to invite a user.
+ properties:
+ email:
+ format: email
+ type: string
+ first_name:
+ type: string
+ last_name:
+ type: string
+ role:
+ $ref: "#/components/schemas/UserProductRoleEnum"
+ required:
+ - email
+ - first_name
+ - last_name
+ - role
+ type: object
+ UpdateUserInfo:
+ description: The user fields to update.
+ minProperties: 1
+ properties:
+ manager_id:
+ description: The user's manager ID. Set to null to remove the manager.
+ format: uuid
+ nullable: true
+ type: string
+ position:
+ description: The user's position.
type: string
- third_party_provider:
- description: The third party provider of the remote user.
- example: GIT_HUB
- $ref: "#/components/schemas/ThirdPartyProviderEnum"
- required:
- - user_id
- - remote_id
- - third_party_provider
type: object
-
User:
description: |-
# User Object
@@ -6844,6 +9782,12 @@ components:
- NOT_FOUND
example: ACTIVE
type: string
+ UserProductRoleEnum:
+ description: The product role assigned to a user.
+ enum:
+ - MEMBER
+ - ADMIN
+ type: string
ThirdPartyProviderEnum:
description: The third party provider of the remote user.
enum:
@@ -6990,7 +9934,7 @@ components:
The updated duration for which the group can be accessed (in
minutes). Use 0 for indefinite.
type: integer
- maximum: 525960 # One year
+ maximum: 153722867 # Largest duration Opal can represent (~292 years)
example: 120
access_level_remote_id:
description: The updated remote ID of the access level granted to this group.
@@ -7189,6 +10133,21 @@ components:
risk_sensitivity_override:
allOf:
- $ref: "#/components/schemas/RiskSensitivityEnum"
+ match_remote_name:
+ description:
+ A bool representing whether or not the group's name is synced from
+ the end system. When true, the name is overwritten with the remote
+ name on each sync. Defaults to false.
+ example: False
+ type: boolean
+ match_remote_description:
+ description:
+ A bool representing whether or not the group's description is
+ synced from the end system. When true, the description is
+ overwritten with the remote description on each sync. Defaults to
+ false.
+ example: False
+ type: boolean
last_successful_sync:
readOnly: true
description: Information about the last successful sync of this group.
@@ -7254,6 +10213,20 @@ components:
- access_level_name
- access_level_remote_id
type: object
+ GroupAccessLevelList:
+ description: A list of access levels defined for a group.
+ example:
+ results:
+ - access_level_name: Developer
+ access_level_remote_id: "30"
+ - access_level_name: Maintainer
+ access_level_remote_id: "40"
+ properties:
+ results:
+ items:
+ $ref: "#/components/schemas/GroupAccessLevel"
+ type: array
+ type: object
GroupUser:
description: |-
# Group Access User Object
@@ -7349,6 +10322,8 @@ components:
- ERR_DRY_RUN_MODE_ENABLED
- ERR_HR_IDP_PROVIDER_NOT_LINKED
- ERR_REMOTE_UNRECOVERABLE_ERROR
+ - ERR_REMOTE_TICKET_NOT_FOUND
+ - ERR_CONNECTION_VALIDATION_FAILED
example:
- SUCCESS
type: string
@@ -7577,6 +10552,25 @@ components:
risk_sensitivity_override:
allOf:
- $ref: "#/components/schemas/RiskSensitivityEnum"
+ match_remote_name:
+ description:
+ A bool representing whether or not the group's name should be
+ synced from the end system. When true, the name is overwritten
+ with the remote name on each sync, so a `name` provided together
+ with this field set to true will be replaced at the next sync. If
+ not provided, the current value is left unchanged.
+ example: False
+ type: boolean
+ match_remote_description:
+ description:
+ A bool representing whether or not the group's description should
+ be synced from the end system. When true, the description is
+ overwritten with the remote description on each sync, so a
+ `description` provided together with this field set to true will
+ be replaced at the next sync. If not provided, the current value
+ is left unchanged.
+ example: False
+ type: boolean
required:
- group_id
type: object
@@ -7615,6 +10609,12 @@ components:
- ZENDESK_GROUP
- ZENDESK_ORGANIZATION
- HUBSPOT_TEAM
+ - TABLEAU_GROUP
+ - CONFLUENCE_GROUP
+ - JIRA_GROUP
+ - DOCUSIGN_GROUP
+ - ZOOM_GROUP
+ - LINEAR_TEAM
example: OPAL_GROUP
type: string
ResourceTypeEnum:
@@ -7657,6 +10657,7 @@ components:
- GCP_BIG_QUERY_DATASET
- GCP_BIG_QUERY_TABLE
- GCP_SERVICE_ACCOUNT
+ - GCP_BILLING_ACCOUNT
- GIT_HUB_REPO
- GIT_HUB_ORG_ROLE
- GIT_LAB_PROJECT
@@ -7706,6 +10707,13 @@ components:
- TWINGATE_RESOURCE
- ZENDESK_ROLE
- HUBSPOT_ROLE
+ - ALICLOUD_RAM_ROLE
+ - ALICLOUD_ECS_INSTANCE
+ - DOCUSIGN_PERMISSION_PROFILE
+ - ZOOM_ROLE
+ - ZOOM_LICENSE
+ - LINEAR_ORGANIZATION
+ - LINEAR_PROJECT
example: AWS_IAM_ROLE
type: string
EntityItemTypeEnum:
@@ -7769,6 +10777,7 @@ components:
- GCP_CLOUD_SQL_POSTGRES_INSTANCE
- GCP_CLOUD_SQL_MYSQL_INSTANCE
- GCP_SERVICE_ACCOUNT
+ - GCP_BILLING_ACCOUNT
- GIT_HUB_REPO
- GIT_HUB_ORG_ROLE
- GIT_LAB_PROJECT
@@ -7838,6 +10847,7 @@ components:
- USER
- ACCESS_REVIEW
- OWNER
+ - EVENT
example: RESOURCE
type: string
UpdateGroupResourcesInfo:
@@ -8566,6 +11576,76 @@ components:
type: object
required:
- team_id
+ tableau_group:
+ description: Remote info for Tableau group.
+ properties:
+ group_id:
+ description: The ID of the Tableau group.
+ example: "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
+ type: string
+ type: object
+ required:
+ - group_id
+ confluence_group:
+ description: Remote info for Confluence group.
+ properties:
+ group_id:
+ description: The ID of the Confluence group.
+ example: "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
+ type: string
+ type: object
+ required:
+ - group_id
+ jira_group:
+ description: Remote info for Jira group.
+ properties:
+ group_id:
+ description: The ID of the Jira group.
+ example: "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
+ type: string
+ type: object
+ required:
+ - group_id
+ docusign_group:
+ description: Remote info for Docusign group.
+ properties:
+ group_id:
+ description: The ID of the Docusign group.
+ example: "12345"
+ type: string
+ type: object
+ required:
+ - group_id
+ zoom_group:
+ description: Remote info for Zoom group.
+ properties:
+ group_id:
+ description: The ID of the Zoom group.
+ example: "SoBVexyrQjqCkcxjpBWi6w"
+ type: string
+ type: object
+ required:
+ - group_id
+ docusign_signing_group:
+ description: Remote info for Docusign signing group.
+ properties:
+ signing_group_id:
+ description: The ID of the Docusign signing group.
+ example: "12345"
+ type: string
+ type: object
+ required:
+ - signing_group_id
+ linear_team:
+ description: Remote info for Linear team.
+ properties:
+ team_id:
+ description: The ID of the Linear team.
+ example: 8caed98e-1234-5678-9abc-def012345678
+ type: string
+ type: object
+ required:
+ - team_id
type: object
ResourceRemoteInfo:
description:
@@ -9010,6 +12090,16 @@ components:
required:
- instance_id
- project_id
+ gcp_billing_account:
+ description: Remote info for a GCP billing account.
+ properties:
+ billing_account_id:
+ description: The resource name of the billing account.
+ example: billingAccounts/012345-567890-ABCDEF
+ type: string
+ type: object
+ required:
+ - billing_account_id
gcp_service_account:
description: Remote info for a GCP service account.
properties:
@@ -9252,6 +12342,16 @@ components:
required:
- profile_id
- user_license_id
+ docusign_permission_profile:
+ description: Remote info for Docusign permission profile.
+ properties:
+ permission_profile_id:
+ description: The ID of the Docusign permission profile.
+ example: "12345"
+ type: string
+ type: object
+ required:
+ - permission_profile_id
salesforce_role:
description: Remote info for Salesforce role.
properties:
@@ -9462,6 +12562,66 @@ components:
type: object
required:
- role_id
+ alicloud_ram_role:
+ description: Remote info for AliCloud RAM role.
+ properties:
+ role_arn:
+ description: The ARN of the AliCloud RAM role.
+ example: "acs:ram::1234567890:role/MyRole"
+ type: string
+ type: object
+ required:
+ - role_arn
+ alicloud_ecs_instance:
+ description: Remote info for AliCloud ECS instance.
+ properties:
+ instance_id:
+ description: The ID of the ECS instance.
+ example: "i-bp1a1234567890abcd"
+ type: string
+ type: object
+ required:
+ - instance_id
+ zoom_role:
+ description: Remote info for Zoom role.
+ properties:
+ role_id:
+ description: The ID of the Zoom role.
+ example: "0"
+ type: string
+ type: object
+ required:
+ - role_id
+ zoom_license:
+ description: Remote info for Zoom license (user type).
+ properties:
+ license_type:
+ description: The Zoom user type representing the license (e.g. "2" for Licensed).
+ example: "2"
+ type: string
+ type: object
+ required:
+ - license_type
+ linear_organization:
+ description: Remote info for Linear organization.
+ properties:
+ org_id:
+ description: The ID of the Linear organization.
+ example: df85baa9-0af5-4f28-a5b5-64e4b2ddeedc
+ type: string
+ type: object
+ required:
+ - org_id
+ linear_project:
+ description: Remote info for Linear project.
+ properties:
+ project_id:
+ description: The ID of the Linear project.
+ example: 58ed91a7-1234-5678-9abc-def012345678
+ type: string
+ type: object
+ required:
+ - project_id
type: object
RiskSensitivityEnum:
type: string
@@ -9760,6 +12920,24 @@ components:
risk_sensitivity_override:
allOf:
- $ref: "#/components/schemas/RiskSensitivityEnum"
+ match_remote_name:
+ description:
+ A bool representing whether or not the resource's name should be
+ synced from the end system. When true, the name is overwritten
+ with the remote name on each sync, so a `name` provided together
+ with this field set to true will be replaced at the next sync.
+ Defaults to false.
+ example: False
+ type: boolean
+ match_remote_description:
+ description:
+ A bool representing whether or not the resource's description
+ should be synced from the end system. When true, the description
+ is overwritten with the remote description on each sync, so a
+ `description` provided together with this field set to true will
+ be replaced at the next sync. Defaults to false.
+ example: False
+ type: boolean
required:
- name
- resource_type
@@ -9939,6 +13117,44 @@ components:
risk_sensitivity_override:
allOf:
- $ref: "#/components/schemas/RiskSensitivityEnum"
+ match_remote_name:
+ description:
+ A bool representing whether or not the group's name should be
+ synced from the end system. When true, the name is overwritten
+ with the remote name on each sync, so a `name` provided together
+ with this field set to true will be replaced at the next sync.
+ Defaults to false.
+ example: False
+ type: boolean
+ match_remote_description:
+ description:
+ A bool representing whether or not the group's description should
+ be synced from the end system. When true, the description is
+ overwritten with the remote description on each sync, so a
+ `description` provided together with this field set to true will
+ be replaced at the next sync. Defaults to false.
+ example: False
+ type: boolean
+ handle:
+ description:
+ Slack user group mention name, without the @. Optional; Slack
+ assigns one if omitted.
+ type: string
+ example: eng-oncall
+ team_id:
+ description:
+ Slack workspace ID. Required when the Slack connection spans
+ multiple workspaces.
+ type: string
+ example: T01234567
+ initial_user_ids:
+ description:
+ Opal user IDs to add as the group's initial members. Required when
+ creating a Slack user group.
+ type: array
+ items:
+ format: uuid
+ type: string
required:
- name
- group_type
@@ -10331,13 +13547,197 @@ components:
- field_name
- field_type
- field_value
+ RequestTemplateCustomFieldCalloutMetadata:
+ description:
+ The message shown to a requester by a `CALLOUT` field, and how prominently to
+ show it.
+ type: object
+ properties:
+ severity:
+ description: How prominently the message is shown.
+ enum:
+ - INFO
+ - WARNING
+ - ERROR
+ type: string
+ example: WARNING
+ text:
+ description: The message shown to the requester.
+ type: string
+ example: This role grants access to production customer data.
+ required:
+ - severity
+ - text
+ RequestTemplateCustomFieldMultiChoiceMetadata:
+ description: The options a requester can pick from in a `MULTI_CHOICE` or `MULTI_SELECT` field.
+ type: object
+ properties:
+ options:
+ items:
+ type: string
+ type: array
+ example:
+ - Incident response
+ - Scheduled maintenance
+ required:
+ - options
+ RequestTemplateCustomFieldInput:
+ description:
+ A field to put on a request template. Separate from `RequestTemplateCustomField`
+ because a callout's name may be omitted on write, while a field read back always
+ has one.
+ type: object
+ properties:
+ name:
+ description:
+ The label shown to the requester. Required for every type except `CALLOUT`,
+ which is display-only -- its name is an internal identifier, never displayed,
+ and is generated if omitted.
+ type: string
+ example: Why do you need this access?
+ description:
+ description: Helper text shown beneath the field.
+ type: string
+ nullable: true
+ type:
+ $ref: "#/components/schemas/RequestTemplateCustomFieldTypeEnum"
+ required:
+ description:
+ Whether the requester must answer. Ignored for `CALLOUT` fields, which
+ collect no answer.
+ type: boolean
+ example: true
+ metadata:
+ $ref: "#/components/schemas/RequestTemplateCustomFieldMetadata"
+ required:
+ - type
+ RequestTemplateCustomFieldMetadata:
+ description:
+ Extra configuration for field types that need it. Exactly one member is set, and
+ which one is determined by the field's `type`.
+ type: object
+ properties:
+ callout_data:
+ $ref: "#/components/schemas/RequestTemplateCustomFieldCalloutMetadata"
+ multi_choice_data:
+ $ref: "#/components/schemas/RequestTemplateCustomFieldMultiChoiceMetadata"
+ RequestTemplateCustomField:
+ description: A field on a request template.
+ type: object
+ properties:
+ name:
+ description:
+ The label shown to the requester. `CALLOUT` fields are display-only, so
+ their name is an internal identifier and is never displayed.
+ type: string
+ example: Why do you need this access?
+ description:
+ description: Helper text shown beneath the field.
+ type: string
+ nullable: true
+ type:
+ $ref: "#/components/schemas/RequestTemplateCustomFieldTypeEnum"
+ required:
+ description:
+ Whether the requester must answer. Always false for `CALLOUT` fields, which
+ collect no answer.
+ type: boolean
+ example: true
+ metadata:
+ $ref: "#/components/schemas/RequestTemplateCustomFieldMetadata"
+ required:
+ - name
+ - type
+ RequestTemplate:
+ description: A template describing what a requester is asked when requesting access.
+ type: object
+ properties:
+ request_template_id:
+ description: The ID of the request template.
+ example: 7c86c85d-0651-43e2-a748-d69d658418e8
+ format: uuid
+ type: string
+ name:
+ description: The name of the request template.
+ example: Production access questions
+ type: string
+ custom_fields:
+ description: The fields on this template, in the order they are shown.
+ items:
+ $ref: "#/components/schemas/RequestTemplateCustomField"
+ type: array
+ required:
+ - request_template_id
+ - name
+ PaginatedRequestTemplateList:
+ type: object
+ properties:
+ next:
+ description: The cursor with which to continue pagination if additional result pages exist.
+ type: string
+ nullable: true
+ example: cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzAyMTMlMkIwMCUzQTAw
+ previous:
+ description: The cursor used to obtain the current result page.
+ type: string
+ nullable: true
+ example: cj0xJnA9MjAyMS0wMS0wNSswMyUzQTI0JTNBNTMuNDMwMjEz
+ results:
+ items:
+ $ref: "#/components/schemas/RequestTemplate"
+ type: array
+ CreateRequestTemplateInfo:
+ description: Information for creating a request template.
+ type: object
+ properties:
+ name:
+ description: The name of the request template.
+ example: Production access questions
+ type: string
+ custom_fields:
+ description: The fields to put on the template, in the order they are shown.
+ items:
+ $ref: "#/components/schemas/RequestTemplateCustomFieldInput"
+ type: array
+ required:
+ - name
+ UpdateRequestTemplateInfo:
+ description:
+ Information for updating a request template. Omitted properties are left
+ unchanged, but `custom_fields` replaces the template's fields wholesale when
+ provided.
+ type: object
+ properties:
+ request_template_id:
+ description: The ID of the request template to update.
+ example: 7c86c85d-0651-43e2-a748-d69d658418e8
+ format: uuid
+ type: string
+ name:
+ description: The new name of the request template.
+ type: string
+ custom_fields:
+ description:
+ The complete set of fields for the template. Any field not included is
+ removed.
+ items:
+ $ref: "#/components/schemas/RequestTemplateCustomFieldInput"
+ type: array
+ required:
+ - request_template_id
RequestTemplateCustomFieldTypeEnum:
- description: The type of the custom request field.
+ description:
+ The type of the custom request field. `CALLOUT` fields are display-only --
+ they
+ show a message to the requester and collect no answer, so they never appear in a
+ request's `custom_fields`.
enum:
- SHORT_TEXT
- LONG_TEXT
- BOOLEAN
- MULTI_CHOICE
+ - MULTI_SELECT
+ - CALLOUT
type: string
RequestList:
description: |-
@@ -10579,6 +13979,21 @@ components:
example:
- f454d283-ca67-4a8a-bdbb-df212eca5347
- f454d283-ca67-4a8a-bdbb-df212eca5348
+ match_remote_name:
+ description:
+ A bool representing whether or not the resource's name is synced
+ from the end system. When true, the name is overwritten with the
+ remote name on each sync. Defaults to false.
+ example: False
+ type: boolean
+ match_remote_description:
+ description:
+ A bool representing whether or not the resource's description is
+ synced from the end system. When true, the description is
+ overwritten with the remote description on each sync. Defaults to
+ false.
+ example: False
+ type: boolean
last_successful_sync:
readOnly: true
description: Information about the last successful sync of this resource.
@@ -10743,6 +14158,25 @@ components:
risk_sensitivity_override:
allOf:
- $ref: "#/components/schemas/RiskSensitivityEnum"
+ match_remote_name:
+ description:
+ A bool representing whether or not the resource's name should be
+ synced from the end system. When true, the name is overwritten
+ with the remote name on each sync, so a `name` provided together
+ with this field set to true will be replaced at the next sync. If
+ not provided, the current value is left unchanged.
+ example: False
+ type: boolean
+ match_remote_description:
+ description:
+ A bool representing whether or not the resource's description
+ should be synced from the end system. When true, the description
+ is overwritten with the remote description on each sync, so a
+ `description` provided together with this field set to true will
+ be replaced at the next sync. If not provided, the current value
+ is left unchanged.
+ example: False
+ type: boolean
configuration_template_id:
description: The ID of the associated configuration template.
example: 06851574-e50d-40ca-8c78-f72ae6ab4304
@@ -11595,7 +15029,8 @@ components:
max_duration_minutes:
description:
The maximum duration for which the resource can be requested (in
- minutes).
+ minutes). Capped at 1 year (525600) unless a longer maximum has been
+ enabled for your organization. Use -1 for an indefinite duration.
type: integer
example: 120
recommended_duration_minutes:
@@ -12952,7 +16387,14 @@ components:
required:
- results
type: object
+ StopCampaignRequest:
+ properties:
+ revoke_unreviewed:
+ default: false
+ description: Revoke all unreviewed access grants. Access grants with no reviewer decision will be immediately revoked.
+ type: boolean
+ type: object
securitySchemes:
BearerAuth:
scheme: bearer
- type: http
\ No newline at end of file
+ type: http
diff --git a/docs/AccessEntityFilters.md b/docs/AccessEntityFilters.md
index 73e34e2..b697c37 100644
--- a/docs/AccessEntityFilters.md
+++ b/docs/AccessEntityFilters.md
@@ -10,6 +10,8 @@ Name | Type | Description | Notes
**entity_item_types** | [**List[EntityItemTypeEnum]**](EntityItemTypeEnum.md) | Filter by entity item types. | [optional]
**entity_name** | [**EntityNameFilter**](EntityNameFilter.md) | | [optional]
**entity_tag** | [**EntityTagFilter**](EntityTagFilter.md) | | [optional]
+**hr_idp_status** | [**IdpStatusFilter**](IdpStatusFilter.md) | | [optional]
+**entity_admin_owner** | [**EntityAdminFilter**](EntityAdminFilter.md) | | [optional]
**entity_ids** | **List[UUID]** | Filter by specific entity UUIDs. | [optional]
**imported_from_app** | **List[UUID]** | Filter by app IDs from which returned nodes will be imported from. | [optional]
**role_remote_ids** | **List[str]** | Filter by role remote IDs. Can only be applied within a hasAccessTo clause. | [optional]
diff --git a/docs/AppTypeEnum.md b/docs/AppTypeEnum.md
index 2bc6e0a..a65437c 100644
--- a/docs/AppTypeEnum.md
+++ b/docs/AppTypeEnum.md
@@ -22,14 +22,20 @@ The type of an app.
* `CUSTOM` (value: `'CUSTOM'`)
+* `CONFLUENCE` (value: `'CONFLUENCE'`)
+
* `CUSTOM_CONNECTOR` (value: `'CUSTOM_CONNECTOR'`)
* `DATABRICKS` (value: `'DATABRICKS'`)
* `DATASTAX_ASTRA` (value: `'DATASTAX_ASTRA'`)
+* `ALICLOUD` (value: `'ALICLOUD'`)
+
* `DEVIN` (value: `'DEVIN'`)
+* `DOCUSIGN` (value: `'DOCUSIGN'`)
+
* `DUO` (value: `'DUO'`)
* `GCP` (value: `'GCP'`)
@@ -50,8 +56,12 @@ The type of an app.
* `INCIDENTIO` (value: `'INCIDENTIO'`)
+* `JIRA` (value: `'JIRA'`)
+
* `LDAP` (value: `'LDAP'`)
+* `LINEAR` (value: `'LINEAR'`)
+
* `MARIADB` (value: `'MARIADB'`)
* `MONGO` (value: `'MONGO'`)
@@ -86,6 +96,8 @@ The type of an app.
* `SLACK` (value: `'SLACK'`)
+* `TABLEAU` (value: `'TABLEAU'`)
+
* `TAILSCALE` (value: `'TAILSCALE'`)
* `TELEPORT` (value: `'TELEPORT'`)
@@ -98,6 +110,8 @@ The type of an app.
* `ZENDESK` (value: `'ZENDESK'`)
+* `ZOOM` (value: `'ZOOM'`)
+
[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
diff --git a/docs/Campaign.md b/docs/Campaign.md
new file mode 100644
index 0000000..e59f4f9
--- /dev/null
+++ b/docs/Campaign.md
@@ -0,0 +1,43 @@
+# Campaign
+
+An access review campaign.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**campaign_id** | **UUID** | The ID of the campaign. |
+**name** | **str** | The name of the campaign. |
+**status** | [**CampaignStatusEnum**](CampaignStatusEnum.md) | |
+**is_template** | **bool** | Whether this campaign is a recurring schedule template. Templates spawn draft campaigns on schedule rather than being reviewed directly. |
+**created_at** | **datetime** | The creation time of the campaign. |
+**updated_at** | **datetime** | The last updated time of the campaign. |
+**created_by_user_id** | **UUID** | The ID of the user who created the campaign. |
+**configuration** | [**CampaignConfiguration**](CampaignConfiguration.md) | The campaign's configuration, if set. | [optional]
+**started_at** | **datetime** | The time the campaign was started, if started. | [optional]
+**started_by_user_id** | **UUID** | The ID of the user who started the campaign, if started. | [optional]
+**stopped_at** | **datetime** | The time the campaign was manually stopped, if stopped. | [optional]
+**stopped_by_user_id** | **UUID** | The ID of the user who stopped the campaign, if stopped. | [optional]
+**ended_at** | **datetime** | The time the campaign reached its scheduled end, if ended. | [optional]
+**ended_by_user_id** | **UUID** | The ID of the user who ended the campaign, if ended. | [optional]
+
+## Example
+
+```python
+from opal_security.models.campaign import Campaign
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of Campaign from a JSON string
+campaign_instance = Campaign.from_json(json)
+# print the JSON string representation of the object
+print(Campaign.to_json())
+
+# convert the object into a dict
+campaign_dict = campaign_instance.to_dict()
+# create an instance of Campaign from a dict
+campaign_from_dict = Campaign.from_dict(campaign_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignConfiguration.md b/docs/CampaignConfiguration.md
new file mode 100644
index 0000000..5a4ab1b
--- /dev/null
+++ b/docs/CampaignConfiguration.md
@@ -0,0 +1,52 @@
+# CampaignConfiguration
+
+Configuration for an access review campaign.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**configuration_id** | **UUID** | The ID of the campaign configuration. |
+**created_at** | **datetime** | The creation time of the configuration. |
+**updated_at** | **datetime** | The last updated time of the configuration. |
+**query** | [**OpalAccessPathQueryBody**](OpalAccessPathQueryBody.md) | Access-path query defining the scope of access to review. Uses the same principalFilter / entitlementFilter shape as ACCESS_PATH OpalQuery. | [optional]
+**reviewer_assignment_policy** | [**UARReviewerAssignmentPolicyEnum**](UARReviewerAssignmentPolicyEnum.md) | |
+**allow_self_review** | **bool** | Whether reviewers can review their own access. |
+**send_reviewer_assignment_notification** | **bool** | Whether to notify reviewers upon assignment. |
+**allow_reviewer_reassignment** | **bool** | Whether reviewers may reassign their reviews to another user. |
+**start_date** | **datetime** | Scheduled start date of the campaign. | [optional]
+**end_date** | **datetime** | Scheduled end date of the campaign. | [optional]
+**timezone** | **str** | IANA timezone used to interpret campaign deadlines (e.g. America/Los_Angeles). |
+**revoke_on** | [**CampaignRevokeOnEnum**](CampaignRevokeOnEnum.md) | |
+**reminder_schedule** | **List[int]** | Days before end date to send reminder notifications. | [optional]
+**reminder_include_manager** | **bool** | Whether to include the reviewer's manager in reminders. |
+**require_reason_on_denial** | **bool** | Whether reviewers must provide a reason when denying (revoking) access. |
+**hide_ai_suggestions** | **bool** | Whether AI suggestions are hidden from reviewers. |
+**custom_start_message** | **str** | Optional custom message included when notifying reviewers that the campaign started. | [optional]
+**group_asset_visibility_policy** | [**CampaignGroupAssetVisibilityPolicyEnum**](CampaignGroupAssetVisibilityPolicyEnum.md) | |
+**is_template** | **bool** | Whether this configuration is a recurring schedule template. |
+**cron_expression** | **str** | Cron expression driving the recurring schedule. Null for one-off campaigns. | [optional]
+**next_scheduled_run** | **datetime** | Next time a draft will be generated from this template. | [optional]
+**last_scheduled_run** | **datetime** | Most recent time a draft was generated from this template. | [optional]
+**recurring_duration_days** | **int** | Deadline window in days applied to each draft generated from this template. | [optional]
+
+## Example
+
+```python
+from opal_security.models.campaign_configuration import CampaignConfiguration
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CampaignConfiguration from a JSON string
+campaign_configuration_instance = CampaignConfiguration.from_json(json)
+# print the JSON string representation of the object
+print(CampaignConfiguration.to_json())
+
+# convert the object into a dict
+campaign_configuration_dict = campaign_configuration_instance.to_dict()
+# create an instance of CampaignConfiguration from a dict
+campaign_configuration_from_dict = CampaignConfiguration.from_dict(campaign_configuration_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignGroupAssetVisibilityPolicyEnum.md b/docs/CampaignGroupAssetVisibilityPolicyEnum.md
new file mode 100644
index 0000000..d3fdd4c
--- /dev/null
+++ b/docs/CampaignGroupAssetVisibilityPolicyEnum.md
@@ -0,0 +1,15 @@
+# CampaignGroupAssetVisibilityPolicyEnum
+
+Controls what group assets reviewers can see during the campaign.
+
+## Enum
+
+* `STRICT` (value: `'STRICT'`)
+
+* `VIEW_VISIBLE_AND_ASSIGNED` (value: `'VIEW_VISIBLE_AND_ASSIGNED'`)
+
+* `VIEW_ALL` (value: `'VIEW_ALL'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignItem.md b/docs/CampaignItem.md
new file mode 100644
index 0000000..0eae0de
--- /dev/null
+++ b/docs/CampaignItem.md
@@ -0,0 +1,44 @@
+# CampaignItem
+
+A campaign review item — one direct access edge under review, matching a row on the admin Reviews tab.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**campaign_item_id** | **UUID** | The ID of the campaign item. |
+**campaign_id** | **UUID** | The ID of the parent campaign. |
+**target_type** | [**CampaignItemTargetTypeEnum**](CampaignItemTargetTypeEnum.md) | |
+**role_assignment_id** | **UUID** | The role assignment ID this item reviews (`target_id` when `target_type` is ROLE_ASSIGNMENT). |
+**status** | [**CampaignItemStatusEnum**](CampaignItemStatusEnum.md) | |
+**created_at** | **datetime** | When the item was created (snapshotted into the campaign). |
+**is_target_deleted** | **bool** | True when the underlying role assignment is soft-deleted. |
+**principal_id** | **UUID** | Principal ID from the role assignment. Null if the RA is missing. | [optional]
+**principal_type** | [**EntityTypeEnum**](EntityTypeEnum.md) | Principal entity type. Null if the RA is missing. | [optional]
+**entity_id** | **UUID** | Entitlement entity ID. Null if the RA is missing. | [optional]
+**entity_type** | [**EntityTypeEnum**](EntityTypeEnum.md) | Entitlement entity type. Null if the RA is missing. | [optional]
+**access_level** | [**ResourceAccessLevel**](ResourceAccessLevel.md) | Access level on the role assignment, if any. | [optional]
+**access_level_name** | **str** | Denormalized access level name stored on the campaign item. | [optional]
+**reviews** | [**List[CampaignItemReview]**](CampaignItemReview.md) | Reviewer assignments and decisions for this item. |
+**admin_override** | [**CampaignItemAdminOverride**](CampaignItemAdminOverride.md) | Admin override, if any. | [optional]
+
+## Example
+
+```python
+from opal_security.models.campaign_item import CampaignItem
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CampaignItem from a JSON string
+campaign_item_instance = CampaignItem.from_json(json)
+# print the JSON string representation of the object
+print(CampaignItem.to_json())
+
+# convert the object into a dict
+campaign_item_dict = campaign_item_instance.to_dict()
+# create an instance of CampaignItem from a dict
+campaign_item_from_dict = CampaignItem.from_dict(campaign_item_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignItemAdminOverride.md b/docs/CampaignItemAdminOverride.md
new file mode 100644
index 0000000..32e7a01
--- /dev/null
+++ b/docs/CampaignItemAdminOverride.md
@@ -0,0 +1,32 @@
+# CampaignItemAdminOverride
+
+Admin override applied to a campaign item. When set, it takes precedence over reviewer decisions for status and end-campaign remediations.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**actor_user_id** | **UUID** | The admin who applied the override. |
+**decision** | [**CampaignItemReviewDecisionEnum**](CampaignItemReviewDecisionEnum.md) | |
+**decided_at** | **datetime** | When the override was applied. |
+
+## Example
+
+```python
+from opal_security.models.campaign_item_admin_override import CampaignItemAdminOverride
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CampaignItemAdminOverride from a JSON string
+campaign_item_admin_override_instance = CampaignItemAdminOverride.from_json(json)
+# print the JSON string representation of the object
+print(CampaignItemAdminOverride.to_json())
+
+# convert the object into a dict
+campaign_item_admin_override_dict = campaign_item_admin_override_instance.to_dict()
+# create an instance of CampaignItemAdminOverride from a dict
+campaign_item_admin_override_from_dict = CampaignItemAdminOverride.from_dict(campaign_item_admin_override_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignItemReview.md b/docs/CampaignItemReview.md
new file mode 100644
index 0000000..8e649c9
--- /dev/null
+++ b/docs/CampaignItemReview.md
@@ -0,0 +1,37 @@
+# CampaignItemReview
+
+A single reviewer's assignment and decision for a campaign item.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**campaign_item_review_id** | **UUID** | The ID of the campaign item review. |
+**campaign_item_id** | **UUID** | The ID of the campaign item. |
+**reviewer_user_id** | **UUID** | The ID of the assigned reviewer. |
+**assignment_source** | [**CampaignItemReviewerAssignmentSourceEnum**](CampaignItemReviewerAssignmentSourceEnum.md) | |
+**decision** | [**CampaignItemReviewDecisionEnum**](CampaignItemReviewDecisionEnum.md) | The reviewer's decision. Null when the reviewer has not yet submitted. | [optional]
+**note** | **str** | Optional note from the reviewer. | [optional]
+**updated_access_level_remote_id** | **str** | Target access level remote ID when decision is CHANGE_ROLE. | [optional]
+**decided_at** | **datetime** | When the decision was finalized. | [optional]
+
+## Example
+
+```python
+from opal_security.models.campaign_item_review import CampaignItemReview
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CampaignItemReview from a JSON string
+campaign_item_review_instance = CampaignItemReview.from_json(json)
+# print the JSON string representation of the object
+print(CampaignItemReview.to_json())
+
+# convert the object into a dict
+campaign_item_review_dict = campaign_item_review_instance.to_dict()
+# create an instance of CampaignItemReview from a dict
+campaign_item_review_from_dict = CampaignItemReview.from_dict(campaign_item_review_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignItemReviewDecisionEnum.md b/docs/CampaignItemReviewDecisionEnum.md
new file mode 100644
index 0000000..5b9f69e
--- /dev/null
+++ b/docs/CampaignItemReviewDecisionEnum.md
@@ -0,0 +1,25 @@
+# CampaignItemReviewDecisionEnum
+
+Decision recorded on a campaign item review row.
+
+## Enum
+
+* `APPROVED` (value: `'APPROVED'`)
+
+* `REVOKED` (value: `'REVOKED'`)
+
+* `CHANGE_ROLE` (value: `'CHANGE_ROLE'`)
+
+* `ADMIN_REVOKED` (value: `'ADMIN_REVOKED'`)
+
+* `NO_ACTION` (value: `'NO_ACTION'`)
+
+* `REASSIGNED` (value: `'REASSIGNED'`)
+
+* `ADMIN_OVERRIDE_APPROVED` (value: `'ADMIN_OVERRIDE_APPROVED'`)
+
+* `ADMIN_OVERRIDE_REVOKED` (value: `'ADMIN_OVERRIDE_REVOKED'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignItemReviewerAssignmentSourceEnum.md b/docs/CampaignItemReviewerAssignmentSourceEnum.md
new file mode 100644
index 0000000..ec4b6eb
--- /dev/null
+++ b/docs/CampaignItemReviewerAssignmentSourceEnum.md
@@ -0,0 +1,15 @@
+# CampaignItemReviewerAssignmentSourceEnum
+
+How a reviewer was assigned to a campaign item.
+
+## Enum
+
+* `MANUAL` (value: `'MANUAL'`)
+
+* `PRINCIPAL_MANAGER` (value: `'PRINCIPAL_MANAGER'`)
+
+* `ASSET_ADMIN_OWNER` (value: `'ASSET_ADMIN_OWNER'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignItemStatusEnum.md b/docs/CampaignItemStatusEnum.md
new file mode 100644
index 0000000..3bbad2a
--- /dev/null
+++ b/docs/CampaignItemStatusEnum.md
@@ -0,0 +1,23 @@
+# CampaignItemStatusEnum
+
+Derived aggregate status for a campaign item. Matches the admin Reviews tab Status column labels (undecided items on a stopped campaign are PENDING, not a separate stopped status).
+
+## Enum
+
+* `PENDING` (value: `'PENDING'`)
+
+* `COMPLETED` (value: `'COMPLETED'`)
+
+* `APPROVED` (value: `'APPROVED'`)
+
+* `REVOKED` (value: `'REVOKED'`)
+
+* `NO_ACTION` (value: `'NO_ACTION'`)
+
+* `CHANGED_ROLE` (value: `'CHANGED_ROLE'`)
+
+* `ADMIN_REVOKED` (value: `'ADMIN_REVOKED'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignItemTargetTypeEnum.md b/docs/CampaignItemTargetTypeEnum.md
new file mode 100644
index 0000000..d6557f8
--- /dev/null
+++ b/docs/CampaignItemTargetTypeEnum.md
@@ -0,0 +1,11 @@
+# CampaignItemTargetTypeEnum
+
+Type of access edge the campaign item reviews.
+
+## Enum
+
+* `ROLE_ASSIGNMENT` (value: `'ROLE_ASSIGNMENT'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignRevokeOnEnum.md b/docs/CampaignRevokeOnEnum.md
new file mode 100644
index 0000000..9e0f7d0
--- /dev/null
+++ b/docs/CampaignRevokeOnEnum.md
@@ -0,0 +1,15 @@
+# CampaignRevokeOnEnum
+
+When access decisions take effect during a campaign.
+
+## Enum
+
+* `ACTION` (value: `'ACTION'`)
+
+* `END` (value: `'END'`)
+
+* `NONE` (value: `'NONE'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignStatusEnum.md b/docs/CampaignStatusEnum.md
new file mode 100644
index 0000000..362f82c
--- /dev/null
+++ b/docs/CampaignStatusEnum.md
@@ -0,0 +1,19 @@
+# CampaignStatusEnum
+
+The current status of a campaign.
+
+## Enum
+
+* `DRAFT` (value: `'DRAFT'`)
+
+* `ONGOING` (value: `'ONGOING'`)
+
+* `COMPLETED` (value: `'COMPLETED'`)
+
+* `STOPPED` (value: `'STOPPED'`)
+
+* `ENDED` (value: `'ENDED'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CampaignsApi.md b/docs/CampaignsApi.md
new file mode 100644
index 0000000..39fac63
--- /dev/null
+++ b/docs/CampaignsApi.md
@@ -0,0 +1,834 @@
+# opal_security.CampaignsApi
+
+All URIs are relative to *https://api.opal.dev/v1*
+
+Method | HTTP request | Description
+------------- | ------------- | -------------
+[**create_campaign**](CampaignsApi.md#create_campaign) | **POST** /campaigns |
+[**end_campaign**](CampaignsApi.md#end_campaign) | **POST** /campaigns/{campaign_id}/end | End campaign
+[**get_campaign**](CampaignsApi.md#get_campaign) | **GET** /campaigns/{campaign_id} | Get campaign by ID
+[**get_campaign_items**](CampaignsApi.md#get_campaign_items) | **GET** /campaigns/{campaign_id}/items | List campaign items
+[**get_campaign_viewer_items**](CampaignsApi.md#get_campaign_viewer_items) | **GET** /campaigns/{campaign_id}/viewer-items | List viewer campaign items
+[**get_campaigns**](CampaignsApi.md#get_campaigns) | **GET** /campaigns |
+[**start_campaign**](CampaignsApi.md#start_campaign) | **POST** /campaigns/{campaign_id}/start | Start campaign
+[**stop_campaign**](CampaignsApi.md#stop_campaign) | **POST** /campaigns/{campaign_id}/stop | Stop campaign
+[**update_campaign**](CampaignsApi.md#update_campaign) | **PUT** /campaigns/{campaign_id} | Update campaign
+
+
+# **create_campaign**
+> Campaign create_campaign(create_campaign_info)
+
+Creates a campaign. Campaign scope only supports direct access edges:
+`configuration.query.edgeFilter.directOnly` defaults to `true`, is
+always stored as `true`, and passing `false` returns 400.
+
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.campaign import Campaign
+from opal_security.models.create_campaign_info import CreateCampaignInfo
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ create_campaign_info = opal_security.CreateCampaignInfo() # CreateCampaignInfo |
+
+ try:
+ api_response = api_instance.create_campaign(create_campaign_info)
+ print("The response of CampaignsApi->create_campaign:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->create_campaign: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **create_campaign_info** | [**CreateCampaignInfo**](CreateCampaignInfo.md)| |
+
+### Return type
+
+[**Campaign**](Campaign.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**201** | The campaign successfully created. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **end_campaign**
+> Campaign end_campaign(campaign_id)
+
+End campaign
+
+Ends a stopped campaign, setting `ended_at` and `ended_by_user_id`,
+applying pending access changes, and queuing report generation.
+Returns 400 unless the campaign is started and stopped and not already
+ended.
+
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.campaign import Campaign
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ campaign_id = UUID('f454d283-ca87-4a8a-bdbb-df212eca5353') # UUID | The ID of the campaign.
+
+ try:
+ # End campaign
+ api_response = api_instance.end_campaign(campaign_id)
+ print("The response of CampaignsApi->end_campaign:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->end_campaign: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **campaign_id** | **UUID**| The ID of the campaign. |
+
+### Return type
+
+[**Campaign**](Campaign.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The ended `Campaign`. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_campaign**
+> Campaign get_campaign(campaign_id)
+
+Get campaign by ID
+
+Returns a `Campaign` object.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.campaign import Campaign
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ campaign_id = UUID('f454d283-ca87-4a8a-bdbb-df212eca5353') # UUID | The ID of the campaign.
+
+ try:
+ # Get campaign by ID
+ api_response = api_instance.get_campaign(campaign_id)
+ print("The response of CampaignsApi->get_campaign:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->get_campaign: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **campaign_id** | **UUID**| The ID of the campaign. |
+
+### Return type
+
+[**Campaign**](Campaign.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The requested `Campaign`. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_campaign_items**
+> PaginatedCampaignItemsList get_campaign_items(campaign_id, cursor=cursor, page_size=page_size, statuses=statuses, reviewer_user_id=reviewer_user_id, unassigned=unassigned, search=search)
+
+List campaign items
+
+Returns a paginated list of review items for a campaign — the same rows
+shown on the admin Reviews tab. Status is derived using the same rules
+as the UI Status column. Soft-deleted role assignments are still
+returned with `is_target_deleted: true`.
+
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.campaign_item_status_enum import CampaignItemStatusEnum
+from opal_security.models.paginated_campaign_items_list import PaginatedCampaignItemsList
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ campaign_id = UUID('f454d283-ca87-4a8a-bdbb-df212eca5353') # UUID | The ID of the campaign.
+ cursor = 'cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw' # str | The pagination cursor value. (optional)
+ page_size = 200 # int | Number of results to return per page. Default is 200; maximum is 500 (the campaign-items list cap). (optional)
+ statuses = [opal_security.CampaignItemStatusEnum()] # List[CampaignItemStatusEnum] | Filter by derived item status. When multiple values are provided, items matching any status are returned (OR). (optional)
+ reviewer_user_id = UUID('32acc112-21ff-4669-91c2-21e27683eaa1') # UUID | Restrict to items assigned to this reviewer user ID. (optional)
+ unassigned = True # bool | When true, restrict to items with no reviewer assigned. (optional)
+ search = 'search_example' # str | Case-insensitive search over principal name, asset name, and reviewer name. (optional)
+
+ try:
+ # List campaign items
+ api_response = api_instance.get_campaign_items(campaign_id, cursor=cursor, page_size=page_size, statuses=statuses, reviewer_user_id=reviewer_user_id, unassigned=unassigned, search=search)
+ print("The response of CampaignsApi->get_campaign_items:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->get_campaign_items: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **campaign_id** | **UUID**| The ID of the campaign. |
+ **cursor** | **str**| The pagination cursor value. | [optional]
+ **page_size** | **int**| Number of results to return per page. Default is 200; maximum is 500 (the campaign-items list cap). | [optional]
+ **statuses** | [**List[CampaignItemStatusEnum]**](CampaignItemStatusEnum.md)| Filter by derived item status. When multiple values are provided, items matching any status are returned (OR). | [optional]
+ **reviewer_user_id** | **UUID**| Restrict to items assigned to this reviewer user ID. | [optional]
+ **unassigned** | **bool**| When true, restrict to items with no reviewer assigned. | [optional]
+ **search** | **str**| Case-insensitive search over principal name, asset name, and reviewer name. | [optional]
+
+### Return type
+
+[**PaginatedCampaignItemsList**](PaginatedCampaignItemsList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | A page of campaign items. | - |
+**404** | Campaign not found. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_campaign_viewer_items**
+> PaginatedViewerCampaignItemsList get_campaign_viewer_items(campaign_id, cursor=cursor, page_size=page_size, sort_field=sort_field, sort_direction=sort_direction, statuses=statuses, access_level_names=access_level_names, principal_ids=principal_ids, entity_ids=entity_ids, item_ids=item_ids, ai_bucket_id=ai_bucket_id)
+
+List viewer campaign items
+
+Returns a paginated list of campaign review items assigned to the
+current authenticated viewer. Matches GraphQL `Campaign.viewerItems`.
+
+Campaign access matches `GET /campaigns/{campaign_id}` and GraphQL
+`campaign(id)`: the caller must have access-review read permission or
+be a reviewer on the campaign. Otherwise the request fails with 403
+(same as get-by-id). Item rows are still scoped to the caller's own
+reviews (empty page when the caller is an admin but not a reviewer).
+
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.paginated_viewer_campaign_items_list import PaginatedViewerCampaignItemsList
+from opal_security.models.sort_direction_enum import SortDirectionEnum
+from opal_security.models.viewer_campaign_item_sort_field_enum import ViewerCampaignItemSortFieldEnum
+from opal_security.models.viewer_campaign_item_status_enum import ViewerCampaignItemStatusEnum
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ campaign_id = UUID('f454d283-ca87-4a8a-bdbb-df212eca5353') # UUID | The ID of the campaign.
+ cursor = 'cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw' # str | The pagination cursor value. (optional)
+ page_size = 200 # int | Number of results to return per page. Default is 200; maximum is 500. (optional)
+ sort_field = opal_security.ViewerCampaignItemSortFieldEnum() # ViewerCampaignItemSortFieldEnum | Sort by. Omit to sort by created_at. (optional)
+ sort_direction = opal_security.SortDirectionEnum() # SortDirectionEnum | Sort direction. (optional)
+ statuses = [opal_security.ViewerCampaignItemStatusEnum()] # List[ViewerCampaignItemStatusEnum] | Filter by review status. When multiple values are provided, items matching any status are returned (OR). (optional)
+ access_level_names = ['access_level_names_example'] # List[str] | Filter by access level name. (optional)
+ principal_ids = None # List[UUID] | Filter by principal ID. (optional)
+ entity_ids = None # List[UUID] | Filter by entity ID. (optional)
+ item_ids = None # List[UUID] | Filter to specific campaign item review IDs. (optional)
+ ai_bucket_id = UUID('38400000-8cf0-11bd-b23e-10b96e4ef00d') # UUID | Restrict to items in this AI-suggestion bucket. (optional)
+
+ try:
+ # List viewer campaign items
+ api_response = api_instance.get_campaign_viewer_items(campaign_id, cursor=cursor, page_size=page_size, sort_field=sort_field, sort_direction=sort_direction, statuses=statuses, access_level_names=access_level_names, principal_ids=principal_ids, entity_ids=entity_ids, item_ids=item_ids, ai_bucket_id=ai_bucket_id)
+ print("The response of CampaignsApi->get_campaign_viewer_items:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->get_campaign_viewer_items: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **campaign_id** | **UUID**| The ID of the campaign. |
+ **cursor** | **str**| The pagination cursor value. | [optional]
+ **page_size** | **int**| Number of results to return per page. Default is 200; maximum is 500. | [optional]
+ **sort_field** | [**ViewerCampaignItemSortFieldEnum**](.md)| Sort by. Omit to sort by created_at. | [optional]
+ **sort_direction** | [**SortDirectionEnum**](.md)| Sort direction. | [optional]
+ **statuses** | [**List[ViewerCampaignItemStatusEnum]**](ViewerCampaignItemStatusEnum.md)| Filter by review status. When multiple values are provided, items matching any status are returned (OR). | [optional]
+ **access_level_names** | [**List[str]**](str.md)| Filter by access level name. | [optional]
+ **principal_ids** | [**List[UUID]**](UUID.md)| Filter by principal ID. | [optional]
+ **entity_ids** | [**List[UUID]**](UUID.md)| Filter by entity ID. | [optional]
+ **item_ids** | [**List[UUID]**](UUID.md)| Filter to specific campaign item review IDs. | [optional]
+ **ai_bucket_id** | **UUID**| Restrict to items in this AI-suggestion bucket. | [optional]
+
+### Return type
+
+[**PaginatedViewerCampaignItemsList**](PaginatedViewerCampaignItemsList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | A page of viewer campaign items. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_campaigns**
+> PaginatedCampaignsList get_campaigns(cursor=cursor, page_size=page_size, name=name, status=status, created_at_after=created_at_after, created_at_before=created_at_before, started_at_after=started_at_after, started_at_before=started_at_before, ended_at_after=ended_at_after, ended_at_before=ended_at_before, stopped_at_after=stopped_at_after, stopped_at_before=stopped_at_before)
+
+Returns a list of `Campaign` objects.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.campaign_status_enum import CampaignStatusEnum
+from opal_security.models.paginated_campaigns_list import PaginatedCampaignsList
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ cursor = 'cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw' # str | The pagination cursor value. (optional)
+ page_size = 200 # int | Number of results to return per page. Default is 200. (optional)
+ name = 'Q3 Access Review' # str | Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive). (optional)
+ status = opal_security.CampaignStatusEnum() # CampaignStatusEnum | Filter by campaign status. Status is derived from lifecycle timestamps and review progress. (optional)
+ created_at_after = '2026-01-01T00:00:00Z' # datetime | Include campaigns created after this timestamp (exclusive). ISO 8601 format. (optional)
+ created_at_before = '2026-12-31T23:59:59Z' # datetime | Include campaigns created before this timestamp (exclusive). ISO 8601 format. (optional)
+ started_at_after = '2026-01-01T00:00:00Z' # datetime | Include campaigns started after this timestamp (exclusive). ISO 8601 format. (optional)
+ started_at_before = '2026-12-31T23:59:59Z' # datetime | Include campaigns started before this timestamp (exclusive). ISO 8601 format. (optional)
+ ended_at_after = '2026-01-01T00:00:00Z' # datetime | Include campaigns ended after this timestamp (exclusive). ISO 8601 format. (optional)
+ ended_at_before = '2026-12-31T23:59:59Z' # datetime | Include campaigns ended before this timestamp (exclusive). ISO 8601 format. (optional)
+ stopped_at_after = '2026-01-01T00:00:00Z' # datetime | Include campaigns stopped after this timestamp (exclusive). ISO 8601 format. (optional)
+ stopped_at_before = '2026-12-31T23:59:59Z' # datetime | Include campaigns stopped before this timestamp (exclusive). ISO 8601 format. (optional)
+
+ try:
+ api_response = api_instance.get_campaigns(cursor=cursor, page_size=page_size, name=name, status=status, created_at_after=created_at_after, created_at_before=created_at_before, started_at_after=started_at_after, started_at_before=started_at_before, ended_at_after=ended_at_after, ended_at_before=ended_at_before, stopped_at_after=stopped_at_after, stopped_at_before=stopped_at_before)
+ print("The response of CampaignsApi->get_campaigns:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->get_campaigns: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **cursor** | **str**| The pagination cursor value. | [optional]
+ **page_size** | **int**| Number of results to return per page. Default is 200. | [optional]
+ **name** | **str**| Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive). | [optional]
+ **status** | [**CampaignStatusEnum**](.md)| Filter by campaign status. Status is derived from lifecycle timestamps and review progress. | [optional]
+ **created_at_after** | **datetime**| Include campaigns created after this timestamp (exclusive). ISO 8601 format. | [optional]
+ **created_at_before** | **datetime**| Include campaigns created before this timestamp (exclusive). ISO 8601 format. | [optional]
+ **started_at_after** | **datetime**| Include campaigns started after this timestamp (exclusive). ISO 8601 format. | [optional]
+ **started_at_before** | **datetime**| Include campaigns started before this timestamp (exclusive). ISO 8601 format. | [optional]
+ **ended_at_after** | **datetime**| Include campaigns ended after this timestamp (exclusive). ISO 8601 format. | [optional]
+ **ended_at_before** | **datetime**| Include campaigns ended before this timestamp (exclusive). ISO 8601 format. | [optional]
+ **stopped_at_after** | **datetime**| Include campaigns stopped after this timestamp (exclusive). ISO 8601 format. | [optional]
+ **stopped_at_before** | **datetime**| Include campaigns stopped before this timestamp (exclusive). ISO 8601 format. | [optional]
+
+### Return type
+
+[**PaginatedCampaignsList**](PaginatedCampaignsList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | A list of campaigns for your organization. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **start_campaign**
+> Campaign start_campaign(campaign_id)
+
+Start campaign
+
+Starts a draft campaign immediately, setting `started_at` and
+`started_by_user_id`. Returns 400 if the campaign is not in draft
+state, or if it is a recurring template (`is_template: true`) —
+templates spawn draft campaigns on their schedule and cannot be
+started directly.
+
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.campaign import Campaign
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ campaign_id = UUID('f454d283-ca87-4a8a-bdbb-df212eca5353') # UUID | The ID of the campaign.
+
+ try:
+ # Start campaign
+ api_response = api_instance.start_campaign(campaign_id)
+ print("The response of CampaignsApi->start_campaign:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->start_campaign: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **campaign_id** | **UUID**| The ID of the campaign. |
+
+### Return type
+
+[**Campaign**](Campaign.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The started `Campaign`. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **stop_campaign**
+> Campaign stop_campaign(campaign_id, stop_campaign_request=stop_campaign_request)
+
+Stop campaign
+
+Stops an ongoing campaign immediately, setting `stopped_at` and
+`stopped_by_user_id`. Returns 400 if the campaign has not started or
+has already stopped.
+
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.campaign import Campaign
+from opal_security.models.stop_campaign_request import StopCampaignRequest
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ campaign_id = UUID('f454d283-ca87-4a8a-bdbb-df212eca5353') # UUID | The ID of the campaign.
+ stop_campaign_request = opal_security.StopCampaignRequest() # StopCampaignRequest | (optional)
+
+ try:
+ # Stop campaign
+ api_response = api_instance.stop_campaign(campaign_id, stop_campaign_request=stop_campaign_request)
+ print("The response of CampaignsApi->stop_campaign:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->stop_campaign: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **campaign_id** | **UUID**| The ID of the campaign. |
+ **stop_campaign_request** | [**StopCampaignRequest**](StopCampaignRequest.md)| | [optional]
+
+### Return type
+
+[**Campaign**](Campaign.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The stopped `Campaign`. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **update_campaign**
+> Campaign update_campaign(campaign_id, update_campaign_info)
+
+Update campaign
+
+Partially updates a campaign. Omitted fields are left unchanged.
+`configuration.query` and `configuration.reviewer_assignment_policy`
+cannot be updated after create; including either field returns 400.
+`configuration.cron_expression` and
+`configuration.recurring_duration_days` may only be set on template
+campaigns; setting them on a one-off campaign returns 400.
+`configuration.is_template` is immutable and not accepted on update.
+Configuration updates on a stopped or ended (non-template) campaign
+return 400. Name-only updates are still allowed.
+
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.campaign import Campaign
+from opal_security.models.update_campaign_info import UpdateCampaignInfo
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.CampaignsApi(api_client)
+ campaign_id = UUID('f454d283-ca87-4a8a-bdbb-df212eca5353') # UUID | The ID of the campaign.
+ update_campaign_info = opal_security.UpdateCampaignInfo() # UpdateCampaignInfo |
+
+ try:
+ # Update campaign
+ api_response = api_instance.update_campaign(campaign_id, update_campaign_info)
+ print("The response of CampaignsApi->update_campaign:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling CampaignsApi->update_campaign: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **campaign_id** | **UUID**| The ID of the campaign. |
+ **update_campaign_info** | [**UpdateCampaignInfo**](UpdateCampaignInfo.md)| |
+
+### Return type
+
+[**Campaign**](Campaign.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The updated `Campaign`. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
diff --git a/docs/CreateCampaignConfigurationInfo.md b/docs/CreateCampaignConfigurationInfo.md
new file mode 100644
index 0000000..7a4ac37
--- /dev/null
+++ b/docs/CreateCampaignConfigurationInfo.md
@@ -0,0 +1,48 @@
+# CreateCampaignConfigurationInfo
+
+Configuration to apply when creating a campaign. `query` is required; other omitted fields use defaults.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**query** | [**OpalAccessPathQueryBody**](OpalAccessPathQueryBody.md) | Access-path query defining the scope of access to review. Required. Uses the same principalFilter / entitlementFilter shape as ACCESS_PATH OpalQuery. Must include at least one of principalFilter or entitlementFilter. Campaign scope only supports direct access edges: `edgeFilter.directOnly` defaults to `true`, is always stored as `true`, and passing `false` returns 400. |
+**reviewer_assignment_policy** | [**UARReviewerAssignmentPolicyEnum**](UARReviewerAssignmentPolicyEnum.md) | | [optional]
+**allow_self_review** | **bool** | Whether reviewers can review their own access. | [optional]
+**send_reviewer_assignment_notification** | **bool** | Whether to notify reviewers upon assignment. | [optional]
+**allow_reviewer_reassignment** | **bool** | Whether reviewers may reassign their reviews to another user. | [optional]
+**start_date** | **datetime** | Scheduled start date of the campaign. | [optional]
+**end_date** | **datetime** | Scheduled end date of the campaign. | [optional]
+**timezone** | **str** | IANA timezone used to interpret campaign deadlines (e.g. America/Los_Angeles). | [optional]
+**revoke_on** | [**CampaignRevokeOnEnum**](CampaignRevokeOnEnum.md) | | [optional]
+**reminder_schedule** | **List[int]** | Days before end date to send reminder notifications. | [optional]
+**reminder_include_manager** | **bool** | Whether to include the reviewer's manager in reminders. | [optional]
+**require_reason_on_denial** | **bool** | Whether reviewers must provide a reason when denying (revoking) access. | [optional]
+**hide_ai_suggestions** | **bool** | Whether AI suggestions are hidden from reviewers. | [optional]
+**custom_start_message** | **str** | Optional custom message included when notifying reviewers that the campaign started. | [optional]
+**group_asset_visibility_policy** | [**CampaignGroupAssetVisibilityPolicyEnum**](CampaignGroupAssetVisibilityPolicyEnum.md) | | [optional]
+**is_template** | **bool** | Whether this configuration is a recurring schedule template. | [optional]
+**cron_expression** | **str** | Cron expression driving the recurring schedule. Null for one-off campaigns. | [optional]
+**recurring_duration_days** | **int** | Deadline window in days applied to each draft generated from this template. | [optional]
+**excluded_role_assignment_ids** | **List[UUID]** | Role assignment IDs to exclude from the campaign scope during population. | [optional]
+
+## Example
+
+```python
+from opal_security.models.create_campaign_configuration_info import CreateCampaignConfigurationInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CreateCampaignConfigurationInfo from a JSON string
+create_campaign_configuration_info_instance = CreateCampaignConfigurationInfo.from_json(json)
+# print the JSON string representation of the object
+print(CreateCampaignConfigurationInfo.to_json())
+
+# convert the object into a dict
+create_campaign_configuration_info_dict = create_campaign_configuration_info_instance.to_dict()
+# create an instance of CreateCampaignConfigurationInfo from a dict
+create_campaign_configuration_info_from_dict = CreateCampaignConfigurationInfo.from_dict(create_campaign_configuration_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CreateCampaignInfo.md b/docs/CreateCampaignInfo.md
new file mode 100644
index 0000000..e7a1851
--- /dev/null
+++ b/docs/CreateCampaignInfo.md
@@ -0,0 +1,31 @@
+# CreateCampaignInfo
+
+# CreateCampaignInfo Object ### Description The `CreateCampaignInfo` object is used to create a campaign. ### Usage Example Use in the `POST Campaigns` endpoint.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**name** | **str** | The name of the campaign. |
+**configuration** | [**CreateCampaignConfigurationInfo**](CreateCampaignConfigurationInfo.md) | Configuration for the campaign. Required; must include a query. Other omitted fields use defaults. |
+
+## Example
+
+```python
+from opal_security.models.create_campaign_info import CreateCampaignInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CreateCampaignInfo from a JSON string
+create_campaign_info_instance = CreateCampaignInfo.from_json(json)
+# print the JSON string representation of the object
+print(CreateCampaignInfo.to_json())
+
+# convert the object into a dict
+create_campaign_info_dict = create_campaign_info_instance.to_dict()
+# create an instance of CreateCampaignInfo from a dict
+create_campaign_info_from_dict = CreateCampaignInfo.from_dict(create_campaign_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CreateGroupInfo.md b/docs/CreateGroupInfo.md
index 28c71d7..13d072d 100644
--- a/docs/CreateGroupInfo.md
+++ b/docs/CreateGroupInfo.md
@@ -15,6 +15,11 @@ Name | Type | Description | Notes
**metadata** | **str** | Deprecated - use remote_info instead. JSON metadata about the remote group. Include only for items linked to remote systems. See [this guide](https://docs.opal.dev/reference/end-system-objects) for details on how to specify this field. The required format is dependent on group_type and should have the following schema: <style type=\"text/css\"> code {max-height:300px !important} </style> ```json { \"$schema\": \"http://json-schema.org/draft-04/schema#\", \"title\": \"Group Metadata\", \"properties\": { \"ad_group\": { \"properties\": { \"object_guid\": { \"type\": \"string\" } }, \"required\": [\"object_guid\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Active Directory Group\" }, \"duo_group\": { \"properties\": { \"group_id\": { \"type\": \"string\" } }, \"required\": [\"group_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Duo Group\" }, \"git_hub_team\": { \"properties\": { \"org_name\": { \"type\": \"string\" }, \"team_slug\": { \"type\": \"string\" } }, \"required\": [\"org_name\", \"team_slug\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GitHub Team\" }, \"google_groups_group\": { \"properties\": { \"group_id\": { \"type\": \"string\" } }, \"required\": [\"group_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Google Groups Group\" }, \"ldap_group\": { \"properties\": { \"group_uid\": { \"type\": \"string\" } }, \"required\": [\"group_uid\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"LDAP Group\" }, \"okta_directory_group\": { \"properties\": { \"group_id\": { \"type\": \"string\" } }, \"required\": [\"group_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Okta Directory Group\" } }, \"additionalProperties\": false, \"minProperties\": 1, \"maxProperties\": 1, \"type\": \"object\" } ``` | [optional]
**custom_request_notification** | **str** | Custom request notification sent upon request approval. | [optional]
**risk_sensitivity_override** | [**RiskSensitivityEnum**](RiskSensitivityEnum.md) | | [optional]
+**match_remote_name** | **bool** | A bool representing whether or not the group's name should be synced from the end system. When true, the name is overwritten with the remote name on each sync, so a `name` provided together with this field set to true will be replaced at the next sync. Defaults to false. | [optional]
+**match_remote_description** | **bool** | A bool representing whether or not the group's description should be synced from the end system. When true, the description is overwritten with the remote description on each sync, so a `description` provided together with this field set to true will be replaced at the next sync. Defaults to false. | [optional]
+**handle** | **str** | Slack user group mention name, without the @. Optional; Slack assigns one if omitted. | [optional]
+**team_id** | **str** | Slack workspace ID. Required when the Slack connection spans multiple workspaces. | [optional]
+**initial_user_ids** | **List[UUID]** | Opal user IDs to add as the group's initial members. Required when creating a Slack user group. | [optional]
## Example
diff --git a/docs/CreatePaladinContextSourceInfo.md b/docs/CreatePaladinContextSourceInfo.md
new file mode 100644
index 0000000..f92a7cf
--- /dev/null
+++ b/docs/CreatePaladinContextSourceInfo.md
@@ -0,0 +1,34 @@
+# CreatePaladinContextSourceInfo
+
+Information for adding a context source to a Paladin.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**source_kind** | [**PaladinContextSourceKind**](PaladinContextSourceKind.md) | |
+**third_party_provider** | [**PaladinContextSourceProvider**](PaladinContextSourceProvider.md) | |
+**remote_id** | **str** | The provider's identifier for the source. The Slack channel ID for a channel, or the Notion/Confluence page ID for a document. |
+**name** | **str** | An optional human-readable name for the source. | [optional]
+**url** | **str** | An optional link to the source. | [optional]
+
+## Example
+
+```python
+from opal_security.models.create_paladin_context_source_info import CreatePaladinContextSourceInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CreatePaladinContextSourceInfo from a JSON string
+create_paladin_context_source_info_instance = CreatePaladinContextSourceInfo.from_json(json)
+# print the JSON string representation of the object
+print(CreatePaladinContextSourceInfo.to_json())
+
+# convert the object into a dict
+create_paladin_context_source_info_dict = create_paladin_context_source_info_instance.to_dict()
+# create an instance of CreatePaladinContextSourceInfo from a dict
+create_paladin_context_source_info_from_dict = CreatePaladinContextSourceInfo.from_dict(create_paladin_context_source_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CreatePaladinInfo.md b/docs/CreatePaladinInfo.md
new file mode 100644
index 0000000..1454695
--- /dev/null
+++ b/docs/CreatePaladinInfo.md
@@ -0,0 +1,35 @@
+# CreatePaladinInfo
+
+Information for creating a Paladin.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**name** | **str** | The name of the Paladin. |
+**owner_id** | **UUID** | The ID of the owner of the Paladin. |
+**monitor_mode** | **bool** | When true, the Paladin reasons about requests but takes no action. Defaults to true. | [optional] [default to True]
+**admin_view_only** | **bool** | When true, recommendations are visible only to admins. Only meaningful when monitor_mode is true. Defaults to false. | [optional] [default to False]
+**enabled_connectors** | [**List[PaladinConnector]**](PaladinConnector.md) | The connectors the Paladin is allowed to use. | [optional]
+**instructions** | **str** | The free-form instructions that guide the Paladin's decisions. Optional; if omitted the Paladin is created without instructions. | [optional]
+
+## Example
+
+```python
+from opal_security.models.create_paladin_info import CreatePaladinInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CreatePaladinInfo from a JSON string
+create_paladin_info_instance = CreatePaladinInfo.from_json(json)
+# print the JSON string representation of the object
+print(CreatePaladinInfo.to_json())
+
+# convert the object into a dict
+create_paladin_info_dict = create_paladin_info_instance.to_dict()
+# create an instance of CreatePaladinInfo from a dict
+create_paladin_info_from_dict = CreatePaladinInfo.from_dict(create_paladin_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CreateRequestTemplateInfo.md b/docs/CreateRequestTemplateInfo.md
new file mode 100644
index 0000000..73d7189
--- /dev/null
+++ b/docs/CreateRequestTemplateInfo.md
@@ -0,0 +1,31 @@
+# CreateRequestTemplateInfo
+
+Information for creating a request template.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**name** | **str** | The name of the request template. |
+**custom_fields** | [**List[RequestTemplateCustomFieldInput]**](RequestTemplateCustomFieldInput.md) | The fields to put on the template, in the order they are shown. | [optional]
+
+## Example
+
+```python
+from opal_security.models.create_request_template_info import CreateRequestTemplateInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CreateRequestTemplateInfo from a JSON string
+create_request_template_info_instance = CreateRequestTemplateInfo.from_json(json)
+# print the JSON string representation of the object
+print(CreateRequestTemplateInfo.to_json())
+
+# convert the object into a dict
+create_request_template_info_dict = create_request_template_info_instance.to_dict()
+# create an instance of CreateRequestTemplateInfo from a dict
+create_request_template_info_from_dict = CreateRequestTemplateInfo.from_dict(create_request_template_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CreateResourceCustomAccessLevelInfo.md b/docs/CreateResourceCustomAccessLevelInfo.md
new file mode 100644
index 0000000..2bbdfd6
--- /dev/null
+++ b/docs/CreateResourceCustomAccessLevelInfo.md
@@ -0,0 +1,33 @@
+# CreateResourceCustomAccessLevelInfo
+
+Info for creating a custom access level.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**access_level** | [**ResourceAccessLevel**](ResourceAccessLevel.md) | |
+**policy** | **str** | The policy document. | [optional]
+**requestable_by_default** | **bool** | Whether the role is requestable. Defaults to false. | [optional]
+**stackable_sensitivity_index** | **int** | The sensitivity index. Null to leave unranked. | [optional]
+
+## Example
+
+```python
+from opal_security.models.create_resource_custom_access_level_info import CreateResourceCustomAccessLevelInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of CreateResourceCustomAccessLevelInfo from a JSON string
+create_resource_custom_access_level_info_instance = CreateResourceCustomAccessLevelInfo.from_json(json)
+# print the JSON string representation of the object
+print(CreateResourceCustomAccessLevelInfo.to_json())
+
+# convert the object into a dict
+create_resource_custom_access_level_info_dict = create_resource_custom_access_level_info_instance.to_dict()
+# create an instance of CreateResourceCustomAccessLevelInfo from a dict
+create_resource_custom_access_level_info_from_dict = CreateResourceCustomAccessLevelInfo.from_dict(create_resource_custom_access_level_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/CreateResourceInfo.md b/docs/CreateResourceInfo.md
index 6d0e662..066af7f 100644
--- a/docs/CreateResourceInfo.md
+++ b/docs/CreateResourceInfo.md
@@ -15,6 +15,8 @@ Name | Type | Description | Notes
**metadata** | **str** | Deprecated - use remote_info instead. JSON metadata about the remote resource. Include only for items linked to remote systems. See [this guide](https://docs.opal.dev/reference/end-system-objects) for details on how to specify this field. The required format is dependent on resource_type and should have the following schema: <style type=\"text/css\"> code {max-height:300px !important} </style> ```json { \"$schema\": \"http://json-schema.org/draft-04/schema#\", \"title\": \"Resource Metadata\", \"properties\": { \"aws_ec2_instance\": { \"properties\": { \"instance_id\": { \"type\": \"string\" }, \"region\": { \"type\": \"string\" } }, \"required\": [\"instance_id\", \"region\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"AWS EC2 Instance\" }, \"aws_eks_cluster\": { \"properties\": { \"cluster_name\": { \"type\": \"string\" }, \"cluster_region\": { \"type\": \"string\" }, \"cluster_arn\": { \"type\": \"string\" } }, \"required\": [\"cluster_name\", \"cluster_region\", \"cluster_arn\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"AWS EKS Cluster\" }, \"aws_rds_instance\": { \"properties\": { \"instance_id\": { \"type\": \"string\" }, \"engine\": { \"type\": \"string\" }, \"region\": { \"type\": \"string\" }, \"resource_id\": { \"type\": \"string\" }, \"database_name\": { \"type\": \"string\" } }, \"required\": [ \"instance_id\", \"engine\", \"region\", \"resource_id\", \"database_name\" ], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"AWS RDS Instance\" }, \"aws_role\": { \"properties\": { \"arn\": { \"type\": \"string\" }, \"name\": { \"type\": \"string\" } }, \"required\": [\"arn\", \"name\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"AWS Role\" }, \"gcp_bucket\": { \"properties\": { \"bucket_id\": { \"type\": \"string\" } }, \"required\": [\"bucket_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP Bucket\" }, \"gcp_compute_instance\": { \"properties\": { \"instance_id\": { \"type\": \"string\" }, \"project_id\": { \"type\": \"string\" }, \"zone\": { \"type\": \"string\" } }, \"required\": [\"instance_id\", \"project_id\", \"zone\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP Compute Instance\" }, \"gcp_folder\": { \"properties\": { \"folder_id\": { \"type\": \"string\" } }, \"required\": [\"folder_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP Folder\" }, \"gcp_gke_cluster\": { \"properties\": { \"cluster_name\": { \"type\": \"string\" } }, \"required\": [\"cluster_name\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP GKE Cluster\" }, \"gcp_project\": { \"properties\": { \"project_id\": { \"type\": \"string\" } }, \"required\": [\"project_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP Project\" }, \"gcp_sql_instance\": { \"properties\": { \"instance_id\": { \"type\": \"string\" }, \"project_id\": { \"type\": \"string\" } }, \"required\": [\"instance_id\", \"project_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP SQL Instance\" }, \"git_hub_repo\": { \"properties\": { \"org_name\": { \"type\": \"string\" }, \"repo_name\": { \"type\": \"string\" } }, \"required\": [\"org_name\", \"repo_name\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GitHub Repo\" }, \"okta_directory_app\": { \"properties\": { \"app_id\": { \"type\": \"string\" }, \"logo_url\": { \"type\": \"string\" } }, \"required\": [\"app_id\", \"logo_url\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Okta Directory App\" }, \"okta_directory_role\": { \"properties\": { \"role_type\": { \"type\": \"string\" }, \"role_id\": { \"type\": \"string\" } }, \"required\": [\"role_type\", \"role_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Okta Directory Role\" }, \"salesforce_profile\": { \"properties\": { \"user_license\": { \"type\": \"string\" } }, \"required\": [\"user_license\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Salesforce Profile\" } }, \"additionalProperties\": false, \"minProperties\": 1, \"maxProperties\": 1, \"type\": \"object\" } ``` | [optional]
**custom_request_notification** | **str** | Custom request notification sent upon request approval. | [optional]
**risk_sensitivity_override** | [**RiskSensitivityEnum**](RiskSensitivityEnum.md) | | [optional]
+**match_remote_name** | **bool** | A bool representing whether or not the resource's name should be synced from the end system. When true, the name is overwritten with the remote name on each sync, so a `name` provided together with this field set to true will be replaced at the next sync. Defaults to false. | [optional]
+**match_remote_description** | **bool** | A bool representing whether or not the resource's description should be synced from the end system. When true, the description is overwritten with the remote description on each sync, so a `description` provided together with this field set to true will be replaced at the next sync. Defaults to false. | [optional]
## Example
diff --git a/docs/EntityAdminFilter.md b/docs/EntityAdminFilter.md
new file mode 100644
index 0000000..9f7931d
--- /dev/null
+++ b/docs/EntityAdminFilter.md
@@ -0,0 +1,31 @@
+# EntityAdminFilter
+
+Filters GROUP and RESOURCE entities by their admin owner. USER entities never match, in either polarity. `not` inverts the match within the resource/group domain (self-negating, like IdpStatusFilter): omit it (or false) to include entities owned by the given owners, set it true to exclude them.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**owner_ids** | **List[UUID]** | The owner (group) UUIDs to match entities against. |
+**var_not** | **bool** | Invert the match — return resources/groups NOT owned by the given owners. | [optional]
+
+## Example
+
+```python
+from opal_security.models.entity_admin_filter import EntityAdminFilter
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of EntityAdminFilter from a JSON string
+entity_admin_filter_instance = EntityAdminFilter.from_json(json)
+# print the JSON string representation of the object
+print(EntityAdminFilter.to_json())
+
+# convert the object into a dict
+entity_admin_filter_dict = entity_admin_filter_instance.to_dict()
+# create an instance of EntityAdminFilter from a dict
+entity_admin_filter_from_dict = EntityAdminFilter.from_dict(entity_admin_filter_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/EntityItemTypeEnum.md b/docs/EntityItemTypeEnum.md
index 63e8d34..cc3dbcb 100644
--- a/docs/EntityItemTypeEnum.md
+++ b/docs/EntityItemTypeEnum.md
@@ -120,6 +120,8 @@ Granular subtype of an entity.
* `GCP_SERVICE_ACCOUNT` (value: `'GCP_SERVICE_ACCOUNT'`)
+* `GCP_BILLING_ACCOUNT` (value: `'GCP_BILLING_ACCOUNT'`)
+
* `GIT_HUB_REPO` (value: `'GIT_HUB_REPO'`)
* `GIT_HUB_ORG_ROLE` (value: `'GIT_HUB_ORG_ROLE'`)
diff --git a/docs/Group.md b/docs/Group.md
index 45928d5..846be1f 100644
--- a/docs/Group.md
+++ b/docs/Group.md
@@ -34,6 +34,8 @@ Name | Type | Description | Notes
**custom_request_notification** | **str** | Custom request notification sent to the requester when the request is approved. | [optional]
**risk_sensitivity** | [**RiskSensitivityEnum**](RiskSensitivityEnum.md) | The risk sensitivity level for the group. When an override is set, this field will match that. | [optional] [readonly]
**risk_sensitivity_override** | [**RiskSensitivityEnum**](RiskSensitivityEnum.md) | | [optional]
+**match_remote_name** | **bool** | A bool representing whether or not the group's name is synced from the end system. When true, the name is overwritten with the remote name on each sync. Defaults to false. | [optional]
+**match_remote_description** | **bool** | A bool representing whether or not the group's description is synced from the end system. When true, the description is overwritten with the remote description on each sync. Defaults to false. | [optional]
**last_successful_sync** | [**SyncTask**](SyncTask.md) | Information about the last successful sync of this group. | [optional] [readonly]
## Example
diff --git a/docs/GroupAccessLevelList.md b/docs/GroupAccessLevelList.md
new file mode 100644
index 0000000..15b4f3a
--- /dev/null
+++ b/docs/GroupAccessLevelList.md
@@ -0,0 +1,30 @@
+# GroupAccessLevelList
+
+A list of access levels defined for a group.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**results** | [**List[GroupAccessLevel]**](GroupAccessLevel.md) | | [optional]
+
+## Example
+
+```python
+from opal_security.models.group_access_level_list import GroupAccessLevelList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of GroupAccessLevelList from a JSON string
+group_access_level_list_instance = GroupAccessLevelList.from_json(json)
+# print the JSON string representation of the object
+print(GroupAccessLevelList.to_json())
+
+# convert the object into a dict
+group_access_level_list_dict = group_access_level_list_instance.to_dict()
+# create an instance of GroupAccessLevelList from a dict
+group_access_level_list_from_dict = GroupAccessLevelList.from_dict(group_access_level_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/GroupRemoteInfo.md b/docs/GroupRemoteInfo.md
index d96154d..bdde6cb 100644
--- a/docs/GroupRemoteInfo.md
+++ b/docs/GroupRemoteInfo.md
@@ -35,6 +35,13 @@ Name | Type | Description | Notes
**slack_user_group** | [**GroupRemoteInfoSlackUserGroup**](GroupRemoteInfoSlackUserGroup.md) | | [optional]
**zendesk_organization** | [**GroupRemoteInfoZendeskOrganization**](GroupRemoteInfoZendeskOrganization.md) | | [optional]
**hubspot_team** | [**GroupRemoteInfoHubspotTeam**](GroupRemoteInfoHubspotTeam.md) | | [optional]
+**tableau_group** | [**GroupRemoteInfoTableauGroup**](GroupRemoteInfoTableauGroup.md) | | [optional]
+**confluence_group** | [**GroupRemoteInfoConfluenceGroup**](GroupRemoteInfoConfluenceGroup.md) | | [optional]
+**jira_group** | [**GroupRemoteInfoJiraGroup**](GroupRemoteInfoJiraGroup.md) | | [optional]
+**docusign_group** | [**GroupRemoteInfoDocusignGroup**](GroupRemoteInfoDocusignGroup.md) | | [optional]
+**zoom_group** | [**GroupRemoteInfoZoomGroup**](GroupRemoteInfoZoomGroup.md) | | [optional]
+**docusign_signing_group** | [**GroupRemoteInfoDocusignSigningGroup**](GroupRemoteInfoDocusignSigningGroup.md) | | [optional]
+**linear_team** | [**GroupRemoteInfoLinearTeam**](GroupRemoteInfoLinearTeam.md) | | [optional]
## Example
diff --git a/docs/GroupRemoteInfoConfluenceGroup.md b/docs/GroupRemoteInfoConfluenceGroup.md
new file mode 100644
index 0000000..e9bff88
--- /dev/null
+++ b/docs/GroupRemoteInfoConfluenceGroup.md
@@ -0,0 +1,30 @@
+# GroupRemoteInfoConfluenceGroup
+
+Remote info for Confluence group.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**group_id** | **str** | The ID of the Confluence group. |
+
+## Example
+
+```python
+from opal_security.models.group_remote_info_confluence_group import GroupRemoteInfoConfluenceGroup
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of GroupRemoteInfoConfluenceGroup from a JSON string
+group_remote_info_confluence_group_instance = GroupRemoteInfoConfluenceGroup.from_json(json)
+# print the JSON string representation of the object
+print(GroupRemoteInfoConfluenceGroup.to_json())
+
+# convert the object into a dict
+group_remote_info_confluence_group_dict = group_remote_info_confluence_group_instance.to_dict()
+# create an instance of GroupRemoteInfoConfluenceGroup from a dict
+group_remote_info_confluence_group_from_dict = GroupRemoteInfoConfluenceGroup.from_dict(group_remote_info_confluence_group_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/GroupRemoteInfoDocusignGroup.md b/docs/GroupRemoteInfoDocusignGroup.md
new file mode 100644
index 0000000..23131d4
--- /dev/null
+++ b/docs/GroupRemoteInfoDocusignGroup.md
@@ -0,0 +1,30 @@
+# GroupRemoteInfoDocusignGroup
+
+Remote info for Docusign group.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**group_id** | **str** | The ID of the Docusign group. |
+
+## Example
+
+```python
+from opal_security.models.group_remote_info_docusign_group import GroupRemoteInfoDocusignGroup
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of GroupRemoteInfoDocusignGroup from a JSON string
+group_remote_info_docusign_group_instance = GroupRemoteInfoDocusignGroup.from_json(json)
+# print the JSON string representation of the object
+print(GroupRemoteInfoDocusignGroup.to_json())
+
+# convert the object into a dict
+group_remote_info_docusign_group_dict = group_remote_info_docusign_group_instance.to_dict()
+# create an instance of GroupRemoteInfoDocusignGroup from a dict
+group_remote_info_docusign_group_from_dict = GroupRemoteInfoDocusignGroup.from_dict(group_remote_info_docusign_group_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/GroupRemoteInfoDocusignSigningGroup.md b/docs/GroupRemoteInfoDocusignSigningGroup.md
new file mode 100644
index 0000000..b2d7442
--- /dev/null
+++ b/docs/GroupRemoteInfoDocusignSigningGroup.md
@@ -0,0 +1,30 @@
+# GroupRemoteInfoDocusignSigningGroup
+
+Remote info for Docusign signing group.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**signing_group_id** | **str** | The ID of the Docusign signing group. |
+
+## Example
+
+```python
+from opal_security.models.group_remote_info_docusign_signing_group import GroupRemoteInfoDocusignSigningGroup
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of GroupRemoteInfoDocusignSigningGroup from a JSON string
+group_remote_info_docusign_signing_group_instance = GroupRemoteInfoDocusignSigningGroup.from_json(json)
+# print the JSON string representation of the object
+print(GroupRemoteInfoDocusignSigningGroup.to_json())
+
+# convert the object into a dict
+group_remote_info_docusign_signing_group_dict = group_remote_info_docusign_signing_group_instance.to_dict()
+# create an instance of GroupRemoteInfoDocusignSigningGroup from a dict
+group_remote_info_docusign_signing_group_from_dict = GroupRemoteInfoDocusignSigningGroup.from_dict(group_remote_info_docusign_signing_group_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/GroupRemoteInfoJiraGroup.md b/docs/GroupRemoteInfoJiraGroup.md
new file mode 100644
index 0000000..50d171d
--- /dev/null
+++ b/docs/GroupRemoteInfoJiraGroup.md
@@ -0,0 +1,30 @@
+# GroupRemoteInfoJiraGroup
+
+Remote info for Jira group.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**group_id** | **str** | The ID of the Jira group. |
+
+## Example
+
+```python
+from opal_security.models.group_remote_info_jira_group import GroupRemoteInfoJiraGroup
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of GroupRemoteInfoJiraGroup from a JSON string
+group_remote_info_jira_group_instance = GroupRemoteInfoJiraGroup.from_json(json)
+# print the JSON string representation of the object
+print(GroupRemoteInfoJiraGroup.to_json())
+
+# convert the object into a dict
+group_remote_info_jira_group_dict = group_remote_info_jira_group_instance.to_dict()
+# create an instance of GroupRemoteInfoJiraGroup from a dict
+group_remote_info_jira_group_from_dict = GroupRemoteInfoJiraGroup.from_dict(group_remote_info_jira_group_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/GroupRemoteInfoLinearTeam.md b/docs/GroupRemoteInfoLinearTeam.md
new file mode 100644
index 0000000..59fba72
--- /dev/null
+++ b/docs/GroupRemoteInfoLinearTeam.md
@@ -0,0 +1,30 @@
+# GroupRemoteInfoLinearTeam
+
+Remote info for Linear team.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**team_id** | **str** | The ID of the Linear team. |
+
+## Example
+
+```python
+from opal_security.models.group_remote_info_linear_team import GroupRemoteInfoLinearTeam
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of GroupRemoteInfoLinearTeam from a JSON string
+group_remote_info_linear_team_instance = GroupRemoteInfoLinearTeam.from_json(json)
+# print the JSON string representation of the object
+print(GroupRemoteInfoLinearTeam.to_json())
+
+# convert the object into a dict
+group_remote_info_linear_team_dict = group_remote_info_linear_team_instance.to_dict()
+# create an instance of GroupRemoteInfoLinearTeam from a dict
+group_remote_info_linear_team_from_dict = GroupRemoteInfoLinearTeam.from_dict(group_remote_info_linear_team_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/GroupRemoteInfoTableauGroup.md b/docs/GroupRemoteInfoTableauGroup.md
new file mode 100644
index 0000000..3c70278
--- /dev/null
+++ b/docs/GroupRemoteInfoTableauGroup.md
@@ -0,0 +1,30 @@
+# GroupRemoteInfoTableauGroup
+
+Remote info for Tableau group.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**group_id** | **str** | The ID of the Tableau group. |
+
+## Example
+
+```python
+from opal_security.models.group_remote_info_tableau_group import GroupRemoteInfoTableauGroup
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of GroupRemoteInfoTableauGroup from a JSON string
+group_remote_info_tableau_group_instance = GroupRemoteInfoTableauGroup.from_json(json)
+# print the JSON string representation of the object
+print(GroupRemoteInfoTableauGroup.to_json())
+
+# convert the object into a dict
+group_remote_info_tableau_group_dict = group_remote_info_tableau_group_instance.to_dict()
+# create an instance of GroupRemoteInfoTableauGroup from a dict
+group_remote_info_tableau_group_from_dict = GroupRemoteInfoTableauGroup.from_dict(group_remote_info_tableau_group_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/GroupRemoteInfoZoomGroup.md b/docs/GroupRemoteInfoZoomGroup.md
new file mode 100644
index 0000000..e238fc1
--- /dev/null
+++ b/docs/GroupRemoteInfoZoomGroup.md
@@ -0,0 +1,30 @@
+# GroupRemoteInfoZoomGroup
+
+Remote info for Zoom group.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**group_id** | **str** | The ID of the Zoom group. |
+
+## Example
+
+```python
+from opal_security.models.group_remote_info_zoom_group import GroupRemoteInfoZoomGroup
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of GroupRemoteInfoZoomGroup from a JSON string
+group_remote_info_zoom_group_instance = GroupRemoteInfoZoomGroup.from_json(json)
+# print the JSON string representation of the object
+print(GroupRemoteInfoZoomGroup.to_json())
+
+# convert the object into a dict
+group_remote_info_zoom_group_dict = group_remote_info_zoom_group_instance.to_dict()
+# create an instance of GroupRemoteInfoZoomGroup from a dict
+group_remote_info_zoom_group_from_dict = GroupRemoteInfoZoomGroup.from_dict(group_remote_info_zoom_group_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/GroupTypeEnum.md b/docs/GroupTypeEnum.md
index ca6fdbf..872a557 100644
--- a/docs/GroupTypeEnum.md
+++ b/docs/GroupTypeEnum.md
@@ -68,6 +68,18 @@ The type of the group.
* `HUBSPOT_TEAM` (value: `'HUBSPOT_TEAM'`)
+* `TABLEAU_GROUP` (value: `'TABLEAU_GROUP'`)
+
+* `CONFLUENCE_GROUP` (value: `'CONFLUENCE_GROUP'`)
+
+* `JIRA_GROUP` (value: `'JIRA_GROUP'`)
+
+* `DOCUSIGN_GROUP` (value: `'DOCUSIGN_GROUP'`)
+
+* `ZOOM_GROUP` (value: `'ZOOM_GROUP'`)
+
+* `LINEAR_TEAM` (value: `'LINEAR_TEAM'`)
+
[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
diff --git a/docs/GroupsApi.md b/docs/GroupsApi.md
index d311da4..e88237c 100644
--- a/docs/GroupsApi.md
+++ b/docs/GroupsApi.md
@@ -11,6 +11,7 @@ Method | HTTP request | Description
[**delete_group**](GroupsApi.md#delete_group) | **DELETE** /groups/{group_id} |
[**delete_group_user**](GroupsApi.md#delete_group_user) | **DELETE** /groups/{group_id}/users/{user_id} |
[**get_group**](GroupsApi.md#get_group) | **GET** /groups/{group_id} | Get group by ID
+[**get_group_access_levels**](GroupsApi.md#get_group_access_levels) | **GET** /groups/{group_id}/access_levels | Get group access levels
[**get_group_containing_group**](GroupsApi.md#get_group_containing_group) | **GET** /groups/{group_id}/containing-groups/{containing_group_id} | Get nested group by ID
[**get_group_containing_groups**](GroupsApi.md#get_group_containing_groups) | **GET** /groups/{group_id}/containing-groups | Get nested groups
[**get_group_message_channels**](GroupsApi.md#get_group_message_channels) | **GET** /groups/{group_id}/message-channels |
@@ -593,6 +594,87 @@ Name | Type | Description | Notes
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **get_group_access_levels**
+> GroupAccessLevelList get_group_access_levels(group_id)
+
+Get group access levels
+
+Returns the list of access levels defined for the group. Groups that only offer default (unnamed) access return an empty list.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.group_access_level_list import GroupAccessLevelList
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.GroupsApi(api_client)
+ group_id = UUID('4baf8423-db0a-4037-a4cf-f79c60cb67a5') # UUID | The ID of the group whose access levels to return.
+
+ try:
+ # Get group access levels
+ api_response = api_instance.get_group_access_levels(group_id)
+ print("The response of GroupsApi->get_group_access_levels:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling GroupsApi->get_group_access_levels: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **group_id** | **UUID**| The ID of the group whose access levels to return. |
+
+### Return type
+
+[**GroupAccessLevelList**](GroupAccessLevelList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The access levels defined for the group. | - |
+**404** | Group not found. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **get_group_containing_group**
> GroupContainingGroup get_group_containing_group(group_id, containing_group_id)
@@ -1257,7 +1339,7 @@ with opal_security.ApiClient(configuration) as api_client:
api_instance = opal_security.GroupsApi(api_client)
group_id = UUID('4baf8423-db0a-4037-a4cf-f79c60cb67a5') # UUID | The ID of the group.
cursor = 'cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw' # str | The pagination cursor value. (optional)
- page_size = 200 # int | Number of results to return per page. Default is 200. (optional)
+ page_size = 200 # int | Number of results to return per page, up to 1000. When set (or when a cursor is provided), the response contains a single page of results and a `next` cursor; the default page size is 200. When both page_size and cursor are omitted, the entire group membership is returned in one response with no `next` cursor. For large groups, prefer setting page_size and following `next`. (optional)
try:
api_response = api_instance.get_group_users(group_id, cursor=cursor, page_size=page_size)
@@ -1276,7 +1358,7 @@ Name | Type | Description | Notes
------------- | ------------- | ------------- | -------------
**group_id** | **UUID**| The ID of the group. |
**cursor** | **str**| The pagination cursor value. | [optional]
- **page_size** | **int**| Number of results to return per page. Default is 200. | [optional]
+ **page_size** | **int**| Number of results to return per page, up to 1000. When set (or when a cursor is provided), the response contains a single page of results and a `next` cursor; the default page size is 200. When both page_size and cursor are omitted, the entire group membership is returned in one response with no `next` cursor. For large groups, prefer setting page_size and following `next`. | [optional]
### Return type
@@ -1373,11 +1455,12 @@ Name | Type | Description | Notes
| Status code | Description | Response headers |
|-------------|-------------|------------------|
**200** | The visibility info of this group. | - |
+**403** | The caller is not authorized to view this group's visibility. | - |
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
# **get_groups**
-> PaginatedGroupsList get_groups(cursor=cursor, page_size=page_size, group_type_filter=group_type_filter, group_ids=group_ids, group_name=group_name, tag_ids=tag_ids)
+> PaginatedGroupsList get_groups(cursor=cursor, page_size=page_size, group_type_filter=group_type_filter, group_ids=group_ids, group_name=group_name, tag_ids=tag_ids, requestable=requestable)
Get groups
@@ -1422,10 +1505,11 @@ with opal_security.ApiClient(configuration) as api_client:
group_ids = [["4baf8423-db0a-4037-a4cf-f79c60cb67a5","1b978423-db0a-4037-a4cf-f79c60cb67b3"]] # List[UUID] | The group ids to filter by. (optional)
group_name = 'example-name' # str | Group name. (optional)
tag_ids = None # List[UUID] | The IDs of the tags to filter by. Returns only groups that have any of these tags applied. (optional)
+ requestable = true # bool | If true, only return groups that allow access requests. Does not check whether the caller is permitted to request the group. (optional)
try:
# Get groups
- api_response = api_instance.get_groups(cursor=cursor, page_size=page_size, group_type_filter=group_type_filter, group_ids=group_ids, group_name=group_name, tag_ids=tag_ids)
+ api_response = api_instance.get_groups(cursor=cursor, page_size=page_size, group_type_filter=group_type_filter, group_ids=group_ids, group_name=group_name, tag_ids=tag_ids, requestable=requestable)
print("The response of GroupsApi->get_groups:\n")
pprint(api_response)
except Exception as e:
@@ -1445,6 +1529,7 @@ Name | Type | Description | Notes
**group_ids** | [**List[UUID]**](UUID.md)| The group ids to filter by. | [optional]
**group_name** | **str**| Group name. | [optional]
**tag_ids** | [**List[UUID]**](UUID.md)| The IDs of the tags to filter by. Returns only groups that have any of these tags applied. | [optional]
+ **requestable** | **bool**| If true, only return groups that allow access requests. Does not check whether the caller is permitted to request the group. | [optional]
### Return type
diff --git a/docs/IdpStatusFilter.md b/docs/IdpStatusFilter.md
new file mode 100644
index 0000000..b4b76ae
--- /dev/null
+++ b/docs/IdpStatusFilter.md
@@ -0,0 +1,31 @@
+# IdpStatusFilter
+
+Filters USER entities by their HR/IDP lifecycle status. Only applies to USER entities; GROUP and RESOURCE entities never match, in either polarity. `statuses` combine with OR. `not` inverts the match within the user domain (e.g. \"IDP status is NOT active\"), so it still returns only users rather than sweeping in groups/resources.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**statuses** | [**List[UserHrIdpStatusEnum]**](UserHrIdpStatusEnum.md) | Match users whose HR/IDP status is one of these values. | [optional]
+**var_not** | **bool** | Invert the match within the user domain (e.g. \"IDP status is NOT active\"). | [optional]
+
+## Example
+
+```python
+from opal_security.models.idp_status_filter import IdpStatusFilter
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of IdpStatusFilter from a JSON string
+idp_status_filter_instance = IdpStatusFilter.from_json(json)
+# print the JSON string representation of the object
+print(IdpStatusFilter.to_json())
+
+# convert the object into a dict
+idp_status_filter_dict = idp_status_filter_instance.to_dict()
+# create an instance of IdpStatusFilter from a dict
+idp_status_filter_from_dict = IdpStatusFilter.from_dict(idp_status_filter_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/InviteUserInfo.md b/docs/InviteUserInfo.md
new file mode 100644
index 0000000..79574a9
--- /dev/null
+++ b/docs/InviteUserInfo.md
@@ -0,0 +1,33 @@
+# InviteUserInfo
+
+The information required to invite a user.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**email** | **str** | |
+**first_name** | **str** | |
+**last_name** | **str** | |
+**role** | [**UserProductRoleEnum**](UserProductRoleEnum.md) | |
+
+## Example
+
+```python
+from opal_security.models.invite_user_info import InviteUserInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of InviteUserInfo from a JSON string
+invite_user_info_instance = InviteUserInfo.from_json(json)
+# print the JSON string representation of the object
+print(InviteUserInfo.to_json())
+
+# convert the object into a dict
+invite_user_info_dict = invite_user_info_instance.to_dict()
+# create an instance of InviteUserInfo from a dict
+invite_user_info_from_dict = InviteUserInfo.from_dict(invite_user_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/OpalAccessPathEdgeFilter.md b/docs/OpalAccessPathEdgeFilter.md
new file mode 100644
index 0000000..b0b9620
--- /dev/null
+++ b/docs/OpalAccessPathEdgeFilter.md
@@ -0,0 +1,31 @@
+# OpalAccessPathEdgeFilter
+
+Constraints on the access path edges themselves.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**direct_only** | **bool** | When true, only return direct (depth-1) principal-to-entitlement edges. | [optional]
+**access_duration_type** | **str** | Constrain results by whether the terminal access expires. | [optional]
+
+## Example
+
+```python
+from opal_security.models.opal_access_path_edge_filter import OpalAccessPathEdgeFilter
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of OpalAccessPathEdgeFilter from a JSON string
+opal_access_path_edge_filter_instance = OpalAccessPathEdgeFilter.from_json(json)
+# print the JSON string representation of the object
+print(OpalAccessPathEdgeFilter.to_json())
+
+# convert the object into a dict
+opal_access_path_edge_filter_dict = opal_access_path_edge_filter_instance.to_dict()
+# create an instance of OpalAccessPathEdgeFilter from a dict
+opal_access_path_edge_filter_from_dict = OpalAccessPathEdgeFilter.from_dict(opal_access_path_edge_filter_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/OpalAccessPathQuery.md b/docs/OpalAccessPathQuery.md
new file mode 100644
index 0000000..8ff8405
--- /dev/null
+++ b/docs/OpalAccessPathQuery.md
@@ -0,0 +1,34 @@
+# OpalAccessPathQuery
+
+Use an Access Path query to retrieve the access edges between principals (users or groups) and their entitlements (resources or groups). You can filter by principal type, entitlement type, access level, and edge characteristics such as depth or expiration. Results are paginated and returned as a list of access path edges.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**type** | **str** | |
+**query** | [**OpalAccessPathQueryBody**](OpalAccessPathQueryBody.md) | | [optional]
+**first** | **int** | Maximum number of results to return. Defaults to 200. | [optional]
+**after** | **str** | Opaque cursor from a previous ACCESS_PATH response to fetch the next page of results. | [optional]
+**include_count** | **bool** | When true, populate totalCount in the response. Defaults to false. | [optional]
+
+## Example
+
+```python
+from opal_security.models.opal_access_path_query import OpalAccessPathQuery
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of OpalAccessPathQuery from a JSON string
+opal_access_path_query_instance = OpalAccessPathQuery.from_json(json)
+# print the JSON string representation of the object
+print(OpalAccessPathQuery.to_json())
+
+# convert the object into a dict
+opal_access_path_query_dict = opal_access_path_query_instance.to_dict()
+# create an instance of OpalAccessPathQuery from a dict
+opal_access_path_query_from_dict = OpalAccessPathQuery.from_dict(opal_access_path_query_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/OpalAccessPathQueryBody.md b/docs/OpalAccessPathQueryBody.md
new file mode 100644
index 0000000..eb0461e
--- /dev/null
+++ b/docs/OpalAccessPathQueryBody.md
@@ -0,0 +1,36 @@
+# OpalAccessPathQueryBody
+
+Edge-query filters for an ACCESS_PATH OpalQuery. At least one of principalFilter or entitlementFilter is required.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**principal_filter** | [**AccessEntityFilters**](AccessEntityFilters.md) | | [optional]
+**entitlement_filter** | [**AccessEntityFilters**](AccessEntityFilters.md) | | [optional]
+**principal_access_filters** | [**AccessRelationshipFilters**](AccessRelationshipFilters.md) | Advanced access filter on the principal side of each path. Restricts results to principals that additionally satisfy these access-edge constraints: `hasAccessTo` keeps only principals that also have access to a matching entity; `isAccessibleBy` keeps only principals that are also accessible by a matching entity. Only takes effect when `principalFilter` is also supplied (it refines that filter); on its own it has no effect. | [optional]
+**entitlement_access_filters** | [**AccessRelationshipFilters**](AccessRelationshipFilters.md) | Advanced access filter on the entitlement side of each path. Restricts results to entitlements that additionally satisfy these access-edge constraints: `hasAccessTo` keeps only entitlements that also have access to a matching entity; `isAccessibleBy` keeps only entitlements that are also accessible by a matching entity. Only takes effect when `entitlementFilter` is also supplied (it refines that filter); on its own it has no effect. | [optional]
+**access_level_remote_ids** | **List[str]** | Filter by access-level remote IDs on the terminal edge. | [optional]
+**access_level_names** | **List[str]** | Filter by access-level display names on the terminal edge. | [optional]
+**edge_filter** | [**OpalAccessPathEdgeFilter**](OpalAccessPathEdgeFilter.md) | | [optional]
+
+## Example
+
+```python
+from opal_security.models.opal_access_path_query_body import OpalAccessPathQueryBody
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of OpalAccessPathQueryBody from a JSON string
+opal_access_path_query_body_instance = OpalAccessPathQueryBody.from_json(json)
+# print the JSON string representation of the object
+print(OpalAccessPathQueryBody.to_json())
+
+# convert the object into a dict
+opal_access_path_query_body_dict = opal_access_path_query_body_instance.to_dict()
+# create an instance of OpalAccessPathQueryBody from a dict
+opal_access_path_query_body_from_dict = OpalAccessPathQueryBody.from_dict(opal_access_path_query_body_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/OpalAccessPathQueryResults.md b/docs/OpalAccessPathQueryResults.md
new file mode 100644
index 0000000..c196f33
--- /dev/null
+++ b/docs/OpalAccessPathQueryResults.md
@@ -0,0 +1,33 @@
+# OpalAccessPathQueryResults
+
+Paginated results of an ACCESS_PATH-type OpalQuery — one edge per matched principal-to-entitlement access path.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**type** | **str** | |
+**edges** | [**List[OpalAccessPathResultEdge]**](OpalAccessPathResultEdge.md) | List of matched access paths. |
+**page_info** | [**PageInfo**](PageInfo.md) | |
+**total_count** | **int** | Exact total number of matching paths when includeCount was true on the request; otherwise null. | [optional]
+
+## Example
+
+```python
+from opal_security.models.opal_access_path_query_results import OpalAccessPathQueryResults
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of OpalAccessPathQueryResults from a JSON string
+opal_access_path_query_results_instance = OpalAccessPathQueryResults.from_json(json)
+# print the JSON string representation of the object
+print(OpalAccessPathQueryResults.to_json())
+
+# convert the object into a dict
+opal_access_path_query_results_dict = opal_access_path_query_results_instance.to_dict()
+# create an instance of OpalAccessPathQueryResults from a dict
+opal_access_path_query_results_from_dict = OpalAccessPathQueryResults.from_dict(opal_access_path_query_results_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/OpalAccessPathResultEdge.md b/docs/OpalAccessPathResultEdge.md
new file mode 100644
index 0000000..35591bd
--- /dev/null
+++ b/docs/OpalAccessPathResultEdge.md
@@ -0,0 +1,31 @@
+# OpalAccessPathResultEdge
+
+A single ACCESS_PATH result edge containing the matched path and its pagination cursor.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**node** | [**OpalAccessPathResultNode**](OpalAccessPathResultNode.md) | |
+**cursor** | **str** | Opaque cursor for this path, used for pagination. |
+
+## Example
+
+```python
+from opal_security.models.opal_access_path_result_edge import OpalAccessPathResultEdge
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of OpalAccessPathResultEdge from a JSON string
+opal_access_path_result_edge_instance = OpalAccessPathResultEdge.from_json(json)
+# print the JSON string representation of the object
+print(OpalAccessPathResultEdge.to_json())
+
+# convert the object into a dict
+opal_access_path_result_edge_dict = opal_access_path_result_edge_instance.to_dict()
+# create an instance of OpalAccessPathResultEdge from a dict
+opal_access_path_result_edge_from_dict = OpalAccessPathResultEdge.from_dict(opal_access_path_result_edge_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/OpalAccessPathResultNode.md b/docs/OpalAccessPathResultNode.md
new file mode 100644
index 0000000..132073a
--- /dev/null
+++ b/docs/OpalAccessPathResultNode.md
@@ -0,0 +1,36 @@
+# OpalAccessPathResultNode
+
+A matched access path from an ACCESS_PATH OpalQuery.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**principal_id** | **UUID** | The principal entity ID. |
+**entitlement_id** | **UUID** | The entitlement entity ID. |
+**access_level_remote_id** | **str** | Remote ID of the terminal access level. | [optional]
+**access_level_name** | **str** | Display name of the terminal access level. | [optional]
+**expiration** | **datetime** | Expiration of the terminal access, if any. | [optional]
+**depth** | **int** | Number of hops from principal to entitlement (path length - 1). |
+**path** | **List[UUID]** | Entity IDs along the path from principal to entitlement. |
+
+## Example
+
+```python
+from opal_security.models.opal_access_path_result_node import OpalAccessPathResultNode
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of OpalAccessPathResultNode from a JSON string
+opal_access_path_result_node_instance = OpalAccessPathResultNode.from_json(json)
+# print the JSON string representation of the object
+print(OpalAccessPathResultNode.to_json())
+
+# convert the object into a dict
+opal_access_path_result_node_dict = opal_access_path_result_node_instance.to_dict()
+# create an instance of OpalAccessPathResultNode from a dict
+opal_access_path_result_node_from_dict = OpalAccessPathResultNode.from_dict(opal_access_path_result_node_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/OpalNodeQuery.md b/docs/OpalNodeQuery.md
index 7ed645d..5319de9 100644
--- a/docs/OpalNodeQuery.md
+++ b/docs/OpalNodeQuery.md
@@ -1,6 +1,6 @@
# OpalNodeQuery
-Request body for a NODE-type OpalQuery. Returns entities (users, resources, groups) matching the given filters.
+Use a Node query to retrieve entities — users, resources, or groups — that match a set of filters. You can filter by entity type, tags, and access relationships. Results are paginated and returned as a list of entity edges.
## Properties
diff --git a/docs/OpalQueriesApi.md b/docs/OpalQueriesApi.md
index 3be1004..f1243ba 100644
--- a/docs/OpalQueriesApi.md
+++ b/docs/OpalQueriesApi.md
@@ -8,11 +8,14 @@ Method | HTTP request | Description
# **run_opal_query**
-> OpalNodeQueryResults run_opal_query(body)
+> OpalQueryResults run_opal_query(run_opal_query_request)
Run an ad-hoc OpalQuery
-Runs an ad-hoc OpalQuery and returns the results. Currently supports NODE queries (users, resources, groups). This endpoint is only available to our OpalQuery beta group. Please contact Opal support if you'd like to be added to the beta.
+Executes an ad-hoc OpalQuery and returns paginated results. Two query types are supported: a **Node** query filters and returns entities (users, resources, or groups); an **Access Path** query returns the access edges between principals and their entitlements. Set `type` to `NODE` or `ACCESS_PATH` in the request body to select the query type.
+
+This endpoint is available to OpalQuery beta participants. To request access, contact Opal support.
+
### Example
@@ -20,8 +23,8 @@ Runs an ad-hoc OpalQuery and returns the results. Currently supports NODE querie
```python
import opal_security
-from opal_security.models.opal_node_query import OpalNodeQuery
-from opal_security.models.opal_node_query_results import OpalNodeQueryResults
+from opal_security.models.opal_query_results import OpalQueryResults
+from opal_security.models.run_opal_query_request import RunOpalQueryRequest
from opal_security.rest import ApiException
from pprint import pprint
@@ -47,11 +50,11 @@ configuration = opal.Configuration(
with opal_security.ApiClient(configuration) as api_client:
# Create an instance of the API class
api_instance = opal_security.OpalQueriesApi(api_client)
- body = opal_security.OpalNodeQuery() # OpalNodeQuery |
+ run_opal_query_request = opal_security.RunOpalQueryRequest() # RunOpalQueryRequest |
try:
# Run an ad-hoc OpalQuery
- api_response = api_instance.run_opal_query(body)
+ api_response = api_instance.run_opal_query(run_opal_query_request)
print("The response of OpalQueriesApi->run_opal_query:\n")
pprint(api_response)
except Exception as e:
@@ -65,11 +68,11 @@ with opal_security.ApiClient(configuration) as api_client:
Name | Type | Description | Notes
------------- | ------------- | ------------- | -------------
- **body** | **OpalNodeQuery**| |
+ **run_opal_query_request** | [**RunOpalQueryRequest**](RunOpalQueryRequest.md)| |
### Return type
-[**OpalNodeQueryResults**](OpalNodeQueryResults.md)
+[**OpalQueryResults**](OpalQueryResults.md)
### Authorization
diff --git a/docs/OpalQueryResults.md b/docs/OpalQueryResults.md
new file mode 100644
index 0000000..3f65866
--- /dev/null
+++ b/docs/OpalQueryResults.md
@@ -0,0 +1,33 @@
+# OpalQueryResults
+
+Paginated results of an OpalQuery. The `type` field discriminates which result schema applies and mirrors the `type` field on the request.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**type** | **str** | |
+**edges** | [**List[OpalAccessPathResultEdge]**](OpalAccessPathResultEdge.md) | List of matched access paths. |
+**page_info** | [**PageInfo**](PageInfo.md) | |
+**total_count** | **int** | Exact total number of matching paths when includeCount was true on the request; otherwise null. | [optional]
+
+## Example
+
+```python
+from opal_security.models.opal_query_results import OpalQueryResults
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of OpalQueryResults from a JSON string
+opal_query_results_instance = OpalQueryResults.from_json(json)
+# print the JSON string representation of the object
+print(OpalQueryResults.to_json())
+
+# convert the object into a dict
+opal_query_results_dict = opal_query_results_instance.to_dict()
+# create an instance of OpalQueryResults from a dict
+opal_query_results_from_dict = OpalQueryResults.from_dict(opal_query_results_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaginatedCampaignItemsList.md b/docs/PaginatedCampaignItemsList.md
new file mode 100644
index 0000000..cc66adf
--- /dev/null
+++ b/docs/PaginatedCampaignItemsList.md
@@ -0,0 +1,33 @@
+# PaginatedCampaignItemsList
+
+A paginated list of campaign items.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**next** | **str** | The cursor with which to continue pagination if additional result pages exist. | [optional]
+**previous** | **str** | The cursor used to obtain the current result page. | [optional]
+**results** | [**List[CampaignItem]**](CampaignItem.md) | |
+**total_count** | **int** | Total number of items matching the filter (across all pages). |
+
+## Example
+
+```python
+from opal_security.models.paginated_campaign_items_list import PaginatedCampaignItemsList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of PaginatedCampaignItemsList from a JSON string
+paginated_campaign_items_list_instance = PaginatedCampaignItemsList.from_json(json)
+# print the JSON string representation of the object
+print(PaginatedCampaignItemsList.to_json())
+
+# convert the object into a dict
+paginated_campaign_items_list_dict = paginated_campaign_items_list_instance.to_dict()
+# create an instance of PaginatedCampaignItemsList from a dict
+paginated_campaign_items_list_from_dict = PaginatedCampaignItemsList.from_dict(paginated_campaign_items_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaginatedCampaignsList.md b/docs/PaginatedCampaignsList.md
new file mode 100644
index 0000000..97bd506
--- /dev/null
+++ b/docs/PaginatedCampaignsList.md
@@ -0,0 +1,32 @@
+# PaginatedCampaignsList
+
+A list of campaigns.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**next** | **str** | The cursor with which to continue pagination if additional result pages exist. | [optional]
+**previous** | **str** | The cursor used to obtain the current result page. | [optional]
+**results** | [**List[Campaign]**](Campaign.md) | |
+
+## Example
+
+```python
+from opal_security.models.paginated_campaigns_list import PaginatedCampaignsList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of PaginatedCampaignsList from a JSON string
+paginated_campaigns_list_instance = PaginatedCampaignsList.from_json(json)
+# print the JSON string representation of the object
+print(PaginatedCampaignsList.to_json())
+
+# convert the object into a dict
+paginated_campaigns_list_dict = paginated_campaigns_list_instance.to_dict()
+# create an instance of PaginatedCampaignsList from a dict
+paginated_campaigns_list_from_dict = PaginatedCampaignsList.from_dict(paginated_campaigns_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaginatedRequestTemplateList.md b/docs/PaginatedRequestTemplateList.md
new file mode 100644
index 0000000..77ca15b
--- /dev/null
+++ b/docs/PaginatedRequestTemplateList.md
@@ -0,0 +1,31 @@
+# PaginatedRequestTemplateList
+
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**next** | **str** | The cursor with which to continue pagination if additional result pages exist. | [optional]
+**previous** | **str** | The cursor used to obtain the current result page. | [optional]
+**results** | [**List[RequestTemplate]**](RequestTemplate.md) | | [optional]
+
+## Example
+
+```python
+from opal_security.models.paginated_request_template_list import PaginatedRequestTemplateList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of PaginatedRequestTemplateList from a JSON string
+paginated_request_template_list_instance = PaginatedRequestTemplateList.from_json(json)
+# print the JSON string representation of the object
+print(PaginatedRequestTemplateList.to_json())
+
+# convert the object into a dict
+paginated_request_template_list_dict = paginated_request_template_list_instance.to_dict()
+# create an instance of PaginatedRequestTemplateList from a dict
+paginated_request_template_list_from_dict = PaginatedRequestTemplateList.from_dict(paginated_request_template_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaginatedViewerCampaignItemsList.md b/docs/PaginatedViewerCampaignItemsList.md
new file mode 100644
index 0000000..9815689
--- /dev/null
+++ b/docs/PaginatedViewerCampaignItemsList.md
@@ -0,0 +1,33 @@
+# PaginatedViewerCampaignItemsList
+
+A paginated list of viewer campaign items.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**next** | **str** | The cursor with which to continue pagination if additional result pages exist. | [optional]
+**previous** | **str** | The cursor used to obtain the current result page. | [optional]
+**results** | [**List[ViewerCampaignItem]**](ViewerCampaignItem.md) | |
+**total_count** | **int** | Total number of items matching the filter (across all pages). |
+
+## Example
+
+```python
+from opal_security.models.paginated_viewer_campaign_items_list import PaginatedViewerCampaignItemsList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of PaginatedViewerCampaignItemsList from a JSON string
+paginated_viewer_campaign_items_list_instance = PaginatedViewerCampaignItemsList.from_json(json)
+# print the JSON string representation of the object
+print(PaginatedViewerCampaignItemsList.to_json())
+
+# convert the object into a dict
+paginated_viewer_campaign_items_list_dict = paginated_viewer_campaign_items_list_instance.to_dict()
+# create an instance of PaginatedViewerCampaignItemsList from a dict
+paginated_viewer_campaign_items_list_from_dict = PaginatedViewerCampaignItemsList.from_dict(paginated_viewer_campaign_items_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/Paladin.md b/docs/Paladin.md
new file mode 100644
index 0000000..a29547c
--- /dev/null
+++ b/docs/Paladin.md
@@ -0,0 +1,36 @@
+# Paladin
+
+# Paladin Object ### Description The `Paladin` object represents a Paladin, Opal's AI access-request reviewer.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**paladin_id** | **UUID** | The ID of the Paladin. Use this value as a reviewer in a request configuration's service_user_ids. |
+**name** | **str** | The name of the Paladin. |
+**owner_id** | **UUID** | The ID of the owner of the Paladin. |
+**monitor_mode** | **bool** | When true, the Paladin reasons about requests but takes no action. Shown as \"Monitor mode\" in the UI. |
+**admin_view_only** | **bool** | When true, the Paladin's recommendations are visible only to admins. Only meaningful when monitor_mode is true. |
+**enabled_connectors** | [**List[PaladinConnector]**](PaladinConnector.md) | The connectors the Paladin is allowed to use. |
+**instructions** | **str** | The free-form instructions that guide the Paladin's decisions. |
+
+## Example
+
+```python
+from opal_security.models.paladin import Paladin
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of Paladin from a JSON string
+paladin_instance = Paladin.from_json(json)
+# print the JSON string representation of the object
+print(Paladin.to_json())
+
+# convert the object into a dict
+paladin_dict = paladin_instance.to_dict()
+# create an instance of Paladin from a dict
+paladin_from_dict = Paladin.from_dict(paladin_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaladinApi.md b/docs/PaladinApi.md
new file mode 100644
index 0000000..ab00c62
--- /dev/null
+++ b/docs/PaladinApi.md
@@ -0,0 +1,659 @@
+# opal_security.PaladinApi
+
+All URIs are relative to *https://api.opal.dev/v1*
+
+Method | HTTP request | Description
+------------- | ------------- | -------------
+[**create_paladin**](PaladinApi.md#create_paladin) | **POST** /paladin | Create Paladin
+[**create_paladin_context_source**](PaladinApi.md#create_paladin_context_source) | **POST** /paladin/{paladin_id}/context-sources | Add a Paladin context source
+[**delete_paladin**](PaladinApi.md#delete_paladin) | **DELETE** /paladin/{paladin_id} | Delete Paladin
+[**delete_paladin_context_source**](PaladinApi.md#delete_paladin_context_source) | **DELETE** /paladin/{paladin_id}/context-sources/{context_source_id} | Remove a Paladin context source
+[**get_paladin**](PaladinApi.md#get_paladin) | **GET** /paladin/{paladin_id} | Get Paladin by ID
+[**get_paladin_from_name**](PaladinApi.md#get_paladin_from_name) | **GET** /paladin/name/{paladin_name} | Get Paladins by name
+[**list_paladin_context_sources**](PaladinApi.md#list_paladin_context_sources) | **GET** /paladin/{paladin_id}/context-sources | List Paladin context sources
+[**update_paladin**](PaladinApi.md#update_paladin) | **PUT** /paladin/{paladin_id} | Update Paladin
+
+
+# **create_paladin**
+> Paladin create_paladin(create_paladin_info)
+
+Create Paladin
+
+Creates a new `Paladin`.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.create_paladin_info import CreatePaladinInfo
+from opal_security.models.paladin import Paladin
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.PaladinApi(api_client)
+ create_paladin_info = opal_security.CreatePaladinInfo() # CreatePaladinInfo |
+
+ try:
+ # Create Paladin
+ api_response = api_instance.create_paladin(create_paladin_info)
+ print("The response of PaladinApi->create_paladin:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling PaladinApi->create_paladin: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **create_paladin_info** | [**CreatePaladinInfo**](CreatePaladinInfo.md)| |
+
+### Return type
+
+[**Paladin**](Paladin.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The created Paladin. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **create_paladin_context_source**
+> PaladinContextSource create_paladin_context_source(paladin_id, create_paladin_context_source_info)
+
+Add a Paladin context source
+
+Configures a context source (a Slack channel or a document) for a Paladin to read. Idempotent, so re-adding an existing source returns it.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.create_paladin_context_source_info import CreatePaladinContextSourceInfo
+from opal_security.models.paladin_context_source import PaladinContextSource
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.PaladinApi(api_client)
+ paladin_id = UUID('32acc112-21ff-4669-91c2-21e27683eaa1') # UUID | The ID of the Paladin.
+ create_paladin_context_source_info = opal_security.CreatePaladinContextSourceInfo() # CreatePaladinContextSourceInfo |
+
+ try:
+ # Add a Paladin context source
+ api_response = api_instance.create_paladin_context_source(paladin_id, create_paladin_context_source_info)
+ print("The response of PaladinApi->create_paladin_context_source:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling PaladinApi->create_paladin_context_source: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **paladin_id** | **UUID**| The ID of the Paladin. |
+ **create_paladin_context_source_info** | [**CreatePaladinContextSourceInfo**](CreatePaladinContextSourceInfo.md)| |
+
+### Return type
+
+[**PaladinContextSource**](PaladinContextSource.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The configured context source. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **delete_paladin**
+> delete_paladin(paladin_id)
+
+Delete Paladin
+
+Deletes a Paladin, removing the underlying service user.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.PaladinApi(api_client)
+ paladin_id = UUID('32acc112-21ff-4669-91c2-21e27683eaa1') # UUID | The ID of the Paladin.
+
+ try:
+ # Delete Paladin
+ api_instance.delete_paladin(paladin_id)
+ except Exception as e:
+ print("Exception when calling PaladinApi->delete_paladin: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **paladin_id** | **UUID**| The ID of the Paladin. |
+
+### Return type
+
+void (empty response body)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: Not defined
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The Paladin was deleted. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **delete_paladin_context_source**
+> delete_paladin_context_source(paladin_id, context_source_id)
+
+Remove a Paladin context source
+
+Removes a context source from a Paladin.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.PaladinApi(api_client)
+ paladin_id = UUID('32acc112-21ff-4669-91c2-21e27683eaa1') # UUID | The ID of the Paladin.
+ context_source_id = UUID('8a1f2c3d-4b5e-6f70-8192-a3b4c5d6e7f8') # UUID | The ID of the context source.
+
+ try:
+ # Remove a Paladin context source
+ api_instance.delete_paladin_context_source(paladin_id, context_source_id)
+ except Exception as e:
+ print("Exception when calling PaladinApi->delete_paladin_context_source: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **paladin_id** | **UUID**| The ID of the Paladin. |
+ **context_source_id** | **UUID**| The ID of the context source. |
+
+### Return type
+
+void (empty response body)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: Not defined
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The context source was removed. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_paladin**
+> Paladin get_paladin(paladin_id)
+
+Get Paladin by ID
+
+Returns a `Paladin` object.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.paladin import Paladin
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.PaladinApi(api_client)
+ paladin_id = UUID('32acc112-21ff-4669-91c2-21e27683eaa1') # UUID | The ID of the Paladin.
+
+ try:
+ # Get Paladin by ID
+ api_response = api_instance.get_paladin(paladin_id)
+ print("The response of PaladinApi->get_paladin:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling PaladinApi->get_paladin: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **paladin_id** | **UUID**| The ID of the Paladin. |
+
+### Return type
+
+[**Paladin**](Paladin.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The Paladin associated with the passed-in ID. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_paladin_from_name**
+> PaladinList get_paladin_from_name(paladin_name)
+
+Get Paladins by name
+
+Returns all Paladins whose name exactly matches the given name. Names are not unique, so the result is a list and may be empty.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.paladin_list import PaladinList
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.PaladinApi(api_client)
+ paladin_name = 'paladin-agent-1' # str | The name of the Paladin.
+
+ try:
+ # Get Paladins by name
+ api_response = api_instance.get_paladin_from_name(paladin_name)
+ print("The response of PaladinApi->get_paladin_from_name:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling PaladinApi->get_paladin_from_name: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **paladin_name** | **str**| The name of the Paladin. |
+
+### Return type
+
+[**PaladinList**](PaladinList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The list of Paladins matching the passed-in name. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **list_paladin_context_sources**
+> PaladinContextSourceList list_paladin_context_sources(paladin_id)
+
+List Paladin context sources
+
+Returns the context sources (Slack channels and documents) configured for a Paladin.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.paladin_context_source_list import PaladinContextSourceList
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.PaladinApi(api_client)
+ paladin_id = UUID('32acc112-21ff-4669-91c2-21e27683eaa1') # UUID | The ID of the Paladin.
+
+ try:
+ # List Paladin context sources
+ api_response = api_instance.list_paladin_context_sources(paladin_id)
+ print("The response of PaladinApi->list_paladin_context_sources:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling PaladinApi->list_paladin_context_sources: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **paladin_id** | **UUID**| The ID of the Paladin. |
+
+### Return type
+
+[**PaladinContextSourceList**](PaladinContextSourceList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The context sources configured for the Paladin. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **update_paladin**
+> Paladin update_paladin(paladin_id, update_paladin_info)
+
+Update Paladin
+
+Updates a `Paladin` object.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.paladin import Paladin
+from opal_security.models.update_paladin_info import UpdatePaladinInfo
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.PaladinApi(api_client)
+ paladin_id = UUID('32acc112-21ff-4669-91c2-21e27683eaa1') # UUID | The ID of the Paladin.
+ update_paladin_info = opal_security.UpdatePaladinInfo() # UpdatePaladinInfo |
+
+ try:
+ # Update Paladin
+ api_response = api_instance.update_paladin(paladin_id, update_paladin_info)
+ print("The response of PaladinApi->update_paladin:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling PaladinApi->update_paladin: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **paladin_id** | **UUID**| The ID of the Paladin. |
+ **update_paladin_info** | [**UpdatePaladinInfo**](UpdatePaladinInfo.md)| |
+
+### Return type
+
+[**Paladin**](Paladin.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The updated Paladin. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
diff --git a/docs/PaladinConnector.md b/docs/PaladinConnector.md
new file mode 100644
index 0000000..8b0cb33
--- /dev/null
+++ b/docs/PaladinConnector.md
@@ -0,0 +1,31 @@
+# PaladinConnector
+
+A connector a Paladin is allowed to use.
+
+## Enum
+
+* `NOTION` (value: `'NOTION'`)
+
+* `JIRA` (value: `'JIRA'`)
+
+* `LINEAR` (value: `'LINEAR'`)
+
+* `SERVICE_NOW` (value: `'SERVICE_NOW'`)
+
+* `NOTION_TICKETS` (value: `'NOTION_TICKETS'`)
+
+* `FRESH_SERVICE` (value: `'FRESH_SERVICE'`)
+
+* `SHORTCUT` (value: `'SHORTCUT'`)
+
+* `SLACK` (value: `'SLACK'`)
+
+* `PAGER_DUTY` (value: `'PAGER_DUTY'`)
+
+* `CONFLUENCE` (value: `'CONFLUENCE'`)
+
+* `FLEET_DM` (value: `'FLEET_DM'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaladinContextSource.md b/docs/PaladinContextSource.md
new file mode 100644
index 0000000..99d8076
--- /dev/null
+++ b/docs/PaladinContextSource.md
@@ -0,0 +1,36 @@
+# PaladinContextSource
+
+# PaladinContextSource Object ### Description A context source (a Slack channel or a document) that a Paladin is configured to read during access-request review.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**id** | **UUID** | The ID of the context source. |
+**paladin_id** | **UUID** | The ID of the Paladin this source belongs to. |
+**source_kind** | [**PaladinContextSourceKind**](PaladinContextSourceKind.md) | |
+**third_party_provider** | [**PaladinContextSourceProvider**](PaladinContextSourceProvider.md) | |
+**remote_id** | **str** | The provider's identifier for the source. The Slack channel ID for a channel, or the Notion/Confluence page ID for a document. |
+**name** | **str** | A human-readable name for the source. |
+**url** | **str** | A link to the source. |
+
+## Example
+
+```python
+from opal_security.models.paladin_context_source import PaladinContextSource
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of PaladinContextSource from a JSON string
+paladin_context_source_instance = PaladinContextSource.from_json(json)
+# print the JSON string representation of the object
+print(PaladinContextSource.to_json())
+
+# convert the object into a dict
+paladin_context_source_dict = paladin_context_source_instance.to_dict()
+# create an instance of PaladinContextSource from a dict
+paladin_context_source_from_dict = PaladinContextSource.from_dict(paladin_context_source_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaladinContextSourceKind.md b/docs/PaladinContextSourceKind.md
new file mode 100644
index 0000000..09dbf67
--- /dev/null
+++ b/docs/PaladinContextSourceKind.md
@@ -0,0 +1,13 @@
+# PaladinContextSourceKind
+
+The kind of source a Paladin can read. A SLACK_CHANNEL is a Slack channel; a DOCUMENT is a Notion or Confluence page.
+
+## Enum
+
+* `SLACK_CHANNEL` (value: `'SLACK_CHANNEL'`)
+
+* `DOCUMENT` (value: `'DOCUMENT'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaladinContextSourceList.md b/docs/PaladinContextSourceList.md
new file mode 100644
index 0000000..8be5e20
--- /dev/null
+++ b/docs/PaladinContextSourceList.md
@@ -0,0 +1,30 @@
+# PaladinContextSourceList
+
+# PaladinContextSourceList Object ### Description A list of `PaladinContextSource` objects.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**results** | [**List[PaladinContextSource]**](PaladinContextSource.md) | |
+
+## Example
+
+```python
+from opal_security.models.paladin_context_source_list import PaladinContextSourceList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of PaladinContextSourceList from a JSON string
+paladin_context_source_list_instance = PaladinContextSourceList.from_json(json)
+# print the JSON string representation of the object
+print(PaladinContextSourceList.to_json())
+
+# convert the object into a dict
+paladin_context_source_list_dict = paladin_context_source_list_instance.to_dict()
+# create an instance of PaladinContextSourceList from a dict
+paladin_context_source_list_from_dict = PaladinContextSourceList.from_dict(paladin_context_source_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaladinContextSourceProvider.md b/docs/PaladinContextSourceProvider.md
new file mode 100644
index 0000000..f6a06a3
--- /dev/null
+++ b/docs/PaladinContextSourceProvider.md
@@ -0,0 +1,15 @@
+# PaladinContextSourceProvider
+
+The integration a Paladin context source comes from.
+
+## Enum
+
+* `SLACK` (value: `'SLACK'`)
+
+* `NOTION` (value: `'NOTION'`)
+
+* `CONFLUENCE` (value: `'CONFLUENCE'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PaladinList.md b/docs/PaladinList.md
new file mode 100644
index 0000000..fc5df40
--- /dev/null
+++ b/docs/PaladinList.md
@@ -0,0 +1,30 @@
+# PaladinList
+
+# PaladinList Object ### Description A list of `Paladin` objects.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**results** | [**List[Paladin]**](Paladin.md) | |
+
+## Example
+
+```python
+from opal_security.models.paladin_list import PaladinList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of PaladinList from a JSON string
+paladin_list_instance = PaladinList.from_json(json)
+# print the JSON string representation of the object
+print(PaladinList.to_json())
+
+# convert the object into a dict
+paladin_list_dict = paladin_list_instance.to_dict()
+# create an instance of PaladinList from a dict
+paladin_list_from_dict = PaladinList.from_dict(paladin_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/PropagationStatusEnum.md b/docs/PropagationStatusEnum.md
index ded75f9..03bb1f8 100644
--- a/docs/PropagationStatusEnum.md
+++ b/docs/PropagationStatusEnum.md
@@ -46,6 +46,10 @@ The status of whether the user has been synced to the group or resource in the r
* `ERR_REMOTE_UNRECOVERABLE_ERROR` (value: `'ERR_REMOTE_UNRECOVERABLE_ERROR'`)
+* `ERR_REMOTE_TICKET_NOT_FOUND` (value: `'ERR_REMOTE_TICKET_NOT_FOUND'`)
+
+* `ERR_CONNECTION_VALIDATION_FAILED` (value: `'ERR_CONNECTION_VALIDATION_FAILED'`)
+
[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
diff --git a/docs/RemindRequest200Response.md b/docs/RemindRequest200Response.md
new file mode 100644
index 0000000..a5aaa7c
--- /dev/null
+++ b/docs/RemindRequest200Response.md
@@ -0,0 +1,29 @@
+# RemindRequest200Response
+
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**success** | **bool** | |
+
+## Example
+
+```python
+from opal_security.models.remind_request200_response import RemindRequest200Response
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of RemindRequest200Response from a JSON string
+remind_request200_response_instance = RemindRequest200Response.from_json(json)
+# print the JSON string representation of the object
+print(RemindRequest200Response.to_json())
+
+# convert the object into a dict
+remind_request200_response_dict = remind_request200_response_instance.to_dict()
+# create an instance of RemindRequest200Response from a dict
+remind_request200_response_from_dict = RemindRequest200Response.from_dict(remind_request200_response_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/RequestConfiguration.md b/docs/RequestConfiguration.md
index 5af185d..80d3b01 100644
--- a/docs/RequestConfiguration.md
+++ b/docs/RequestConfiguration.md
@@ -10,7 +10,7 @@ Name | Type | Description | Notes
**allow_requests** | **bool** | A bool representing whether or not to allow requests for this resource. |
**auto_approval** | **bool** | A bool representing whether or not to automatically approve requests for this resource. |
**require_mfa_to_request** | **bool** | A bool representing whether or not to require MFA for requesting access to this resource. |
-**max_duration_minutes** | **int** | The maximum duration for which the resource can be requested (in minutes). | [optional]
+**max_duration_minutes** | **int** | The maximum duration for which the resource can be requested (in minutes). Capped at 1 year (525600) unless a longer maximum has been enabled for your organization. Use -1 for an indefinite duration. | [optional]
**recommended_duration_minutes** | **int** | The recommended duration for which the resource should be requested (in minutes). -1 represents an indefinite duration. | [optional]
**require_support_ticket** | **bool** | A bool representing whether or not access requests to the resource require an access ticket. |
**extensions_duration_in_minutes** | **int** | The duration for which access can be extended (in minutes). Set to 0 to disable extensions. When > 0, extensions are enabled for the specified duration. | [optional]
diff --git a/docs/RequestTemplate.md b/docs/RequestTemplate.md
new file mode 100644
index 0000000..9707a43
--- /dev/null
+++ b/docs/RequestTemplate.md
@@ -0,0 +1,32 @@
+# RequestTemplate
+
+A template describing what a requester is asked when requesting access.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**request_template_id** | **UUID** | The ID of the request template. |
+**name** | **str** | The name of the request template. |
+**custom_fields** | [**List[RequestTemplateCustomField]**](RequestTemplateCustomField.md) | The fields on this template, in the order they are shown. | [optional]
+
+## Example
+
+```python
+from opal_security.models.request_template import RequestTemplate
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of RequestTemplate from a JSON string
+request_template_instance = RequestTemplate.from_json(json)
+# print the JSON string representation of the object
+print(RequestTemplate.to_json())
+
+# convert the object into a dict
+request_template_dict = request_template_instance.to_dict()
+# create an instance of RequestTemplate from a dict
+request_template_from_dict = RequestTemplate.from_dict(request_template_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/RequestTemplateCustomField.md b/docs/RequestTemplateCustomField.md
new file mode 100644
index 0000000..e7d8904
--- /dev/null
+++ b/docs/RequestTemplateCustomField.md
@@ -0,0 +1,34 @@
+# RequestTemplateCustomField
+
+A field on a request template.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**name** | **str** | The label shown to the requester. `CALLOUT` fields are display-only, so their name is an internal identifier and is never displayed. |
+**description** | **str** | Helper text shown beneath the field. | [optional]
+**type** | [**RequestTemplateCustomFieldTypeEnum**](RequestTemplateCustomFieldTypeEnum.md) | |
+**required** | **bool** | Whether the requester must answer. Always false for `CALLOUT` fields, which collect no answer. | [optional]
+**metadata** | [**RequestTemplateCustomFieldMetadata**](RequestTemplateCustomFieldMetadata.md) | | [optional]
+
+## Example
+
+```python
+from opal_security.models.request_template_custom_field import RequestTemplateCustomField
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of RequestTemplateCustomField from a JSON string
+request_template_custom_field_instance = RequestTemplateCustomField.from_json(json)
+# print the JSON string representation of the object
+print(RequestTemplateCustomField.to_json())
+
+# convert the object into a dict
+request_template_custom_field_dict = request_template_custom_field_instance.to_dict()
+# create an instance of RequestTemplateCustomField from a dict
+request_template_custom_field_from_dict = RequestTemplateCustomField.from_dict(request_template_custom_field_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/RequestTemplateCustomFieldCalloutMetadata.md b/docs/RequestTemplateCustomFieldCalloutMetadata.md
new file mode 100644
index 0000000..616d0b0
--- /dev/null
+++ b/docs/RequestTemplateCustomFieldCalloutMetadata.md
@@ -0,0 +1,31 @@
+# RequestTemplateCustomFieldCalloutMetadata
+
+The message shown to a requester by a `CALLOUT` field, and how prominently to show it.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**severity** | **str** | How prominently the message is shown. |
+**text** | **str** | The message shown to the requester. |
+
+## Example
+
+```python
+from opal_security.models.request_template_custom_field_callout_metadata import RequestTemplateCustomFieldCalloutMetadata
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of RequestTemplateCustomFieldCalloutMetadata from a JSON string
+request_template_custom_field_callout_metadata_instance = RequestTemplateCustomFieldCalloutMetadata.from_json(json)
+# print the JSON string representation of the object
+print(RequestTemplateCustomFieldCalloutMetadata.to_json())
+
+# convert the object into a dict
+request_template_custom_field_callout_metadata_dict = request_template_custom_field_callout_metadata_instance.to_dict()
+# create an instance of RequestTemplateCustomFieldCalloutMetadata from a dict
+request_template_custom_field_callout_metadata_from_dict = RequestTemplateCustomFieldCalloutMetadata.from_dict(request_template_custom_field_callout_metadata_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/RequestTemplateCustomFieldInput.md b/docs/RequestTemplateCustomFieldInput.md
new file mode 100644
index 0000000..8b40cfc
--- /dev/null
+++ b/docs/RequestTemplateCustomFieldInput.md
@@ -0,0 +1,34 @@
+# RequestTemplateCustomFieldInput
+
+A field to put on a request template. Separate from `RequestTemplateCustomField` because a callout's name may be omitted on write, while a field read back always has one.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**name** | **str** | The label shown to the requester. Required for every type except `CALLOUT`, which is display-only -- its name is an internal identifier, never displayed, and is generated if omitted. | [optional]
+**description** | **str** | Helper text shown beneath the field. | [optional]
+**type** | [**RequestTemplateCustomFieldTypeEnum**](RequestTemplateCustomFieldTypeEnum.md) | |
+**required** | **bool** | Whether the requester must answer. Ignored for `CALLOUT` fields, which collect no answer. | [optional]
+**metadata** | [**RequestTemplateCustomFieldMetadata**](RequestTemplateCustomFieldMetadata.md) | | [optional]
+
+## Example
+
+```python
+from opal_security.models.request_template_custom_field_input import RequestTemplateCustomFieldInput
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of RequestTemplateCustomFieldInput from a JSON string
+request_template_custom_field_input_instance = RequestTemplateCustomFieldInput.from_json(json)
+# print the JSON string representation of the object
+print(RequestTemplateCustomFieldInput.to_json())
+
+# convert the object into a dict
+request_template_custom_field_input_dict = request_template_custom_field_input_instance.to_dict()
+# create an instance of RequestTemplateCustomFieldInput from a dict
+request_template_custom_field_input_from_dict = RequestTemplateCustomFieldInput.from_dict(request_template_custom_field_input_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/RequestTemplateCustomFieldMetadata.md b/docs/RequestTemplateCustomFieldMetadata.md
new file mode 100644
index 0000000..6bc7429
--- /dev/null
+++ b/docs/RequestTemplateCustomFieldMetadata.md
@@ -0,0 +1,31 @@
+# RequestTemplateCustomFieldMetadata
+
+Extra configuration for field types that need it. Exactly one member is set, and which one is determined by the field's `type`.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**callout_data** | [**RequestTemplateCustomFieldCalloutMetadata**](RequestTemplateCustomFieldCalloutMetadata.md) | | [optional]
+**multi_choice_data** | [**RequestTemplateCustomFieldMultiChoiceMetadata**](RequestTemplateCustomFieldMultiChoiceMetadata.md) | | [optional]
+
+## Example
+
+```python
+from opal_security.models.request_template_custom_field_metadata import RequestTemplateCustomFieldMetadata
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of RequestTemplateCustomFieldMetadata from a JSON string
+request_template_custom_field_metadata_instance = RequestTemplateCustomFieldMetadata.from_json(json)
+# print the JSON string representation of the object
+print(RequestTemplateCustomFieldMetadata.to_json())
+
+# convert the object into a dict
+request_template_custom_field_metadata_dict = request_template_custom_field_metadata_instance.to_dict()
+# create an instance of RequestTemplateCustomFieldMetadata from a dict
+request_template_custom_field_metadata_from_dict = RequestTemplateCustomFieldMetadata.from_dict(request_template_custom_field_metadata_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/RequestTemplateCustomFieldMultiChoiceMetadata.md b/docs/RequestTemplateCustomFieldMultiChoiceMetadata.md
new file mode 100644
index 0000000..e1c164f
--- /dev/null
+++ b/docs/RequestTemplateCustomFieldMultiChoiceMetadata.md
@@ -0,0 +1,30 @@
+# RequestTemplateCustomFieldMultiChoiceMetadata
+
+The options a requester can pick from in a `MULTI_CHOICE` or `MULTI_SELECT` field.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**options** | **List[str]** | |
+
+## Example
+
+```python
+from opal_security.models.request_template_custom_field_multi_choice_metadata import RequestTemplateCustomFieldMultiChoiceMetadata
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of RequestTemplateCustomFieldMultiChoiceMetadata from a JSON string
+request_template_custom_field_multi_choice_metadata_instance = RequestTemplateCustomFieldMultiChoiceMetadata.from_json(json)
+# print the JSON string representation of the object
+print(RequestTemplateCustomFieldMultiChoiceMetadata.to_json())
+
+# convert the object into a dict
+request_template_custom_field_multi_choice_metadata_dict = request_template_custom_field_multi_choice_metadata_instance.to_dict()
+# create an instance of RequestTemplateCustomFieldMultiChoiceMetadata from a dict
+request_template_custom_field_multi_choice_metadata_from_dict = RequestTemplateCustomFieldMultiChoiceMetadata.from_dict(request_template_custom_field_multi_choice_metadata_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/RequestTemplateCustomFieldTypeEnum.md b/docs/RequestTemplateCustomFieldTypeEnum.md
index 9a6bebc..24be109 100644
--- a/docs/RequestTemplateCustomFieldTypeEnum.md
+++ b/docs/RequestTemplateCustomFieldTypeEnum.md
@@ -1,6 +1,6 @@
# RequestTemplateCustomFieldTypeEnum
-The type of the custom request field.
+The type of the custom request field. `CALLOUT` fields are display-only -- they show a message to the requester and collect no answer, so they never appear in a request's `custom_fields`.
## Enum
@@ -12,6 +12,10 @@ The type of the custom request field.
* `MULTI_CHOICE` (value: `'MULTI_CHOICE'`)
+* `MULTI_SELECT` (value: `'MULTI_SELECT'`)
+
+* `CALLOUT` (value: `'CALLOUT'`)
+
[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
diff --git a/docs/RequestTemplatesApi.md b/docs/RequestTemplatesApi.md
new file mode 100644
index 0000000..fd9b478
--- /dev/null
+++ b/docs/RequestTemplatesApi.md
@@ -0,0 +1,393 @@
+# opal_security.RequestTemplatesApi
+
+All URIs are relative to *https://api.opal.dev/v1*
+
+Method | HTTP request | Description
+------------- | ------------- | -------------
+[**create_request_template**](RequestTemplatesApi.md#create_request_template) | **POST** /request-templates |
+[**delete_request_template**](RequestTemplatesApi.md#delete_request_template) | **DELETE** /request-templates/{request_template_id} |
+[**get_request_template**](RequestTemplatesApi.md#get_request_template) | **GET** /request-templates/{request_template_id} |
+[**get_request_templates**](RequestTemplatesApi.md#get_request_templates) | **GET** /request-templates |
+[**update_request_template**](RequestTemplatesApi.md#update_request_template) | **PUT** /request-templates |
+
+
+# **create_request_template**
+> RequestTemplate create_request_template(create_request_template_info)
+
+Creates a request template.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.create_request_template_info import CreateRequestTemplateInfo
+from opal_security.models.request_template import RequestTemplate
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.RequestTemplatesApi(api_client)
+ create_request_template_info = opal_security.CreateRequestTemplateInfo() # CreateRequestTemplateInfo |
+
+ try:
+ api_response = api_instance.create_request_template(create_request_template_info)
+ print("The response of RequestTemplatesApi->create_request_template:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling RequestTemplatesApi->create_request_template: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **create_request_template_info** | [**CreateRequestTemplateInfo**](CreateRequestTemplateInfo.md)| |
+
+### Return type
+
+[**RequestTemplate**](RequestTemplate.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The request template just created. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **delete_request_template**
+> delete_request_template(request_template_id)
+
+Deletes a request template.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.RequestTemplatesApi(api_client)
+ request_template_id = UUID('4baf8423-db0a-4037-a4cf-f79c60cb67a5') # UUID | The ID of the request template.
+
+ try:
+ api_instance.delete_request_template(request_template_id)
+ except Exception as e:
+ print("Exception when calling RequestTemplatesApi->delete_request_template: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **request_template_id** | **UUID**| The ID of the request template. |
+
+### Return type
+
+void (empty response body)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: Not defined
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The request template was successfully deleted. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_request_template**
+> RequestTemplate get_request_template(request_template_id)
+
+Returns a `RequestTemplate` object.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.request_template import RequestTemplate
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.RequestTemplatesApi(api_client)
+ request_template_id = UUID('4baf8423-db0a-4037-a4cf-f79c60cb67a5') # UUID | The ID of the request template.
+
+ try:
+ api_response = api_instance.get_request_template(request_template_id)
+ print("The response of RequestTemplatesApi->get_request_template:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling RequestTemplatesApi->get_request_template: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **request_template_id** | **UUID**| The ID of the request template. |
+
+### Return type
+
+[**RequestTemplate**](RequestTemplate.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The requested request template. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_request_templates**
+> PaginatedRequestTemplateList get_request_templates()
+
+Returns a list of `RequestTemplate` objects.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.paginated_request_template_list import PaginatedRequestTemplateList
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.RequestTemplatesApi(api_client)
+
+ try:
+ api_response = api_instance.get_request_templates()
+ print("The response of RequestTemplatesApi->get_request_templates:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling RequestTemplatesApi->get_request_templates: %s\n" % e)
+```
+
+
+
+### Parameters
+
+This endpoint does not need any parameter.
+
+### Return type
+
+[**PaginatedRequestTemplateList**](PaginatedRequestTemplateList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | One page worth of request templates for your organization. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **update_request_template**
+> RequestTemplate update_request_template(update_request_template_info)
+
+Updates a request template.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.request_template import RequestTemplate
+from opal_security.models.update_request_template_info import UpdateRequestTemplateInfo
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.RequestTemplatesApi(api_client)
+ update_request_template_info = opal_security.UpdateRequestTemplateInfo() # UpdateRequestTemplateInfo | Request template to be updated
+
+ try:
+ api_response = api_instance.update_request_template(update_request_template_info)
+ print("The response of RequestTemplatesApi->update_request_template:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling RequestTemplatesApi->update_request_template: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **update_request_template_info** | [**UpdateRequestTemplateInfo**](UpdateRequestTemplateInfo.md)| Request template to be updated |
+
+### Return type
+
+[**RequestTemplate**](RequestTemplate.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The request template just updated. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
diff --git a/docs/RequestsApi.md b/docs/RequestsApi.md
index 20b3a31..913052d 100644
--- a/docs/RequestsApi.md
+++ b/docs/RequestsApi.md
@@ -5,6 +5,7 @@ All URIs are relative to *https://api.opal.dev/v1*
Method | HTTP request | Description
------------- | ------------- | -------------
[**approve_request**](RequestsApi.md#approve_request) | **POST** /requests/{id}/approve |
+[**cancel_request**](RequestsApi.md#cancel_request) | **POST** /requests/{id}/cancel | Cancel request
[**create_request**](RequestsApi.md#create_request) | **POST** /requests |
[**create_request_comment**](RequestsApi.md#create_request_comment) | **POST** /requests/{id}/comments |
[**deny_request**](RequestsApi.md#deny_request) | **POST** /requests/{id}/deny |
@@ -12,6 +13,8 @@ Method | HTTP request | Description
[**get_request_comments**](RequestsApi.md#get_request_comments) | **GET** /requests/{id}/comments |
[**get_requests**](RequestsApi.md#get_requests) | **GET** /requests | Get requests
[**get_requests_relay**](RequestsApi.md#get_requests_relay) | **GET** /requests/relay | Get requests via Relay
+[**remind_request**](RequestsApi.md#remind_request) | **POST** /requests/{id}/remind | Send request reminder
+[**remind_request_reviewer**](RequestsApi.md#remind_request_reviewer) | **POST** /requests/{id}/reviewers/{reviewer_id}/remind | Send reminder to a reviewer
# **approve_request**
@@ -94,6 +97,89 @@ Name | Type | Description | Notes
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **cancel_request**
+> Request cancel_request(id)
+
+Cancel request
+
+Cancels a pending access request.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.request import Request
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.RequestsApi(api_client)
+ id = UUID('38400000-8cf0-11bd-b23e-10b96e4ef00d') # UUID | The ID of the request to cancel.
+
+ try:
+ # Cancel request
+ api_response = api_instance.cancel_request(id)
+ print("The response of RequestsApi->cancel_request:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling RequestsApi->cancel_request: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **id** | **UUID**| The ID of the request to cancel. |
+
+### Return type
+
+[**Request**](Request.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The canceled request. | - |
+**403** | The authenticated user cannot cancel this request. | - |
+**404** | The request was not found. | - |
+**409** | The request has already been actioned. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **create_request**
> CreateRequest200Response create_request(create_request_info)
@@ -678,3 +764,171 @@ Name | Type | Description | Notes
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **remind_request**
+> RemindRequest200Response remind_request(id)
+
+Send request reminder
+
+Sends a reminder to all pending reviewers of the request.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.remind_request200_response import RemindRequest200Response
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.RequestsApi(api_client)
+ id = UUID('38400000-8cf0-11bd-b23e-10b96e4ef00d') # UUID | The ID of the request whose reviewers should be reminded.
+
+ try:
+ # Send request reminder
+ api_response = api_instance.remind_request(id)
+ print("The response of RequestsApi->remind_request:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling RequestsApi->remind_request: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **id** | **UUID**| The ID of the request whose reviewers should be reminded. |
+
+### Return type
+
+[**RemindRequest200Response**](RemindRequest200Response.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The reminder was sent, or the request was already resolved. | - |
+**400** | Unknown JSON fields in the request body. | - |
+**404** | The request was not found. | - |
+**429** | The reviewer reminder cooldown has not elapsed. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **remind_request_reviewer**
+> RemindRequest200Response remind_request_reviewer(id, reviewer_id)
+
+Send reminder to a reviewer
+
+Sends a reminder to one pending reviewer of the request.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.remind_request200_response import RemindRequest200Response
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.RequestsApi(api_client)
+ id = UUID('38400000-8cf0-11bd-b23e-10b96e4ef00d') # UUID | The ID of the request whose reviewer should be reminded.
+ reviewer_id = UUID('38400000-8cf0-11bd-b23e-10b96e4ef00d') # UUID | The ID of the pending reviewer to remind.
+
+ try:
+ # Send reminder to a reviewer
+ api_response = api_instance.remind_request_reviewer(id, reviewer_id)
+ print("The response of RequestsApi->remind_request_reviewer:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling RequestsApi->remind_request_reviewer: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **id** | **UUID**| The ID of the request whose reviewer should be reminded. |
+ **reviewer_id** | **UUID**| The ID of the pending reviewer to remind. |
+
+### Return type
+
+[**RemindRequest200Response**](RemindRequest200Response.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The reminder was sent, or the request was already resolved. | - |
+**400** | Unknown JSON fields, or the user is not a pending reviewer of the request. | - |
+**404** | The request was not found. | - |
+**429** | The reviewer reminder cooldown has not elapsed. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
diff --git a/docs/Resource.md b/docs/Resource.md
index f87a8d0..ce00690 100644
--- a/docs/Resource.md
+++ b/docs/Resource.md
@@ -37,6 +37,8 @@ Name | Type | Description | Notes
**remote_info** | [**ResourceRemoteInfo**](ResourceRemoteInfo.md) | | [optional]
**ancestor_resource_ids** | **List[UUID]** | List of resource IDs that are ancestors of this resource. | [optional]
**descendant_resource_ids** | **List[UUID]** | List of resource IDs that are descendants of this resource. | [optional]
+**match_remote_name** | **bool** | A bool representing whether or not the resource's name is synced from the end system. When true, the name is overwritten with the remote name on each sync. Defaults to false. | [optional]
+**match_remote_description** | **bool** | A bool representing whether or not the resource's description is synced from the end system. When true, the description is overwritten with the remote description on each sync. Defaults to false. | [optional]
**last_successful_sync** | [**SyncTask**](SyncTask.md) | Information about the last successful sync of this resource. | [optional] [readonly]
## Example
diff --git a/docs/ResourceAccessLevelList.md b/docs/ResourceAccessLevelList.md
new file mode 100644
index 0000000..0fac1b3
--- /dev/null
+++ b/docs/ResourceAccessLevelList.md
@@ -0,0 +1,30 @@
+# ResourceAccessLevelList
+
+A list of access levels defined for a resource.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**results** | [**List[ResourceAccessLevel]**](ResourceAccessLevel.md) | | [optional]
+
+## Example
+
+```python
+from opal_security.models.resource_access_level_list import ResourceAccessLevelList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceAccessLevelList from a JSON string
+resource_access_level_list_instance = ResourceAccessLevelList.from_json(json)
+# print the JSON string representation of the object
+print(ResourceAccessLevelList.to_json())
+
+# convert the object into a dict
+resource_access_level_list_dict = resource_access_level_list_instance.to_dict()
+# create an instance of ResourceAccessLevelList from a dict
+resource_access_level_list_from_dict = ResourceAccessLevelList.from_dict(resource_access_level_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceCustomAccessLevelList.md b/docs/ResourceCustomAccessLevelList.md
new file mode 100644
index 0000000..b83c8a4
--- /dev/null
+++ b/docs/ResourceCustomAccessLevelList.md
@@ -0,0 +1,30 @@
+# ResourceCustomAccessLevelList
+
+A list of custom access levels.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**custom_access_levels** | [**List[ResourceCustomAccessLevelResponse]**](ResourceCustomAccessLevelResponse.md) | |
+
+## Example
+
+```python
+from opal_security.models.resource_custom_access_level_list import ResourceCustomAccessLevelList
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceCustomAccessLevelList from a JSON string
+resource_custom_access_level_list_instance = ResourceCustomAccessLevelList.from_json(json)
+# print the JSON string representation of the object
+print(ResourceCustomAccessLevelList.to_json())
+
+# convert the object into a dict
+resource_custom_access_level_list_dict = resource_custom_access_level_list_instance.to_dict()
+# create an instance of ResourceCustomAccessLevelList from a dict
+resource_custom_access_level_list_from_dict = ResourceCustomAccessLevelList.from_dict(resource_custom_access_level_list_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceCustomAccessLevelResponse.md b/docs/ResourceCustomAccessLevelResponse.md
new file mode 100644
index 0000000..0547d73
--- /dev/null
+++ b/docs/ResourceCustomAccessLevelResponse.md
@@ -0,0 +1,38 @@
+# ResourceCustomAccessLevelResponse
+
+A custom access level for a resource.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**resource_custom_access_level_id** | **UUID** | The unique ID of the custom access level. |
+**resource_id** | **UUID** | The resource this access level belongs to. |
+**access_level** | [**ResourceAccessLevel**](ResourceAccessLevel.md) | |
+**policy** | **str** | The policy document for this access level. | [optional]
+**requestable_by_default** | **bool** | Whether this role is requestable. |
+**stackable_sensitivity_index** | **int** | The sensitivity index in the access hierarchy. Null if unranked. | [optional]
+**member_resource_ids** | **List[UUID]** | When addressed via a parent resource, lists the child resource IDs that back this aggregated entry. | [optional]
+**created_at** | **datetime** | | [optional]
+**updated_at** | **datetime** | | [optional]
+
+## Example
+
+```python
+from opal_security.models.resource_custom_access_level_response import ResourceCustomAccessLevelResponse
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceCustomAccessLevelResponse from a JSON string
+resource_custom_access_level_response_instance = ResourceCustomAccessLevelResponse.from_json(json)
+# print the JSON string representation of the object
+print(ResourceCustomAccessLevelResponse.to_json())
+
+# convert the object into a dict
+resource_custom_access_level_response_dict = resource_custom_access_level_response_instance.to_dict()
+# create an instance of ResourceCustomAccessLevelResponse from a dict
+resource_custom_access_level_response_from_dict = ResourceCustomAccessLevelResponse.from_dict(resource_custom_access_level_response_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceRemoteInfo.md b/docs/ResourceRemoteInfo.md
index aad6e03..8b95acd 100644
--- a/docs/ResourceRemoteInfo.md
+++ b/docs/ResourceRemoteInfo.md
@@ -38,6 +38,7 @@ Name | Type | Description | Notes
**gcp_gke_cluster** | [**ResourceRemoteInfoGcpGkeCluster**](ResourceRemoteInfoGcpGkeCluster.md) | | [optional]
**gcp_project** | [**ResourceRemoteInfoGcpProject**](ResourceRemoteInfoGcpProject.md) | | [optional]
**gcp_sql_instance** | [**ResourceRemoteInfoGcpSqlInstance**](ResourceRemoteInfoGcpSqlInstance.md) | | [optional]
+**gcp_billing_account** | [**ResourceRemoteInfoGcpBillingAccount**](ResourceRemoteInfoGcpBillingAccount.md) | | [optional]
**gcp_service_account** | [**ResourceRemoteInfoGcpServiceAccount**](ResourceRemoteInfoGcpServiceAccount.md) | | [optional]
**google_workspace_role** | [**ResourceRemoteInfoGoogleWorkspaceRole**](ResourceRemoteInfoGoogleWorkspaceRole.md) | | [optional]
**github_repo** | [**ResourceRemoteInfoGithubRepo**](ResourceRemoteInfoGithubRepo.md) | | [optional]
@@ -58,6 +59,7 @@ Name | Type | Description | Notes
**workday_role** | [**ResourceRemoteInfoWorkdayRole**](ResourceRemoteInfoWorkdayRole.md) | | [optional]
**salesforce_permission_set** | [**ResourceRemoteInfoSalesforcePermissionSet**](ResourceRemoteInfoSalesforcePermissionSet.md) | | [optional]
**salesforce_profile** | [**ResourceRemoteInfoSalesforceProfile**](ResourceRemoteInfoSalesforceProfile.md) | | [optional]
+**docusign_permission_profile** | [**ResourceRemoteInfoDocusignPermissionProfile**](ResourceRemoteInfoDocusignPermissionProfile.md) | | [optional]
**salesforce_role** | [**ResourceRemoteInfoSalesforceRole**](ResourceRemoteInfoSalesforceRole.md) | | [optional]
**teleport_role** | [**ResourceRemoteInfoTeleportRole**](ResourceRemoteInfoTeleportRole.md) | | [optional]
**datastax_astra_role** | [**ResourceRemoteInfoDatastaxAstraRole**](ResourceRemoteInfoDatastaxAstraRole.md) | | [optional]
@@ -78,6 +80,12 @@ Name | Type | Description | Notes
**grafana_role** | [**ResourceRemoteInfoGrafanaRole**](ResourceRemoteInfoGrafanaRole.md) | | [optional]
**zendesk_role** | [**ResourceRemoteInfoZendeskRole**](ResourceRemoteInfoZendeskRole.md) | | [optional]
**hubspot_role** | [**ResourceRemoteInfoHubspotRole**](ResourceRemoteInfoHubspotRole.md) | | [optional]
+**alicloud_ram_role** | [**ResourceRemoteInfoAlicloudRamRole**](ResourceRemoteInfoAlicloudRamRole.md) | | [optional]
+**alicloud_ecs_instance** | [**ResourceRemoteInfoAlicloudEcsInstance**](ResourceRemoteInfoAlicloudEcsInstance.md) | | [optional]
+**zoom_role** | [**ResourceRemoteInfoZoomRole**](ResourceRemoteInfoZoomRole.md) | | [optional]
+**zoom_license** | [**ResourceRemoteInfoZoomLicense**](ResourceRemoteInfoZoomLicense.md) | | [optional]
+**linear_organization** | [**ResourceRemoteInfoLinearOrganization**](ResourceRemoteInfoLinearOrganization.md) | | [optional]
+**linear_project** | [**ResourceRemoteInfoLinearProject**](ResourceRemoteInfoLinearProject.md) | | [optional]
## Example
diff --git a/docs/ResourceRemoteInfoAlicloudEcsInstance.md b/docs/ResourceRemoteInfoAlicloudEcsInstance.md
new file mode 100644
index 0000000..d0a080a
--- /dev/null
+++ b/docs/ResourceRemoteInfoAlicloudEcsInstance.md
@@ -0,0 +1,30 @@
+# ResourceRemoteInfoAlicloudEcsInstance
+
+Remote info for AliCloud ECS instance.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**instance_id** | **str** | The ID of the ECS instance. |
+
+## Example
+
+```python
+from opal_security.models.resource_remote_info_alicloud_ecs_instance import ResourceRemoteInfoAlicloudEcsInstance
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceRemoteInfoAlicloudEcsInstance from a JSON string
+resource_remote_info_alicloud_ecs_instance_instance = ResourceRemoteInfoAlicloudEcsInstance.from_json(json)
+# print the JSON string representation of the object
+print(ResourceRemoteInfoAlicloudEcsInstance.to_json())
+
+# convert the object into a dict
+resource_remote_info_alicloud_ecs_instance_dict = resource_remote_info_alicloud_ecs_instance_instance.to_dict()
+# create an instance of ResourceRemoteInfoAlicloudEcsInstance from a dict
+resource_remote_info_alicloud_ecs_instance_from_dict = ResourceRemoteInfoAlicloudEcsInstance.from_dict(resource_remote_info_alicloud_ecs_instance_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceRemoteInfoAlicloudRamRole.md b/docs/ResourceRemoteInfoAlicloudRamRole.md
new file mode 100644
index 0000000..5473583
--- /dev/null
+++ b/docs/ResourceRemoteInfoAlicloudRamRole.md
@@ -0,0 +1,30 @@
+# ResourceRemoteInfoAlicloudRamRole
+
+Remote info for AliCloud RAM role.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**role_arn** | **str** | The ARN of the AliCloud RAM role. |
+
+## Example
+
+```python
+from opal_security.models.resource_remote_info_alicloud_ram_role import ResourceRemoteInfoAlicloudRamRole
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceRemoteInfoAlicloudRamRole from a JSON string
+resource_remote_info_alicloud_ram_role_instance = ResourceRemoteInfoAlicloudRamRole.from_json(json)
+# print the JSON string representation of the object
+print(ResourceRemoteInfoAlicloudRamRole.to_json())
+
+# convert the object into a dict
+resource_remote_info_alicloud_ram_role_dict = resource_remote_info_alicloud_ram_role_instance.to_dict()
+# create an instance of ResourceRemoteInfoAlicloudRamRole from a dict
+resource_remote_info_alicloud_ram_role_from_dict = ResourceRemoteInfoAlicloudRamRole.from_dict(resource_remote_info_alicloud_ram_role_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceRemoteInfoDocusignPermissionProfile.md b/docs/ResourceRemoteInfoDocusignPermissionProfile.md
new file mode 100644
index 0000000..4b1024a
--- /dev/null
+++ b/docs/ResourceRemoteInfoDocusignPermissionProfile.md
@@ -0,0 +1,30 @@
+# ResourceRemoteInfoDocusignPermissionProfile
+
+Remote info for Docusign permission profile.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**permission_profile_id** | **str** | The ID of the Docusign permission profile. |
+
+## Example
+
+```python
+from opal_security.models.resource_remote_info_docusign_permission_profile import ResourceRemoteInfoDocusignPermissionProfile
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceRemoteInfoDocusignPermissionProfile from a JSON string
+resource_remote_info_docusign_permission_profile_instance = ResourceRemoteInfoDocusignPermissionProfile.from_json(json)
+# print the JSON string representation of the object
+print(ResourceRemoteInfoDocusignPermissionProfile.to_json())
+
+# convert the object into a dict
+resource_remote_info_docusign_permission_profile_dict = resource_remote_info_docusign_permission_profile_instance.to_dict()
+# create an instance of ResourceRemoteInfoDocusignPermissionProfile from a dict
+resource_remote_info_docusign_permission_profile_from_dict = ResourceRemoteInfoDocusignPermissionProfile.from_dict(resource_remote_info_docusign_permission_profile_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceRemoteInfoGcpBillingAccount.md b/docs/ResourceRemoteInfoGcpBillingAccount.md
new file mode 100644
index 0000000..7248ebb
--- /dev/null
+++ b/docs/ResourceRemoteInfoGcpBillingAccount.md
@@ -0,0 +1,30 @@
+# ResourceRemoteInfoGcpBillingAccount
+
+Remote info for a GCP billing account.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**billing_account_id** | **str** | The resource name of the billing account. |
+
+## Example
+
+```python
+from opal_security.models.resource_remote_info_gcp_billing_account import ResourceRemoteInfoGcpBillingAccount
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceRemoteInfoGcpBillingAccount from a JSON string
+resource_remote_info_gcp_billing_account_instance = ResourceRemoteInfoGcpBillingAccount.from_json(json)
+# print the JSON string representation of the object
+print(ResourceRemoteInfoGcpBillingAccount.to_json())
+
+# convert the object into a dict
+resource_remote_info_gcp_billing_account_dict = resource_remote_info_gcp_billing_account_instance.to_dict()
+# create an instance of ResourceRemoteInfoGcpBillingAccount from a dict
+resource_remote_info_gcp_billing_account_from_dict = ResourceRemoteInfoGcpBillingAccount.from_dict(resource_remote_info_gcp_billing_account_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceRemoteInfoLinearOrganization.md b/docs/ResourceRemoteInfoLinearOrganization.md
new file mode 100644
index 0000000..3998ea3
--- /dev/null
+++ b/docs/ResourceRemoteInfoLinearOrganization.md
@@ -0,0 +1,30 @@
+# ResourceRemoteInfoLinearOrganization
+
+Remote info for Linear organization.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**org_id** | **str** | The ID of the Linear organization. |
+
+## Example
+
+```python
+from opal_security.models.resource_remote_info_linear_organization import ResourceRemoteInfoLinearOrganization
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceRemoteInfoLinearOrganization from a JSON string
+resource_remote_info_linear_organization_instance = ResourceRemoteInfoLinearOrganization.from_json(json)
+# print the JSON string representation of the object
+print(ResourceRemoteInfoLinearOrganization.to_json())
+
+# convert the object into a dict
+resource_remote_info_linear_organization_dict = resource_remote_info_linear_organization_instance.to_dict()
+# create an instance of ResourceRemoteInfoLinearOrganization from a dict
+resource_remote_info_linear_organization_from_dict = ResourceRemoteInfoLinearOrganization.from_dict(resource_remote_info_linear_organization_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceRemoteInfoLinearProject.md b/docs/ResourceRemoteInfoLinearProject.md
new file mode 100644
index 0000000..87f3ba3
--- /dev/null
+++ b/docs/ResourceRemoteInfoLinearProject.md
@@ -0,0 +1,30 @@
+# ResourceRemoteInfoLinearProject
+
+Remote info for Linear project.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**project_id** | **str** | The ID of the Linear project. |
+
+## Example
+
+```python
+from opal_security.models.resource_remote_info_linear_project import ResourceRemoteInfoLinearProject
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceRemoteInfoLinearProject from a JSON string
+resource_remote_info_linear_project_instance = ResourceRemoteInfoLinearProject.from_json(json)
+# print the JSON string representation of the object
+print(ResourceRemoteInfoLinearProject.to_json())
+
+# convert the object into a dict
+resource_remote_info_linear_project_dict = resource_remote_info_linear_project_instance.to_dict()
+# create an instance of ResourceRemoteInfoLinearProject from a dict
+resource_remote_info_linear_project_from_dict = ResourceRemoteInfoLinearProject.from_dict(resource_remote_info_linear_project_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceRemoteInfoZoomLicense.md b/docs/ResourceRemoteInfoZoomLicense.md
new file mode 100644
index 0000000..3d4f3aa
--- /dev/null
+++ b/docs/ResourceRemoteInfoZoomLicense.md
@@ -0,0 +1,30 @@
+# ResourceRemoteInfoZoomLicense
+
+Remote info for Zoom license (user type).
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**license_type** | **str** | The Zoom user type representing the license (e.g. \"2\" for Licensed). |
+
+## Example
+
+```python
+from opal_security.models.resource_remote_info_zoom_license import ResourceRemoteInfoZoomLicense
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceRemoteInfoZoomLicense from a JSON string
+resource_remote_info_zoom_license_instance = ResourceRemoteInfoZoomLicense.from_json(json)
+# print the JSON string representation of the object
+print(ResourceRemoteInfoZoomLicense.to_json())
+
+# convert the object into a dict
+resource_remote_info_zoom_license_dict = resource_remote_info_zoom_license_instance.to_dict()
+# create an instance of ResourceRemoteInfoZoomLicense from a dict
+resource_remote_info_zoom_license_from_dict = ResourceRemoteInfoZoomLicense.from_dict(resource_remote_info_zoom_license_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceRemoteInfoZoomRole.md b/docs/ResourceRemoteInfoZoomRole.md
new file mode 100644
index 0000000..1066295
--- /dev/null
+++ b/docs/ResourceRemoteInfoZoomRole.md
@@ -0,0 +1,30 @@
+# ResourceRemoteInfoZoomRole
+
+Remote info for Zoom role.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**role_id** | **str** | The ID of the Zoom role. |
+
+## Example
+
+```python
+from opal_security.models.resource_remote_info_zoom_role import ResourceRemoteInfoZoomRole
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ResourceRemoteInfoZoomRole from a JSON string
+resource_remote_info_zoom_role_instance = ResourceRemoteInfoZoomRole.from_json(json)
+# print the JSON string representation of the object
+print(ResourceRemoteInfoZoomRole.to_json())
+
+# convert the object into a dict
+resource_remote_info_zoom_role_dict = resource_remote_info_zoom_role_instance.to_dict()
+# create an instance of ResourceRemoteInfoZoomRole from a dict
+resource_remote_info_zoom_role_from_dict = ResourceRemoteInfoZoomRole.from_dict(resource_remote_info_zoom_role_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ResourceTypeEnum.md b/docs/ResourceTypeEnum.md
index 6c667fc..7f6602f 100644
--- a/docs/ResourceTypeEnum.md
+++ b/docs/ResourceTypeEnum.md
@@ -78,6 +78,8 @@ The type of the resource.
* `GCP_SERVICE_ACCOUNT` (value: `'GCP_SERVICE_ACCOUNT'`)
+* `GCP_BILLING_ACCOUNT` (value: `'GCP_BILLING_ACCOUNT'`)
+
* `GIT_HUB_REPO` (value: `'GIT_HUB_REPO'`)
* `GIT_HUB_ORG_ROLE` (value: `'GIT_HUB_ORG_ROLE'`)
@@ -176,6 +178,20 @@ The type of the resource.
* `HUBSPOT_ROLE` (value: `'HUBSPOT_ROLE'`)
+* `ALICLOUD_RAM_ROLE` (value: `'ALICLOUD_RAM_ROLE'`)
+
+* `ALICLOUD_ECS_INSTANCE` (value: `'ALICLOUD_ECS_INSTANCE'`)
+
+* `DOCUSIGN_PERMISSION_PROFILE` (value: `'DOCUSIGN_PERMISSION_PROFILE'`)
+
+* `ZOOM_ROLE` (value: `'ZOOM_ROLE'`)
+
+* `ZOOM_LICENSE` (value: `'ZOOM_LICENSE'`)
+
+* `LINEAR_ORGANIZATION` (value: `'LINEAR_ORGANIZATION'`)
+
+* `LINEAR_PROJECT` (value: `'LINEAR_PROJECT'`)
+
[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
diff --git a/docs/ResourcesApi.md b/docs/ResourcesApi.md
index 531db7c..7409a81 100644
--- a/docs/ResourcesApi.md
+++ b/docs/ResourcesApi.md
@@ -7,10 +7,14 @@ Method | HTTP request | Description
[**add_resource_nhi**](ResourcesApi.md#add_resource_nhi) | **POST** /resources/{resource_id}/non-human-identities/{non_human_identity_id} |
[**add_resource_user**](ResourcesApi.md#add_resource_user) | **POST** /resources/{resource_id}/users/{user_id} |
[**create_resource**](ResourcesApi.md#create_resource) | **POST** /resources |
+[**create_resource_custom_access_level**](ResourcesApi.md#create_resource_custom_access_level) | **POST** /resources/{resource_id}/custom-access-levels |
[**delete_resource**](ResourcesApi.md#delete_resource) | **DELETE** /resources/{resource_id} |
+[**delete_resource_custom_access_level**](ResourcesApi.md#delete_resource_custom_access_level) | **DELETE** /resources/{resource_id}/custom-access-levels/{access_level_remote_id} |
[**delete_resource_nhi**](ResourcesApi.md#delete_resource_nhi) | **DELETE** /resources/{resource_id}/non-human-identities/{non_human_identity_id} |
[**delete_resource_user**](ResourcesApi.md#delete_resource_user) | **DELETE** /resources/{resource_id}/users/{user_id} |
[**get_resource**](ResourcesApi.md#get_resource) | **GET** /resources/{resource_id} | Get resource by ID
+[**get_resource_access_levels**](ResourcesApi.md#get_resource_access_levels) | **GET** /resources/{resource_id}/access_levels | Get resource access levels
+[**get_resource_custom_access_levels**](ResourcesApi.md#get_resource_custom_access_levels) | **GET** /resources/{resource_id}/custom-access-levels |
[**get_resource_groups**](ResourcesApi.md#get_resource_groups) | **GET** /resources/{resource_id}/groups |
[**get_resource_message_channels**](ResourcesApi.md#get_resource_message_channels) | **GET** /resources/{resource_id}/message-channels |
[**get_resource_nhis**](ResourcesApi.md#get_resource_nhis) | **GET** /resources/{resource_id}/non-human-identities |
@@ -29,6 +33,7 @@ Method | HTTP request | Description
[**set_resource_reviewers**](ResourcesApi.md#set_resource_reviewers) | **PUT** /resources/{resource_id}/reviewers |
[**set_resource_scoped_role_permissions**](ResourcesApi.md#set_resource_scoped_role_permissions) | **PUT** /resources/{resource_id}/scoped-role-permissions |
[**set_resource_visibility**](ResourcesApi.md#set_resource_visibility) | **PUT** /resources/{resource_id}/visibility |
+[**update_resource_custom_access_level**](ResourcesApi.md#update_resource_custom_access_level) | **PATCH** /resources/{resource_id}/custom-access-levels/{access_level_remote_id} |
[**update_resource_user**](ResourcesApi.md#update_resource_user) | **PUT** /resources/{resource_id}/users/{user_id} |
[**update_resources**](ResourcesApi.md#update_resources) | **PUT** /resources |
@@ -279,6 +284,89 @@ Name | Type | Description | Notes
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **create_resource_custom_access_level**
+> ResourceCustomAccessLevelResponse create_resource_custom_access_level(resource_id, create_resource_custom_access_level_info)
+
+Creates a custom access level on a resource. If the resource is a parent type, the role is created on all child resources.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.create_resource_custom_access_level_info import CreateResourceCustomAccessLevelInfo
+from opal_security.models.resource_custom_access_level_response import ResourceCustomAccessLevelResponse
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.ResourcesApi(api_client)
+ resource_id = UUID('1b978423-db0a-4037-a4cf-f79c60cb67b3') # UUID | The ID of the resource.
+ create_resource_custom_access_level_info = opal_security.CreateResourceCustomAccessLevelInfo() # CreateResourceCustomAccessLevelInfo |
+
+ try:
+ api_response = api_instance.create_resource_custom_access_level(resource_id, create_resource_custom_access_level_info)
+ print("The response of ResourcesApi->create_resource_custom_access_level:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling ResourcesApi->create_resource_custom_access_level: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **resource_id** | **UUID**| The ID of the resource. |
+ **create_resource_custom_access_level_info** | [**CreateResourceCustomAccessLevelInfo**](CreateResourceCustomAccessLevelInfo.md)| |
+
+### Return type
+
+[**ResourceCustomAccessLevelResponse**](ResourceCustomAccessLevelResponse.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The created custom access level. | - |
+**400** | Unsupported resource type. | - |
+**404** | Resource not found or access denied. | - |
+**409** | A custom access level with this remote ID already exists. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **delete_resource**
> delete_resource(resource_id)
@@ -353,6 +441,84 @@ void (empty response body)
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **delete_resource_custom_access_level**
+> delete_resource_custom_access_level(resource_id, access_level_remote_id)
+
+Deletes a custom access level identified by its remote ID. If the resource is a parent type, the deletion fans out to all child resources.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.ResourcesApi(api_client)
+ resource_id = UUID('1b978423-db0a-4037-a4cf-f79c60cb67b3') # UUID | The ID of the resource.
+ access_level_remote_id = 'admin' # str | The remote ID of the access level.
+
+ try:
+ api_instance.delete_resource_custom_access_level(resource_id, access_level_remote_id)
+ except Exception as e:
+ print("Exception when calling ResourcesApi->delete_resource_custom_access_level: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **resource_id** | **UUID**| The ID of the resource. |
+ **access_level_remote_id** | **str**| The remote ID of the access level. |
+
+### Return type
+
+void (empty response body)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: Not defined
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | Successfully deleted. | - |
+**400** | Unsupported resource type. | - |
+**404** | Resource or access level not found, or access denied. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **delete_resource_nhi**
> delete_resource_nhi(resource_id, non_human_identity_id, access_level_remote_id=access_level_remote_id)
@@ -589,6 +755,166 @@ Name | Type | Description | Notes
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **get_resource_access_levels**
+> ResourceAccessLevelList get_resource_access_levels(resource_id)
+
+Get resource access levels
+
+Returns the list of access levels defined for the resource. Resources that only offer default (unnamed) access return an empty list.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.resource_access_level_list import ResourceAccessLevelList
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.ResourcesApi(api_client)
+ resource_id = UUID('4baf8423-db0a-4037-a4cf-f79c60cb67a5') # UUID | The ID of the resource whose access levels to return.
+
+ try:
+ # Get resource access levels
+ api_response = api_instance.get_resource_access_levels(resource_id)
+ print("The response of ResourcesApi->get_resource_access_levels:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling ResourcesApi->get_resource_access_levels: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **resource_id** | **UUID**| The ID of the resource whose access levels to return. |
+
+### Return type
+
+[**ResourceAccessLevelList**](ResourceAccessLevelList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The access levels defined for the resource. | - |
+**404** | Resource not found. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **get_resource_custom_access_levels**
+> ResourceCustomAccessLevelList get_resource_custom_access_levels(resource_id)
+
+Returns all custom access levels for a resource. If the resource is a parent type (e.g. GitHubOrg), returns aggregated roles across child resources.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.resource_custom_access_level_list import ResourceCustomAccessLevelList
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.ResourcesApi(api_client)
+ resource_id = UUID('1b978423-db0a-4037-a4cf-f79c60cb67b3') # UUID | The ID of the resource.
+
+ try:
+ api_response = api_instance.get_resource_custom_access_levels(resource_id)
+ print("The response of ResourcesApi->get_resource_custom_access_levels:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling ResourcesApi->get_resource_custom_access_levels: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **resource_id** | **UUID**| The ID of the resource. |
+
+### Return type
+
+[**ResourceCustomAccessLevelList**](ResourceCustomAccessLevelList.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The custom access levels for the resource. | - |
+**400** | Unsupported resource type. | - |
+**404** | Resource not found or access denied. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **get_resource_groups**
> GroupResourceList get_resource_groups(resource_id)
@@ -1370,6 +1696,7 @@ Name | Type | Description | Notes
| Status code | Description | Response headers |
|-------------|-------------|------------------|
**200** | The visibility info of this resource. | - |
+**403** | The caller is not authorized to view this resource's visibility. | - |
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
@@ -2034,6 +2361,90 @@ Name | Type | Description | Notes
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **update_resource_custom_access_level**
+> ResourceCustomAccessLevelResponse update_resource_custom_access_level(resource_id, access_level_remote_id, update_resource_custom_access_level_info)
+
+Updates a custom access level identified by its remote ID. If the resource is a parent type, the update fans out to all child resources.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.resource_custom_access_level_response import ResourceCustomAccessLevelResponse
+from opal_security.models.update_resource_custom_access_level_info import UpdateResourceCustomAccessLevelInfo
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.ResourcesApi(api_client)
+ resource_id = UUID('1b978423-db0a-4037-a4cf-f79c60cb67b3') # UUID | The ID of the resource.
+ access_level_remote_id = 'admin' # str | The remote ID of the access level.
+ update_resource_custom_access_level_info = opal_security.UpdateResourceCustomAccessLevelInfo() # UpdateResourceCustomAccessLevelInfo |
+
+ try:
+ api_response = api_instance.update_resource_custom_access_level(resource_id, access_level_remote_id, update_resource_custom_access_level_info)
+ print("The response of ResourcesApi->update_resource_custom_access_level:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling ResourcesApi->update_resource_custom_access_level: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **resource_id** | **UUID**| The ID of the resource. |
+ **access_level_remote_id** | **str**| The remote ID of the access level. |
+ **update_resource_custom_access_level_info** | [**UpdateResourceCustomAccessLevelInfo**](UpdateResourceCustomAccessLevelInfo.md)| |
+
+### Return type
+
+[**ResourceCustomAccessLevelResponse**](ResourceCustomAccessLevelResponse.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The updated custom access level. | - |
+**400** | Unsupported resource type. | - |
+**404** | Resource or access level not found, or access denied. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **update_resource_user**
> ResourceUser update_resource_user(resource_id, user_id, update_resource_user_request)
diff --git a/docs/RolePermissionTargetTypeEnum.md b/docs/RolePermissionTargetTypeEnum.md
index c29e9ad..797d338 100644
--- a/docs/RolePermissionTargetTypeEnum.md
+++ b/docs/RolePermissionTargetTypeEnum.md
@@ -18,6 +18,8 @@ The type of the target for the role permission.
* `OWNER` (value: `'OWNER'`)
+* `EVENT` (value: `'EVENT'`)
+
[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
diff --git a/docs/RunOpalQueryRequest.md b/docs/RunOpalQueryRequest.md
new file mode 100644
index 0000000..5a90726
--- /dev/null
+++ b/docs/RunOpalQueryRequest.md
@@ -0,0 +1,34 @@
+# RunOpalQueryRequest
+
+Request body for an ad-hoc OpalQuery. Set `type` to `NODE` to query entities, or `ACCESS_PATH` to query access edges. The fields available in `query` differ by type — refer to each tab for the full schema.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**type** | **str** | |
+**query** | [**OpalAccessPathQueryBody**](OpalAccessPathQueryBody.md) | | [optional]
+**first** | **int** | Maximum number of results to return. Defaults to 200. | [optional]
+**after** | **str** | Opaque cursor from a previous ACCESS_PATH response to fetch the next page of results. | [optional]
+**include_count** | **bool** | When true, populate totalCount in the response. Defaults to false. | [optional]
+
+## Example
+
+```python
+from opal_security.models.run_opal_query_request import RunOpalQueryRequest
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of RunOpalQueryRequest from a JSON string
+run_opal_query_request_instance = RunOpalQueryRequest.from_json(json)
+# print the JSON string representation of the object
+print(RunOpalQueryRequest.to_json())
+
+# convert the object into a dict
+run_opal_query_request_dict = run_opal_query_request_instance.to_dict()
+# create an instance of RunOpalQueryRequest from a dict
+run_opal_query_request_from_dict = RunOpalQueryRequest.from_dict(run_opal_query_request_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/SortDirectionEnum.md b/docs/SortDirectionEnum.md
new file mode 100644
index 0000000..40f192d
--- /dev/null
+++ b/docs/SortDirectionEnum.md
@@ -0,0 +1,13 @@
+# SortDirectionEnum
+
+Sort direction for viewer campaign items.
+
+## Enum
+
+* `ASC` (value: `'ASC'`)
+
+* `DESC` (value: `'DESC'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/StopCampaignRequest.md b/docs/StopCampaignRequest.md
new file mode 100644
index 0000000..da1e878
--- /dev/null
+++ b/docs/StopCampaignRequest.md
@@ -0,0 +1,29 @@
+# StopCampaignRequest
+
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**revoke_unreviewed** | **bool** | Revoke all unreviewed access grants. Access grants with no reviewer decision will be immediately revoked. | [optional] [default to False]
+
+## Example
+
+```python
+from opal_security.models.stop_campaign_request import StopCampaignRequest
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of StopCampaignRequest from a JSON string
+stop_campaign_request_instance = StopCampaignRequest.from_json(json)
+# print the JSON string representation of the object
+print(StopCampaignRequest.to_json())
+
+# convert the object into a dict
+stop_campaign_request_dict = stop_campaign_request_instance.to_dict()
+# create an instance of StopCampaignRequest from a dict
+stop_campaign_request_from_dict = StopCampaignRequest.from_dict(stop_campaign_request_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/StringMatchType.md b/docs/StringMatchType.md
index ab78865..c7a971a 100644
--- a/docs/StringMatchType.md
+++ b/docs/StringMatchType.md
@@ -1,6 +1,6 @@
# StringMatchType
-How to match a string value against entity names.
+How to match a string value against entity names. REGEX matches the value as a case-insensitive regular expression.
## Enum
@@ -12,6 +12,8 @@ How to match a string value against entity names.
* `ENDS_WITH` (value: `'ENDS_WITH'`)
+* `REGEX` (value: `'REGEX'`)
+
[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
diff --git a/docs/UarsApi.md b/docs/UarsApi.md
index 24d66dd..a14213f 100644
--- a/docs/UarsApi.md
+++ b/docs/UarsApi.md
@@ -12,7 +12,7 @@ Method | HTTP request | Description
# **create_uar**
> UAR create_uar(create_uar_info)
-Starts a User Access Review.
+Starts a User Access Review. Deprecated in favor of `POST /campaigns`.
### Example
@@ -90,7 +90,7 @@ Name | Type | Description | Notes
# **get_uar**
> UAR get_uar(uar_id)
-Retrieves a specific UAR.
+Retrieves a specific UAR. Deprecated in favor of `GET /campaigns/{campaign_id}`.
### Example
@@ -167,7 +167,7 @@ Name | Type | Description | Notes
# **get_uars**
> PaginatedUARsList get_uars(cursor=cursor, page_size=page_size)
-Returns a list of `UAR` objects.
+Returns a list of `UAR` objects. Deprecated in favor of `GET /campaigns`.
### Example
diff --git a/docs/UpdateCampaignConfigurationInfo.md b/docs/UpdateCampaignConfigurationInfo.md
new file mode 100644
index 0000000..b38d08d
--- /dev/null
+++ b/docs/UpdateCampaignConfigurationInfo.md
@@ -0,0 +1,44 @@
+# UpdateCampaignConfigurationInfo
+
+Configuration fields to update on a campaign. All fields are optional; omitted fields are left unchanged. `query` and `reviewer_assignment_policy` are set at create time and cannot be updated here; including either field returns 400. `cron_expression` and `recurring_duration_days` may only be set when the campaign is a template; setting them on a one-off campaign returns 400. `is_template` is immutable and not accepted on update.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**allow_self_review** | **bool** | Whether reviewers can review their own access. | [optional]
+**send_reviewer_assignment_notification** | **bool** | Whether to notify reviewers upon assignment. | [optional]
+**allow_reviewer_reassignment** | **bool** | Whether reviewers may reassign their reviews to another user. | [optional]
+**start_date** | **datetime** | Scheduled start date of the campaign. May only be updated while the campaign has not started (started_at is null). When set, the date's calendar day in the campaign timezone must be at least tomorrow. | [optional]
+**end_date** | **datetime** | Scheduled end date of the campaign. When set, the date's calendar day in the campaign timezone must be at least tomorrow. | [optional]
+**timezone** | **str** | IANA timezone used to interpret campaign deadlines (e.g. America/Los_Angeles). | [optional]
+**revoke_on** | [**CampaignRevokeOnEnum**](CampaignRevokeOnEnum.md) | | [optional]
+**reminder_schedule** | **List[int]** | Days before end date to send reminder notifications. | [optional]
+**reminder_include_manager** | **bool** | Whether to include the reviewer's manager in reminders. | [optional]
+**require_reason_on_denial** | **bool** | Whether reviewers must provide a reason when denying (revoking) access. | [optional]
+**hide_ai_suggestions** | **bool** | Whether AI suggestions are hidden from reviewers. | [optional]
+**custom_start_message** | **str** | Optional custom message included when notifying reviewers that the campaign started. | [optional]
+**group_asset_visibility_policy** | [**CampaignGroupAssetVisibilityPolicyEnum**](CampaignGroupAssetVisibilityPolicyEnum.md) | | [optional]
+**cron_expression** | **str** | Cron expression driving the recurring schedule. Only valid on template campaigns. Pass an empty string to clear the active months (next_scheduled_run is cleared); the campaign remains a template. | [optional]
+**recurring_duration_days** | **int** | Deadline window in days applied to each draft generated from this template. Only valid on template campaigns. | [optional]
+
+## Example
+
+```python
+from opal_security.models.update_campaign_configuration_info import UpdateCampaignConfigurationInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of UpdateCampaignConfigurationInfo from a JSON string
+update_campaign_configuration_info_instance = UpdateCampaignConfigurationInfo.from_json(json)
+# print the JSON string representation of the object
+print(UpdateCampaignConfigurationInfo.to_json())
+
+# convert the object into a dict
+update_campaign_configuration_info_dict = update_campaign_configuration_info_instance.to_dict()
+# create an instance of UpdateCampaignConfigurationInfo from a dict
+update_campaign_configuration_info_from_dict = UpdateCampaignConfigurationInfo.from_dict(update_campaign_configuration_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/UpdateCampaignInfo.md b/docs/UpdateCampaignInfo.md
new file mode 100644
index 0000000..6870a0e
--- /dev/null
+++ b/docs/UpdateCampaignInfo.md
@@ -0,0 +1,31 @@
+# UpdateCampaignInfo
+
+# UpdateCampaignInfo Object ### Description The `UpdateCampaignInfo` object is used to partially update a campaign. Omitted fields are left unchanged. ### Usage Example Use in the `PUT Campaign` endpoint.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**name** | **str** | The name of the campaign. | [optional]
+**configuration** | [**UpdateCampaignConfigurationInfo**](UpdateCampaignConfigurationInfo.md) | Configuration fields to create or update. | [optional]
+
+## Example
+
+```python
+from opal_security.models.update_campaign_info import UpdateCampaignInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of UpdateCampaignInfo from a JSON string
+update_campaign_info_instance = UpdateCampaignInfo.from_json(json)
+# print the JSON string representation of the object
+print(UpdateCampaignInfo.to_json())
+
+# convert the object into a dict
+update_campaign_info_dict = update_campaign_info_instance.to_dict()
+# create an instance of UpdateCampaignInfo from a dict
+update_campaign_info_from_dict = UpdateCampaignInfo.from_dict(update_campaign_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/UpdateGroupInfo.md b/docs/UpdateGroupInfo.md
index 489f5e1..da77dad 100644
--- a/docs/UpdateGroupInfo.md
+++ b/docs/UpdateGroupInfo.md
@@ -27,6 +27,8 @@ Name | Type | Description | Notes
**request_configuration_list** | [**CreateRequestConfigurationInfoList**](CreateRequestConfigurationInfoList.md) | The request configuration list of the configuration template. If not provided, the default request configuration will be used. Deprecated in favor of `request_configurations`. | [optional]
**custom_request_notification** | **str** | Custom request notification sent to the requester when the request is approved. | [optional]
**risk_sensitivity_override** | [**RiskSensitivityEnum**](RiskSensitivityEnum.md) | | [optional]
+**match_remote_name** | **bool** | A bool representing whether or not the group's name should be synced from the end system. When true, the name is overwritten with the remote name on each sync, so a `name` provided together with this field set to true will be replaced at the next sync. If not provided, the current value is left unchanged. | [optional]
+**match_remote_description** | **bool** | A bool representing whether or not the group's description should be synced from the end system. When true, the description is overwritten with the remote description on each sync, so a `description` provided together with this field set to true will be replaced at the next sync. If not provided, the current value is left unchanged. | [optional]
## Example
diff --git a/docs/UpdatePaladinInfo.md b/docs/UpdatePaladinInfo.md
new file mode 100644
index 0000000..34e6a5a
--- /dev/null
+++ b/docs/UpdatePaladinInfo.md
@@ -0,0 +1,34 @@
+# UpdatePaladinInfo
+
+Information for updating a Paladin.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**name** | **str** | The name of the Paladin. |
+**monitor_mode** | **bool** | When true, the Paladin reasons about requests but takes no action. If omitted, the existing value is preserved. | [optional]
+**admin_view_only** | **bool** | When true, recommendations are visible only to admins. Only meaningful when monitor_mode is true. If omitted, the existing value is preserved. | [optional]
+**enabled_connectors** | [**List[PaladinConnector]**](PaladinConnector.md) | The connectors the Paladin is allowed to use. If omitted, the existing connectors are preserved. | [optional]
+**instructions** | **str** | The free-form instructions that guide the Paladin's decisions. If omitted, the existing instructions are preserved. | [optional]
+
+## Example
+
+```python
+from opal_security.models.update_paladin_info import UpdatePaladinInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of UpdatePaladinInfo from a JSON string
+update_paladin_info_instance = UpdatePaladinInfo.from_json(json)
+# print the JSON string representation of the object
+print(UpdatePaladinInfo.to_json())
+
+# convert the object into a dict
+update_paladin_info_dict = update_paladin_info_instance.to_dict()
+# create an instance of UpdatePaladinInfo from a dict
+update_paladin_info_from_dict = UpdatePaladinInfo.from_dict(update_paladin_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/UpdateRequestTemplateInfo.md b/docs/UpdateRequestTemplateInfo.md
new file mode 100644
index 0000000..2650918
--- /dev/null
+++ b/docs/UpdateRequestTemplateInfo.md
@@ -0,0 +1,32 @@
+# UpdateRequestTemplateInfo
+
+Information for updating a request template. Omitted properties are left unchanged, but `custom_fields` replaces the template's fields wholesale when provided.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**request_template_id** | **UUID** | The ID of the request template to update. |
+**name** | **str** | The new name of the request template. | [optional]
+**custom_fields** | [**List[RequestTemplateCustomFieldInput]**](RequestTemplateCustomFieldInput.md) | The complete set of fields for the template. Any field not included is removed. | [optional]
+
+## Example
+
+```python
+from opal_security.models.update_request_template_info import UpdateRequestTemplateInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of UpdateRequestTemplateInfo from a JSON string
+update_request_template_info_instance = UpdateRequestTemplateInfo.from_json(json)
+# print the JSON string representation of the object
+print(UpdateRequestTemplateInfo.to_json())
+
+# convert the object into a dict
+update_request_template_info_dict = update_request_template_info_instance.to_dict()
+# create an instance of UpdateRequestTemplateInfo from a dict
+update_request_template_info_from_dict = UpdateRequestTemplateInfo.from_dict(update_request_template_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/UpdateResourceCustomAccessLevelInfo.md b/docs/UpdateResourceCustomAccessLevelInfo.md
new file mode 100644
index 0000000..8512b0b
--- /dev/null
+++ b/docs/UpdateResourceCustomAccessLevelInfo.md
@@ -0,0 +1,34 @@
+# UpdateResourceCustomAccessLevelInfo
+
+Info for updating a custom access level.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**access_level_name** | **str** | The new human-readable name. | [optional]
+**policy** | **str** | The new policy document. | [optional]
+**requestable_by_default** | **bool** | Whether the role is requestable. | [optional]
+**stackable_sensitivity_index** | **int** | The new sensitivity index. | [optional]
+**clear_stackable_sensitivity_index** | **bool** | Set to true to remove from the hierarchy. | [optional]
+
+## Example
+
+```python
+from opal_security.models.update_resource_custom_access_level_info import UpdateResourceCustomAccessLevelInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of UpdateResourceCustomAccessLevelInfo from a JSON string
+update_resource_custom_access_level_info_instance = UpdateResourceCustomAccessLevelInfo.from_json(json)
+# print the JSON string representation of the object
+print(UpdateResourceCustomAccessLevelInfo.to_json())
+
+# convert the object into a dict
+update_resource_custom_access_level_info_dict = update_resource_custom_access_level_info_instance.to_dict()
+# create an instance of UpdateResourceCustomAccessLevelInfo from a dict
+update_resource_custom_access_level_info_from_dict = UpdateResourceCustomAccessLevelInfo.from_dict(update_resource_custom_access_level_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/UpdateResourceInfo.md b/docs/UpdateResourceInfo.md
index 29865dd..07513a9 100644
--- a/docs/UpdateResourceInfo.md
+++ b/docs/UpdateResourceInfo.md
@@ -22,6 +22,8 @@ Name | Type | Description | Notes
**ticket_propagation** | [**TicketPropagationConfiguration**](TicketPropagationConfiguration.md) | | [optional]
**custom_request_notification** | **str** | Custom request notification sent upon request approval. | [optional]
**risk_sensitivity_override** | [**RiskSensitivityEnum**](RiskSensitivityEnum.md) | | [optional]
+**match_remote_name** | **bool** | A bool representing whether or not the resource's name should be synced from the end system. When true, the name is overwritten with the remote name on each sync, so a `name` provided together with this field set to true will be replaced at the next sync. If not provided, the current value is left unchanged. | [optional]
+**match_remote_description** | **bool** | A bool representing whether or not the resource's description should be synced from the end system. When true, the description is overwritten with the remote description on each sync, so a `description` provided together with this field set to true will be replaced at the next sync. If not provided, the current value is left unchanged. | [optional]
**configuration_template_id** | **UUID** | The ID of the associated configuration template. | [optional]
**request_template_id** | **UUID** | The ID of the associated request template. Deprecated in favor of `request_configurations`. | [optional]
**is_requestable** | **bool** | A bool representing whether or not to allow access requests to this resource. Deprecated in favor of `request_configurations`. | [optional]
diff --git a/docs/UpdateUserInfo.md b/docs/UpdateUserInfo.md
new file mode 100644
index 0000000..5d3d851
--- /dev/null
+++ b/docs/UpdateUserInfo.md
@@ -0,0 +1,31 @@
+# UpdateUserInfo
+
+The user fields to update.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**manager_id** | **UUID** | The user's manager ID. Set to null to remove the manager. | [optional]
+**position** | **str** | The user's position. | [optional]
+
+## Example
+
+```python
+from opal_security.models.update_user_info import UpdateUserInfo
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of UpdateUserInfo from a JSON string
+update_user_info_instance = UpdateUserInfo.from_json(json)
+# print the JSON string representation of the object
+print(UpdateUserInfo.to_json())
+
+# convert the object into a dict
+update_user_info_dict = update_user_info_instance.to_dict()
+# create an instance of UpdateUserInfo from a dict
+update_user_info_from_dict = UpdateUserInfo.from_dict(update_user_info_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/UserProductRoleEnum.md b/docs/UserProductRoleEnum.md
new file mode 100644
index 0000000..42efd34
--- /dev/null
+++ b/docs/UserProductRoleEnum.md
@@ -0,0 +1,13 @@
+# UserProductRoleEnum
+
+The product role assigned to a user.
+
+## Enum
+
+* `MEMBER` (value: `'MEMBER'`)
+
+* `ADMIN` (value: `'ADMIN'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/UsersApi.md b/docs/UsersApi.md
index 262d8ec..2a2ebcb 100644
--- a/docs/UsersApi.md
+++ b/docs/UsersApi.md
@@ -4,12 +4,96 @@ All URIs are relative to *https://api.opal.dev/v1*
Method | HTTP request | Description
------------- | ------------- | -------------
+[**delete_user**](UsersApi.md#delete_user) | **DELETE** /users/{user_id} |
[**get_remote_users**](UsersApi.md#get_remote_users) | **GET** /users/remote_users |
[**get_user_tags**](UsersApi.md#get_user_tags) | **GET** /users/{user_id}/tags |
+[**get_user_whoami**](UsersApi.md#get_user_whoami) | **GET** /users/whoami |
[**get_users**](UsersApi.md#get_users) | **GET** /users |
+[**invite_user**](UsersApi.md#invite_user) | **POST** /users |
+[**update_user**](UsersApi.md#update_user) | **PATCH** /users/{user_id} |
[**user**](UsersApi.md#user) | **GET** /user |
+# **delete_user**
+> User delete_user(user_id)
+
+Deletes a user from your organization.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.user import User
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.UsersApi(api_client)
+ user_id = UUID('38400000-8cf0-11bd-b23e-10b96e4ef00d') # UUID | The ID of the user to delete.
+
+ try:
+ api_response = api_instance.delete_user(user_id)
+ print("The response of UsersApi->delete_user:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling UsersApi->delete_user: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **user_id** | **UUID**| The ID of the user to delete. |
+
+### Return type
+
+[**User**](User.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The deleted user. | - |
+**403** | The caller is not authorized to delete the user. | - |
+**404** | The user was not found. | - |
+**409** | The user cannot be deleted in its current state. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **get_remote_users**
> PaginatedRemoteUsersList get_remote_users(third_party_provider=third_party_provider, user_id=user_id, remote_id=remote_id, cursor=cursor, page_size=page_size)
@@ -173,6 +257,79 @@ Name | Type | Description | Notes
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **get_user_whoami**
+> User get_user_whoami()
+
+Returns the user that the provided API token authenticates as.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.user import User
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.UsersApi(api_client)
+
+ try:
+ api_response = api_instance.get_user_whoami()
+ print("The response of UsersApi->get_user_whoami:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling UsersApi->get_user_whoami: %s\n" % e)
+```
+
+
+
+### Parameters
+
+This endpoint does not need any parameter.
+
+### Return type
+
+[**User**](User.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: Not defined
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The user that the API token authenticates as. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **get_users**
> PaginatedUsersList get_users(cursor=cursor, page_size=page_size, tag_ids=tag_ids)
@@ -254,6 +411,171 @@ Name | Type | Description | Notes
[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+# **invite_user**
+> User invite_user(invite_user_info)
+
+Invites a user to your organization.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.invite_user_info import InviteUserInfo
+from opal_security.models.user import User
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.UsersApi(api_client)
+ invite_user_info = opal_security.InviteUserInfo() # InviteUserInfo |
+
+ try:
+ api_response = api_instance.invite_user(invite_user_info)
+ print("The response of UsersApi->invite_user:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling UsersApi->invite_user: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **invite_user_info** | [**InviteUserInfo**](InviteUserInfo.md)| |
+
+### Return type
+
+[**User**](User.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The invited user. | - |
+**400** | The invite input is invalid. | - |
+**403** | The caller is not authorized to invite users. | - |
+**409** | The user already belongs to another organization. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
+# **update_user**
+> User update_user(user_id, update_user_info)
+
+Updates a user's position or manager.
+
+### Example
+
+* Bearer Authentication (BearerAuth):
+
+```python
+import opal_security
+from opal_security.models.update_user_info import UpdateUserInfo
+from opal_security.models.user import User
+from opal_security.rest import ApiException
+from pprint import pprint
+
+# Defining the host is optional and defaults to https://api.opal.dev/v1
+# See configuration.py for a list of all supported configuration parameters.
+import opal_security as opal
+
+configuration = opal.Configuration(
+ host = "https://api.opal.dev/v1"
+)
+
+# The client must configure the authentication and authorization parameters
+# in accordance with the API server security policy.
+# Examples for each auth method are provided below, use the example that
+# satisfies your auth use case.
+
+# Configure Bearer authorization: BearerAuth
+configuration = opal.Configuration(
+ access_token = os.environ["BEARER_TOKEN"]
+)
+
+# Enter a context with an instance of the API client
+with opal_security.ApiClient(configuration) as api_client:
+ # Create an instance of the API class
+ api_instance = opal_security.UsersApi(api_client)
+ user_id = UUID('38400000-8cf0-11bd-b23e-10b96e4ef00d') # UUID | The ID of the user to update.
+ update_user_info = opal_security.UpdateUserInfo() # UpdateUserInfo |
+
+ try:
+ api_response = api_instance.update_user(user_id, update_user_info)
+ print("The response of UsersApi->update_user:\n")
+ pprint(api_response)
+ except Exception as e:
+ print("Exception when calling UsersApi->update_user: %s\n" % e)
+```
+
+
+
+### Parameters
+
+
+Name | Type | Description | Notes
+------------- | ------------- | ------------- | -------------
+ **user_id** | **UUID**| The ID of the user to update. |
+ **update_user_info** | [**UpdateUserInfo**](UpdateUserInfo.md)| |
+
+### Return type
+
+[**User**](User.md)
+
+### Authorization
+
+[BearerAuth](../README.md#BearerAuth)
+
+### HTTP request headers
+
+ - **Content-Type**: application/json
+ - **Accept**: application/json
+
+### HTTP response details
+
+| Status code | Description | Response headers |
+|-------------|-------------|------------------|
+**200** | The updated user. | - |
+**400** | The update input is invalid. | - |
+**403** | The caller is not authorized to update the user. | - |
+**404** | The user was not found. | - |
+**409** | The user is managed by an identity provider or is immutable. | - |
+
+[[Back to top]](#) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to Model list]](../README.md#documentation-for-models) [[Back to README]](../README.md)
+
# **user**
> User user(user_id=user_id, email=email)
diff --git a/docs/ViewerCampaignItem.md b/docs/ViewerCampaignItem.md
new file mode 100644
index 0000000..9007a13
--- /dev/null
+++ b/docs/ViewerCampaignItem.md
@@ -0,0 +1,47 @@
+# ViewerCampaignItem
+
+A campaign review item assigned to the current viewer, matching GraphQL `ViewerCampaignItem`.
+
+## Properties
+
+Name | Type | Description | Notes
+------------ | ------------- | ------------- | -------------
+**campaign_item_review_id** | **UUID** | The ID of the campaign item review. |
+**decision** | [**ViewerCampaignItemReviewDecisionEnum**](ViewerCampaignItemReviewDecisionEnum.md) | The reviewer's decision. Null when undecided. | [optional]
+**note** | **str** | Optional note from the reviewer. | [optional]
+**decided_at** | **datetime** | When the decision was finalized. | [optional]
+**pending_decision** | [**ViewerCampaignItemReviewDecisionEnum**](ViewerCampaignItemReviewDecisionEnum.md) | Pending decision staged by the viewer, if any. | [optional]
+**pending_note** | **str** | Pending note attached to the reviewer's pending decision. | [optional]
+**updated_access_level_remote_id** | **str** | Target access level remote ID when decision is CHANGE_ROLE. | [optional]
+**pending_updated_access_level_remote_id** | **str** | Pending target access level remote ID when decision is CHANGE_ROLE. | [optional]
+**reassigned_to_reviewer_ids** | **List[UUID]** | User IDs this review was reassigned to. | [optional]
+**principal_id** | **UUID** | Principal ID from the role assignment. |
+**principal_type** | [**EntityTypeEnum**](EntityTypeEnum.md) | |
+**entity_id** | **UUID** | Entity ID from the role assignment. |
+**entity_type** | [**EntityTypeEnum**](EntityTypeEnum.md) | |
+**access_level_name** | **str** | Denormalized access level name. | [optional]
+**access_level_remote_id** | **str** | Access level remote ID from the role assignment. | [optional]
+**granted_at** | **datetime** | When the access was originally granted. |
+**expires_at** | **datetime** | When the access expires, if set. | [optional]
+**role_assignment_id** | **UUID** | ID of the underlying role assignment. |
+
+## Example
+
+```python
+from opal_security.models.viewer_campaign_item import ViewerCampaignItem
+
+# TODO update the JSON string below
+json = "{}"
+# create an instance of ViewerCampaignItem from a JSON string
+viewer_campaign_item_instance = ViewerCampaignItem.from_json(json)
+# print the JSON string representation of the object
+print(ViewerCampaignItem.to_json())
+
+# convert the object into a dict
+viewer_campaign_item_dict = viewer_campaign_item_instance.to_dict()
+# create an instance of ViewerCampaignItem from a dict
+viewer_campaign_item_from_dict = ViewerCampaignItem.from_dict(viewer_campaign_item_dict)
+```
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ViewerCampaignItemReviewDecisionEnum.md b/docs/ViewerCampaignItemReviewDecisionEnum.md
new file mode 100644
index 0000000..cba3ff1
--- /dev/null
+++ b/docs/ViewerCampaignItemReviewDecisionEnum.md
@@ -0,0 +1,21 @@
+# ViewerCampaignItemReviewDecisionEnum
+
+Decision recorded on a campaign item review row.
+
+## Enum
+
+* `APPROVED` (value: `'APPROVED'`)
+
+* `REVOKED` (value: `'REVOKED'`)
+
+* `CHANGE_ROLE` (value: `'CHANGE_ROLE'`)
+
+* `ADMIN_REVOKED` (value: `'ADMIN_REVOKED'`)
+
+* `NO_ACTION` (value: `'NO_ACTION'`)
+
+* `REASSIGNED` (value: `'REASSIGNED'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ViewerCampaignItemSortFieldEnum.md b/docs/ViewerCampaignItemSortFieldEnum.md
new file mode 100644
index 0000000..c8c6788
--- /dev/null
+++ b/docs/ViewerCampaignItemSortFieldEnum.md
@@ -0,0 +1,17 @@
+# ViewerCampaignItemSortFieldEnum
+
+Sort field for viewer campaign items.
+
+## Enum
+
+* `PRINCIPAL_NAME` (value: `'PRINCIPAL_NAME'`)
+
+* `ENTITY_NAME` (value: `'ENTITY_NAME'`)
+
+* `EXPIRATION` (value: `'EXPIRATION'`)
+
+* `LAST_USED` (value: `'LAST_USED'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/docs/ViewerCampaignItemStatusEnum.md b/docs/ViewerCampaignItemStatusEnum.md
new file mode 100644
index 0000000..ee61c09
--- /dev/null
+++ b/docs/ViewerCampaignItemStatusEnum.md
@@ -0,0 +1,21 @@
+# ViewerCampaignItemStatusEnum
+
+Decision status for a viewer campaign item.
+
+## Enum
+
+* `APPROVED` (value: `'APPROVED'`)
+
+* `REVOKED` (value: `'REVOKED'`)
+
+* `CHANGE_ROLE` (value: `'CHANGE_ROLE'`)
+
+* `NO_ACTION` (value: `'NO_ACTION'`)
+
+* `PENDING` (value: `'PENDING'`)
+
+* `REASSIGNED` (value: `'REASSIGNED'`)
+
+[[Back to Model list]](../README.md#documentation-for-models) [[Back to API list]](../README.md#documentation-for-api-endpoints) [[Back to README]](../README.md)
+
+
diff --git a/opal_security/__init__.py b/opal_security/__init__.py
index bfd68aa..6f79fd3 100644
--- a/opal_security/__init__.py
+++ b/opal_security/__init__.py
@@ -22,6 +22,7 @@
"AccessRulesApi",
"AppsApi",
"BundlesApi",
+ "CampaignsApi",
"ConfigurationTemplatesApi",
"DelegationsApi",
"EventStreamsApi",
@@ -34,6 +35,8 @@
"OnCallSchedulesApi",
"OpalQueriesApi",
"OwnersApi",
+ "PaladinApi",
+ "RequestTemplatesApi",
"RequestsApi",
"ResourcesApi",
"SessionsApi",
@@ -75,9 +78,23 @@
"Bundle",
"BundleGroup",
"BundleResource",
+ "Campaign",
+ "CampaignConfiguration",
+ "CampaignGroupAssetVisibilityPolicyEnum",
+ "CampaignItem",
+ "CampaignItemAdminOverride",
+ "CampaignItemReview",
+ "CampaignItemReviewDecisionEnum",
+ "CampaignItemReviewerAssignmentSourceEnum",
+ "CampaignItemStatusEnum",
+ "CampaignItemTargetTypeEnum",
+ "CampaignRevokeOnEnum",
+ "CampaignStatusEnum",
"Condition",
"ConfigurationTemplate",
"CreateBundleInfo",
+ "CreateCampaignConfigurationInfo",
+ "CreateCampaignInfo",
"CreateConfigurationTemplateInfo",
"CreateDelegationRequest",
"CreateEventStreamInfo",
@@ -88,6 +105,8 @@
"CreateMessageChannelInfo",
"CreateOnCallScheduleInfo",
"CreateOwnerInfo",
+ "CreatePaladinContextSourceInfo",
+ "CreatePaladinInfo",
"CreateRequest200Response",
"CreateRequestCommentRequest",
"CreateRequestConfigurationInfoList",
@@ -96,11 +115,14 @@
"CreateRequestInfoGroupsInner",
"CreateRequestInfoResourcesInner",
"CreateRequestInfoSupportTicket",
+ "CreateRequestTemplateInfo",
+ "CreateResourceCustomAccessLevelInfo",
"CreateResourceInfo",
"CreateTagInfo",
"CreateUARInfo",
"Delegation",
"DenyRequestRequest",
+ "EntityAdminFilter",
"EntityItemTypeEnum",
"EntityNameFilter",
"EntityTagFilter",
@@ -113,6 +135,7 @@
"GetResourceUser200Response",
"Group",
"GroupAccessLevel",
+ "GroupAccessLevelList",
"GroupBinding",
"GroupBindingGroup",
"GroupContainingGroup",
@@ -123,9 +146,12 @@
"GroupRemoteInfoAzureAdMicrosoft365Group",
"GroupRemoteInfoAzureAdSecurityGroup",
"GroupRemoteInfoClickhouseRole",
+ "GroupRemoteInfoConfluenceGroup",
"GroupRemoteInfoConnectorGroup",
"GroupRemoteInfoDatabricksAccountGroup",
"GroupRemoteInfoDevinGroup",
+ "GroupRemoteInfoDocusignGroup",
+ "GroupRemoteInfoDocusignSigningGroup",
"GroupRemoteInfoDuoGroup",
"GroupRemoteInfoGithubEnterpriseTeam",
"GroupRemoteInfoGithubTeam",
@@ -134,19 +160,23 @@
"GroupRemoteInfoGrafanaTeam",
"GroupRemoteInfoHubspotTeam",
"GroupRemoteInfoIncidentioOnCallSchedule",
+ "GroupRemoteInfoJiraGroup",
"GroupRemoteInfoLdapGroup",
+ "GroupRemoteInfoLinearTeam",
"GroupRemoteInfoOktaGroup",
"GroupRemoteInfoOktaGroupRule",
"GroupRemoteInfoPagerdutyOnCallSchedule",
"GroupRemoteInfoRootlyOnCallSchedule",
"GroupRemoteInfoSlackUserGroup",
"GroupRemoteInfoSnowflakeRole",
+ "GroupRemoteInfoTableauGroup",
"GroupRemoteInfoTailscaleGroup",
"GroupRemoteInfoTwingateGroup",
"GroupRemoteInfoTwingateGroupSynced",
"GroupRemoteInfoWorkdayUserSecurityGroup",
"GroupRemoteInfoZendeskGroup",
"GroupRemoteInfoZendeskOrganization",
+ "GroupRemoteInfoZoomGroup",
"GroupResource",
"GroupResourceList",
"GroupTypeEnum",
@@ -155,6 +185,8 @@
"GroupWithAccessLevel",
"IdpGroupMapping",
"IdpGroupMappingList",
+ "IdpStatusFilter",
+ "InviteUserInfo",
"MessageChannel",
"MessageChannelIDList",
"MessageChannelList",
@@ -163,11 +195,18 @@
"OnCallScheduleIDList",
"OnCallScheduleList",
"OnCallScheduleProviderEnum",
+ "OpalAccessPathEdgeFilter",
+ "OpalAccessPathQuery",
+ "OpalAccessPathQueryBody",
+ "OpalAccessPathQueryResults",
+ "OpalAccessPathResultEdge",
+ "OpalAccessPathResultNode",
"OpalNodeQuery",
"OpalNodeQueryBody",
"OpalNodeQueryResults",
"OpalQueryResultEdge",
"OpalQueryResultNode",
+ "OpalQueryResults",
"Owner",
"PageInfo",
"PaginatedAccessRulesList",
@@ -175,6 +214,8 @@
"PaginatedBundleGroupList",
"PaginatedBundleList",
"PaginatedBundleResourceList",
+ "PaginatedCampaignItemsList",
+ "PaginatedCampaignsList",
"PaginatedConfigurationTemplateList",
"PaginatedDelegationsList",
"PaginatedEventList",
@@ -182,14 +223,24 @@
"PaginatedGroupsList",
"PaginatedOwnersList",
"PaginatedRemoteUsersList",
+ "PaginatedRequestTemplateList",
"PaginatedResourcesList",
"PaginatedTagsList",
"PaginatedTokensList",
"PaginatedUARsList",
"PaginatedUsersList",
+ "PaginatedViewerCampaignItemsList",
+ "Paladin",
+ "PaladinConnector",
+ "PaladinContextSource",
+ "PaladinContextSourceKind",
+ "PaladinContextSourceList",
+ "PaladinContextSourceProvider",
+ "PaladinList",
"PropagationStatus",
"PropagationStatusEnum",
"RDSEngineEnum",
+ "RemindRequest200Response",
"RemoteUser",
"Request",
"RequestApprovalEnum",
@@ -206,14 +257,25 @@
"RequestReviewerStages",
"RequestStage",
"RequestStatusEnum",
+ "RequestTemplate",
+ "RequestTemplateCustomField",
+ "RequestTemplateCustomFieldCalloutMetadata",
+ "RequestTemplateCustomFieldInput",
+ "RequestTemplateCustomFieldMetadata",
+ "RequestTemplateCustomFieldMultiChoiceMetadata",
"RequestTemplateCustomFieldTypeEnum",
"RequestedItem",
"Resource",
"ResourceAccessLevel",
+ "ResourceAccessLevelList",
"ResourceAccessUser",
"ResourceAccessUserList",
+ "ResourceCustomAccessLevelList",
+ "ResourceCustomAccessLevelResponse",
"ResourceNHI",
"ResourceRemoteInfo",
+ "ResourceRemoteInfoAlicloudEcsInstance",
+ "ResourceRemoteInfoAlicloudRamRole",
"ResourceRemoteInfoAnthropicWorkspace",
"ResourceRemoteInfoAwsAccount",
"ResourceRemoteInfoAwsEc2Instance",
@@ -246,8 +308,10 @@
"ResourceRemoteInfoDatastaxAstraRole",
"ResourceRemoteInfoDevinOrganization",
"ResourceRemoteInfoDevinRole",
+ "ResourceRemoteInfoDocusignPermissionProfile",
"ResourceRemoteInfoGcpBigQueryDataset",
"ResourceRemoteInfoGcpBigQueryTable",
+ "ResourceRemoteInfoGcpBillingAccount",
"ResourceRemoteInfoGcpBucket",
"ResourceRemoteInfoGcpComputeInstance",
"ResourceRemoteInfoGcpFolder",
@@ -267,6 +331,8 @@
"ResourceRemoteInfoGrafanaRole",
"ResourceRemoteInfoHubspotRole",
"ResourceRemoteInfoIlevelAdvancedRole",
+ "ResourceRemoteInfoLinearOrganization",
+ "ResourceRemoteInfoLinearProject",
"ResourceRemoteInfoNetsuiteRole",
"ResourceRemoteInfoOktaApp",
"ResourceRemoteInfoOktaCustomRole",
@@ -286,6 +352,8 @@
"ResourceRemoteInfoTwingateResource",
"ResourceRemoteInfoWorkdayRole",
"ResourceRemoteInfoZendeskRole",
+ "ResourceRemoteInfoZoomLicense",
+ "ResourceRemoteInfoZoomRole",
"ResourceTypeEnum",
"ResourceUser",
"ResourceUserAccessStatus",
@@ -301,10 +369,13 @@
"RuleClauses",
"RuleConjunction",
"RuleDisjunction",
+ "RunOpalQueryRequest",
"ScopedRolePermission",
"ScopedRolePermissionList",
"Session",
"SessionsList",
+ "SortDirectionEnum",
+ "StopCampaignRequest",
"StringMatchType",
"SubEvent",
"SyncError",
@@ -322,6 +393,8 @@
"UARReviewerAssignmentPolicyEnum",
"UARScope",
"UpdateAccessRuleInfo",
+ "UpdateCampaignConfigurationInfo",
+ "UpdateCampaignInfo",
"UpdateConfigurationTemplateInfo",
"UpdateEventStreamInfo",
"UpdateGroupBindingInfo",
@@ -334,14 +407,23 @@
"UpdateIdpGroupMappingsRequestMappingsInner",
"UpdateOwnerInfo",
"UpdateOwnerInfoList",
+ "UpdatePaladinInfo",
+ "UpdateRequestTemplateInfo",
+ "UpdateResourceCustomAccessLevelInfo",
"UpdateResourceInfo",
"UpdateResourceInfoList",
"UpdateResourceUserRequest",
+ "UpdateUserInfo",
"User",
"UserAttributeSelector",
"UserHrIdpStatusEnum",
"UserIDList",
"UserList",
+ "UserProductRoleEnum",
+ "ViewerCampaignItem",
+ "ViewerCampaignItemReviewDecisionEnum",
+ "ViewerCampaignItemSortFieldEnum",
+ "ViewerCampaignItemStatusEnum",
"VisibilityInfo",
"VisibilityTypeEnum",
"WebhookApiKeyCredential",
@@ -355,6 +437,7 @@
from opal_security.api.access_rules_api import AccessRulesApi as AccessRulesApi
from opal_security.api.apps_api import AppsApi as AppsApi
from opal_security.api.bundles_api import BundlesApi as BundlesApi
+from opal_security.api.campaigns_api import CampaignsApi as CampaignsApi
from opal_security.api.configuration_templates_api import ConfigurationTemplatesApi as ConfigurationTemplatesApi
from opal_security.api.delegations_api import DelegationsApi as DelegationsApi
from opal_security.api.event_streams_api import EventStreamsApi as EventStreamsApi
@@ -367,6 +450,8 @@
from opal_security.api.on_call_schedules_api import OnCallSchedulesApi as OnCallSchedulesApi
from opal_security.api.opal_queries_api import OpalQueriesApi as OpalQueriesApi
from opal_security.api.owners_api import OwnersApi as OwnersApi
+from opal_security.api.paladin_api import PaladinApi as PaladinApi
+from opal_security.api.request_templates_api import RequestTemplatesApi as RequestTemplatesApi
from opal_security.api.requests_api import RequestsApi as RequestsApi
from opal_security.api.resources_api import ResourcesApi as ResourcesApi
from opal_security.api.sessions_api import SessionsApi as SessionsApi
@@ -412,9 +497,23 @@
from opal_security.models.bundle import Bundle as Bundle
from opal_security.models.bundle_group import BundleGroup as BundleGroup
from opal_security.models.bundle_resource import BundleResource as BundleResource
+from opal_security.models.campaign import Campaign as Campaign
+from opal_security.models.campaign_configuration import CampaignConfiguration as CampaignConfiguration
+from opal_security.models.campaign_group_asset_visibility_policy_enum import CampaignGroupAssetVisibilityPolicyEnum as CampaignGroupAssetVisibilityPolicyEnum
+from opal_security.models.campaign_item import CampaignItem as CampaignItem
+from opal_security.models.campaign_item_admin_override import CampaignItemAdminOverride as CampaignItemAdminOverride
+from opal_security.models.campaign_item_review import CampaignItemReview as CampaignItemReview
+from opal_security.models.campaign_item_review_decision_enum import CampaignItemReviewDecisionEnum as CampaignItemReviewDecisionEnum
+from opal_security.models.campaign_item_reviewer_assignment_source_enum import CampaignItemReviewerAssignmentSourceEnum as CampaignItemReviewerAssignmentSourceEnum
+from opal_security.models.campaign_item_status_enum import CampaignItemStatusEnum as CampaignItemStatusEnum
+from opal_security.models.campaign_item_target_type_enum import CampaignItemTargetTypeEnum as CampaignItemTargetTypeEnum
+from opal_security.models.campaign_revoke_on_enum import CampaignRevokeOnEnum as CampaignRevokeOnEnum
+from opal_security.models.campaign_status_enum import CampaignStatusEnum as CampaignStatusEnum
from opal_security.models.condition import Condition as Condition
from opal_security.models.configuration_template import ConfigurationTemplate as ConfigurationTemplate
from opal_security.models.create_bundle_info import CreateBundleInfo as CreateBundleInfo
+from opal_security.models.create_campaign_configuration_info import CreateCampaignConfigurationInfo as CreateCampaignConfigurationInfo
+from opal_security.models.create_campaign_info import CreateCampaignInfo as CreateCampaignInfo
from opal_security.models.create_configuration_template_info import CreateConfigurationTemplateInfo as CreateConfigurationTemplateInfo
from opal_security.models.create_delegation_request import CreateDelegationRequest as CreateDelegationRequest
from opal_security.models.create_event_stream_info import CreateEventStreamInfo as CreateEventStreamInfo
@@ -425,6 +524,8 @@
from opal_security.models.create_message_channel_info import CreateMessageChannelInfo as CreateMessageChannelInfo
from opal_security.models.create_on_call_schedule_info import CreateOnCallScheduleInfo as CreateOnCallScheduleInfo
from opal_security.models.create_owner_info import CreateOwnerInfo as CreateOwnerInfo
+from opal_security.models.create_paladin_context_source_info import CreatePaladinContextSourceInfo as CreatePaladinContextSourceInfo
+from opal_security.models.create_paladin_info import CreatePaladinInfo as CreatePaladinInfo
from opal_security.models.create_request200_response import CreateRequest200Response as CreateRequest200Response
from opal_security.models.create_request_comment_request import CreateRequestCommentRequest as CreateRequestCommentRequest
from opal_security.models.create_request_configuration_info_list import CreateRequestConfigurationInfoList as CreateRequestConfigurationInfoList
@@ -433,11 +534,14 @@
from opal_security.models.create_request_info_groups_inner import CreateRequestInfoGroupsInner as CreateRequestInfoGroupsInner
from opal_security.models.create_request_info_resources_inner import CreateRequestInfoResourcesInner as CreateRequestInfoResourcesInner
from opal_security.models.create_request_info_support_ticket import CreateRequestInfoSupportTicket as CreateRequestInfoSupportTicket
+from opal_security.models.create_request_template_info import CreateRequestTemplateInfo as CreateRequestTemplateInfo
+from opal_security.models.create_resource_custom_access_level_info import CreateResourceCustomAccessLevelInfo as CreateResourceCustomAccessLevelInfo
from opal_security.models.create_resource_info import CreateResourceInfo as CreateResourceInfo
from opal_security.models.create_tag_info import CreateTagInfo as CreateTagInfo
from opal_security.models.create_uar_info import CreateUARInfo as CreateUARInfo
from opal_security.models.delegation import Delegation as Delegation
from opal_security.models.deny_request_request import DenyRequestRequest as DenyRequestRequest
+from opal_security.models.entity_admin_filter import EntityAdminFilter as EntityAdminFilter
from opal_security.models.entity_item_type_enum import EntityItemTypeEnum as EntityItemTypeEnum
from opal_security.models.entity_name_filter import EntityNameFilter as EntityNameFilter
from opal_security.models.entity_tag_filter import EntityTagFilter as EntityTagFilter
@@ -450,6 +554,7 @@
from opal_security.models.get_resource_user200_response import GetResourceUser200Response as GetResourceUser200Response
from opal_security.models.group import Group as Group
from opal_security.models.group_access_level import GroupAccessLevel as GroupAccessLevel
+from opal_security.models.group_access_level_list import GroupAccessLevelList as GroupAccessLevelList
from opal_security.models.group_binding import GroupBinding as GroupBinding
from opal_security.models.group_binding_group import GroupBindingGroup as GroupBindingGroup
from opal_security.models.group_containing_group import GroupContainingGroup as GroupContainingGroup
@@ -460,9 +565,12 @@
from opal_security.models.group_remote_info_azure_ad_microsoft365_group import GroupRemoteInfoAzureAdMicrosoft365Group as GroupRemoteInfoAzureAdMicrosoft365Group
from opal_security.models.group_remote_info_azure_ad_security_group import GroupRemoteInfoAzureAdSecurityGroup as GroupRemoteInfoAzureAdSecurityGroup
from opal_security.models.group_remote_info_clickhouse_role import GroupRemoteInfoClickhouseRole as GroupRemoteInfoClickhouseRole
+from opal_security.models.group_remote_info_confluence_group import GroupRemoteInfoConfluenceGroup as GroupRemoteInfoConfluenceGroup
from opal_security.models.group_remote_info_connector_group import GroupRemoteInfoConnectorGroup as GroupRemoteInfoConnectorGroup
from opal_security.models.group_remote_info_databricks_account_group import GroupRemoteInfoDatabricksAccountGroup as GroupRemoteInfoDatabricksAccountGroup
from opal_security.models.group_remote_info_devin_group import GroupRemoteInfoDevinGroup as GroupRemoteInfoDevinGroup
+from opal_security.models.group_remote_info_docusign_group import GroupRemoteInfoDocusignGroup as GroupRemoteInfoDocusignGroup
+from opal_security.models.group_remote_info_docusign_signing_group import GroupRemoteInfoDocusignSigningGroup as GroupRemoteInfoDocusignSigningGroup
from opal_security.models.group_remote_info_duo_group import GroupRemoteInfoDuoGroup as GroupRemoteInfoDuoGroup
from opal_security.models.group_remote_info_github_enterprise_team import GroupRemoteInfoGithubEnterpriseTeam as GroupRemoteInfoGithubEnterpriseTeam
from opal_security.models.group_remote_info_github_team import GroupRemoteInfoGithubTeam as GroupRemoteInfoGithubTeam
@@ -471,19 +579,23 @@
from opal_security.models.group_remote_info_grafana_team import GroupRemoteInfoGrafanaTeam as GroupRemoteInfoGrafanaTeam
from opal_security.models.group_remote_info_hubspot_team import GroupRemoteInfoHubspotTeam as GroupRemoteInfoHubspotTeam
from opal_security.models.group_remote_info_incidentio_on_call_schedule import GroupRemoteInfoIncidentioOnCallSchedule as GroupRemoteInfoIncidentioOnCallSchedule
+from opal_security.models.group_remote_info_jira_group import GroupRemoteInfoJiraGroup as GroupRemoteInfoJiraGroup
from opal_security.models.group_remote_info_ldap_group import GroupRemoteInfoLdapGroup as GroupRemoteInfoLdapGroup
+from opal_security.models.group_remote_info_linear_team import GroupRemoteInfoLinearTeam as GroupRemoteInfoLinearTeam
from opal_security.models.group_remote_info_okta_group import GroupRemoteInfoOktaGroup as GroupRemoteInfoOktaGroup
from opal_security.models.group_remote_info_okta_group_rule import GroupRemoteInfoOktaGroupRule as GroupRemoteInfoOktaGroupRule
from opal_security.models.group_remote_info_pagerduty_on_call_schedule import GroupRemoteInfoPagerdutyOnCallSchedule as GroupRemoteInfoPagerdutyOnCallSchedule
from opal_security.models.group_remote_info_rootly_on_call_schedule import GroupRemoteInfoRootlyOnCallSchedule as GroupRemoteInfoRootlyOnCallSchedule
from opal_security.models.group_remote_info_slack_user_group import GroupRemoteInfoSlackUserGroup as GroupRemoteInfoSlackUserGroup
from opal_security.models.group_remote_info_snowflake_role import GroupRemoteInfoSnowflakeRole as GroupRemoteInfoSnowflakeRole
+from opal_security.models.group_remote_info_tableau_group import GroupRemoteInfoTableauGroup as GroupRemoteInfoTableauGroup
from opal_security.models.group_remote_info_tailscale_group import GroupRemoteInfoTailscaleGroup as GroupRemoteInfoTailscaleGroup
from opal_security.models.group_remote_info_twingate_group import GroupRemoteInfoTwingateGroup as GroupRemoteInfoTwingateGroup
from opal_security.models.group_remote_info_twingate_group_synced import GroupRemoteInfoTwingateGroupSynced as GroupRemoteInfoTwingateGroupSynced
from opal_security.models.group_remote_info_workday_user_security_group import GroupRemoteInfoWorkdayUserSecurityGroup as GroupRemoteInfoWorkdayUserSecurityGroup
from opal_security.models.group_remote_info_zendesk_group import GroupRemoteInfoZendeskGroup as GroupRemoteInfoZendeskGroup
from opal_security.models.group_remote_info_zendesk_organization import GroupRemoteInfoZendeskOrganization as GroupRemoteInfoZendeskOrganization
+from opal_security.models.group_remote_info_zoom_group import GroupRemoteInfoZoomGroup as GroupRemoteInfoZoomGroup
from opal_security.models.group_resource import GroupResource as GroupResource
from opal_security.models.group_resource_list import GroupResourceList as GroupResourceList
from opal_security.models.group_type_enum import GroupTypeEnum as GroupTypeEnum
@@ -492,6 +604,8 @@
from opal_security.models.group_with_access_level import GroupWithAccessLevel as GroupWithAccessLevel
from opal_security.models.idp_group_mapping import IdpGroupMapping as IdpGroupMapping
from opal_security.models.idp_group_mapping_list import IdpGroupMappingList as IdpGroupMappingList
+from opal_security.models.idp_status_filter import IdpStatusFilter as IdpStatusFilter
+from opal_security.models.invite_user_info import InviteUserInfo as InviteUserInfo
from opal_security.models.message_channel import MessageChannel as MessageChannel
from opal_security.models.message_channel_id_list import MessageChannelIDList as MessageChannelIDList
from opal_security.models.message_channel_list import MessageChannelList as MessageChannelList
@@ -500,11 +614,18 @@
from opal_security.models.on_call_schedule_id_list import OnCallScheduleIDList as OnCallScheduleIDList
from opal_security.models.on_call_schedule_list import OnCallScheduleList as OnCallScheduleList
from opal_security.models.on_call_schedule_provider_enum import OnCallScheduleProviderEnum as OnCallScheduleProviderEnum
+from opal_security.models.opal_access_path_edge_filter import OpalAccessPathEdgeFilter as OpalAccessPathEdgeFilter
+from opal_security.models.opal_access_path_query import OpalAccessPathQuery as OpalAccessPathQuery
+from opal_security.models.opal_access_path_query_body import OpalAccessPathQueryBody as OpalAccessPathQueryBody
+from opal_security.models.opal_access_path_query_results import OpalAccessPathQueryResults as OpalAccessPathQueryResults
+from opal_security.models.opal_access_path_result_edge import OpalAccessPathResultEdge as OpalAccessPathResultEdge
+from opal_security.models.opal_access_path_result_node import OpalAccessPathResultNode as OpalAccessPathResultNode
from opal_security.models.opal_node_query import OpalNodeQuery as OpalNodeQuery
from opal_security.models.opal_node_query_body import OpalNodeQueryBody as OpalNodeQueryBody
from opal_security.models.opal_node_query_results import OpalNodeQueryResults as OpalNodeQueryResults
from opal_security.models.opal_query_result_edge import OpalQueryResultEdge as OpalQueryResultEdge
from opal_security.models.opal_query_result_node import OpalQueryResultNode as OpalQueryResultNode
+from opal_security.models.opal_query_results import OpalQueryResults as OpalQueryResults
from opal_security.models.owner import Owner as Owner
from opal_security.models.page_info import PageInfo as PageInfo
from opal_security.models.paginated_access_rules_list import PaginatedAccessRulesList as PaginatedAccessRulesList
@@ -512,6 +633,8 @@
from opal_security.models.paginated_bundle_group_list import PaginatedBundleGroupList as PaginatedBundleGroupList
from opal_security.models.paginated_bundle_list import PaginatedBundleList as PaginatedBundleList
from opal_security.models.paginated_bundle_resource_list import PaginatedBundleResourceList as PaginatedBundleResourceList
+from opal_security.models.paginated_campaign_items_list import PaginatedCampaignItemsList as PaginatedCampaignItemsList
+from opal_security.models.paginated_campaigns_list import PaginatedCampaignsList as PaginatedCampaignsList
from opal_security.models.paginated_configuration_template_list import PaginatedConfigurationTemplateList as PaginatedConfigurationTemplateList
from opal_security.models.paginated_delegations_list import PaginatedDelegationsList as PaginatedDelegationsList
from opal_security.models.paginated_event_list import PaginatedEventList as PaginatedEventList
@@ -519,14 +642,24 @@
from opal_security.models.paginated_groups_list import PaginatedGroupsList as PaginatedGroupsList
from opal_security.models.paginated_owners_list import PaginatedOwnersList as PaginatedOwnersList
from opal_security.models.paginated_remote_users_list import PaginatedRemoteUsersList as PaginatedRemoteUsersList
+from opal_security.models.paginated_request_template_list import PaginatedRequestTemplateList as PaginatedRequestTemplateList
from opal_security.models.paginated_resources_list import PaginatedResourcesList as PaginatedResourcesList
from opal_security.models.paginated_tags_list import PaginatedTagsList as PaginatedTagsList
from opal_security.models.paginated_tokens_list import PaginatedTokensList as PaginatedTokensList
from opal_security.models.paginated_uars_list import PaginatedUARsList as PaginatedUARsList
from opal_security.models.paginated_users_list import PaginatedUsersList as PaginatedUsersList
+from opal_security.models.paginated_viewer_campaign_items_list import PaginatedViewerCampaignItemsList as PaginatedViewerCampaignItemsList
+from opal_security.models.paladin import Paladin as Paladin
+from opal_security.models.paladin_connector import PaladinConnector as PaladinConnector
+from opal_security.models.paladin_context_source import PaladinContextSource as PaladinContextSource
+from opal_security.models.paladin_context_source_kind import PaladinContextSourceKind as PaladinContextSourceKind
+from opal_security.models.paladin_context_source_list import PaladinContextSourceList as PaladinContextSourceList
+from opal_security.models.paladin_context_source_provider import PaladinContextSourceProvider as PaladinContextSourceProvider
+from opal_security.models.paladin_list import PaladinList as PaladinList
from opal_security.models.propagation_status import PropagationStatus as PropagationStatus
from opal_security.models.propagation_status_enum import PropagationStatusEnum as PropagationStatusEnum
from opal_security.models.rds_engine_enum import RDSEngineEnum as RDSEngineEnum
+from opal_security.models.remind_request200_response import RemindRequest200Response as RemindRequest200Response
from opal_security.models.remote_user import RemoteUser as RemoteUser
from opal_security.models.request import Request as Request
from opal_security.models.request_approval_enum import RequestApprovalEnum as RequestApprovalEnum
@@ -543,14 +676,25 @@
from opal_security.models.request_reviewer_stages import RequestReviewerStages as RequestReviewerStages
from opal_security.models.request_stage import RequestStage as RequestStage
from opal_security.models.request_status_enum import RequestStatusEnum as RequestStatusEnum
+from opal_security.models.request_template import RequestTemplate as RequestTemplate
+from opal_security.models.request_template_custom_field import RequestTemplateCustomField as RequestTemplateCustomField
+from opal_security.models.request_template_custom_field_callout_metadata import RequestTemplateCustomFieldCalloutMetadata as RequestTemplateCustomFieldCalloutMetadata
+from opal_security.models.request_template_custom_field_input import RequestTemplateCustomFieldInput as RequestTemplateCustomFieldInput
+from opal_security.models.request_template_custom_field_metadata import RequestTemplateCustomFieldMetadata as RequestTemplateCustomFieldMetadata
+from opal_security.models.request_template_custom_field_multi_choice_metadata import RequestTemplateCustomFieldMultiChoiceMetadata as RequestTemplateCustomFieldMultiChoiceMetadata
from opal_security.models.request_template_custom_field_type_enum import RequestTemplateCustomFieldTypeEnum as RequestTemplateCustomFieldTypeEnum
from opal_security.models.requested_item import RequestedItem as RequestedItem
from opal_security.models.resource import Resource as Resource
from opal_security.models.resource_access_level import ResourceAccessLevel as ResourceAccessLevel
+from opal_security.models.resource_access_level_list import ResourceAccessLevelList as ResourceAccessLevelList
from opal_security.models.resource_access_user import ResourceAccessUser as ResourceAccessUser
from opal_security.models.resource_access_user_list import ResourceAccessUserList as ResourceAccessUserList
+from opal_security.models.resource_custom_access_level_list import ResourceCustomAccessLevelList as ResourceCustomAccessLevelList
+from opal_security.models.resource_custom_access_level_response import ResourceCustomAccessLevelResponse as ResourceCustomAccessLevelResponse
from opal_security.models.resource_nhi import ResourceNHI as ResourceNHI
from opal_security.models.resource_remote_info import ResourceRemoteInfo as ResourceRemoteInfo
+from opal_security.models.resource_remote_info_alicloud_ecs_instance import ResourceRemoteInfoAlicloudEcsInstance as ResourceRemoteInfoAlicloudEcsInstance
+from opal_security.models.resource_remote_info_alicloud_ram_role import ResourceRemoteInfoAlicloudRamRole as ResourceRemoteInfoAlicloudRamRole
from opal_security.models.resource_remote_info_anthropic_workspace import ResourceRemoteInfoAnthropicWorkspace as ResourceRemoteInfoAnthropicWorkspace
from opal_security.models.resource_remote_info_aws_account import ResourceRemoteInfoAwsAccount as ResourceRemoteInfoAwsAccount
from opal_security.models.resource_remote_info_aws_ec2_instance import ResourceRemoteInfoAwsEc2Instance as ResourceRemoteInfoAwsEc2Instance
@@ -583,8 +727,10 @@
from opal_security.models.resource_remote_info_datastax_astra_role import ResourceRemoteInfoDatastaxAstraRole as ResourceRemoteInfoDatastaxAstraRole
from opal_security.models.resource_remote_info_devin_organization import ResourceRemoteInfoDevinOrganization as ResourceRemoteInfoDevinOrganization
from opal_security.models.resource_remote_info_devin_role import ResourceRemoteInfoDevinRole as ResourceRemoteInfoDevinRole
+from opal_security.models.resource_remote_info_docusign_permission_profile import ResourceRemoteInfoDocusignPermissionProfile as ResourceRemoteInfoDocusignPermissionProfile
from opal_security.models.resource_remote_info_gcp_big_query_dataset import ResourceRemoteInfoGcpBigQueryDataset as ResourceRemoteInfoGcpBigQueryDataset
from opal_security.models.resource_remote_info_gcp_big_query_table import ResourceRemoteInfoGcpBigQueryTable as ResourceRemoteInfoGcpBigQueryTable
+from opal_security.models.resource_remote_info_gcp_billing_account import ResourceRemoteInfoGcpBillingAccount as ResourceRemoteInfoGcpBillingAccount
from opal_security.models.resource_remote_info_gcp_bucket import ResourceRemoteInfoGcpBucket as ResourceRemoteInfoGcpBucket
from opal_security.models.resource_remote_info_gcp_compute_instance import ResourceRemoteInfoGcpComputeInstance as ResourceRemoteInfoGcpComputeInstance
from opal_security.models.resource_remote_info_gcp_folder import ResourceRemoteInfoGcpFolder as ResourceRemoteInfoGcpFolder
@@ -604,6 +750,8 @@
from opal_security.models.resource_remote_info_grafana_role import ResourceRemoteInfoGrafanaRole as ResourceRemoteInfoGrafanaRole
from opal_security.models.resource_remote_info_hubspot_role import ResourceRemoteInfoHubspotRole as ResourceRemoteInfoHubspotRole
from opal_security.models.resource_remote_info_ilevel_advanced_role import ResourceRemoteInfoIlevelAdvancedRole as ResourceRemoteInfoIlevelAdvancedRole
+from opal_security.models.resource_remote_info_linear_organization import ResourceRemoteInfoLinearOrganization as ResourceRemoteInfoLinearOrganization
+from opal_security.models.resource_remote_info_linear_project import ResourceRemoteInfoLinearProject as ResourceRemoteInfoLinearProject
from opal_security.models.resource_remote_info_netsuite_role import ResourceRemoteInfoNetsuiteRole as ResourceRemoteInfoNetsuiteRole
from opal_security.models.resource_remote_info_okta_app import ResourceRemoteInfoOktaApp as ResourceRemoteInfoOktaApp
from opal_security.models.resource_remote_info_okta_custom_role import ResourceRemoteInfoOktaCustomRole as ResourceRemoteInfoOktaCustomRole
@@ -623,6 +771,8 @@
from opal_security.models.resource_remote_info_twingate_resource import ResourceRemoteInfoTwingateResource as ResourceRemoteInfoTwingateResource
from opal_security.models.resource_remote_info_workday_role import ResourceRemoteInfoWorkdayRole as ResourceRemoteInfoWorkdayRole
from opal_security.models.resource_remote_info_zendesk_role import ResourceRemoteInfoZendeskRole as ResourceRemoteInfoZendeskRole
+from opal_security.models.resource_remote_info_zoom_license import ResourceRemoteInfoZoomLicense as ResourceRemoteInfoZoomLicense
+from opal_security.models.resource_remote_info_zoom_role import ResourceRemoteInfoZoomRole as ResourceRemoteInfoZoomRole
from opal_security.models.resource_type_enum import ResourceTypeEnum as ResourceTypeEnum
from opal_security.models.resource_user import ResourceUser as ResourceUser
from opal_security.models.resource_user_access_status import ResourceUserAccessStatus as ResourceUserAccessStatus
@@ -638,10 +788,13 @@
from opal_security.models.rule_clauses import RuleClauses as RuleClauses
from opal_security.models.rule_conjunction import RuleConjunction as RuleConjunction
from opal_security.models.rule_disjunction import RuleDisjunction as RuleDisjunction
+from opal_security.models.run_opal_query_request import RunOpalQueryRequest as RunOpalQueryRequest
from opal_security.models.scoped_role_permission import ScopedRolePermission as ScopedRolePermission
from opal_security.models.scoped_role_permission_list import ScopedRolePermissionList as ScopedRolePermissionList
from opal_security.models.session import Session as Session
from opal_security.models.sessions_list import SessionsList as SessionsList
+from opal_security.models.sort_direction_enum import SortDirectionEnum as SortDirectionEnum
+from opal_security.models.stop_campaign_request import StopCampaignRequest as StopCampaignRequest
from opal_security.models.string_match_type import StringMatchType as StringMatchType
from opal_security.models.sub_event import SubEvent as SubEvent
from opal_security.models.sync_error import SyncError as SyncError
@@ -659,6 +812,8 @@
from opal_security.models.uar_reviewer_assignment_policy_enum import UARReviewerAssignmentPolicyEnum as UARReviewerAssignmentPolicyEnum
from opal_security.models.uar_scope import UARScope as UARScope
from opal_security.models.update_access_rule_info import UpdateAccessRuleInfo as UpdateAccessRuleInfo
+from opal_security.models.update_campaign_configuration_info import UpdateCampaignConfigurationInfo as UpdateCampaignConfigurationInfo
+from opal_security.models.update_campaign_info import UpdateCampaignInfo as UpdateCampaignInfo
from opal_security.models.update_configuration_template_info import UpdateConfigurationTemplateInfo as UpdateConfigurationTemplateInfo
from opal_security.models.update_event_stream_info import UpdateEventStreamInfo as UpdateEventStreamInfo
from opal_security.models.update_group_binding_info import UpdateGroupBindingInfo as UpdateGroupBindingInfo
@@ -671,14 +826,23 @@
from opal_security.models.update_idp_group_mappings_request_mappings_inner import UpdateIdpGroupMappingsRequestMappingsInner as UpdateIdpGroupMappingsRequestMappingsInner
from opal_security.models.update_owner_info import UpdateOwnerInfo as UpdateOwnerInfo
from opal_security.models.update_owner_info_list import UpdateOwnerInfoList as UpdateOwnerInfoList
+from opal_security.models.update_paladin_info import UpdatePaladinInfo as UpdatePaladinInfo
+from opal_security.models.update_request_template_info import UpdateRequestTemplateInfo as UpdateRequestTemplateInfo
+from opal_security.models.update_resource_custom_access_level_info import UpdateResourceCustomAccessLevelInfo as UpdateResourceCustomAccessLevelInfo
from opal_security.models.update_resource_info import UpdateResourceInfo as UpdateResourceInfo
from opal_security.models.update_resource_info_list import UpdateResourceInfoList as UpdateResourceInfoList
from opal_security.models.update_resource_user_request import UpdateResourceUserRequest as UpdateResourceUserRequest
+from opal_security.models.update_user_info import UpdateUserInfo as UpdateUserInfo
from opal_security.models.user import User as User
from opal_security.models.user_attribute_selector import UserAttributeSelector as UserAttributeSelector
from opal_security.models.user_hr_idp_status_enum import UserHrIdpStatusEnum as UserHrIdpStatusEnum
from opal_security.models.user_id_list import UserIDList as UserIDList
from opal_security.models.user_list import UserList as UserList
+from opal_security.models.user_product_role_enum import UserProductRoleEnum as UserProductRoleEnum
+from opal_security.models.viewer_campaign_item import ViewerCampaignItem as ViewerCampaignItem
+from opal_security.models.viewer_campaign_item_review_decision_enum import ViewerCampaignItemReviewDecisionEnum as ViewerCampaignItemReviewDecisionEnum
+from opal_security.models.viewer_campaign_item_sort_field_enum import ViewerCampaignItemSortFieldEnum as ViewerCampaignItemSortFieldEnum
+from opal_security.models.viewer_campaign_item_status_enum import ViewerCampaignItemStatusEnum as ViewerCampaignItemStatusEnum
from opal_security.models.visibility_info import VisibilityInfo as VisibilityInfo
from opal_security.models.visibility_type_enum import VisibilityTypeEnum as VisibilityTypeEnum
from opal_security.models.webhook_api_key_credential import WebhookApiKeyCredential as WebhookApiKeyCredential
diff --git a/opal_security/api/__init__.py b/opal_security/api/__init__.py
index 27c0e8e..482f12c 100644
--- a/opal_security/api/__init__.py
+++ b/opal_security/api/__init__.py
@@ -4,6 +4,7 @@
from opal_security.api.access_rules_api import AccessRulesApi
from opal_security.api.apps_api import AppsApi
from opal_security.api.bundles_api import BundlesApi
+from opal_security.api.campaigns_api import CampaignsApi
from opal_security.api.configuration_templates_api import ConfigurationTemplatesApi
from opal_security.api.delegations_api import DelegationsApi
from opal_security.api.event_streams_api import EventStreamsApi
@@ -16,6 +17,8 @@
from opal_security.api.on_call_schedules_api import OnCallSchedulesApi
from opal_security.api.opal_queries_api import OpalQueriesApi
from opal_security.api.owners_api import OwnersApi
+from opal_security.api.paladin_api import PaladinApi
+from opal_security.api.request_templates_api import RequestTemplatesApi
from opal_security.api.requests_api import RequestsApi
from opal_security.api.resources_api import ResourcesApi
from opal_security.api.sessions_api import SessionsApi
diff --git a/opal_security/api/campaigns_api.py b/opal_security/api/campaigns_api.py
new file mode 100644
index 0000000..99cc2c8
--- /dev/null
+++ b/opal_security/api/campaigns_api.py
@@ -0,0 +1,3013 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+import warnings
+from pydantic import validate_call, Field, StrictFloat, StrictStr, StrictInt
+from typing import Any, Dict, List, Optional, Tuple, Union
+from typing_extensions import Annotated
+
+from datetime import datetime
+from pydantic import Field, StrictBool, StrictStr
+from typing import List, Optional
+from typing_extensions import Annotated
+from uuid import UUID
+from opal_security.models.campaign import Campaign
+from opal_security.models.campaign_item_status_enum import CampaignItemStatusEnum
+from opal_security.models.campaign_status_enum import CampaignStatusEnum
+from opal_security.models.create_campaign_info import CreateCampaignInfo
+from opal_security.models.paginated_campaign_items_list import PaginatedCampaignItemsList
+from opal_security.models.paginated_campaigns_list import PaginatedCampaignsList
+from opal_security.models.paginated_viewer_campaign_items_list import PaginatedViewerCampaignItemsList
+from opal_security.models.sort_direction_enum import SortDirectionEnum
+from opal_security.models.stop_campaign_request import StopCampaignRequest
+from opal_security.models.update_campaign_info import UpdateCampaignInfo
+from opal_security.models.viewer_campaign_item_sort_field_enum import ViewerCampaignItemSortFieldEnum
+from opal_security.models.viewer_campaign_item_status_enum import ViewerCampaignItemStatusEnum
+
+from opal_security.api_client import ApiClient, RequestSerialized
+from opal_security.api_response import ApiResponse
+from opal_security.rest import RESTResponseType
+
+
+class CampaignsApi:
+ """NOTE: This class is auto generated by OpenAPI Generator
+ Ref: https://openapi-generator.tech
+
+ Do not edit the class manually.
+ """
+
+ def __init__(self, api_client=None) -> None:
+ if api_client is None:
+ api_client = ApiClient.get_default()
+ self.api_client = api_client
+
+
+ @validate_call
+ def create_campaign(
+ self,
+ create_campaign_info: CreateCampaignInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Campaign:
+ """create_campaign
+
+ Creates a campaign. Campaign scope only supports direct access edges: `configuration.query.edgeFilter.directOnly` defaults to `true`, is always stored as `true`, and passing `false` returns 400.
+
+ :param create_campaign_info: (required)
+ :type create_campaign_info: CreateCampaignInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_campaign_serialize(
+ create_campaign_info=create_campaign_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '201': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def create_campaign_with_http_info(
+ self,
+ create_campaign_info: CreateCampaignInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Campaign]:
+ """create_campaign
+
+ Creates a campaign. Campaign scope only supports direct access edges: `configuration.query.edgeFilter.directOnly` defaults to `true`, is always stored as `true`, and passing `false` returns 400.
+
+ :param create_campaign_info: (required)
+ :type create_campaign_info: CreateCampaignInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_campaign_serialize(
+ create_campaign_info=create_campaign_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '201': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def create_campaign_without_preload_content(
+ self,
+ create_campaign_info: CreateCampaignInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """create_campaign
+
+ Creates a campaign. Campaign scope only supports direct access edges: `configuration.query.edgeFilter.directOnly` defaults to `true`, is always stored as `true`, and passing `false` returns 400.
+
+ :param create_campaign_info: (required)
+ :type create_campaign_info: CreateCampaignInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_campaign_serialize(
+ create_campaign_info=create_campaign_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '201': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _create_campaign_serialize(
+ self,
+ create_campaign_info,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+ if create_campaign_info is not None:
+ _body_params = create_campaign_info
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/campaigns',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def end_campaign(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Campaign:
+ """End campaign
+
+ Ends a stopped campaign, setting `ended_at` and `ended_by_user_id`, applying pending access changes, and queuing report generation. Returns 400 unless the campaign is started and stopped and not already ended.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._end_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def end_campaign_with_http_info(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Campaign]:
+ """End campaign
+
+ Ends a stopped campaign, setting `ended_at` and `ended_by_user_id`, applying pending access changes, and queuing report generation. Returns 400 unless the campaign is started and stopped and not already ended.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._end_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def end_campaign_without_preload_content(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """End campaign
+
+ Ends a stopped campaign, setting `ended_at` and `ended_by_user_id`, applying pending access changes, and queuing report generation. Returns 400 unless the campaign is started and stopped and not already ended.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._end_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _end_campaign_serialize(
+ self,
+ campaign_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if campaign_id is not None:
+ _path_params['campaign_id'] = campaign_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/campaigns/{campaign_id}/end',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_campaign(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Campaign:
+ """Get campaign by ID
+
+ Returns a `Campaign` object.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_campaign_with_http_info(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Campaign]:
+ """Get campaign by ID
+
+ Returns a `Campaign` object.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_campaign_without_preload_content(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Get campaign by ID
+
+ Returns a `Campaign` object.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_campaign_serialize(
+ self,
+ campaign_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if campaign_id is not None:
+ _path_params['campaign_id'] = campaign_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/campaigns/{campaign_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_campaign_items(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=500, strict=True)]], Field(description="Number of results to return per page. Default is 200; maximum is 500 (the campaign-items list cap). ")] = None,
+ statuses: Annotated[Optional[List[CampaignItemStatusEnum]], Field(description="Filter by derived item status. When multiple values are provided, items matching any status are returned (OR). ")] = None,
+ reviewer_user_id: Annotated[Optional[UUID], Field(description="Restrict to items assigned to this reviewer user ID.")] = None,
+ unassigned: Annotated[Optional[StrictBool], Field(description="When true, restrict to items with no reviewer assigned.")] = None,
+ search: Annotated[Optional[StrictStr], Field(description="Case-insensitive search over principal name, asset name, and reviewer name. ")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaginatedCampaignItemsList:
+ """List campaign items
+
+ Returns a paginated list of review items for a campaign — the same rows shown on the admin Reviews tab. Status is derived using the same rules as the UI Status column. Soft-deleted role assignments are still returned with `is_target_deleted: true`.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200; maximum is 500 (the campaign-items list cap).
+ :type page_size: int
+ :param statuses: Filter by derived item status. When multiple values are provided, items matching any status are returned (OR).
+ :type statuses: List[CampaignItemStatusEnum]
+ :param reviewer_user_id: Restrict to items assigned to this reviewer user ID.
+ :type reviewer_user_id: UUID
+ :param unassigned: When true, restrict to items with no reviewer assigned.
+ :type unassigned: bool
+ :param search: Case-insensitive search over principal name, asset name, and reviewer name.
+ :type search: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_items_serialize(
+ campaign_id=campaign_id,
+ cursor=cursor,
+ page_size=page_size,
+ statuses=statuses,
+ reviewer_user_id=reviewer_user_id,
+ unassigned=unassigned,
+ search=search,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedCampaignItemsList",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_campaign_items_with_http_info(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=500, strict=True)]], Field(description="Number of results to return per page. Default is 200; maximum is 500 (the campaign-items list cap). ")] = None,
+ statuses: Annotated[Optional[List[CampaignItemStatusEnum]], Field(description="Filter by derived item status. When multiple values are provided, items matching any status are returned (OR). ")] = None,
+ reviewer_user_id: Annotated[Optional[UUID], Field(description="Restrict to items assigned to this reviewer user ID.")] = None,
+ unassigned: Annotated[Optional[StrictBool], Field(description="When true, restrict to items with no reviewer assigned.")] = None,
+ search: Annotated[Optional[StrictStr], Field(description="Case-insensitive search over principal name, asset name, and reviewer name. ")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaginatedCampaignItemsList]:
+ """List campaign items
+
+ Returns a paginated list of review items for a campaign — the same rows shown on the admin Reviews tab. Status is derived using the same rules as the UI Status column. Soft-deleted role assignments are still returned with `is_target_deleted: true`.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200; maximum is 500 (the campaign-items list cap).
+ :type page_size: int
+ :param statuses: Filter by derived item status. When multiple values are provided, items matching any status are returned (OR).
+ :type statuses: List[CampaignItemStatusEnum]
+ :param reviewer_user_id: Restrict to items assigned to this reviewer user ID.
+ :type reviewer_user_id: UUID
+ :param unassigned: When true, restrict to items with no reviewer assigned.
+ :type unassigned: bool
+ :param search: Case-insensitive search over principal name, asset name, and reviewer name.
+ :type search: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_items_serialize(
+ campaign_id=campaign_id,
+ cursor=cursor,
+ page_size=page_size,
+ statuses=statuses,
+ reviewer_user_id=reviewer_user_id,
+ unassigned=unassigned,
+ search=search,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedCampaignItemsList",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_campaign_items_without_preload_content(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=500, strict=True)]], Field(description="Number of results to return per page. Default is 200; maximum is 500 (the campaign-items list cap). ")] = None,
+ statuses: Annotated[Optional[List[CampaignItemStatusEnum]], Field(description="Filter by derived item status. When multiple values are provided, items matching any status are returned (OR). ")] = None,
+ reviewer_user_id: Annotated[Optional[UUID], Field(description="Restrict to items assigned to this reviewer user ID.")] = None,
+ unassigned: Annotated[Optional[StrictBool], Field(description="When true, restrict to items with no reviewer assigned.")] = None,
+ search: Annotated[Optional[StrictStr], Field(description="Case-insensitive search over principal name, asset name, and reviewer name. ")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """List campaign items
+
+ Returns a paginated list of review items for a campaign — the same rows shown on the admin Reviews tab. Status is derived using the same rules as the UI Status column. Soft-deleted role assignments are still returned with `is_target_deleted: true`.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200; maximum is 500 (the campaign-items list cap).
+ :type page_size: int
+ :param statuses: Filter by derived item status. When multiple values are provided, items matching any status are returned (OR).
+ :type statuses: List[CampaignItemStatusEnum]
+ :param reviewer_user_id: Restrict to items assigned to this reviewer user ID.
+ :type reviewer_user_id: UUID
+ :param unassigned: When true, restrict to items with no reviewer assigned.
+ :type unassigned: bool
+ :param search: Case-insensitive search over principal name, asset name, and reviewer name.
+ :type search: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_items_serialize(
+ campaign_id=campaign_id,
+ cursor=cursor,
+ page_size=page_size,
+ statuses=statuses,
+ reviewer_user_id=reviewer_user_id,
+ unassigned=unassigned,
+ search=search,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedCampaignItemsList",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_campaign_items_serialize(
+ self,
+ campaign_id,
+ cursor,
+ page_size,
+ statuses,
+ reviewer_user_id,
+ unassigned,
+ search,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ 'statuses': 'multi',
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if campaign_id is not None:
+ _path_params['campaign_id'] = campaign_id
+ # process the query parameters
+ if cursor is not None:
+
+ _query_params.append(('cursor', cursor))
+
+ if page_size is not None:
+
+ _query_params.append(('page_size', page_size))
+
+ if statuses is not None:
+
+ _query_params.append(('statuses', statuses))
+
+ if reviewer_user_id is not None:
+
+ _query_params.append(('reviewer_user_id', reviewer_user_id))
+
+ if unassigned is not None:
+
+ _query_params.append(('unassigned', unassigned))
+
+ if search is not None:
+
+ _query_params.append(('search', search))
+
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/campaigns/{campaign_id}/items',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_campaign_viewer_items(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=500, strict=True)]], Field(description="Number of results to return per page. Default is 200; maximum is 500. ")] = None,
+ sort_field: Annotated[Optional[ViewerCampaignItemSortFieldEnum], Field(description="Sort by. Omit to sort by created_at. ")] = None,
+ sort_direction: Annotated[Optional[SortDirectionEnum], Field(description="Sort direction.")] = None,
+ statuses: Annotated[Optional[List[ViewerCampaignItemStatusEnum]], Field(description="Filter by review status. When multiple values are provided, items matching any status are returned (OR). ")] = None,
+ access_level_names: Annotated[Optional[List[StrictStr]], Field(description="Filter by access level name.")] = None,
+ principal_ids: Annotated[Optional[List[UUID]], Field(description="Filter by principal ID.")] = None,
+ entity_ids: Annotated[Optional[List[UUID]], Field(description="Filter by entity ID.")] = None,
+ item_ids: Annotated[Optional[List[UUID]], Field(description="Filter to specific campaign item review IDs.")] = None,
+ ai_bucket_id: Annotated[Optional[UUID], Field(description="Restrict to items in this AI-suggestion bucket.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaginatedViewerCampaignItemsList:
+ """List viewer campaign items
+
+ Returns a paginated list of campaign review items assigned to the current authenticated viewer. Matches GraphQL `Campaign.viewerItems`. Campaign access matches `GET /campaigns/{campaign_id}` and GraphQL `campaign(id)`: the caller must have access-review read permission or be a reviewer on the campaign. Otherwise the request fails with 403 (same as get-by-id). Item rows are still scoped to the caller's own reviews (empty page when the caller is an admin but not a reviewer).
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200; maximum is 500.
+ :type page_size: int
+ :param sort_field: Sort by. Omit to sort by created_at.
+ :type sort_field: ViewerCampaignItemSortFieldEnum
+ :param sort_direction: Sort direction.
+ :type sort_direction: SortDirectionEnum
+ :param statuses: Filter by review status. When multiple values are provided, items matching any status are returned (OR).
+ :type statuses: List[ViewerCampaignItemStatusEnum]
+ :param access_level_names: Filter by access level name.
+ :type access_level_names: List[str]
+ :param principal_ids: Filter by principal ID.
+ :type principal_ids: List[UUID]
+ :param entity_ids: Filter by entity ID.
+ :type entity_ids: List[UUID]
+ :param item_ids: Filter to specific campaign item review IDs.
+ :type item_ids: List[UUID]
+ :param ai_bucket_id: Restrict to items in this AI-suggestion bucket.
+ :type ai_bucket_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_viewer_items_serialize(
+ campaign_id=campaign_id,
+ cursor=cursor,
+ page_size=page_size,
+ sort_field=sort_field,
+ sort_direction=sort_direction,
+ statuses=statuses,
+ access_level_names=access_level_names,
+ principal_ids=principal_ids,
+ entity_ids=entity_ids,
+ item_ids=item_ids,
+ ai_bucket_id=ai_bucket_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedViewerCampaignItemsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_campaign_viewer_items_with_http_info(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=500, strict=True)]], Field(description="Number of results to return per page. Default is 200; maximum is 500. ")] = None,
+ sort_field: Annotated[Optional[ViewerCampaignItemSortFieldEnum], Field(description="Sort by. Omit to sort by created_at. ")] = None,
+ sort_direction: Annotated[Optional[SortDirectionEnum], Field(description="Sort direction.")] = None,
+ statuses: Annotated[Optional[List[ViewerCampaignItemStatusEnum]], Field(description="Filter by review status. When multiple values are provided, items matching any status are returned (OR). ")] = None,
+ access_level_names: Annotated[Optional[List[StrictStr]], Field(description="Filter by access level name.")] = None,
+ principal_ids: Annotated[Optional[List[UUID]], Field(description="Filter by principal ID.")] = None,
+ entity_ids: Annotated[Optional[List[UUID]], Field(description="Filter by entity ID.")] = None,
+ item_ids: Annotated[Optional[List[UUID]], Field(description="Filter to specific campaign item review IDs.")] = None,
+ ai_bucket_id: Annotated[Optional[UUID], Field(description="Restrict to items in this AI-suggestion bucket.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaginatedViewerCampaignItemsList]:
+ """List viewer campaign items
+
+ Returns a paginated list of campaign review items assigned to the current authenticated viewer. Matches GraphQL `Campaign.viewerItems`. Campaign access matches `GET /campaigns/{campaign_id}` and GraphQL `campaign(id)`: the caller must have access-review read permission or be a reviewer on the campaign. Otherwise the request fails with 403 (same as get-by-id). Item rows are still scoped to the caller's own reviews (empty page when the caller is an admin but not a reviewer).
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200; maximum is 500.
+ :type page_size: int
+ :param sort_field: Sort by. Omit to sort by created_at.
+ :type sort_field: ViewerCampaignItemSortFieldEnum
+ :param sort_direction: Sort direction.
+ :type sort_direction: SortDirectionEnum
+ :param statuses: Filter by review status. When multiple values are provided, items matching any status are returned (OR).
+ :type statuses: List[ViewerCampaignItemStatusEnum]
+ :param access_level_names: Filter by access level name.
+ :type access_level_names: List[str]
+ :param principal_ids: Filter by principal ID.
+ :type principal_ids: List[UUID]
+ :param entity_ids: Filter by entity ID.
+ :type entity_ids: List[UUID]
+ :param item_ids: Filter to specific campaign item review IDs.
+ :type item_ids: List[UUID]
+ :param ai_bucket_id: Restrict to items in this AI-suggestion bucket.
+ :type ai_bucket_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_viewer_items_serialize(
+ campaign_id=campaign_id,
+ cursor=cursor,
+ page_size=page_size,
+ sort_field=sort_field,
+ sort_direction=sort_direction,
+ statuses=statuses,
+ access_level_names=access_level_names,
+ principal_ids=principal_ids,
+ entity_ids=entity_ids,
+ item_ids=item_ids,
+ ai_bucket_id=ai_bucket_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedViewerCampaignItemsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_campaign_viewer_items_without_preload_content(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=500, strict=True)]], Field(description="Number of results to return per page. Default is 200; maximum is 500. ")] = None,
+ sort_field: Annotated[Optional[ViewerCampaignItemSortFieldEnum], Field(description="Sort by. Omit to sort by created_at. ")] = None,
+ sort_direction: Annotated[Optional[SortDirectionEnum], Field(description="Sort direction.")] = None,
+ statuses: Annotated[Optional[List[ViewerCampaignItemStatusEnum]], Field(description="Filter by review status. When multiple values are provided, items matching any status are returned (OR). ")] = None,
+ access_level_names: Annotated[Optional[List[StrictStr]], Field(description="Filter by access level name.")] = None,
+ principal_ids: Annotated[Optional[List[UUID]], Field(description="Filter by principal ID.")] = None,
+ entity_ids: Annotated[Optional[List[UUID]], Field(description="Filter by entity ID.")] = None,
+ item_ids: Annotated[Optional[List[UUID]], Field(description="Filter to specific campaign item review IDs.")] = None,
+ ai_bucket_id: Annotated[Optional[UUID], Field(description="Restrict to items in this AI-suggestion bucket.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """List viewer campaign items
+
+ Returns a paginated list of campaign review items assigned to the current authenticated viewer. Matches GraphQL `Campaign.viewerItems`. Campaign access matches `GET /campaigns/{campaign_id}` and GraphQL `campaign(id)`: the caller must have access-review read permission or be a reviewer on the campaign. Otherwise the request fails with 403 (same as get-by-id). Item rows are still scoped to the caller's own reviews (empty page when the caller is an admin but not a reviewer).
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200; maximum is 500.
+ :type page_size: int
+ :param sort_field: Sort by. Omit to sort by created_at.
+ :type sort_field: ViewerCampaignItemSortFieldEnum
+ :param sort_direction: Sort direction.
+ :type sort_direction: SortDirectionEnum
+ :param statuses: Filter by review status. When multiple values are provided, items matching any status are returned (OR).
+ :type statuses: List[ViewerCampaignItemStatusEnum]
+ :param access_level_names: Filter by access level name.
+ :type access_level_names: List[str]
+ :param principal_ids: Filter by principal ID.
+ :type principal_ids: List[UUID]
+ :param entity_ids: Filter by entity ID.
+ :type entity_ids: List[UUID]
+ :param item_ids: Filter to specific campaign item review IDs.
+ :type item_ids: List[UUID]
+ :param ai_bucket_id: Restrict to items in this AI-suggestion bucket.
+ :type ai_bucket_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaign_viewer_items_serialize(
+ campaign_id=campaign_id,
+ cursor=cursor,
+ page_size=page_size,
+ sort_field=sort_field,
+ sort_direction=sort_direction,
+ statuses=statuses,
+ access_level_names=access_level_names,
+ principal_ids=principal_ids,
+ entity_ids=entity_ids,
+ item_ids=item_ids,
+ ai_bucket_id=ai_bucket_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedViewerCampaignItemsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_campaign_viewer_items_serialize(
+ self,
+ campaign_id,
+ cursor,
+ page_size,
+ sort_field,
+ sort_direction,
+ statuses,
+ access_level_names,
+ principal_ids,
+ entity_ids,
+ item_ids,
+ ai_bucket_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ 'statuses': 'multi',
+ 'access_level_names': 'multi',
+ 'principal_ids': 'multi',
+ 'entity_ids': 'multi',
+ 'item_ids': 'multi',
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if campaign_id is not None:
+ _path_params['campaign_id'] = campaign_id
+ # process the query parameters
+ if cursor is not None:
+
+ _query_params.append(('cursor', cursor))
+
+ if page_size is not None:
+
+ _query_params.append(('page_size', page_size))
+
+ if sort_field is not None:
+
+ _query_params.append(('sort_field', sort_field.value))
+
+ if sort_direction is not None:
+
+ _query_params.append(('sort_direction', sort_direction.value))
+
+ if statuses is not None:
+
+ _query_params.append(('statuses', statuses))
+
+ if access_level_names is not None:
+
+ _query_params.append(('access_level_names', access_level_names))
+
+ if principal_ids is not None:
+
+ _query_params.append(('principal_ids', principal_ids))
+
+ if entity_ids is not None:
+
+ _query_params.append(('entity_ids', entity_ids))
+
+ if item_ids is not None:
+
+ _query_params.append(('item_ids', item_ids))
+
+ if ai_bucket_id is not None:
+
+ _query_params.append(('ai_bucket_id', ai_bucket_id))
+
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/campaigns/{campaign_id}/viewer-items',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_campaigns(
+ self,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ name: Annotated[Optional[StrictStr], Field(description="Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive).")] = None,
+ status: Annotated[Optional[CampaignStatusEnum], Field(description="Filter by campaign status. Status is derived from lifecycle timestamps and review progress.")] = None,
+ created_at_after: Annotated[Optional[datetime], Field(description="Include campaigns created after this timestamp (exclusive). ISO 8601 format.")] = None,
+ created_at_before: Annotated[Optional[datetime], Field(description="Include campaigns created before this timestamp (exclusive). ISO 8601 format.")] = None,
+ started_at_after: Annotated[Optional[datetime], Field(description="Include campaigns started after this timestamp (exclusive). ISO 8601 format.")] = None,
+ started_at_before: Annotated[Optional[datetime], Field(description="Include campaigns started before this timestamp (exclusive). ISO 8601 format.")] = None,
+ ended_at_after: Annotated[Optional[datetime], Field(description="Include campaigns ended after this timestamp (exclusive). ISO 8601 format.")] = None,
+ ended_at_before: Annotated[Optional[datetime], Field(description="Include campaigns ended before this timestamp (exclusive). ISO 8601 format.")] = None,
+ stopped_at_after: Annotated[Optional[datetime], Field(description="Include campaigns stopped after this timestamp (exclusive). ISO 8601 format.")] = None,
+ stopped_at_before: Annotated[Optional[datetime], Field(description="Include campaigns stopped before this timestamp (exclusive). ISO 8601 format.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaginatedCampaignsList:
+ """get_campaigns
+
+ Returns a list of `Campaign` objects.
+
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
+ :param name: Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive).
+ :type name: str
+ :param status: Filter by campaign status. Status is derived from lifecycle timestamps and review progress.
+ :type status: CampaignStatusEnum
+ :param created_at_after: Include campaigns created after this timestamp (exclusive). ISO 8601 format.
+ :type created_at_after: datetime
+ :param created_at_before: Include campaigns created before this timestamp (exclusive). ISO 8601 format.
+ :type created_at_before: datetime
+ :param started_at_after: Include campaigns started after this timestamp (exclusive). ISO 8601 format.
+ :type started_at_after: datetime
+ :param started_at_before: Include campaigns started before this timestamp (exclusive). ISO 8601 format.
+ :type started_at_before: datetime
+ :param ended_at_after: Include campaigns ended after this timestamp (exclusive). ISO 8601 format.
+ :type ended_at_after: datetime
+ :param ended_at_before: Include campaigns ended before this timestamp (exclusive). ISO 8601 format.
+ :type ended_at_before: datetime
+ :param stopped_at_after: Include campaigns stopped after this timestamp (exclusive). ISO 8601 format.
+ :type stopped_at_after: datetime
+ :param stopped_at_before: Include campaigns stopped before this timestamp (exclusive). ISO 8601 format.
+ :type stopped_at_before: datetime
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaigns_serialize(
+ cursor=cursor,
+ page_size=page_size,
+ name=name,
+ status=status,
+ created_at_after=created_at_after,
+ created_at_before=created_at_before,
+ started_at_after=started_at_after,
+ started_at_before=started_at_before,
+ ended_at_after=ended_at_after,
+ ended_at_before=ended_at_before,
+ stopped_at_after=stopped_at_after,
+ stopped_at_before=stopped_at_before,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedCampaignsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_campaigns_with_http_info(
+ self,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ name: Annotated[Optional[StrictStr], Field(description="Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive).")] = None,
+ status: Annotated[Optional[CampaignStatusEnum], Field(description="Filter by campaign status. Status is derived from lifecycle timestamps and review progress.")] = None,
+ created_at_after: Annotated[Optional[datetime], Field(description="Include campaigns created after this timestamp (exclusive). ISO 8601 format.")] = None,
+ created_at_before: Annotated[Optional[datetime], Field(description="Include campaigns created before this timestamp (exclusive). ISO 8601 format.")] = None,
+ started_at_after: Annotated[Optional[datetime], Field(description="Include campaigns started after this timestamp (exclusive). ISO 8601 format.")] = None,
+ started_at_before: Annotated[Optional[datetime], Field(description="Include campaigns started before this timestamp (exclusive). ISO 8601 format.")] = None,
+ ended_at_after: Annotated[Optional[datetime], Field(description="Include campaigns ended after this timestamp (exclusive). ISO 8601 format.")] = None,
+ ended_at_before: Annotated[Optional[datetime], Field(description="Include campaigns ended before this timestamp (exclusive). ISO 8601 format.")] = None,
+ stopped_at_after: Annotated[Optional[datetime], Field(description="Include campaigns stopped after this timestamp (exclusive). ISO 8601 format.")] = None,
+ stopped_at_before: Annotated[Optional[datetime], Field(description="Include campaigns stopped before this timestamp (exclusive). ISO 8601 format.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaginatedCampaignsList]:
+ """get_campaigns
+
+ Returns a list of `Campaign` objects.
+
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
+ :param name: Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive).
+ :type name: str
+ :param status: Filter by campaign status. Status is derived from lifecycle timestamps and review progress.
+ :type status: CampaignStatusEnum
+ :param created_at_after: Include campaigns created after this timestamp (exclusive). ISO 8601 format.
+ :type created_at_after: datetime
+ :param created_at_before: Include campaigns created before this timestamp (exclusive). ISO 8601 format.
+ :type created_at_before: datetime
+ :param started_at_after: Include campaigns started after this timestamp (exclusive). ISO 8601 format.
+ :type started_at_after: datetime
+ :param started_at_before: Include campaigns started before this timestamp (exclusive). ISO 8601 format.
+ :type started_at_before: datetime
+ :param ended_at_after: Include campaigns ended after this timestamp (exclusive). ISO 8601 format.
+ :type ended_at_after: datetime
+ :param ended_at_before: Include campaigns ended before this timestamp (exclusive). ISO 8601 format.
+ :type ended_at_before: datetime
+ :param stopped_at_after: Include campaigns stopped after this timestamp (exclusive). ISO 8601 format.
+ :type stopped_at_after: datetime
+ :param stopped_at_before: Include campaigns stopped before this timestamp (exclusive). ISO 8601 format.
+ :type stopped_at_before: datetime
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaigns_serialize(
+ cursor=cursor,
+ page_size=page_size,
+ name=name,
+ status=status,
+ created_at_after=created_at_after,
+ created_at_before=created_at_before,
+ started_at_after=started_at_after,
+ started_at_before=started_at_before,
+ ended_at_after=ended_at_after,
+ ended_at_before=ended_at_before,
+ stopped_at_after=stopped_at_after,
+ stopped_at_before=stopped_at_before,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedCampaignsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_campaigns_without_preload_content(
+ self,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ name: Annotated[Optional[StrictStr], Field(description="Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive).")] = None,
+ status: Annotated[Optional[CampaignStatusEnum], Field(description="Filter by campaign status. Status is derived from lifecycle timestamps and review progress.")] = None,
+ created_at_after: Annotated[Optional[datetime], Field(description="Include campaigns created after this timestamp (exclusive). ISO 8601 format.")] = None,
+ created_at_before: Annotated[Optional[datetime], Field(description="Include campaigns created before this timestamp (exclusive). ISO 8601 format.")] = None,
+ started_at_after: Annotated[Optional[datetime], Field(description="Include campaigns started after this timestamp (exclusive). ISO 8601 format.")] = None,
+ started_at_before: Annotated[Optional[datetime], Field(description="Include campaigns started before this timestamp (exclusive). ISO 8601 format.")] = None,
+ ended_at_after: Annotated[Optional[datetime], Field(description="Include campaigns ended after this timestamp (exclusive). ISO 8601 format.")] = None,
+ ended_at_before: Annotated[Optional[datetime], Field(description="Include campaigns ended before this timestamp (exclusive). ISO 8601 format.")] = None,
+ stopped_at_after: Annotated[Optional[datetime], Field(description="Include campaigns stopped after this timestamp (exclusive). ISO 8601 format.")] = None,
+ stopped_at_before: Annotated[Optional[datetime], Field(description="Include campaigns stopped before this timestamp (exclusive). ISO 8601 format.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """get_campaigns
+
+ Returns a list of `Campaign` objects.
+
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
+ :param name: Campaign name to filter by. Returns campaigns whose names contain this substring (case-insensitive).
+ :type name: str
+ :param status: Filter by campaign status. Status is derived from lifecycle timestamps and review progress.
+ :type status: CampaignStatusEnum
+ :param created_at_after: Include campaigns created after this timestamp (exclusive). ISO 8601 format.
+ :type created_at_after: datetime
+ :param created_at_before: Include campaigns created before this timestamp (exclusive). ISO 8601 format.
+ :type created_at_before: datetime
+ :param started_at_after: Include campaigns started after this timestamp (exclusive). ISO 8601 format.
+ :type started_at_after: datetime
+ :param started_at_before: Include campaigns started before this timestamp (exclusive). ISO 8601 format.
+ :type started_at_before: datetime
+ :param ended_at_after: Include campaigns ended after this timestamp (exclusive). ISO 8601 format.
+ :type ended_at_after: datetime
+ :param ended_at_before: Include campaigns ended before this timestamp (exclusive). ISO 8601 format.
+ :type ended_at_before: datetime
+ :param stopped_at_after: Include campaigns stopped after this timestamp (exclusive). ISO 8601 format.
+ :type stopped_at_after: datetime
+ :param stopped_at_before: Include campaigns stopped before this timestamp (exclusive). ISO 8601 format.
+ :type stopped_at_before: datetime
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_campaigns_serialize(
+ cursor=cursor,
+ page_size=page_size,
+ name=name,
+ status=status,
+ created_at_after=created_at_after,
+ created_at_before=created_at_before,
+ started_at_after=started_at_after,
+ started_at_before=started_at_before,
+ ended_at_after=ended_at_after,
+ ended_at_before=ended_at_before,
+ stopped_at_after=stopped_at_after,
+ stopped_at_before=stopped_at_before,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedCampaignsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_campaigns_serialize(
+ self,
+ cursor,
+ page_size,
+ name,
+ status,
+ created_at_after,
+ created_at_before,
+ started_at_after,
+ started_at_before,
+ ended_at_after,
+ ended_at_before,
+ stopped_at_after,
+ stopped_at_before,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ if cursor is not None:
+
+ _query_params.append(('cursor', cursor))
+
+ if page_size is not None:
+
+ _query_params.append(('page_size', page_size))
+
+ if name is not None:
+
+ _query_params.append(('name', name))
+
+ if status is not None:
+
+ _query_params.append(('status', status.value))
+
+ if created_at_after is not None:
+ if isinstance(created_at_after, datetime):
+ _query_params.append(
+ (
+ 'created_at_after',
+ created_at_after.strftime(
+ self.api_client.configuration.datetime_format
+ )
+ )
+ )
+ else:
+ _query_params.append(('created_at_after', created_at_after))
+
+ if created_at_before is not None:
+ if isinstance(created_at_before, datetime):
+ _query_params.append(
+ (
+ 'created_at_before',
+ created_at_before.strftime(
+ self.api_client.configuration.datetime_format
+ )
+ )
+ )
+ else:
+ _query_params.append(('created_at_before', created_at_before))
+
+ if started_at_after is not None:
+ if isinstance(started_at_after, datetime):
+ _query_params.append(
+ (
+ 'started_at_after',
+ started_at_after.strftime(
+ self.api_client.configuration.datetime_format
+ )
+ )
+ )
+ else:
+ _query_params.append(('started_at_after', started_at_after))
+
+ if started_at_before is not None:
+ if isinstance(started_at_before, datetime):
+ _query_params.append(
+ (
+ 'started_at_before',
+ started_at_before.strftime(
+ self.api_client.configuration.datetime_format
+ )
+ )
+ )
+ else:
+ _query_params.append(('started_at_before', started_at_before))
+
+ if ended_at_after is not None:
+ if isinstance(ended_at_after, datetime):
+ _query_params.append(
+ (
+ 'ended_at_after',
+ ended_at_after.strftime(
+ self.api_client.configuration.datetime_format
+ )
+ )
+ )
+ else:
+ _query_params.append(('ended_at_after', ended_at_after))
+
+ if ended_at_before is not None:
+ if isinstance(ended_at_before, datetime):
+ _query_params.append(
+ (
+ 'ended_at_before',
+ ended_at_before.strftime(
+ self.api_client.configuration.datetime_format
+ )
+ )
+ )
+ else:
+ _query_params.append(('ended_at_before', ended_at_before))
+
+ if stopped_at_after is not None:
+ if isinstance(stopped_at_after, datetime):
+ _query_params.append(
+ (
+ 'stopped_at_after',
+ stopped_at_after.strftime(
+ self.api_client.configuration.datetime_format
+ )
+ )
+ )
+ else:
+ _query_params.append(('stopped_at_after', stopped_at_after))
+
+ if stopped_at_before is not None:
+ if isinstance(stopped_at_before, datetime):
+ _query_params.append(
+ (
+ 'stopped_at_before',
+ stopped_at_before.strftime(
+ self.api_client.configuration.datetime_format
+ )
+ )
+ )
+ else:
+ _query_params.append(('stopped_at_before', stopped_at_before))
+
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/campaigns',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def start_campaign(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Campaign:
+ """Start campaign
+
+ Starts a draft campaign immediately, setting `started_at` and `started_by_user_id`. Returns 400 if the campaign is not in draft state, or if it is a recurring template (`is_template: true`) — templates spawn draft campaigns on their schedule and cannot be started directly.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._start_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def start_campaign_with_http_info(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Campaign]:
+ """Start campaign
+
+ Starts a draft campaign immediately, setting `started_at` and `started_by_user_id`. Returns 400 if the campaign is not in draft state, or if it is a recurring template (`is_template: true`) — templates spawn draft campaigns on their schedule and cannot be started directly.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._start_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def start_campaign_without_preload_content(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Start campaign
+
+ Starts a draft campaign immediately, setting `started_at` and `started_by_user_id`. Returns 400 if the campaign is not in draft state, or if it is a recurring template (`is_template: true`) — templates spawn draft campaigns on their schedule and cannot be started directly.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._start_campaign_serialize(
+ campaign_id=campaign_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _start_campaign_serialize(
+ self,
+ campaign_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if campaign_id is not None:
+ _path_params['campaign_id'] = campaign_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/campaigns/{campaign_id}/start',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def stop_campaign(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ stop_campaign_request: Optional[StopCampaignRequest] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Campaign:
+ """Stop campaign
+
+ Stops an ongoing campaign immediately, setting `stopped_at` and `stopped_by_user_id`. Returns 400 if the campaign has not started or has already stopped.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param stop_campaign_request:
+ :type stop_campaign_request: StopCampaignRequest
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._stop_campaign_serialize(
+ campaign_id=campaign_id,
+ stop_campaign_request=stop_campaign_request,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def stop_campaign_with_http_info(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ stop_campaign_request: Optional[StopCampaignRequest] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Campaign]:
+ """Stop campaign
+
+ Stops an ongoing campaign immediately, setting `stopped_at` and `stopped_by_user_id`. Returns 400 if the campaign has not started or has already stopped.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param stop_campaign_request:
+ :type stop_campaign_request: StopCampaignRequest
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._stop_campaign_serialize(
+ campaign_id=campaign_id,
+ stop_campaign_request=stop_campaign_request,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def stop_campaign_without_preload_content(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ stop_campaign_request: Optional[StopCampaignRequest] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Stop campaign
+
+ Stops an ongoing campaign immediately, setting `stopped_at` and `stopped_by_user_id`. Returns 400 if the campaign has not started or has already stopped.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param stop_campaign_request:
+ :type stop_campaign_request: StopCampaignRequest
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._stop_campaign_serialize(
+ campaign_id=campaign_id,
+ stop_campaign_request=stop_campaign_request,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _stop_campaign_serialize(
+ self,
+ campaign_id,
+ stop_campaign_request,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if campaign_id is not None:
+ _path_params['campaign_id'] = campaign_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+ if stop_campaign_request is not None:
+ _body_params = stop_campaign_request
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/campaigns/{campaign_id}/stop',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def update_campaign(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ update_campaign_info: UpdateCampaignInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Campaign:
+ """Update campaign
+
+ Partially updates a campaign. Omitted fields are left unchanged. `configuration.query` and `configuration.reviewer_assignment_policy` cannot be updated after create; including either field returns 400. `configuration.cron_expression` and `configuration.recurring_duration_days` may only be set on template campaigns; setting them on a one-off campaign returns 400. `configuration.is_template` is immutable and not accepted on update. Configuration updates on a stopped or ended (non-template) campaign return 400. Name-only updates are still allowed.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param update_campaign_info: (required)
+ :type update_campaign_info: UpdateCampaignInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_campaign_serialize(
+ campaign_id=campaign_id,
+ update_campaign_info=update_campaign_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def update_campaign_with_http_info(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ update_campaign_info: UpdateCampaignInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Campaign]:
+ """Update campaign
+
+ Partially updates a campaign. Omitted fields are left unchanged. `configuration.query` and `configuration.reviewer_assignment_policy` cannot be updated after create; including either field returns 400. `configuration.cron_expression` and `configuration.recurring_duration_days` may only be set on template campaigns; setting them on a one-off campaign returns 400. `configuration.is_template` is immutable and not accepted on update. Configuration updates on a stopped or ended (non-template) campaign return 400. Name-only updates are still allowed.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param update_campaign_info: (required)
+ :type update_campaign_info: UpdateCampaignInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_campaign_serialize(
+ campaign_id=campaign_id,
+ update_campaign_info=update_campaign_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def update_campaign_without_preload_content(
+ self,
+ campaign_id: Annotated[UUID, Field(description="The ID of the campaign.")],
+ update_campaign_info: UpdateCampaignInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Update campaign
+
+ Partially updates a campaign. Omitted fields are left unchanged. `configuration.query` and `configuration.reviewer_assignment_policy` cannot be updated after create; including either field returns 400. `configuration.cron_expression` and `configuration.recurring_duration_days` may only be set on template campaigns; setting them on a one-off campaign returns 400. `configuration.is_template` is immutable and not accepted on update. Configuration updates on a stopped or ended (non-template) campaign return 400. Name-only updates are still allowed.
+
+ :param campaign_id: The ID of the campaign. (required)
+ :type campaign_id: UUID
+ :param update_campaign_info: (required)
+ :type update_campaign_info: UpdateCampaignInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_campaign_serialize(
+ campaign_id=campaign_id,
+ update_campaign_info=update_campaign_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Campaign",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _update_campaign_serialize(
+ self,
+ campaign_id,
+ update_campaign_info,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if campaign_id is not None:
+ _path_params['campaign_id'] = campaign_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+ if update_campaign_info is not None:
+ _body_params = update_campaign_info
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='PUT',
+ resource_path='/campaigns/{campaign_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
diff --git a/opal_security/api/groups_api.py b/opal_security/api/groups_api.py
index 37436ce..ab370c4 100644
--- a/opal_security/api/groups_api.py
+++ b/opal_security/api/groups_api.py
@@ -17,7 +17,7 @@
from typing import Any, Dict, List, Optional, Tuple, Union
from typing_extensions import Annotated
-from pydantic import Field, StrictStr
+from pydantic import Field, StrictBool, StrictStr
from typing import List, Optional
from typing_extensions import Annotated
from uuid import UUID
@@ -25,6 +25,7 @@
from opal_security.models.add_group_user_request import AddGroupUserRequest
from opal_security.models.create_group_info import CreateGroupInfo
from opal_security.models.group import Group
+from opal_security.models.group_access_level_list import GroupAccessLevelList
from opal_security.models.group_containing_group import GroupContainingGroup
from opal_security.models.group_containing_group_list import GroupContainingGroupList
from opal_security.models.group_resource import GroupResource
@@ -679,7 +680,7 @@ def add_group_user(
self,
group_id: Annotated[UUID, Field(description="The ID of the group.")],
user_id: Annotated[UUID, Field(description="The ID of the user to add.")],
- duration_minutes: Annotated[Optional[Annotated[int, Field(le=525960, strict=True)]], Field(description="The duration for which the group can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
+ duration_minutes: Annotated[Optional[Annotated[int, Field(le=153722867, strict=True)]], Field(description="The duration for which the group can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level to grant to this user. If omitted, the default access level remote ID value (empty string) is used.")] = None,
add_group_user_request: Optional[AddGroupUserRequest] = None,
_request_timeout: Union[
@@ -762,7 +763,7 @@ def add_group_user_with_http_info(
self,
group_id: Annotated[UUID, Field(description="The ID of the group.")],
user_id: Annotated[UUID, Field(description="The ID of the user to add.")],
- duration_minutes: Annotated[Optional[Annotated[int, Field(le=525960, strict=True)]], Field(description="The duration for which the group can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
+ duration_minutes: Annotated[Optional[Annotated[int, Field(le=153722867, strict=True)]], Field(description="The duration for which the group can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level to grant to this user. If omitted, the default access level remote ID value (empty string) is used.")] = None,
add_group_user_request: Optional[AddGroupUserRequest] = None,
_request_timeout: Union[
@@ -845,7 +846,7 @@ def add_group_user_without_preload_content(
self,
group_id: Annotated[UUID, Field(description="The ID of the group.")],
user_id: Annotated[UUID, Field(description="The ID of the user to add.")],
- duration_minutes: Annotated[Optional[Annotated[int, Field(le=525960, strict=True)]], Field(description="The duration for which the group can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
+ duration_minutes: Annotated[Optional[Annotated[int, Field(le=153722867, strict=True)]], Field(description="The duration for which the group can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level to grant to this user. If omitted, the default access level remote ID value (empty string) is used.")] = None,
add_group_user_request: Optional[AddGroupUserRequest] = None,
_request_timeout: Union[
@@ -2087,6 +2088,270 @@ def _get_group_serialize(
+ @validate_call
+ def get_group_access_levels(
+ self,
+ group_id: Annotated[UUID, Field(description="The ID of the group whose access levels to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> GroupAccessLevelList:
+ """Get group access levels
+
+ Returns the list of access levels defined for the group. Groups that only offer default (unnamed) access return an empty list.
+
+ :param group_id: The ID of the group whose access levels to return. (required)
+ :type group_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_group_access_levels_serialize(
+ group_id=group_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "GroupAccessLevelList",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_group_access_levels_with_http_info(
+ self,
+ group_id: Annotated[UUID, Field(description="The ID of the group whose access levels to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[GroupAccessLevelList]:
+ """Get group access levels
+
+ Returns the list of access levels defined for the group. Groups that only offer default (unnamed) access return an empty list.
+
+ :param group_id: The ID of the group whose access levels to return. (required)
+ :type group_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_group_access_levels_serialize(
+ group_id=group_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "GroupAccessLevelList",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_group_access_levels_without_preload_content(
+ self,
+ group_id: Annotated[UUID, Field(description="The ID of the group whose access levels to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Get group access levels
+
+ Returns the list of access levels defined for the group. Groups that only offer default (unnamed) access return an empty list.
+
+ :param group_id: The ID of the group whose access levels to return. (required)
+ :type group_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_group_access_levels_serialize(
+ group_id=group_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "GroupAccessLevelList",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_group_access_levels_serialize(
+ self,
+ group_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if group_id is not None:
+ _path_params['group_id'] = group_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/groups/{group_id}/access_levels',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
@validate_call
def get_group_containing_group(
self,
@@ -4218,7 +4483,7 @@ def get_group_users(
self,
group_id: Annotated[UUID, Field(description="The ID of the group.")],
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page, up to 1000. When set (or when a cursor is provided), the response contains a single page of results and a `next` cursor; the default page size is 200. When both page_size and cursor are omitted, the entire group membership is returned in one response with no `next` cursor. For large groups, prefer setting page_size and following `next`.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4240,7 +4505,7 @@ def get_group_users(
:type group_id: UUID
:param cursor: The pagination cursor value.
:type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
+ :param page_size: Number of results to return per page, up to 1000. When set (or when a cursor is provided), the response contains a single page of results and a `next` cursor; the default page size is 200. When both page_size and cursor are omitted, the entire group membership is returned in one response with no `next` cursor. For large groups, prefer setting page_size and following `next`.
:type page_size: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -4293,7 +4558,7 @@ def get_group_users_with_http_info(
self,
group_id: Annotated[UUID, Field(description="The ID of the group.")],
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page, up to 1000. When set (or when a cursor is provided), the response contains a single page of results and a `next` cursor; the default page size is 200. When both page_size and cursor are omitted, the entire group membership is returned in one response with no `next` cursor. For large groups, prefer setting page_size and following `next`.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4315,7 +4580,7 @@ def get_group_users_with_http_info(
:type group_id: UUID
:param cursor: The pagination cursor value.
:type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
+ :param page_size: Number of results to return per page, up to 1000. When set (or when a cursor is provided), the response contains a single page of results and a `next` cursor; the default page size is 200. When both page_size and cursor are omitted, the entire group membership is returned in one response with no `next` cursor. For large groups, prefer setting page_size and following `next`.
:type page_size: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -4368,7 +4633,7 @@ def get_group_users_without_preload_content(
self,
group_id: Annotated[UUID, Field(description="The ID of the group.")],
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page, up to 1000. When set (or when a cursor is provided), the response contains a single page of results and a `next` cursor; the default page size is 200. When both page_size and cursor are omitted, the entire group membership is returned in one response with no `next` cursor. For large groups, prefer setting page_size and following `next`.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4390,7 +4655,7 @@ def get_group_users_without_preload_content(
:type group_id: UUID
:param cursor: The pagination cursor value.
:type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
+ :param page_size: Number of results to return per page, up to 1000. When set (or when a cursor is provided), the response contains a single page of results and a `next` cursor; the default page size is 200. When both page_size and cursor are omitted, the entire group membership is returned in one response with no `next` cursor. For large groups, prefer setting page_size and following `next`.
:type page_size: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -4563,6 +4828,7 @@ def get_group_visibility(
_response_types_map: Dict[str, Optional[str]] = {
'200': "VisibilityInfo",
+ '403': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -4630,6 +4896,7 @@ def get_group_visibility_with_http_info(
_response_types_map: Dict[str, Optional[str]] = {
'200': "VisibilityInfo",
+ '403': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -4697,6 +4964,7 @@ def get_group_visibility_without_preload_content(
_response_types_map: Dict[str, Optional[str]] = {
'200': "VisibilityInfo",
+ '403': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -4778,6 +5046,7 @@ def get_groups(
group_ids: Annotated[Optional[List[UUID]], Field(description="The group ids to filter by.")] = None,
group_name: Annotated[Optional[StrictStr], Field(description="Group name.")] = None,
tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only groups that have any of these tags applied.")] = None,
+ requestable: Annotated[Optional[StrictBool], Field(description="If true, only return groups that allow access requests. Does not check whether the caller is permitted to request the group.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4807,6 +5076,8 @@ def get_groups(
:type group_name: str
:param tag_ids: The IDs of the tags to filter by. Returns only groups that have any of these tags applied.
:type tag_ids: List[UUID]
+ :param requestable: If true, only return groups that allow access requests. Does not check whether the caller is permitted to request the group.
+ :type requestable: bool
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -4836,6 +5107,7 @@ def get_groups(
group_ids=group_ids,
group_name=group_name,
tag_ids=tag_ids,
+ requestable=requestable,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -4865,6 +5137,7 @@ def get_groups_with_http_info(
group_ids: Annotated[Optional[List[UUID]], Field(description="The group ids to filter by.")] = None,
group_name: Annotated[Optional[StrictStr], Field(description="Group name.")] = None,
tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only groups that have any of these tags applied.")] = None,
+ requestable: Annotated[Optional[StrictBool], Field(description="If true, only return groups that allow access requests. Does not check whether the caller is permitted to request the group.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4894,6 +5167,8 @@ def get_groups_with_http_info(
:type group_name: str
:param tag_ids: The IDs of the tags to filter by. Returns only groups that have any of these tags applied.
:type tag_ids: List[UUID]
+ :param requestable: If true, only return groups that allow access requests. Does not check whether the caller is permitted to request the group.
+ :type requestable: bool
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -4923,6 +5198,7 @@ def get_groups_with_http_info(
group_ids=group_ids,
group_name=group_name,
tag_ids=tag_ids,
+ requestable=requestable,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -4952,6 +5228,7 @@ def get_groups_without_preload_content(
group_ids: Annotated[Optional[List[UUID]], Field(description="The group ids to filter by.")] = None,
group_name: Annotated[Optional[StrictStr], Field(description="Group name.")] = None,
tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only groups that have any of these tags applied.")] = None,
+ requestable: Annotated[Optional[StrictBool], Field(description="If true, only return groups that allow access requests. Does not check whether the caller is permitted to request the group.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4981,6 +5258,8 @@ def get_groups_without_preload_content(
:type group_name: str
:param tag_ids: The IDs of the tags to filter by. Returns only groups that have any of these tags applied.
:type tag_ids: List[UUID]
+ :param requestable: If true, only return groups that allow access requests. Does not check whether the caller is permitted to request the group.
+ :type requestable: bool
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5010,6 +5289,7 @@ def get_groups_without_preload_content(
group_ids=group_ids,
group_name=group_name,
tag_ids=tag_ids,
+ requestable=requestable,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5034,6 +5314,7 @@ def _get_groups_serialize(
group_ids,
group_name,
tag_ids,
+ requestable,
_request_auth,
_content_type,
_headers,
@@ -5082,6 +5363,10 @@ def _get_groups_serialize(
_query_params.append(('tag_ids', tag_ids))
+ if requestable is not None:
+
+ _query_params.append(('requestable', requestable))
+
# process the header parameters
# process the form parameters
# process the body parameter
diff --git a/opal_security/api/opal_queries_api.py b/opal_security/api/opal_queries_api.py
index e5bb1df..b86726b 100644
--- a/opal_security/api/opal_queries_api.py
+++ b/opal_security/api/opal_queries_api.py
@@ -17,8 +17,8 @@
from typing import Any, Dict, List, Optional, Tuple, Union
from typing_extensions import Annotated
-from opal_security.models.opal_node_query import OpalNodeQuery
-from opal_security.models.opal_node_query_results import OpalNodeQueryResults
+from opal_security.models.opal_query_results import OpalQueryResults
+from opal_security.models.run_opal_query_request import RunOpalQueryRequest
from opal_security.api_client import ApiClient, RequestSerialized
from opal_security.api_response import ApiResponse
@@ -41,7 +41,7 @@ def __init__(self, api_client=None) -> None:
@validate_call
def run_opal_query(
self,
- body: OpalNodeQuery,
+ run_opal_query_request: RunOpalQueryRequest,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -54,13 +54,13 @@ def run_opal_query(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> OpalNodeQueryResults:
+ ) -> OpalQueryResults:
"""Run an ad-hoc OpalQuery
- Runs an ad-hoc OpalQuery and returns the results. Currently supports NODE queries (users, resources, groups). This endpoint is only available to our OpalQuery beta group. Please contact Opal support if you'd like to be added to the beta.
+ Executes an ad-hoc OpalQuery and returns paginated results. Two query types are supported: a **Node** query filters and returns entities (users, resources, or groups); an **Access Path** query returns the access edges between principals and their entitlements. Set `type` to `NODE` or `ACCESS_PATH` in the request body to select the query type. This endpoint is available to OpalQuery beta participants. To request access, contact Opal support.
- :param body: (required)
- :type body: OpalNodeQuery
+ :param run_opal_query_request: (required)
+ :type run_opal_query_request: RunOpalQueryRequest
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -84,7 +84,7 @@ def run_opal_query(
""" # noqa: E501
_param = self._run_opal_query_serialize(
- body=body,
+ run_opal_query_request=run_opal_query_request,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -92,7 +92,7 @@ def run_opal_query(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "OpalNodeQueryResults",
+ '200': "OpalQueryResults",
}
response_data = self.api_client.call_api(
*_param,
@@ -108,7 +108,7 @@ def run_opal_query(
@validate_call
def run_opal_query_with_http_info(
self,
- body: OpalNodeQuery,
+ run_opal_query_request: RunOpalQueryRequest,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -121,13 +121,13 @@ def run_opal_query_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[OpalNodeQueryResults]:
+ ) -> ApiResponse[OpalQueryResults]:
"""Run an ad-hoc OpalQuery
- Runs an ad-hoc OpalQuery and returns the results. Currently supports NODE queries (users, resources, groups). This endpoint is only available to our OpalQuery beta group. Please contact Opal support if you'd like to be added to the beta.
+ Executes an ad-hoc OpalQuery and returns paginated results. Two query types are supported: a **Node** query filters and returns entities (users, resources, or groups); an **Access Path** query returns the access edges between principals and their entitlements. Set `type` to `NODE` or `ACCESS_PATH` in the request body to select the query type. This endpoint is available to OpalQuery beta participants. To request access, contact Opal support.
- :param body: (required)
- :type body: OpalNodeQuery
+ :param run_opal_query_request: (required)
+ :type run_opal_query_request: RunOpalQueryRequest
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -151,7 +151,7 @@ def run_opal_query_with_http_info(
""" # noqa: E501
_param = self._run_opal_query_serialize(
- body=body,
+ run_opal_query_request=run_opal_query_request,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -159,7 +159,7 @@ def run_opal_query_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "OpalNodeQueryResults",
+ '200': "OpalQueryResults",
}
response_data = self.api_client.call_api(
*_param,
@@ -175,7 +175,7 @@ def run_opal_query_with_http_info(
@validate_call
def run_opal_query_without_preload_content(
self,
- body: OpalNodeQuery,
+ run_opal_query_request: RunOpalQueryRequest,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -191,10 +191,10 @@ def run_opal_query_without_preload_content(
) -> RESTResponseType:
"""Run an ad-hoc OpalQuery
- Runs an ad-hoc OpalQuery and returns the results. Currently supports NODE queries (users, resources, groups). This endpoint is only available to our OpalQuery beta group. Please contact Opal support if you'd like to be added to the beta.
+ Executes an ad-hoc OpalQuery and returns paginated results. Two query types are supported: a **Node** query filters and returns entities (users, resources, or groups); an **Access Path** query returns the access edges between principals and their entitlements. Set `type` to `NODE` or `ACCESS_PATH` in the request body to select the query type. This endpoint is available to OpalQuery beta participants. To request access, contact Opal support.
- :param body: (required)
- :type body: OpalNodeQuery
+ :param run_opal_query_request: (required)
+ :type run_opal_query_request: RunOpalQueryRequest
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -218,7 +218,7 @@ def run_opal_query_without_preload_content(
""" # noqa: E501
_param = self._run_opal_query_serialize(
- body=body,
+ run_opal_query_request=run_opal_query_request,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -226,7 +226,7 @@ def run_opal_query_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "OpalNodeQueryResults",
+ '200': "OpalQueryResults",
}
response_data = self.api_client.call_api(
*_param,
@@ -237,7 +237,7 @@ def run_opal_query_without_preload_content(
def _run_opal_query_serialize(
self,
- body,
+ run_opal_query_request,
_request_auth,
_content_type,
_headers,
@@ -263,8 +263,8 @@ def _run_opal_query_serialize(
# process the header parameters
# process the form parameters
# process the body parameter
- if body is not None:
- _body_params = body
+ if run_opal_query_request is not None:
+ _body_params = run_opal_query_request
# set the HTTP header `Accept`
diff --git a/opal_security/api/paladin_api.py b/opal_security/api/paladin_api.py
new file mode 100644
index 0000000..b5db725
--- /dev/null
+++ b/opal_security/api/paladin_api.py
@@ -0,0 +1,2204 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+import warnings
+from pydantic import validate_call, Field, StrictFloat, StrictStr, StrictInt
+from typing import Any, Dict, List, Optional, Tuple, Union
+from typing_extensions import Annotated
+
+from pydantic import Field, StrictStr
+from typing_extensions import Annotated
+from uuid import UUID
+from opal_security.models.create_paladin_context_source_info import CreatePaladinContextSourceInfo
+from opal_security.models.create_paladin_info import CreatePaladinInfo
+from opal_security.models.paladin import Paladin
+from opal_security.models.paladin_context_source import PaladinContextSource
+from opal_security.models.paladin_context_source_list import PaladinContextSourceList
+from opal_security.models.paladin_list import PaladinList
+from opal_security.models.update_paladin_info import UpdatePaladinInfo
+
+from opal_security.api_client import ApiClient, RequestSerialized
+from opal_security.api_response import ApiResponse
+from opal_security.rest import RESTResponseType
+
+
+class PaladinApi:
+ """NOTE: This class is auto generated by OpenAPI Generator
+ Ref: https://openapi-generator.tech
+
+ Do not edit the class manually.
+ """
+
+ def __init__(self, api_client=None) -> None:
+ if api_client is None:
+ api_client = ApiClient.get_default()
+ self.api_client = api_client
+
+
+ @validate_call
+ def create_paladin(
+ self,
+ create_paladin_info: CreatePaladinInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Paladin:
+ """Create Paladin
+
+ Creates a new `Paladin`.
+
+ :param create_paladin_info: (required)
+ :type create_paladin_info: CreatePaladinInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_paladin_serialize(
+ create_paladin_info=create_paladin_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def create_paladin_with_http_info(
+ self,
+ create_paladin_info: CreatePaladinInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Paladin]:
+ """Create Paladin
+
+ Creates a new `Paladin`.
+
+ :param create_paladin_info: (required)
+ :type create_paladin_info: CreatePaladinInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_paladin_serialize(
+ create_paladin_info=create_paladin_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def create_paladin_without_preload_content(
+ self,
+ create_paladin_info: CreatePaladinInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Create Paladin
+
+ Creates a new `Paladin`.
+
+ :param create_paladin_info: (required)
+ :type create_paladin_info: CreatePaladinInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_paladin_serialize(
+ create_paladin_info=create_paladin_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _create_paladin_serialize(
+ self,
+ create_paladin_info,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+ if create_paladin_info is not None:
+ _body_params = create_paladin_info
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/paladin',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def create_paladin_context_source(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ create_paladin_context_source_info: CreatePaladinContextSourceInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaladinContextSource:
+ """Add a Paladin context source
+
+ Configures a context source (a Slack channel or a document) for a Paladin to read. Idempotent, so re-adding an existing source returns it.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param create_paladin_context_source_info: (required)
+ :type create_paladin_context_source_info: CreatePaladinContextSourceInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_paladin_context_source_serialize(
+ paladin_id=paladin_id,
+ create_paladin_context_source_info=create_paladin_context_source_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinContextSource",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def create_paladin_context_source_with_http_info(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ create_paladin_context_source_info: CreatePaladinContextSourceInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaladinContextSource]:
+ """Add a Paladin context source
+
+ Configures a context source (a Slack channel or a document) for a Paladin to read. Idempotent, so re-adding an existing source returns it.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param create_paladin_context_source_info: (required)
+ :type create_paladin_context_source_info: CreatePaladinContextSourceInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_paladin_context_source_serialize(
+ paladin_id=paladin_id,
+ create_paladin_context_source_info=create_paladin_context_source_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinContextSource",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def create_paladin_context_source_without_preload_content(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ create_paladin_context_source_info: CreatePaladinContextSourceInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Add a Paladin context source
+
+ Configures a context source (a Slack channel or a document) for a Paladin to read. Idempotent, so re-adding an existing source returns it.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param create_paladin_context_source_info: (required)
+ :type create_paladin_context_source_info: CreatePaladinContextSourceInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_paladin_context_source_serialize(
+ paladin_id=paladin_id,
+ create_paladin_context_source_info=create_paladin_context_source_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinContextSource",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _create_paladin_context_source_serialize(
+ self,
+ paladin_id,
+ create_paladin_context_source_info,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if paladin_id is not None:
+ _path_params['paladin_id'] = paladin_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+ if create_paladin_context_source_info is not None:
+ _body_params = create_paladin_context_source_info
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/paladin/{paladin_id}/context-sources',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def delete_paladin(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> None:
+ """Delete Paladin
+
+ Deletes a Paladin, removing the underlying service user.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_paladin_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def delete_paladin_with_http_info(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[None]:
+ """Delete Paladin
+
+ Deletes a Paladin, removing the underlying service user.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_paladin_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def delete_paladin_without_preload_content(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Delete Paladin
+
+ Deletes a Paladin, removing the underlying service user.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_paladin_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _delete_paladin_serialize(
+ self,
+ paladin_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if paladin_id is not None:
+ _path_params['paladin_id'] = paladin_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='DELETE',
+ resource_path='/paladin/{paladin_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def delete_paladin_context_source(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ context_source_id: Annotated[UUID, Field(description="The ID of the context source.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> None:
+ """Remove a Paladin context source
+
+ Removes a context source from a Paladin.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param context_source_id: The ID of the context source. (required)
+ :type context_source_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_paladin_context_source_serialize(
+ paladin_id=paladin_id,
+ context_source_id=context_source_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def delete_paladin_context_source_with_http_info(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ context_source_id: Annotated[UUID, Field(description="The ID of the context source.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[None]:
+ """Remove a Paladin context source
+
+ Removes a context source from a Paladin.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param context_source_id: The ID of the context source. (required)
+ :type context_source_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_paladin_context_source_serialize(
+ paladin_id=paladin_id,
+ context_source_id=context_source_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def delete_paladin_context_source_without_preload_content(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ context_source_id: Annotated[UUID, Field(description="The ID of the context source.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Remove a Paladin context source
+
+ Removes a context source from a Paladin.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param context_source_id: The ID of the context source. (required)
+ :type context_source_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_paladin_context_source_serialize(
+ paladin_id=paladin_id,
+ context_source_id=context_source_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _delete_paladin_context_source_serialize(
+ self,
+ paladin_id,
+ context_source_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if paladin_id is not None:
+ _path_params['paladin_id'] = paladin_id
+ if context_source_id is not None:
+ _path_params['context_source_id'] = context_source_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='DELETE',
+ resource_path='/paladin/{paladin_id}/context-sources/{context_source_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_paladin(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Paladin:
+ """Get Paladin by ID
+
+ Returns a `Paladin` object.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_paladin_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_paladin_with_http_info(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Paladin]:
+ """Get Paladin by ID
+
+ Returns a `Paladin` object.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_paladin_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_paladin_without_preload_content(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Get Paladin by ID
+
+ Returns a `Paladin` object.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_paladin_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_paladin_serialize(
+ self,
+ paladin_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if paladin_id is not None:
+ _path_params['paladin_id'] = paladin_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/paladin/{paladin_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_paladin_from_name(
+ self,
+ paladin_name: Annotated[StrictStr, Field(description="The name of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaladinList:
+ """Get Paladins by name
+
+ Returns all Paladins whose name exactly matches the given name. Names are not unique, so the result is a list and may be empty.
+
+ :param paladin_name: The name of the Paladin. (required)
+ :type paladin_name: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_paladin_from_name_serialize(
+ paladin_name=paladin_name,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_paladin_from_name_with_http_info(
+ self,
+ paladin_name: Annotated[StrictStr, Field(description="The name of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaladinList]:
+ """Get Paladins by name
+
+ Returns all Paladins whose name exactly matches the given name. Names are not unique, so the result is a list and may be empty.
+
+ :param paladin_name: The name of the Paladin. (required)
+ :type paladin_name: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_paladin_from_name_serialize(
+ paladin_name=paladin_name,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_paladin_from_name_without_preload_content(
+ self,
+ paladin_name: Annotated[StrictStr, Field(description="The name of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Get Paladins by name
+
+ Returns all Paladins whose name exactly matches the given name. Names are not unique, so the result is a list and may be empty.
+
+ :param paladin_name: The name of the Paladin. (required)
+ :type paladin_name: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_paladin_from_name_serialize(
+ paladin_name=paladin_name,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_paladin_from_name_serialize(
+ self,
+ paladin_name,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if paladin_name is not None:
+ _path_params['paladin_name'] = paladin_name
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/paladin/name/{paladin_name}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def list_paladin_context_sources(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaladinContextSourceList:
+ """List Paladin context sources
+
+ Returns the context sources (Slack channels and documents) configured for a Paladin.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._list_paladin_context_sources_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinContextSourceList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def list_paladin_context_sources_with_http_info(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaladinContextSourceList]:
+ """List Paladin context sources
+
+ Returns the context sources (Slack channels and documents) configured for a Paladin.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._list_paladin_context_sources_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinContextSourceList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def list_paladin_context_sources_without_preload_content(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """List Paladin context sources
+
+ Returns the context sources (Slack channels and documents) configured for a Paladin.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._list_paladin_context_sources_serialize(
+ paladin_id=paladin_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaladinContextSourceList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _list_paladin_context_sources_serialize(
+ self,
+ paladin_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if paladin_id is not None:
+ _path_params['paladin_id'] = paladin_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/paladin/{paladin_id}/context-sources',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def update_paladin(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ update_paladin_info: UpdatePaladinInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Paladin:
+ """Update Paladin
+
+ Updates a `Paladin` object.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param update_paladin_info: (required)
+ :type update_paladin_info: UpdatePaladinInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_paladin_serialize(
+ paladin_id=paladin_id,
+ update_paladin_info=update_paladin_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def update_paladin_with_http_info(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ update_paladin_info: UpdatePaladinInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Paladin]:
+ """Update Paladin
+
+ Updates a `Paladin` object.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param update_paladin_info: (required)
+ :type update_paladin_info: UpdatePaladinInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_paladin_serialize(
+ paladin_id=paladin_id,
+ update_paladin_info=update_paladin_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def update_paladin_without_preload_content(
+ self,
+ paladin_id: Annotated[UUID, Field(description="The ID of the Paladin.")],
+ update_paladin_info: UpdatePaladinInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Update Paladin
+
+ Updates a `Paladin` object.
+
+ :param paladin_id: The ID of the Paladin. (required)
+ :type paladin_id: UUID
+ :param update_paladin_info: (required)
+ :type update_paladin_info: UpdatePaladinInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_paladin_serialize(
+ paladin_id=paladin_id,
+ update_paladin_info=update_paladin_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Paladin",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _update_paladin_serialize(
+ self,
+ paladin_id,
+ update_paladin_info,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if paladin_id is not None:
+ _path_params['paladin_id'] = paladin_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+ if update_paladin_info is not None:
+ _body_params = update_paladin_info
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='PUT',
+ resource_path='/paladin/{paladin_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
diff --git a/opal_security/api/request_templates_api.py b/opal_security/api/request_templates_api.py
new file mode 100644
index 0000000..92e7a9d
--- /dev/null
+++ b/opal_security/api/request_templates_api.py
@@ -0,0 +1,1352 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+import warnings
+from pydantic import validate_call, Field, StrictFloat, StrictStr, StrictInt
+from typing import Any, Dict, List, Optional, Tuple, Union
+from typing_extensions import Annotated
+
+from pydantic import Field
+from typing_extensions import Annotated
+from uuid import UUID
+from opal_security.models.create_request_template_info import CreateRequestTemplateInfo
+from opal_security.models.paginated_request_template_list import PaginatedRequestTemplateList
+from opal_security.models.request_template import RequestTemplate
+from opal_security.models.update_request_template_info import UpdateRequestTemplateInfo
+
+from opal_security.api_client import ApiClient, RequestSerialized
+from opal_security.api_response import ApiResponse
+from opal_security.rest import RESTResponseType
+
+
+class RequestTemplatesApi:
+ """NOTE: This class is auto generated by OpenAPI Generator
+ Ref: https://openapi-generator.tech
+
+ Do not edit the class manually.
+ """
+
+ def __init__(self, api_client=None) -> None:
+ if api_client is None:
+ api_client = ApiClient.get_default()
+ self.api_client = api_client
+
+
+ @validate_call
+ def create_request_template(
+ self,
+ create_request_template_info: CreateRequestTemplateInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RequestTemplate:
+ """create_request_template
+
+ Creates a request template.
+
+ :param create_request_template_info: (required)
+ :type create_request_template_info: CreateRequestTemplateInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_request_template_serialize(
+ create_request_template_info=create_request_template_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def create_request_template_with_http_info(
+ self,
+ create_request_template_info: CreateRequestTemplateInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[RequestTemplate]:
+ """create_request_template
+
+ Creates a request template.
+
+ :param create_request_template_info: (required)
+ :type create_request_template_info: CreateRequestTemplateInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_request_template_serialize(
+ create_request_template_info=create_request_template_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def create_request_template_without_preload_content(
+ self,
+ create_request_template_info: CreateRequestTemplateInfo,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """create_request_template
+
+ Creates a request template.
+
+ :param create_request_template_info: (required)
+ :type create_request_template_info: CreateRequestTemplateInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._create_request_template_serialize(
+ create_request_template_info=create_request_template_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _create_request_template_serialize(
+ self,
+ create_request_template_info,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+ if create_request_template_info is not None:
+ _body_params = create_request_template_info
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/request-templates',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def delete_request_template(
+ self,
+ request_template_id: Annotated[UUID, Field(description="The ID of the request template.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> None:
+ """delete_request_template
+
+ Deletes a request template.
+
+ :param request_template_id: The ID of the request template. (required)
+ :type request_template_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_request_template_serialize(
+ request_template_id=request_template_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def delete_request_template_with_http_info(
+ self,
+ request_template_id: Annotated[UUID, Field(description="The ID of the request template.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[None]:
+ """delete_request_template
+
+ Deletes a request template.
+
+ :param request_template_id: The ID of the request template. (required)
+ :type request_template_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_request_template_serialize(
+ request_template_id=request_template_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def delete_request_template_without_preload_content(
+ self,
+ request_template_id: Annotated[UUID, Field(description="The ID of the request template.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """delete_request_template
+
+ Deletes a request template.
+
+ :param request_template_id: The ID of the request template. (required)
+ :type request_template_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_request_template_serialize(
+ request_template_id=request_template_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _delete_request_template_serialize(
+ self,
+ request_template_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if request_template_id is not None:
+ _path_params['request_template_id'] = request_template_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='DELETE',
+ resource_path='/request-templates/{request_template_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_request_template(
+ self,
+ request_template_id: Annotated[UUID, Field(description="The ID of the request template.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RequestTemplate:
+ """get_request_template
+
+ Returns a `RequestTemplate` object.
+
+ :param request_template_id: The ID of the request template. (required)
+ :type request_template_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_request_template_serialize(
+ request_template_id=request_template_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_request_template_with_http_info(
+ self,
+ request_template_id: Annotated[UUID, Field(description="The ID of the request template.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[RequestTemplate]:
+ """get_request_template
+
+ Returns a `RequestTemplate` object.
+
+ :param request_template_id: The ID of the request template. (required)
+ :type request_template_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_request_template_serialize(
+ request_template_id=request_template_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_request_template_without_preload_content(
+ self,
+ request_template_id: Annotated[UUID, Field(description="The ID of the request template.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """get_request_template
+
+ Returns a `RequestTemplate` object.
+
+ :param request_template_id: The ID of the request template. (required)
+ :type request_template_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_request_template_serialize(
+ request_template_id=request_template_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_request_template_serialize(
+ self,
+ request_template_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if request_template_id is not None:
+ _path_params['request_template_id'] = request_template_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/request-templates/{request_template_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_request_templates(
+ self,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaginatedRequestTemplateList:
+ """get_request_templates
+
+ Returns a list of `RequestTemplate` objects.
+
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_request_templates_serialize(
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedRequestTemplateList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_request_templates_with_http_info(
+ self,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaginatedRequestTemplateList]:
+ """get_request_templates
+
+ Returns a list of `RequestTemplate` objects.
+
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_request_templates_serialize(
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedRequestTemplateList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_request_templates_without_preload_content(
+ self,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """get_request_templates
+
+ Returns a list of `RequestTemplate` objects.
+
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_request_templates_serialize(
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedRequestTemplateList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_request_templates_serialize(
+ self,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/request-templates',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def update_request_template(
+ self,
+ update_request_template_info: Annotated[UpdateRequestTemplateInfo, Field(description="Request template to be updated")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RequestTemplate:
+ """update_request_template
+
+ Updates a request template.
+
+ :param update_request_template_info: Request template to be updated (required)
+ :type update_request_template_info: UpdateRequestTemplateInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_request_template_serialize(
+ update_request_template_info=update_request_template_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def update_request_template_with_http_info(
+ self,
+ update_request_template_info: Annotated[UpdateRequestTemplateInfo, Field(description="Request template to be updated")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[RequestTemplate]:
+ """update_request_template
+
+ Updates a request template.
+
+ :param update_request_template_info: Request template to be updated (required)
+ :type update_request_template_info: UpdateRequestTemplateInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_request_template_serialize(
+ update_request_template_info=update_request_template_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def update_request_template_without_preload_content(
+ self,
+ update_request_template_info: Annotated[UpdateRequestTemplateInfo, Field(description="Request template to be updated")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """update_request_template
+
+ Updates a request template.
+
+ :param update_request_template_info: Request template to be updated (required)
+ :type update_request_template_info: UpdateRequestTemplateInfo
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._update_request_template_serialize(
+ update_request_template_info=update_request_template_info,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RequestTemplate",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _update_request_template_serialize(
+ self,
+ update_request_template_info,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+ if update_request_template_info is not None:
+ _body_params = update_request_template_info
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='PUT',
+ resource_path='/request-templates',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
diff --git a/opal_security/api/requests_api.py b/opal_security/api/requests_api.py
index 4de25ad..5dbe18b 100644
--- a/opal_security/api/requests_api.py
+++ b/opal_security/api/requests_api.py
@@ -27,6 +27,7 @@
from opal_security.models.create_request_comment_request import CreateRequestCommentRequest
from opal_security.models.create_request_info import CreateRequestInfo
from opal_security.models.deny_request_request import DenyRequestRequest
+from opal_security.models.remind_request200_response import RemindRequest200Response
from opal_security.models.request import Request
from opal_security.models.request_comment_list import RequestCommentList
from opal_security.models.request_connection import RequestConnection
@@ -340,6 +341,276 @@ def _approve_request_serialize(
+ @validate_call
+ def cancel_request(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request to cancel.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> Request:
+ """Cancel request
+
+ Cancels a pending access request.
+
+ :param id: The ID of the request to cancel. (required)
+ :type id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._cancel_request_serialize(
+ id=id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Request",
+ '403': None,
+ '404': None,
+ '409': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def cancel_request_with_http_info(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request to cancel.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[Request]:
+ """Cancel request
+
+ Cancels a pending access request.
+
+ :param id: The ID of the request to cancel. (required)
+ :type id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._cancel_request_serialize(
+ id=id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Request",
+ '403': None,
+ '404': None,
+ '409': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def cancel_request_without_preload_content(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request to cancel.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Cancel request
+
+ Cancels a pending access request.
+
+ :param id: The ID of the request to cancel. (required)
+ :type id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._cancel_request_serialize(
+ id=id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "Request",
+ '403': None,
+ '404': None,
+ '409': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _cancel_request_serialize(
+ self,
+ id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if id is not None:
+ _path_params['id'] = id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/requests/{id}/cancel',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
@validate_call
def create_request(
self,
@@ -2479,3 +2750,558 @@ def _get_requests_relay_serialize(
)
+
+
+ @validate_call
+ def remind_request(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request whose reviewers should be reminded.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RemindRequest200Response:
+ """Send request reminder
+
+ Sends a reminder to all pending reviewers of the request.
+
+ :param id: The ID of the request whose reviewers should be reminded. (required)
+ :type id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._remind_request_serialize(
+ id=id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RemindRequest200Response",
+ '400': None,
+ '404': None,
+ '429': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def remind_request_with_http_info(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request whose reviewers should be reminded.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[RemindRequest200Response]:
+ """Send request reminder
+
+ Sends a reminder to all pending reviewers of the request.
+
+ :param id: The ID of the request whose reviewers should be reminded. (required)
+ :type id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._remind_request_serialize(
+ id=id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RemindRequest200Response",
+ '400': None,
+ '404': None,
+ '429': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def remind_request_without_preload_content(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request whose reviewers should be reminded.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Send request reminder
+
+ Sends a reminder to all pending reviewers of the request.
+
+ :param id: The ID of the request whose reviewers should be reminded. (required)
+ :type id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._remind_request_serialize(
+ id=id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RemindRequest200Response",
+ '400': None,
+ '404': None,
+ '429': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _remind_request_serialize(
+ self,
+ id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if id is not None:
+ _path_params['id'] = id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/requests/{id}/remind',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def remind_request_reviewer(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request whose reviewer should be reminded.")],
+ reviewer_id: Annotated[UUID, Field(description="The ID of the pending reviewer to remind.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RemindRequest200Response:
+ """Send reminder to a reviewer
+
+ Sends a reminder to one pending reviewer of the request.
+
+ :param id: The ID of the request whose reviewer should be reminded. (required)
+ :type id: UUID
+ :param reviewer_id: The ID of the pending reviewer to remind. (required)
+ :type reviewer_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._remind_request_reviewer_serialize(
+ id=id,
+ reviewer_id=reviewer_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RemindRequest200Response",
+ '400': None,
+ '404': None,
+ '429': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def remind_request_reviewer_with_http_info(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request whose reviewer should be reminded.")],
+ reviewer_id: Annotated[UUID, Field(description="The ID of the pending reviewer to remind.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[RemindRequest200Response]:
+ """Send reminder to a reviewer
+
+ Sends a reminder to one pending reviewer of the request.
+
+ :param id: The ID of the request whose reviewer should be reminded. (required)
+ :type id: UUID
+ :param reviewer_id: The ID of the pending reviewer to remind. (required)
+ :type reviewer_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._remind_request_reviewer_serialize(
+ id=id,
+ reviewer_id=reviewer_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RemindRequest200Response",
+ '400': None,
+ '404': None,
+ '429': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def remind_request_reviewer_without_preload_content(
+ self,
+ id: Annotated[UUID, Field(description="The ID of the request whose reviewer should be reminded.")],
+ reviewer_id: Annotated[UUID, Field(description="The ID of the pending reviewer to remind.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Send reminder to a reviewer
+
+ Sends a reminder to one pending reviewer of the request.
+
+ :param id: The ID of the request whose reviewer should be reminded. (required)
+ :type id: UUID
+ :param reviewer_id: The ID of the pending reviewer to remind. (required)
+ :type reviewer_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._remind_request_reviewer_serialize(
+ id=id,
+ reviewer_id=reviewer_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "RemindRequest200Response",
+ '400': None,
+ '404': None,
+ '429': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _remind_request_reviewer_serialize(
+ self,
+ id,
+ reviewer_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if id is not None:
+ _path_params['id'] = id
+ if reviewer_id is not None:
+ _path_params['reviewer_id'] = reviewer_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='POST',
+ resource_path='/requests/{id}/reviewers/{reviewer_id}/remind',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
diff --git a/opal_security/api/resources_api.py b/opal_security/api/resources_api.py
index 02aa00b..1bfb731 100644
--- a/opal_security/api/resources_api.py
+++ b/opal_security/api/resources_api.py
@@ -24,6 +24,7 @@
from opal_security.models.access_list import AccessList
from opal_security.models.add_resource_nhi_request import AddResourceNhiRequest
from opal_security.models.add_resource_user_request import AddResourceUserRequest
+from opal_security.models.create_resource_custom_access_level_info import CreateResourceCustomAccessLevelInfo
from opal_security.models.create_resource_info import CreateResourceInfo
from opal_security.models.get_resource_user200_response import GetResourceUser200Response
from opal_security.models.group_resource_list import GroupResourceList
@@ -31,7 +32,10 @@
from opal_security.models.message_channel_list import MessageChannelList
from opal_security.models.paginated_resources_list import PaginatedResourcesList
from opal_security.models.resource import Resource
+from opal_security.models.resource_access_level_list import ResourceAccessLevelList
from opal_security.models.resource_access_user_list import ResourceAccessUserList
+from opal_security.models.resource_custom_access_level_list import ResourceCustomAccessLevelList
+from opal_security.models.resource_custom_access_level_response import ResourceCustomAccessLevelResponse
from opal_security.models.resource_nhi import ResourceNHI
from opal_security.models.resource_type_enum import ResourceTypeEnum
from opal_security.models.resource_user import ResourceUser
@@ -41,6 +45,7 @@
from opal_security.models.reviewer_stage_list import ReviewerStageList
from opal_security.models.scoped_role_permission_list import ScopedRolePermissionList
from opal_security.models.tags_list import TagsList
+from opal_security.models.update_resource_custom_access_level_info import UpdateResourceCustomAccessLevelInfo
from opal_security.models.update_resource_info_list import UpdateResourceInfoList
from opal_security.models.update_resource_user_request import UpdateResourceUserRequest
from opal_security.models.visibility_info import VisibilityInfo
@@ -372,7 +377,7 @@ def add_resource_user(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
user_id: Annotated[UUID, Field(description="The ID of the user to add.")],
- duration_minutes: Annotated[Optional[Annotated[int, Field(le=525960, strict=True)]], Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
+ duration_minutes: Annotated[Optional[Annotated[int, Field(le=153722867, strict=True)]], Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level to grant to this user. If omitted, the default access level remote ID value (empty string) is used.")] = None,
add_resource_user_request: Optional[AddResourceUserRequest] = None,
_request_timeout: Union[
@@ -455,7 +460,7 @@ def add_resource_user_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
user_id: Annotated[UUID, Field(description="The ID of the user to add.")],
- duration_minutes: Annotated[Optional[Annotated[int, Field(le=525960, strict=True)]], Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
+ duration_minutes: Annotated[Optional[Annotated[int, Field(le=153722867, strict=True)]], Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level to grant to this user. If omitted, the default access level remote ID value (empty string) is used.")] = None,
add_resource_user_request: Optional[AddResourceUserRequest] = None,
_request_timeout: Union[
@@ -538,7 +543,7 @@ def add_resource_user_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
user_id: Annotated[UUID, Field(description="The ID of the user to add.")],
- duration_minutes: Annotated[Optional[Annotated[int, Field(le=525960, strict=True)]], Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
+ duration_minutes: Annotated[Optional[Annotated[int, Field(le=153722867, strict=True)]], Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")] = None,
access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level to grant to this user. If omitted, the default access level remote ID value (empty string) is used.")] = None,
add_resource_user_request: Optional[AddResourceUserRequest] = None,
_request_timeout: Union[
@@ -980,9 +985,10 @@ def _create_resource_serialize(
@validate_call
- def delete_resource(
+ def create_resource_custom_access_level(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ create_resource_custom_access_level_info: CreateResourceCustomAccessLevelInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -995,13 +1001,15 @@ def delete_resource(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> None:
- """delete_resource
+ ) -> ResourceCustomAccessLevelResponse:
+ """create_resource_custom_access_level
- Deletes a resource.
+ Creates a custom access level on a resource. If the resource is a parent type, the role is created on all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param create_resource_custom_access_level_info: (required)
+ :type create_resource_custom_access_level_info: CreateResourceCustomAccessLevelInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1024,8 +1032,9 @@ def delete_resource(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_serialize(
+ _param = self._create_resource_custom_access_level_serialize(
resource_id=resource_id,
+ create_resource_custom_access_level_info=create_resource_custom_access_level_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1033,7 +1042,10 @@ def delete_resource(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': None,
+ '200': "ResourceCustomAccessLevelResponse",
+ '400': None,
+ '404': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -1047,9 +1059,10 @@ def delete_resource(
@validate_call
- def delete_resource_with_http_info(
+ def create_resource_custom_access_level_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ create_resource_custom_access_level_info: CreateResourceCustomAccessLevelInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1062,13 +1075,15 @@ def delete_resource_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[None]:
- """delete_resource
+ ) -> ApiResponse[ResourceCustomAccessLevelResponse]:
+ """create_resource_custom_access_level
- Deletes a resource.
+ Creates a custom access level on a resource. If the resource is a parent type, the role is created on all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param create_resource_custom_access_level_info: (required)
+ :type create_resource_custom_access_level_info: CreateResourceCustomAccessLevelInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1091,8 +1106,9 @@ def delete_resource_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_serialize(
+ _param = self._create_resource_custom_access_level_serialize(
resource_id=resource_id,
+ create_resource_custom_access_level_info=create_resource_custom_access_level_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1100,7 +1116,10 @@ def delete_resource_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': None,
+ '200': "ResourceCustomAccessLevelResponse",
+ '400': None,
+ '404': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -1114,9 +1133,10 @@ def delete_resource_with_http_info(
@validate_call
- def delete_resource_without_preload_content(
+ def create_resource_custom_access_level_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ create_resource_custom_access_level_info: CreateResourceCustomAccessLevelInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1130,12 +1150,14 @@ def delete_resource_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """delete_resource
+ """create_resource_custom_access_level
- Deletes a resource.
+ Creates a custom access level on a resource. If the resource is a parent type, the role is created on all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param create_resource_custom_access_level_info: (required)
+ :type create_resource_custom_access_level_info: CreateResourceCustomAccessLevelInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1158,8 +1180,9 @@ def delete_resource_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_serialize(
+ _param = self._create_resource_custom_access_level_serialize(
resource_id=resource_id,
+ create_resource_custom_access_level_info=create_resource_custom_access_level_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1167,7 +1190,10 @@ def delete_resource_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': None,
+ '200': "ResourceCustomAccessLevelResponse",
+ '400': None,
+ '404': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -1176,9 +1202,10 @@ def delete_resource_without_preload_content(
return response_data.response
- def _delete_resource_serialize(
+ def _create_resource_custom_access_level_serialize(
self,
resource_id,
+ create_resource_custom_access_level_info,
_request_auth,
_content_type,
_headers,
@@ -1206,9 +1233,31 @@ def _delete_resource_serialize(
# process the header parameters
# process the form parameters
# process the body parameter
+ if create_resource_custom_access_level_info is not None:
+ _body_params = create_resource_custom_access_level_info
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
# authentication setting
_auth_settings: List[str] = [
@@ -1216,8 +1265,8 @@ def _delete_resource_serialize(
]
return self.api_client.param_serialize(
- method='DELETE',
- resource_path='/resources/{resource_id}',
+ method='POST',
+ resource_path='/resources/{resource_id}/custom-access-levels',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -1234,11 +1283,9 @@ def _delete_resource_serialize(
@validate_call
- def delete_resource_nhi(
+ def delete_resource(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- non_human_identity_id: Annotated[UUID, Field(description="The resource ID of the non-human identity to remove from this resource.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1252,16 +1299,12 @@ def delete_resource_nhi(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> None:
- """delete_resource_nhi
+ """delete_resource
- Removes a non-human identity's direct access from this resource.
+ Deletes a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param non_human_identity_id: The resource ID of the non-human identity to remove from this resource. (required)
- :type non_human_identity_id: UUID
- :param access_level_remote_id: The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
- :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1284,10 +1327,8 @@ def delete_resource_nhi(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_nhi_serialize(
+ _param = self._delete_resource_serialize(
resource_id=resource_id,
- non_human_identity_id=non_human_identity_id,
- access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1309,11 +1350,9 @@ def delete_resource_nhi(
@validate_call
- def delete_resource_nhi_with_http_info(
+ def delete_resource_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- non_human_identity_id: Annotated[UUID, Field(description="The resource ID of the non-human identity to remove from this resource.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1327,16 +1366,12 @@ def delete_resource_nhi_with_http_info(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> ApiResponse[None]:
- """delete_resource_nhi
+ """delete_resource
- Removes a non-human identity's direct access from this resource.
+ Deletes a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param non_human_identity_id: The resource ID of the non-human identity to remove from this resource. (required)
- :type non_human_identity_id: UUID
- :param access_level_remote_id: The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
- :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1359,10 +1394,8 @@ def delete_resource_nhi_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_nhi_serialize(
+ _param = self._delete_resource_serialize(
resource_id=resource_id,
- non_human_identity_id=non_human_identity_id,
- access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1384,11 +1417,9 @@ def delete_resource_nhi_with_http_info(
@validate_call
- def delete_resource_nhi_without_preload_content(
+ def delete_resource_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- non_human_identity_id: Annotated[UUID, Field(description="The resource ID of the non-human identity to remove from this resource.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1402,16 +1433,12 @@ def delete_resource_nhi_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """delete_resource_nhi
+ """delete_resource
- Removes a non-human identity's direct access from this resource.
+ Deletes a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param non_human_identity_id: The resource ID of the non-human identity to remove from this resource. (required)
- :type non_human_identity_id: UUID
- :param access_level_remote_id: The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
- :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1434,10 +1461,8 @@ def delete_resource_nhi_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_nhi_serialize(
+ _param = self._delete_resource_serialize(
resource_id=resource_id,
- non_human_identity_id=non_human_identity_id,
- access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1454,11 +1479,9 @@ def delete_resource_nhi_without_preload_content(
return response_data.response
- def _delete_resource_nhi_serialize(
+ def _delete_resource_serialize(
self,
resource_id,
- non_human_identity_id,
- access_level_remote_id,
_request_auth,
_content_type,
_headers,
@@ -1482,13 +1505,7 @@ def _delete_resource_nhi_serialize(
# process the path parameters
if resource_id is not None:
_path_params['resource_id'] = resource_id
- if non_human_identity_id is not None:
- _path_params['non_human_identity_id'] = non_human_identity_id
# process the query parameters
- if access_level_remote_id is not None:
-
- _query_params.append(('access_level_remote_id', access_level_remote_id))
-
# process the header parameters
# process the form parameters
# process the body parameter
@@ -1503,7 +1520,7 @@ def _delete_resource_nhi_serialize(
return self.api_client.param_serialize(
method='DELETE',
- resource_path='/resources/{resource_id}/non-human-identities/{non_human_identity_id}',
+ resource_path='/resources/{resource_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -1520,11 +1537,10 @@ def _delete_resource_nhi_serialize(
@validate_call
- def delete_resource_user(
+ def delete_resource_custom_access_level(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of a user to remove from this resource.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
+ access_level_remote_id: Annotated[StrictStr, Field(description="The remote ID of the access level.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1538,15 +1554,13 @@ def delete_resource_user(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> None:
- """delete_resource_user
+ """delete_resource_custom_access_level
- Removes a user's direct access from this resource.
+ Deletes a custom access level identified by its remote ID. If the resource is a parent type, the deletion fans out to all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of a user to remove from this resource. (required)
- :type user_id: UUID
- :param access_level_remote_id: The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :param access_level_remote_id: The remote ID of the access level. (required)
:type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -1570,9 +1584,8 @@ def delete_resource_user(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_user_serialize(
+ _param = self._delete_resource_custom_access_level_serialize(
resource_id=resource_id,
- user_id=user_id,
access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -1582,6 +1595,8 @@ def delete_resource_user(
_response_types_map: Dict[str, Optional[str]] = {
'200': None,
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -1595,11 +1610,10 @@ def delete_resource_user(
@validate_call
- def delete_resource_user_with_http_info(
+ def delete_resource_custom_access_level_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of a user to remove from this resource.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
+ access_level_remote_id: Annotated[StrictStr, Field(description="The remote ID of the access level.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1613,15 +1627,13 @@ def delete_resource_user_with_http_info(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> ApiResponse[None]:
- """delete_resource_user
+ """delete_resource_custom_access_level
- Removes a user's direct access from this resource.
+ Deletes a custom access level identified by its remote ID. If the resource is a parent type, the deletion fans out to all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of a user to remove from this resource. (required)
- :type user_id: UUID
- :param access_level_remote_id: The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :param access_level_remote_id: The remote ID of the access level. (required)
:type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -1645,9 +1657,8 @@ def delete_resource_user_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_user_serialize(
+ _param = self._delete_resource_custom_access_level_serialize(
resource_id=resource_id,
- user_id=user_id,
access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -1657,6 +1668,8 @@ def delete_resource_user_with_http_info(
_response_types_map: Dict[str, Optional[str]] = {
'200': None,
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -1670,11 +1683,10 @@ def delete_resource_user_with_http_info(
@validate_call
- def delete_resource_user_without_preload_content(
+ def delete_resource_custom_access_level_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of a user to remove from this resource.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
+ access_level_remote_id: Annotated[StrictStr, Field(description="The remote ID of the access level.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1688,15 +1700,13 @@ def delete_resource_user_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """delete_resource_user
+ """delete_resource_custom_access_level
- Removes a user's direct access from this resource.
+ Deletes a custom access level identified by its remote ID. If the resource is a parent type, the deletion fans out to all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of a user to remove from this resource. (required)
- :type user_id: UUID
- :param access_level_remote_id: The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :param access_level_remote_id: The remote ID of the access level. (required)
:type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -1720,9 +1730,8 @@ def delete_resource_user_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._delete_resource_user_serialize(
+ _param = self._delete_resource_custom_access_level_serialize(
resource_id=resource_id,
- user_id=user_id,
access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -1732,6 +1741,8 @@ def delete_resource_user_without_preload_content(
_response_types_map: Dict[str, Optional[str]] = {
'200': None,
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -1740,10 +1751,9 @@ def delete_resource_user_without_preload_content(
return response_data.response
- def _delete_resource_user_serialize(
+ def _delete_resource_custom_access_level_serialize(
self,
resource_id,
- user_id,
access_level_remote_id,
_request_auth,
_content_type,
@@ -1768,13 +1778,9 @@ def _delete_resource_user_serialize(
# process the path parameters
if resource_id is not None:
_path_params['resource_id'] = resource_id
- if user_id is not None:
- _path_params['user_id'] = user_id
- # process the query parameters
if access_level_remote_id is not None:
-
- _query_params.append(('access_level_remote_id', access_level_remote_id))
-
+ _path_params['access_level_remote_id'] = access_level_remote_id
+ # process the query parameters
# process the header parameters
# process the form parameters
# process the body parameter
@@ -1789,7 +1795,7 @@ def _delete_resource_user_serialize(
return self.api_client.param_serialize(
method='DELETE',
- resource_path='/resources/{resource_id}/users/{user_id}',
+ resource_path='/resources/{resource_id}/custom-access-levels/{access_level_remote_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -1806,9 +1812,11 @@ def _delete_resource_user_serialize(
@validate_call
- def get_resource(
+ def delete_resource_nhi(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ non_human_identity_id: Annotated[UUID, Field(description="The resource ID of the non-human identity to remove from this resource.")],
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1821,13 +1829,17 @@ def get_resource(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> Resource:
- """Get resource by ID
+ ) -> None:
+ """delete_resource_nhi
- Retrieves a resource.
+ Removes a non-human identity's direct access from this resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param non_human_identity_id: The resource ID of the non-human identity to remove from this resource. (required)
+ :type non_human_identity_id: UUID
+ :param access_level_remote_id: The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1850,8 +1862,10 @@ def get_resource(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_serialize(
+ _param = self._delete_resource_nhi_serialize(
resource_id=resource_id,
+ non_human_identity_id=non_human_identity_id,
+ access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1859,7 +1873,7 @@ def get_resource(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "Resource",
+ '200': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -1873,9 +1887,11 @@ def get_resource(
@validate_call
- def get_resource_with_http_info(
+ def delete_resource_nhi_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ non_human_identity_id: Annotated[UUID, Field(description="The resource ID of the non-human identity to remove from this resource.")],
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1888,13 +1904,17 @@ def get_resource_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[Resource]:
- """Get resource by ID
+ ) -> ApiResponse[None]:
+ """delete_resource_nhi
- Retrieves a resource.
+ Removes a non-human identity's direct access from this resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param non_human_identity_id: The resource ID of the non-human identity to remove from this resource. (required)
+ :type non_human_identity_id: UUID
+ :param access_level_remote_id: The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1917,8 +1937,10 @@ def get_resource_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_serialize(
+ _param = self._delete_resource_nhi_serialize(
resource_id=resource_id,
+ non_human_identity_id=non_human_identity_id,
+ access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1926,7 +1948,7 @@ def get_resource_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "Resource",
+ '200': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -1940,9 +1962,11 @@ def get_resource_with_http_info(
@validate_call
- def get_resource_without_preload_content(
+ def delete_resource_nhi_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ non_human_identity_id: Annotated[UUID, Field(description="The resource ID of the non-human identity to remove from this resource.")],
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -1956,12 +1980,16 @@ def get_resource_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """Get resource by ID
+ """delete_resource_nhi
- Retrieves a resource.
+ Removes a non-human identity's direct access from this resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param non_human_identity_id: The resource ID of the non-human identity to remove from this resource. (required)
+ :type non_human_identity_id: UUID
+ :param access_level_remote_id: The remote ID of the access level for which this non-human identity has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -1984,8 +2012,10 @@ def get_resource_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_serialize(
+ _param = self._delete_resource_nhi_serialize(
resource_id=resource_id,
+ non_human_identity_id=non_human_identity_id,
+ access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -1993,7 +2023,7 @@ def get_resource_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "Resource",
+ '200': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -2002,9 +2032,11 @@ def get_resource_without_preload_content(
return response_data.response
- def _get_resource_serialize(
+ def _delete_resource_nhi_serialize(
self,
resource_id,
+ non_human_identity_id,
+ access_level_remote_id,
_request_auth,
_content_type,
_headers,
@@ -2028,19 +2060,18 @@ def _get_resource_serialize(
# process the path parameters
if resource_id is not None:
_path_params['resource_id'] = resource_id
+ if non_human_identity_id is not None:
+ _path_params['non_human_identity_id'] = non_human_identity_id
# process the query parameters
+ if access_level_remote_id is not None:
+
+ _query_params.append(('access_level_remote_id', access_level_remote_id))
+
# process the header parameters
# process the form parameters
# process the body parameter
- # set the HTTP header `Accept`
- if 'Accept' not in _header_params:
- _header_params['Accept'] = self.api_client.select_header_accept(
- [
- 'application/json'
- ]
- )
# authentication setting
@@ -2049,8 +2080,8 @@ def _get_resource_serialize(
]
return self.api_client.param_serialize(
- method='GET',
- resource_path='/resources/{resource_id}',
+ method='DELETE',
+ resource_path='/resources/{resource_id}/non-human-identities/{non_human_identity_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -2067,9 +2098,11 @@ def _get_resource_serialize(
@validate_call
- def get_resource_groups(
+ def delete_resource_user(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource that the groups grant access to.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ user_id: Annotated[UUID, Field(description="The ID of a user to remove from this resource.")],
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -2082,13 +2115,17 @@ def get_resource_groups(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> GroupResourceList:
- """get_resource_groups
+ ) -> None:
+ """delete_resource_user
- Returns a list of groups that grant access to the resource
+ Removes a user's direct access from this resource.
- :param resource_id: The ID of the resource that the groups grant access to. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param user_id: The ID of a user to remove from this resource. (required)
+ :type user_id: UUID
+ :param access_level_remote_id: The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -2111,8 +2148,10 @@ def get_resource_groups(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_groups_serialize(
+ _param = self._delete_resource_user_serialize(
resource_id=resource_id,
+ user_id=user_id,
+ access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -2120,7 +2159,7 @@ def get_resource_groups(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "GroupResourceList",
+ '200': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -2134,9 +2173,11 @@ def get_resource_groups(
@validate_call
- def get_resource_groups_with_http_info(
+ def delete_resource_user_with_http_info(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource that the groups grant access to.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ user_id: Annotated[UUID, Field(description="The ID of a user to remove from this resource.")],
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -2149,13 +2190,17 @@ def get_resource_groups_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[GroupResourceList]:
- """get_resource_groups
+ ) -> ApiResponse[None]:
+ """delete_resource_user
- Returns a list of groups that grant access to the resource
+ Removes a user's direct access from this resource.
- :param resource_id: The ID of the resource that the groups grant access to. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param user_id: The ID of a user to remove from this resource. (required)
+ :type user_id: UUID
+ :param access_level_remote_id: The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -2178,8 +2223,10 @@ def get_resource_groups_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_groups_serialize(
+ _param = self._delete_resource_user_serialize(
resource_id=resource_id,
+ user_id=user_id,
+ access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -2187,7 +2234,7 @@ def get_resource_groups_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "GroupResourceList",
+ '200': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -2201,9 +2248,11 @@ def get_resource_groups_with_http_info(
@validate_call
- def get_resource_groups_without_preload_content(
+ def delete_resource_user_without_preload_content(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource that the groups grant access to.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ user_id: Annotated[UUID, Field(description="The ID of a user to remove from this resource.")],
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -2217,12 +2266,16 @@ def get_resource_groups_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_resource_groups
+ """delete_resource_user
- Returns a list of groups that grant access to the resource
+ Removes a user's direct access from this resource.
- :param resource_id: The ID of the resource that the groups grant access to. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param user_id: The ID of a user to remove from this resource. (required)
+ :type user_id: UUID
+ :param access_level_remote_id: The remote ID of the access level for which this user has direct access. If omitted, the default access level remote ID value (empty string) is assumed.
+ :type access_level_remote_id: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -2245,8 +2298,10 @@ def get_resource_groups_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_groups_serialize(
+ _param = self._delete_resource_user_serialize(
resource_id=resource_id,
+ user_id=user_id,
+ access_level_remote_id=access_level_remote_id,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -2254,7 +2309,7 @@ def get_resource_groups_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "GroupResourceList",
+ '200': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -2263,9 +2318,11 @@ def get_resource_groups_without_preload_content(
return response_data.response
- def _get_resource_groups_serialize(
+ def _delete_resource_user_serialize(
self,
resource_id,
+ user_id,
+ access_level_remote_id,
_request_auth,
_content_type,
_headers,
@@ -2289,19 +2346,18 @@ def _get_resource_groups_serialize(
# process the path parameters
if resource_id is not None:
_path_params['resource_id'] = resource_id
+ if user_id is not None:
+ _path_params['user_id'] = user_id
# process the query parameters
+ if access_level_remote_id is not None:
+
+ _query_params.append(('access_level_remote_id', access_level_remote_id))
+
# process the header parameters
# process the form parameters
# process the body parameter
- # set the HTTP header `Accept`
- if 'Accept' not in _header_params:
- _header_params['Accept'] = self.api_client.select_header_accept(
- [
- 'application/json'
- ]
- )
# authentication setting
@@ -2310,8 +2366,8 @@ def _get_resource_groups_serialize(
]
return self.api_client.param_serialize(
- method='GET',
- resource_path='/resources/{resource_id}/groups',
+ method='DELETE',
+ resource_path='/resources/{resource_id}/users/{user_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -2328,7 +2384,7 @@ def _get_resource_groups_serialize(
@validate_call
- def get_resource_message_channels(
+ def get_resource(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
@@ -2343,10 +2399,10 @@ def get_resource_message_channels(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> MessageChannelList:
- """get_resource_message_channels
+ ) -> Resource:
+ """Get resource by ID
- Gets the list of audit message channels attached to a resource.
+ Retrieves a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
@@ -2372,7 +2428,7 @@ def get_resource_message_channels(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_message_channels_serialize(
+ _param = self._get_resource_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -2381,7 +2437,7 @@ def get_resource_message_channels(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "MessageChannelList",
+ '200': "Resource",
}
response_data = self.api_client.call_api(
*_param,
@@ -2395,7 +2451,7 @@ def get_resource_message_channels(
@validate_call
- def get_resource_message_channels_with_http_info(
+ def get_resource_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
@@ -2410,10 +2466,10 @@ def get_resource_message_channels_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[MessageChannelList]:
- """get_resource_message_channels
+ ) -> ApiResponse[Resource]:
+ """Get resource by ID
- Gets the list of audit message channels attached to a resource.
+ Retrieves a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
@@ -2439,7 +2495,7 @@ def get_resource_message_channels_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_message_channels_serialize(
+ _param = self._get_resource_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -2448,7 +2504,7 @@ def get_resource_message_channels_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "MessageChannelList",
+ '200': "Resource",
}
response_data = self.api_client.call_api(
*_param,
@@ -2462,7 +2518,7 @@ def get_resource_message_channels_with_http_info(
@validate_call
- def get_resource_message_channels_without_preload_content(
+ def get_resource_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
@@ -2478,9 +2534,9 @@ def get_resource_message_channels_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_resource_message_channels
+ """Get resource by ID
- Gets the list of audit message channels attached to a resource.
+ Retrieves a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
@@ -2506,7 +2562,7 @@ def get_resource_message_channels_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_message_channels_serialize(
+ _param = self._get_resource_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -2515,7 +2571,7 @@ def get_resource_message_channels_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "MessageChannelList",
+ '200': "Resource",
}
response_data = self.api_client.call_api(
*_param,
@@ -2524,7 +2580,7 @@ def get_resource_message_channels_without_preload_content(
return response_data.response
- def _get_resource_message_channels_serialize(
+ def _get_resource_serialize(
self,
resource_id,
_request_auth,
@@ -2572,7 +2628,7 @@ def _get_resource_message_channels_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/message-channels',
+ resource_path='/resources/{resource_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -2589,10 +2645,9 @@ def _get_resource_message_channels_serialize(
@validate_call
- def get_resource_nhis(
+ def get_resource_access_levels(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose access levels to return.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -2605,15 +2660,13 @@ def get_resource_nhis(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> AccessList:
- """get_resource_nhis
+ ) -> ResourceAccessLevelList:
+ """Get resource access levels
- Gets the list of non-human identities with access to this resource.
+ Returns the list of access levels defined for the resource. Resources that only offer default (unnamed) access return an empty list.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose access levels to return. (required)
:type resource_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -2636,9 +2689,8 @@ def get_resource_nhis(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_nhis_serialize(
+ _param = self._get_resource_access_levels_serialize(
resource_id=resource_id,
- limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -2646,7 +2698,8 @@ def get_resource_nhis(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "AccessList",
+ '200': "ResourceAccessLevelList",
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -2660,10 +2713,9 @@ def get_resource_nhis(
@validate_call
- def get_resource_nhis_with_http_info(
+ def get_resource_access_levels_with_http_info(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose access levels to return.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -2676,15 +2728,13 @@ def get_resource_nhis_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[AccessList]:
- """get_resource_nhis
+ ) -> ApiResponse[ResourceAccessLevelList]:
+ """Get resource access levels
- Gets the list of non-human identities with access to this resource.
+ Returns the list of access levels defined for the resource. Resources that only offer default (unnamed) access return an empty list.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose access levels to return. (required)
:type resource_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -2707,9 +2757,8 @@ def get_resource_nhis_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_nhis_serialize(
+ _param = self._get_resource_access_levels_serialize(
resource_id=resource_id,
- limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -2717,7 +2766,8 @@ def get_resource_nhis_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "AccessList",
+ '200': "ResourceAccessLevelList",
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -2731,10 +2781,9 @@ def get_resource_nhis_with_http_info(
@validate_call
- def get_resource_nhis_without_preload_content(
+ def get_resource_access_levels_without_preload_content(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose access levels to return.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -2748,14 +2797,12 @@ def get_resource_nhis_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_resource_nhis
+ """Get resource access levels
- Gets the list of non-human identities with access to this resource.
+ Returns the list of access levels defined for the resource. Resources that only offer default (unnamed) access return an empty list.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose access levels to return. (required)
:type resource_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -2778,9 +2825,8 @@ def get_resource_nhis_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_nhis_serialize(
+ _param = self._get_resource_access_levels_serialize(
resource_id=resource_id,
- limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -2788,7 +2834,8 @@ def get_resource_nhis_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "AccessList",
+ '200': "ResourceAccessLevelList",
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -2797,10 +2844,9 @@ def get_resource_nhis_without_preload_content(
return response_data.response
- def _get_resource_nhis_serialize(
+ def _get_resource_access_levels_serialize(
self,
resource_id,
- limit,
_request_auth,
_content_type,
_headers,
@@ -2825,10 +2871,6 @@ def _get_resource_nhis_serialize(
if resource_id is not None:
_path_params['resource_id'] = resource_id
# process the query parameters
- if limit is not None:
-
- _query_params.append(('limit', limit))
-
# process the header parameters
# process the form parameters
# process the body parameter
@@ -2850,7 +2892,7 @@ def _get_resource_nhis_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/non-human-identities',
+ resource_path='/resources/{resource_id}/access_levels',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -2867,7 +2909,7 @@ def _get_resource_nhis_serialize(
@validate_call
- def get_resource_reviewer_stages(
+ def get_resource_custom_access_levels(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
@@ -2882,10 +2924,10 @@ def get_resource_reviewer_stages(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> List[ReviewerStage]:
- """get_resource_reviewer_stages
+ ) -> ResourceCustomAccessLevelList:
+ """get_resource_custom_access_levels
- Gets the list reviewer stages for a resource.
+ Returns all custom access levels for a resource. If the resource is a parent type (e.g. GitHubOrg), returns aggregated roles across child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
@@ -2911,7 +2953,7 @@ def get_resource_reviewer_stages(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_reviewer_stages_serialize(
+ _param = self._get_resource_custom_access_levels_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -2920,7 +2962,9 @@ def get_resource_reviewer_stages(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[ReviewerStage]",
+ '200': "ResourceCustomAccessLevelList",
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -2934,7 +2978,7 @@ def get_resource_reviewer_stages(
@validate_call
- def get_resource_reviewer_stages_with_http_info(
+ def get_resource_custom_access_levels_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
@@ -2949,10 +2993,10 @@ def get_resource_reviewer_stages_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[List[ReviewerStage]]:
- """get_resource_reviewer_stages
+ ) -> ApiResponse[ResourceCustomAccessLevelList]:
+ """get_resource_custom_access_levels
- Gets the list reviewer stages for a resource.
+ Returns all custom access levels for a resource. If the resource is a parent type (e.g. GitHubOrg), returns aggregated roles across child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
@@ -2978,7 +3022,7 @@ def get_resource_reviewer_stages_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_reviewer_stages_serialize(
+ _param = self._get_resource_custom_access_levels_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -2987,7 +3031,9 @@ def get_resource_reviewer_stages_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[ReviewerStage]",
+ '200': "ResourceCustomAccessLevelList",
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -3001,7 +3047,7 @@ def get_resource_reviewer_stages_with_http_info(
@validate_call
- def get_resource_reviewer_stages_without_preload_content(
+ def get_resource_custom_access_levels_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
@@ -3017,9 +3063,9 @@ def get_resource_reviewer_stages_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_resource_reviewer_stages
+ """get_resource_custom_access_levels
- Gets the list reviewer stages for a resource.
+ Returns all custom access levels for a resource. If the resource is a parent type (e.g. GitHubOrg), returns aggregated roles across child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
@@ -3045,7 +3091,7 @@ def get_resource_reviewer_stages_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_reviewer_stages_serialize(
+ _param = self._get_resource_custom_access_levels_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -3054,7 +3100,9 @@ def get_resource_reviewer_stages_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[ReviewerStage]",
+ '200': "ResourceCustomAccessLevelList",
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -3063,7 +3111,7 @@ def get_resource_reviewer_stages_without_preload_content(
return response_data.response
- def _get_resource_reviewer_stages_serialize(
+ def _get_resource_custom_access_levels_serialize(
self,
resource_id,
_request_auth,
@@ -3111,7 +3159,7 @@ def _get_resource_reviewer_stages_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/reviewer-stages',
+ resource_path='/resources/{resource_id}/custom-access-levels',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -3128,9 +3176,9 @@ def _get_resource_reviewer_stages_serialize(
@validate_call
- def get_resource_reviewers(
+ def get_resource_groups(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource that the groups grant access to.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3143,12 +3191,12 @@ def get_resource_reviewers(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> List[UUID]:
- """get_resource_reviewers
+ ) -> GroupResourceList:
+ """get_resource_groups
- Gets the list of owner IDs of the reviewers for a resource.
+ Returns a list of groups that grant access to the resource
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource that the groups grant access to. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -3172,7 +3220,7 @@ def get_resource_reviewers(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_reviewers_serialize(
+ _param = self._get_resource_groups_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -3181,7 +3229,7 @@ def get_resource_reviewers(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "GroupResourceList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3195,9 +3243,9 @@ def get_resource_reviewers(
@validate_call
- def get_resource_reviewers_with_http_info(
+ def get_resource_groups_with_http_info(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource that the groups grant access to.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3210,12 +3258,12 @@ def get_resource_reviewers_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[List[UUID]]:
- """get_resource_reviewers
+ ) -> ApiResponse[GroupResourceList]:
+ """get_resource_groups
- Gets the list of owner IDs of the reviewers for a resource.
+ Returns a list of groups that grant access to the resource
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource that the groups grant access to. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -3239,7 +3287,7 @@ def get_resource_reviewers_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_reviewers_serialize(
+ _param = self._get_resource_groups_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -3248,7 +3296,7 @@ def get_resource_reviewers_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "GroupResourceList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3262,9 +3310,9 @@ def get_resource_reviewers_with_http_info(
@validate_call
- def get_resource_reviewers_without_preload_content(
+ def get_resource_groups_without_preload_content(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource that the groups grant access to.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3278,11 +3326,11 @@ def get_resource_reviewers_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_resource_reviewers
+ """get_resource_groups
- Gets the list of owner IDs of the reviewers for a resource.
+ Returns a list of groups that grant access to the resource
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource that the groups grant access to. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -3306,7 +3354,7 @@ def get_resource_reviewers_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_reviewers_serialize(
+ _param = self._get_resource_groups_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -3315,7 +3363,7 @@ def get_resource_reviewers_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "GroupResourceList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3324,7 +3372,7 @@ def get_resource_reviewers_without_preload_content(
return response_data.response
- def _get_resource_reviewers_serialize(
+ def _get_resource_groups_serialize(
self,
resource_id,
_request_auth,
@@ -3372,7 +3420,7 @@ def _get_resource_reviewers_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/reviewers',
+ resource_path='/resources/{resource_id}/groups',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -3389,9 +3437,9 @@ def _get_resource_reviewers_serialize(
@validate_call
- def get_resource_scoped_role_permissions(
+ def get_resource_message_channels(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3404,12 +3452,12 @@ def get_resource_scoped_role_permissions(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ScopedRolePermissionList:
- """get_resource_scoped_role_permissions
+ ) -> MessageChannelList:
+ """get_resource_message_channels
- Returns all the scoped role permissions that apply to the given resource. Only OPAL_SCOPED_ROLE resource type supports this field.
+ Gets the list of audit message channels attached to a resource.
- :param resource_id: The ID of the resource whose scoped role permissions belong to. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -3433,7 +3481,7 @@ def get_resource_scoped_role_permissions(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_scoped_role_permissions_serialize(
+ _param = self._get_resource_message_channels_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -3442,7 +3490,7 @@ def get_resource_scoped_role_permissions(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ScopedRolePermissionList",
+ '200': "MessageChannelList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3456,9 +3504,9 @@ def get_resource_scoped_role_permissions(
@validate_call
- def get_resource_scoped_role_permissions_with_http_info(
+ def get_resource_message_channels_with_http_info(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3471,12 +3519,12 @@ def get_resource_scoped_role_permissions_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[ScopedRolePermissionList]:
- """get_resource_scoped_role_permissions
+ ) -> ApiResponse[MessageChannelList]:
+ """get_resource_message_channels
- Returns all the scoped role permissions that apply to the given resource. Only OPAL_SCOPED_ROLE resource type supports this field.
+ Gets the list of audit message channels attached to a resource.
- :param resource_id: The ID of the resource whose scoped role permissions belong to. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -3500,7 +3548,7 @@ def get_resource_scoped_role_permissions_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_scoped_role_permissions_serialize(
+ _param = self._get_resource_message_channels_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -3509,7 +3557,7 @@ def get_resource_scoped_role_permissions_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ScopedRolePermissionList",
+ '200': "MessageChannelList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3523,9 +3571,9 @@ def get_resource_scoped_role_permissions_with_http_info(
@validate_call
- def get_resource_scoped_role_permissions_without_preload_content(
+ def get_resource_message_channels_without_preload_content(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3539,11 +3587,11 @@ def get_resource_scoped_role_permissions_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_resource_scoped_role_permissions
+ """get_resource_message_channels
- Returns all the scoped role permissions that apply to the given resource. Only OPAL_SCOPED_ROLE resource type supports this field.
+ Gets the list of audit message channels attached to a resource.
- :param resource_id: The ID of the resource whose scoped role permissions belong to. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -3567,7 +3615,7 @@ def get_resource_scoped_role_permissions_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_scoped_role_permissions_serialize(
+ _param = self._get_resource_message_channels_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -3576,7 +3624,7 @@ def get_resource_scoped_role_permissions_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ScopedRolePermissionList",
+ '200': "MessageChannelList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3585,7 +3633,7 @@ def get_resource_scoped_role_permissions_without_preload_content(
return response_data.response
- def _get_resource_scoped_role_permissions_serialize(
+ def _get_resource_message_channels_serialize(
self,
resource_id,
_request_auth,
@@ -3633,7 +3681,7 @@ def _get_resource_scoped_role_permissions_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/scoped-role-permissions',
+ resource_path='/resources/{resource_id}/message-channels',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -3650,9 +3698,10 @@ def _get_resource_scoped_role_permissions_serialize(
@validate_call
- def get_resource_tags(
+ def get_resource_nhis(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose tags to return.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3665,13 +3714,15 @@ def get_resource_tags(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> TagsList:
- """get_resource_tags
+ ) -> AccessList:
+ """get_resource_nhis
- Returns all tags applied to the resource.
+ Gets the list of non-human identities with access to this resource.
- :param resource_id: The ID of the resource whose tags to return. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -3694,8 +3745,9 @@ def get_resource_tags(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_tags_serialize(
+ _param = self._get_resource_nhis_serialize(
resource_id=resource_id,
+ limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -3703,7 +3755,7 @@ def get_resource_tags(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "TagsList",
+ '200': "AccessList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3717,9 +3769,10 @@ def get_resource_tags(
@validate_call
- def get_resource_tags_with_http_info(
+ def get_resource_nhis_with_http_info(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose tags to return.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3732,13 +3785,15 @@ def get_resource_tags_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[TagsList]:
- """get_resource_tags
+ ) -> ApiResponse[AccessList]:
+ """get_resource_nhis
- Returns all tags applied to the resource.
+ Gets the list of non-human identities with access to this resource.
- :param resource_id: The ID of the resource whose tags to return. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -3761,8 +3816,9 @@ def get_resource_tags_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_tags_serialize(
+ _param = self._get_resource_nhis_serialize(
resource_id=resource_id,
+ limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -3770,7 +3826,7 @@ def get_resource_tags_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "TagsList",
+ '200': "AccessList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3784,9 +3840,10 @@ def get_resource_tags_with_http_info(
@validate_call
- def get_resource_tags_without_preload_content(
+ def get_resource_nhis_without_preload_content(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose tags to return.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3800,12 +3857,14 @@ def get_resource_tags_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_resource_tags
+ """get_resource_nhis
- Returns all tags applied to the resource.
+ Gets the list of non-human identities with access to this resource.
- :param resource_id: The ID of the resource whose tags to return. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -3828,8 +3887,9 @@ def get_resource_tags_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_tags_serialize(
+ _param = self._get_resource_nhis_serialize(
resource_id=resource_id,
+ limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -3837,7 +3897,7 @@ def get_resource_tags_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "TagsList",
+ '200': "AccessList",
}
response_data = self.api_client.call_api(
*_param,
@@ -3846,9 +3906,10 @@ def get_resource_tags_without_preload_content(
return response_data.response
- def _get_resource_tags_serialize(
+ def _get_resource_nhis_serialize(
self,
resource_id,
+ limit,
_request_auth,
_content_type,
_headers,
@@ -3873,6 +3934,10 @@ def _get_resource_tags_serialize(
if resource_id is not None:
_path_params['resource_id'] = resource_id
# process the query parameters
+ if limit is not None:
+
+ _query_params.append(('limit', limit))
+
# process the header parameters
# process the form parameters
# process the body parameter
@@ -3894,7 +3959,7 @@ def _get_resource_tags_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/tags',
+ resource_path='/resources/{resource_id}/non-human-identities',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -3911,11 +3976,9 @@ def _get_resource_tags_serialize(
@validate_call
- def get_resource_user(
+ def get_resource_reviewer_stages(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of the user.")],
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -3928,17 +3991,13 @@ def get_resource_user(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> GetResourceUser200Response:
- """Get resource user
+ ) -> List[ReviewerStage]:
+ """get_resource_reviewer_stages
- Returns information about a specific user's access to a resource.
+ Gets the list reviewer stages for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of the user. (required)
- :type user_id: UUID
- :param cursor: The pagination cursor value.
- :type cursor: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -3961,10 +4020,8 @@ def get_resource_user(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_user_serialize(
+ _param = self._get_resource_reviewer_stages_serialize(
resource_id=resource_id,
- user_id=user_id,
- cursor=cursor,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -3972,8 +4029,7 @@ def get_resource_user(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "GetResourceUser200Response",
- '404': None,
+ '200': "List[ReviewerStage]",
}
response_data = self.api_client.call_api(
*_param,
@@ -3987,11 +4043,9 @@ def get_resource_user(
@validate_call
- def get_resource_user_with_http_info(
+ def get_resource_reviewer_stages_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of the user.")],
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4004,17 +4058,13 @@ def get_resource_user_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[GetResourceUser200Response]:
- """Get resource user
+ ) -> ApiResponse[List[ReviewerStage]]:
+ """get_resource_reviewer_stages
- Returns information about a specific user's access to a resource.
+ Gets the list reviewer stages for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of the user. (required)
- :type user_id: UUID
- :param cursor: The pagination cursor value.
- :type cursor: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -4037,10 +4087,8 @@ def get_resource_user_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_user_serialize(
+ _param = self._get_resource_reviewer_stages_serialize(
resource_id=resource_id,
- user_id=user_id,
- cursor=cursor,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -4048,8 +4096,7 @@ def get_resource_user_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "GetResourceUser200Response",
- '404': None,
+ '200': "List[ReviewerStage]",
}
response_data = self.api_client.call_api(
*_param,
@@ -4063,11 +4110,9 @@ def get_resource_user_with_http_info(
@validate_call
- def get_resource_user_without_preload_content(
+ def get_resource_reviewer_stages_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of the user.")],
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4081,16 +4126,12 @@ def get_resource_user_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """Get resource user
+ """get_resource_reviewer_stages
- Returns information about a specific user's access to a resource.
+ Gets the list reviewer stages for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of the user. (required)
- :type user_id: UUID
- :param cursor: The pagination cursor value.
- :type cursor: str
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -4113,10 +4154,8 @@ def get_resource_user_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_user_serialize(
+ _param = self._get_resource_reviewer_stages_serialize(
resource_id=resource_id,
- user_id=user_id,
- cursor=cursor,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -4124,8 +4163,7 @@ def get_resource_user_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "GetResourceUser200Response",
- '404': None,
+ '200': "List[ReviewerStage]",
}
response_data = self.api_client.call_api(
*_param,
@@ -4134,11 +4172,9 @@ def get_resource_user_without_preload_content(
return response_data.response
- def _get_resource_user_serialize(
+ def _get_resource_reviewer_stages_serialize(
self,
resource_id,
- user_id,
- cursor,
_request_auth,
_content_type,
_headers,
@@ -4162,13 +4198,7 @@ def _get_resource_user_serialize(
# process the path parameters
if resource_id is not None:
_path_params['resource_id'] = resource_id
- if user_id is not None:
- _path_params['user_id'] = user_id
# process the query parameters
- if cursor is not None:
-
- _query_params.append(('cursor', cursor))
-
# process the header parameters
# process the form parameters
# process the body parameter
@@ -4190,7 +4220,7 @@ def _get_resource_user_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/users/{user_id}',
+ resource_path='/resources/{resource_id}/reviewer-stages',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -4207,10 +4237,9 @@ def _get_resource_user_serialize(
@validate_call
- def get_resource_users(
+ def get_resource_reviewers(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4223,15 +4252,13 @@ def get_resource_users(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ResourceAccessUserList:
- """Get resource users
+ ) -> List[UUID]:
+ """get_resource_reviewers
- Gets the list of users for this resource.
+ Gets the list of owner IDs of the reviewers for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -4254,9 +4281,8 @@ def get_resource_users(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_users_serialize(
+ _param = self._get_resource_reviewers_serialize(
resource_id=resource_id,
- limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -4264,7 +4290,7 @@ def get_resource_users(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceAccessUserList",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -4278,10 +4304,9 @@ def get_resource_users(
@validate_call
- def get_resource_users_with_http_info(
+ def get_resource_reviewers_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4294,15 +4319,13 @@ def get_resource_users_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[ResourceAccessUserList]:
- """Get resource users
+ ) -> ApiResponse[List[UUID]]:
+ """get_resource_reviewers
- Gets the list of users for this resource.
+ Gets the list of owner IDs of the reviewers for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -4325,9 +4348,8 @@ def get_resource_users_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_users_serialize(
+ _param = self._get_resource_reviewers_serialize(
resource_id=resource_id,
- limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -4335,7 +4357,7 @@ def get_resource_users_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceAccessUserList",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -4349,10 +4371,9 @@ def get_resource_users_with_http_info(
@validate_call
- def get_resource_users_without_preload_content(
+ def get_resource_reviewers_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4366,14 +4387,12 @@ def get_resource_users_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """Get resource users
+ """get_resource_reviewers
- Gets the list of users for this resource.
+ Gets the list of owner IDs of the reviewers for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -4396,9 +4415,8 @@ def get_resource_users_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_users_serialize(
+ _param = self._get_resource_reviewers_serialize(
resource_id=resource_id,
- limit=limit,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -4406,7 +4424,7 @@ def get_resource_users_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceAccessUserList",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -4415,10 +4433,9 @@ def get_resource_users_without_preload_content(
return response_data.response
- def _get_resource_users_serialize(
+ def _get_resource_reviewers_serialize(
self,
resource_id,
- limit,
_request_auth,
_content_type,
_headers,
@@ -4443,10 +4460,6 @@ def _get_resource_users_serialize(
if resource_id is not None:
_path_params['resource_id'] = resource_id
# process the query parameters
- if limit is not None:
-
- _query_params.append(('limit', limit))
-
# process the header parameters
# process the form parameters
# process the body parameter
@@ -4468,7 +4481,7 @@ def _get_resource_users_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/users',
+ resource_path='/resources/{resource_id}/reviewers',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -4485,9 +4498,9 @@ def _get_resource_users_serialize(
@validate_call
- def get_resource_visibility(
+ def get_resource_scoped_role_permissions(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4500,12 +4513,12 @@ def get_resource_visibility(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> VisibilityInfo:
- """get_resource_visibility
+ ) -> ScopedRolePermissionList:
+ """get_resource_scoped_role_permissions
- Gets the visibility of this resource.
+ Returns all the scoped role permissions that apply to the given resource. Only OPAL_SCOPED_ROLE resource type supports this field.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose scoped role permissions belong to. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -4529,7 +4542,7 @@ def get_resource_visibility(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_visibility_serialize(
+ _param = self._get_resource_scoped_role_permissions_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -4538,7 +4551,7 @@ def get_resource_visibility(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "VisibilityInfo",
+ '200': "ScopedRolePermissionList",
}
response_data = self.api_client.call_api(
*_param,
@@ -4552,9 +4565,9 @@ def get_resource_visibility(
@validate_call
- def get_resource_visibility_with_http_info(
+ def get_resource_scoped_role_permissions_with_http_info(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4567,12 +4580,12 @@ def get_resource_visibility_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[VisibilityInfo]:
- """get_resource_visibility
+ ) -> ApiResponse[ScopedRolePermissionList]:
+ """get_resource_scoped_role_permissions
- Gets the visibility of this resource.
+ Returns all the scoped role permissions that apply to the given resource. Only OPAL_SCOPED_ROLE resource type supports this field.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose scoped role permissions belong to. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -4596,7 +4609,7 @@ def get_resource_visibility_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_visibility_serialize(
+ _param = self._get_resource_scoped_role_permissions_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -4605,7 +4618,7 @@ def get_resource_visibility_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "VisibilityInfo",
+ '200': "ScopedRolePermissionList",
}
response_data = self.api_client.call_api(
*_param,
@@ -4619,9 +4632,9 @@ def get_resource_visibility_with_http_info(
@validate_call
- def get_resource_visibility_without_preload_content(
+ def get_resource_scoped_role_permissions_without_preload_content(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to.")],
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4635,11 +4648,11 @@ def get_resource_visibility_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_resource_visibility
+ """get_resource_scoped_role_permissions
- Gets the visibility of this resource.
+ Returns all the scoped role permissions that apply to the given resource. Only OPAL_SCOPED_ROLE resource type supports this field.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose scoped role permissions belong to. (required)
:type resource_id: UUID
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
@@ -4663,7 +4676,7 @@ def get_resource_visibility_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resource_visibility_serialize(
+ _param = self._get_resource_scoped_role_permissions_serialize(
resource_id=resource_id,
_request_auth=_request_auth,
_content_type=_content_type,
@@ -4672,7 +4685,7 @@ def get_resource_visibility_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "VisibilityInfo",
+ '200': "ScopedRolePermissionList",
}
response_data = self.api_client.call_api(
*_param,
@@ -4681,7 +4694,7 @@ def get_resource_visibility_without_preload_content(
return response_data.response
- def _get_resource_visibility_serialize(
+ def _get_resource_scoped_role_permissions_serialize(
self,
resource_id,
_request_auth,
@@ -4729,7 +4742,7 @@ def _get_resource_visibility_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/{resource_id}/visibility',
+ resource_path='/resources/{resource_id}/scoped-role-permissions',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -4746,7 +4759,1304 @@ def _get_resource_visibility_serialize(
@validate_call
- def get_resources(
+ def get_resource_tags(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose tags to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> TagsList:
+ """get_resource_tags
+
+ Returns all tags applied to the resource.
+
+ :param resource_id: The ID of the resource whose tags to return. (required)
+ :type resource_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_tags_serialize(
+ resource_id=resource_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "TagsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_resource_tags_with_http_info(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose tags to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[TagsList]:
+ """get_resource_tags
+
+ Returns all tags applied to the resource.
+
+ :param resource_id: The ID of the resource whose tags to return. (required)
+ :type resource_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_tags_serialize(
+ resource_id=resource_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "TagsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_resource_tags_without_preload_content(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose tags to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """get_resource_tags
+
+ Returns all tags applied to the resource.
+
+ :param resource_id: The ID of the resource whose tags to return. (required)
+ :type resource_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_tags_serialize(
+ resource_id=resource_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "TagsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_resource_tags_serialize(
+ self,
+ resource_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if resource_id is not None:
+ _path_params['resource_id'] = resource_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/resources/{resource_id}/tags',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_resource_user(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ user_id: Annotated[UUID, Field(description="The ID of the user.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> GetResourceUser200Response:
+ """Get resource user
+
+ Returns information about a specific user's access to a resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param user_id: The ID of the user. (required)
+ :type user_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_user_serialize(
+ resource_id=resource_id,
+ user_id=user_id,
+ cursor=cursor,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "GetResourceUser200Response",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_resource_user_with_http_info(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ user_id: Annotated[UUID, Field(description="The ID of the user.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[GetResourceUser200Response]:
+ """Get resource user
+
+ Returns information about a specific user's access to a resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param user_id: The ID of the user. (required)
+ :type user_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_user_serialize(
+ resource_id=resource_id,
+ user_id=user_id,
+ cursor=cursor,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "GetResourceUser200Response",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_resource_user_without_preload_content(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ user_id: Annotated[UUID, Field(description="The ID of the user.")],
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Get resource user
+
+ Returns information about a specific user's access to a resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param user_id: The ID of the user. (required)
+ :type user_id: UUID
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_user_serialize(
+ resource_id=resource_id,
+ user_id=user_id,
+ cursor=cursor,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "GetResourceUser200Response",
+ '404': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_resource_user_serialize(
+ self,
+ resource_id,
+ user_id,
+ cursor,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if resource_id is not None:
+ _path_params['resource_id'] = resource_id
+ if user_id is not None:
+ _path_params['user_id'] = user_id
+ # process the query parameters
+ if cursor is not None:
+
+ _query_params.append(('cursor', cursor))
+
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/resources/{resource_id}/users/{user_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_resource_users(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ResourceAccessUserList:
+ """Get resource users
+
+ Gets the list of users for this resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_users_serialize(
+ resource_id=resource_id,
+ limit=limit,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "ResourceAccessUserList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_resource_users_with_http_info(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[ResourceAccessUserList]:
+ """Get resource users
+
+ Gets the list of users for this resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_users_serialize(
+ resource_id=resource_id,
+ limit=limit,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "ResourceAccessUserList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_resource_users_without_preload_content(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """Get resource users
+
+ Gets the list of users for this resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_users_serialize(
+ resource_id=resource_id,
+ limit=limit,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "ResourceAccessUserList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_resource_users_serialize(
+ self,
+ resource_id,
+ limit,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if resource_id is not None:
+ _path_params['resource_id'] = resource_id
+ # process the query parameters
+ if limit is not None:
+
+ _query_params.append(('limit', limit))
+
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/resources/{resource_id}/users',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_resource_visibility(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> VisibilityInfo:
+ """get_resource_visibility
+
+ Gets the visibility of this resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_visibility_serialize(
+ resource_id=resource_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "VisibilityInfo",
+ '403': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_resource_visibility_with_http_info(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[VisibilityInfo]:
+ """get_resource_visibility
+
+ Gets the visibility of this resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_visibility_serialize(
+ resource_id=resource_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "VisibilityInfo",
+ '403': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_resource_visibility_without_preload_content(
+ self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """get_resource_visibility
+
+ Gets the visibility of this resource.
+
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resource_visibility_serialize(
+ resource_id=resource_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "VisibilityInfo",
+ '403': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_resource_visibility_serialize(
+ self,
+ resource_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if resource_id is not None:
+ _path_params['resource_id'] = resource_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/resources/{resource_id}/visibility',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_resources(
+ self,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ resource_type_filter: Annotated[Optional[ResourceTypeEnum], Field(description="The resource type to filter by. Required when remote_id is provided.")] = None,
+ resource_ids: Annotated[Optional[List[UUID]], Field(description="The resource ids to filter by.")] = None,
+ resource_name: Annotated[Optional[StrictStr], Field(description="Resource name.")] = None,
+ parent_resource_id: Annotated[Optional[UUID], Field(description="The parent resource id to filter by.")] = None,
+ ancestor_resource_id: Annotated[Optional[UUID], Field(description="The ancestor resource id to filter by. Returns all resources that are descendants of the specified resource.")] = None,
+ remote_id: Annotated[Optional[StrictStr], Field(description="Filter resources by their remote id. This will return all resources that have a remote id that matches the provided remote id. Note that this requires resource_type_filter to be provided.")] = None,
+ tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only resources that have any of these tags applied.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaginatedResourcesList:
+ """Get resources
+
+ Returns a list of resources for your organization.
+
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
+ :param resource_type_filter: The resource type to filter by. Required when remote_id is provided.
+ :type resource_type_filter: ResourceTypeEnum
+ :param resource_ids: The resource ids to filter by.
+ :type resource_ids: List[UUID]
+ :param resource_name: Resource name.
+ :type resource_name: str
+ :param parent_resource_id: The parent resource id to filter by.
+ :type parent_resource_id: UUID
+ :param ancestor_resource_id: The ancestor resource id to filter by. Returns all resources that are descendants of the specified resource.
+ :type ancestor_resource_id: UUID
+ :param remote_id: Filter resources by their remote id. This will return all resources that have a remote id that matches the provided remote id. Note that this requires resource_type_filter to be provided.
+ :type remote_id: str
+ :param tag_ids: The IDs of the tags to filter by. Returns only resources that have any of these tags applied.
+ :type tag_ids: List[UUID]
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resources_serialize(
+ cursor=cursor,
+ page_size=page_size,
+ resource_type_filter=resource_type_filter,
+ resource_ids=resource_ids,
+ resource_name=resource_name,
+ parent_resource_id=parent_resource_id,
+ ancestor_resource_id=ancestor_resource_id,
+ remote_id=remote_id,
+ tag_ids=tag_ids,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedResourcesList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_resources_with_http_info(
+ self,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ resource_type_filter: Annotated[Optional[ResourceTypeEnum], Field(description="The resource type to filter by. Required when remote_id is provided.")] = None,
+ resource_ids: Annotated[Optional[List[UUID]], Field(description="The resource ids to filter by.")] = None,
+ resource_name: Annotated[Optional[StrictStr], Field(description="Resource name.")] = None,
+ parent_resource_id: Annotated[Optional[UUID], Field(description="The parent resource id to filter by.")] = None,
+ ancestor_resource_id: Annotated[Optional[UUID], Field(description="The ancestor resource id to filter by. Returns all resources that are descendants of the specified resource.")] = None,
+ remote_id: Annotated[Optional[StrictStr], Field(description="Filter resources by their remote id. This will return all resources that have a remote id that matches the provided remote id. Note that this requires resource_type_filter to be provided.")] = None,
+ tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only resources that have any of these tags applied.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaginatedResourcesList]:
+ """Get resources
+
+ Returns a list of resources for your organization.
+
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
+ :param resource_type_filter: The resource type to filter by. Required when remote_id is provided.
+ :type resource_type_filter: ResourceTypeEnum
+ :param resource_ids: The resource ids to filter by.
+ :type resource_ids: List[UUID]
+ :param resource_name: Resource name.
+ :type resource_name: str
+ :param parent_resource_id: The parent resource id to filter by.
+ :type parent_resource_id: UUID
+ :param ancestor_resource_id: The ancestor resource id to filter by. Returns all resources that are descendants of the specified resource.
+ :type ancestor_resource_id: UUID
+ :param remote_id: Filter resources by their remote id. This will return all resources that have a remote id that matches the provided remote id. Note that this requires resource_type_filter to be provided.
+ :type remote_id: str
+ :param tag_ids: The IDs of the tags to filter by. Returns only resources that have any of these tags applied.
+ :type tag_ids: List[UUID]
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_resources_serialize(
+ cursor=cursor,
+ page_size=page_size,
+ resource_type_filter=resource_type_filter,
+ resource_ids=resource_ids,
+ resource_name=resource_name,
+ parent_resource_id=parent_resource_id,
+ ancestor_resource_id=ancestor_resource_id,
+ remote_id=remote_id,
+ tag_ids=tag_ids,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedResourcesList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_resources_without_preload_content(
self,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
@@ -4769,7 +6079,7 @@ def get_resources(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> PaginatedResourcesList:
+ ) -> RESTResponseType:
"""Get resources
Returns a list of resources for your organization.
@@ -4831,7 +6141,190 @@ def get_resources(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedResourcesList",
+ '200': "PaginatedResourcesList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_resources_serialize(
+ self,
+ cursor,
+ page_size,
+ resource_type_filter,
+ resource_ids,
+ resource_name,
+ parent_resource_id,
+ ancestor_resource_id,
+ remote_id,
+ tag_ids,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ 'resource_ids': 'csv',
+ 'tag_ids': 'multi',
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ if cursor is not None:
+
+ _query_params.append(('cursor', cursor))
+
+ if page_size is not None:
+
+ _query_params.append(('page_size', page_size))
+
+ if resource_type_filter is not None:
+
+ _query_params.append(('resource_type_filter', resource_type_filter.value))
+
+ if resource_ids is not None:
+
+ _query_params.append(('resource_ids', resource_ids))
+
+ if resource_name is not None:
+
+ _query_params.append(('resource_name', resource_name))
+
+ if parent_resource_id is not None:
+
+ _query_params.append(('parent_resource_id', parent_resource_id))
+
+ if ancestor_resource_id is not None:
+
+ _query_params.append(('ancestor_resource_id', ancestor_resource_id))
+
+ if remote_id is not None:
+
+ _query_params.append(('remote_id', remote_id))
+
+ if tag_ids is not None:
+
+ _query_params.append(('tag_ids', tag_ids))
+
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/resources',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_user_resources(
+ self,
+ user_id: Annotated[UUID, Field(description="The ID of the user.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ include_unmanaged: Annotated[Optional[StrictBool], Field(description="Include user's access to unmanaged resources.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ResourceAccessUserList:
+ """get_user_resources
+
+ Gets the list of resources for this user.
+
+ :param user_id: The ID of the user. (required)
+ :type user_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param include_unmanaged: Include user's access to unmanaged resources.
+ :type include_unmanaged: bool
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_user_resources_serialize(
+ user_id=user_id,
+ limit=limit,
+ cursor=cursor,
+ include_unmanaged=include_unmanaged,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "ResourceAccessUserList",
}
response_data = self.api_client.call_api(
*_param,
@@ -4845,17 +6338,12 @@ def get_resources(
@validate_call
- def get_resources_with_http_info(
+ def get_user_resources_with_http_info(
self,
+ user_id: Annotated[UUID, Field(description="The ID of the user.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
- resource_type_filter: Annotated[Optional[ResourceTypeEnum], Field(description="The resource type to filter by. Required when remote_id is provided.")] = None,
- resource_ids: Annotated[Optional[List[UUID]], Field(description="The resource ids to filter by.")] = None,
- resource_name: Annotated[Optional[StrictStr], Field(description="Resource name.")] = None,
- parent_resource_id: Annotated[Optional[UUID], Field(description="The parent resource id to filter by.")] = None,
- ancestor_resource_id: Annotated[Optional[UUID], Field(description="The ancestor resource id to filter by. Returns all resources that are descendants of the specified resource.")] = None,
- remote_id: Annotated[Optional[StrictStr], Field(description="Filter resources by their remote id. This will return all resources that have a remote id that matches the provided remote id. Note that this requires resource_type_filter to be provided.")] = None,
- tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only resources that have any of these tags applied.")] = None,
+ include_unmanaged: Annotated[Optional[StrictBool], Field(description="Include user's access to unmanaged resources.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4868,29 +6356,19 @@ def get_resources_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[PaginatedResourcesList]:
- """Get resources
+ ) -> ApiResponse[ResourceAccessUserList]:
+ """get_user_resources
- Returns a list of resources for your organization.
+ Gets the list of resources for this user.
+ :param user_id: The ID of the user. (required)
+ :type user_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
:param cursor: The pagination cursor value.
:type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
- :type page_size: int
- :param resource_type_filter: The resource type to filter by. Required when remote_id is provided.
- :type resource_type_filter: ResourceTypeEnum
- :param resource_ids: The resource ids to filter by.
- :type resource_ids: List[UUID]
- :param resource_name: Resource name.
- :type resource_name: str
- :param parent_resource_id: The parent resource id to filter by.
- :type parent_resource_id: UUID
- :param ancestor_resource_id: The ancestor resource id to filter by. Returns all resources that are descendants of the specified resource.
- :type ancestor_resource_id: UUID
- :param remote_id: Filter resources by their remote id. This will return all resources that have a remote id that matches the provided remote id. Note that this requires resource_type_filter to be provided.
- :type remote_id: str
- :param tag_ids: The IDs of the tags to filter by. Returns only resources that have any of these tags applied.
- :type tag_ids: List[UUID]
+ :param include_unmanaged: Include user's access to unmanaged resources.
+ :type include_unmanaged: bool
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -4913,16 +6391,11 @@ def get_resources_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resources_serialize(
+ _param = self._get_user_resources_serialize(
+ user_id=user_id,
+ limit=limit,
cursor=cursor,
- page_size=page_size,
- resource_type_filter=resource_type_filter,
- resource_ids=resource_ids,
- resource_name=resource_name,
- parent_resource_id=parent_resource_id,
- ancestor_resource_id=ancestor_resource_id,
- remote_id=remote_id,
- tag_ids=tag_ids,
+ include_unmanaged=include_unmanaged,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -4930,7 +6403,7 @@ def get_resources_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedResourcesList",
+ '200': "ResourceAccessUserList",
}
response_data = self.api_client.call_api(
*_param,
@@ -4944,17 +6417,12 @@ def get_resources_with_http_info(
@validate_call
- def get_resources_without_preload_content(
+ def get_user_resources_without_preload_content(
self,
+ user_id: Annotated[UUID, Field(description="The ID of the user.")],
+ limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
- resource_type_filter: Annotated[Optional[ResourceTypeEnum], Field(description="The resource type to filter by. Required when remote_id is provided.")] = None,
- resource_ids: Annotated[Optional[List[UUID]], Field(description="The resource ids to filter by.")] = None,
- resource_name: Annotated[Optional[StrictStr], Field(description="Resource name.")] = None,
- parent_resource_id: Annotated[Optional[UUID], Field(description="The parent resource id to filter by.")] = None,
- ancestor_resource_id: Annotated[Optional[UUID], Field(description="The ancestor resource id to filter by. Returns all resources that are descendants of the specified resource.")] = None,
- remote_id: Annotated[Optional[StrictStr], Field(description="Filter resources by their remote id. This will return all resources that have a remote id that matches the provided remote id. Note that this requires resource_type_filter to be provided.")] = None,
- tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only resources that have any of these tags applied.")] = None,
+ include_unmanaged: Annotated[Optional[StrictBool], Field(description="Include user's access to unmanaged resources.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -4968,28 +6436,18 @@ def get_resources_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """Get resources
+ """get_user_resources
- Returns a list of resources for your organization.
+ Gets the list of resources for this user.
+ :param user_id: The ID of the user. (required)
+ :type user_id: UUID
+ :param limit: Limit the number of results returned.
+ :type limit: int
:param cursor: The pagination cursor value.
:type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
- :type page_size: int
- :param resource_type_filter: The resource type to filter by. Required when remote_id is provided.
- :type resource_type_filter: ResourceTypeEnum
- :param resource_ids: The resource ids to filter by.
- :type resource_ids: List[UUID]
- :param resource_name: Resource name.
- :type resource_name: str
- :param parent_resource_id: The parent resource id to filter by.
- :type parent_resource_id: UUID
- :param ancestor_resource_id: The ancestor resource id to filter by. Returns all resources that are descendants of the specified resource.
- :type ancestor_resource_id: UUID
- :param remote_id: Filter resources by their remote id. This will return all resources that have a remote id that matches the provided remote id. Note that this requires resource_type_filter to be provided.
- :type remote_id: str
- :param tag_ids: The IDs of the tags to filter by. Returns only resources that have any of these tags applied.
- :type tag_ids: List[UUID]
+ :param include_unmanaged: Include user's access to unmanaged resources.
+ :type include_unmanaged: bool
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5012,16 +6470,11 @@ def get_resources_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_resources_serialize(
+ _param = self._get_user_resources_serialize(
+ user_id=user_id,
+ limit=limit,
cursor=cursor,
- page_size=page_size,
- resource_type_filter=resource_type_filter,
- resource_ids=resource_ids,
- resource_name=resource_name,
- parent_resource_id=parent_resource_id,
- ancestor_resource_id=ancestor_resource_id,
- remote_id=remote_id,
- tag_ids=tag_ids,
+ include_unmanaged=include_unmanaged,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5029,7 +6482,7 @@ def get_resources_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedResourcesList",
+ '200': "ResourceAccessUserList",
}
response_data = self.api_client.call_api(
*_param,
@@ -5038,17 +6491,12 @@ def get_resources_without_preload_content(
return response_data.response
- def _get_resources_serialize(
+ def _get_user_resources_serialize(
self,
+ user_id,
+ limit,
cursor,
- page_size,
- resource_type_filter,
- resource_ids,
- resource_name,
- parent_resource_id,
- ancestor_resource_id,
- remote_id,
- tag_ids,
+ include_unmanaged,
_request_auth,
_content_type,
_headers,
@@ -5058,8 +6506,6 @@ def _get_resources_serialize(
_host = None
_collection_formats: Dict[str, str] = {
- 'resource_ids': 'csv',
- 'tag_ids': 'multi',
}
_path_params: Dict[str, str] = {}
@@ -5072,42 +6518,20 @@ def _get_resources_serialize(
_body_params: Optional[bytes] = None
# process the path parameters
+ if user_id is not None:
+ _path_params['user_id'] = user_id
# process the query parameters
- if cursor is not None:
-
- _query_params.append(('cursor', cursor))
-
- if page_size is not None:
-
- _query_params.append(('page_size', page_size))
-
- if resource_type_filter is not None:
-
- _query_params.append(('resource_type_filter', resource_type_filter.value))
-
- if resource_ids is not None:
-
- _query_params.append(('resource_ids', resource_ids))
-
- if resource_name is not None:
-
- _query_params.append(('resource_name', resource_name))
-
- if parent_resource_id is not None:
-
- _query_params.append(('parent_resource_id', parent_resource_id))
-
- if ancestor_resource_id is not None:
+ if limit is not None:
- _query_params.append(('ancestor_resource_id', ancestor_resource_id))
+ _query_params.append(('limit', limit))
- if remote_id is not None:
+ if cursor is not None:
- _query_params.append(('remote_id', remote_id))
+ _query_params.append(('cursor', cursor))
- if tag_ids is not None:
+ if include_unmanaged is not None:
- _query_params.append(('tag_ids', tag_ids))
+ _query_params.append(('include_unmanaged', include_unmanaged))
# process the header parameters
# process the form parameters
@@ -5130,7 +6554,7 @@ def _get_resources_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources',
+ resource_path='/resources/users/{user_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -5147,12 +6571,13 @@ def _get_resources_serialize(
@validate_call
- def get_user_resources(
+ def resource_user_access_status_retrieve(
self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
user_id: Annotated[UUID, Field(description="The ID of the user.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.")] = None,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- include_unmanaged: Annotated[Optional[StrictBool], Field(description="Include user's access to unmanaged resources.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5165,19 +6590,21 @@ def get_user_resources(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ResourceAccessUserList:
- """get_user_resources
+ ) -> ResourceUserAccessStatus:
+ """(Deprecated) resource_user_access_status_retrieve
- Gets the list of resources for this user.
+ Get user's access status to a resource.
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
:param user_id: The ID of the user. (required)
:type user_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
+ :param access_level_remote_id: The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.
+ :type access_level_remote_id: str
:param cursor: The pagination cursor value.
:type cursor: str
- :param include_unmanaged: Include user's access to unmanaged resources.
- :type include_unmanaged: bool
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5199,12 +6626,14 @@ def get_user_resources(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /resource-user-access-status/{resource_id}/{user_id} is deprecated.", DeprecationWarning)
- _param = self._get_user_resources_serialize(
+ _param = self._resource_user_access_status_retrieve_serialize(
+ resource_id=resource_id,
user_id=user_id,
- limit=limit,
+ access_level_remote_id=access_level_remote_id,
cursor=cursor,
- include_unmanaged=include_unmanaged,
+ page_size=page_size,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5212,7 +6641,7 @@ def get_user_resources(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceAccessUserList",
+ '200': "ResourceUserAccessStatus",
}
response_data = self.api_client.call_api(
*_param,
@@ -5226,12 +6655,13 @@ def get_user_resources(
@validate_call
- def get_user_resources_with_http_info(
+ def resource_user_access_status_retrieve_with_http_info(
self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
user_id: Annotated[UUID, Field(description="The ID of the user.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.")] = None,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- include_unmanaged: Annotated[Optional[StrictBool], Field(description="Include user's access to unmanaged resources.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5244,19 +6674,21 @@ def get_user_resources_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[ResourceAccessUserList]:
- """get_user_resources
+ ) -> ApiResponse[ResourceUserAccessStatus]:
+ """(Deprecated) resource_user_access_status_retrieve
- Gets the list of resources for this user.
+ Get user's access status to a resource.
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
:param user_id: The ID of the user. (required)
:type user_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
+ :param access_level_remote_id: The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.
+ :type access_level_remote_id: str
:param cursor: The pagination cursor value.
:type cursor: str
- :param include_unmanaged: Include user's access to unmanaged resources.
- :type include_unmanaged: bool
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5278,12 +6710,14 @@ def get_user_resources_with_http_info(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /resource-user-access-status/{resource_id}/{user_id} is deprecated.", DeprecationWarning)
- _param = self._get_user_resources_serialize(
+ _param = self._resource_user_access_status_retrieve_serialize(
+ resource_id=resource_id,
user_id=user_id,
- limit=limit,
+ access_level_remote_id=access_level_remote_id,
cursor=cursor,
- include_unmanaged=include_unmanaged,
+ page_size=page_size,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5291,7 +6725,7 @@ def get_user_resources_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceAccessUserList",
+ '200': "ResourceUserAccessStatus",
}
response_data = self.api_client.call_api(
*_param,
@@ -5305,12 +6739,13 @@ def get_user_resources_with_http_info(
@validate_call
- def get_user_resources_without_preload_content(
+ def resource_user_access_status_retrieve_without_preload_content(
self,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
user_id: Annotated[UUID, Field(description="The ID of the user.")],
- limit: Annotated[Optional[StrictInt], Field(description="Limit the number of results returned.")] = None,
+ access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.")] = None,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- include_unmanaged: Annotated[Optional[StrictBool], Field(description="Include user's access to unmanaged resources.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5324,18 +6759,20 @@ def get_user_resources_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_user_resources
+ """(Deprecated) resource_user_access_status_retrieve
- Gets the list of resources for this user.
+ Get user's access status to a resource.
+ :param resource_id: The ID of the resource. (required)
+ :type resource_id: UUID
:param user_id: The ID of the user. (required)
:type user_id: UUID
- :param limit: Limit the number of results returned.
- :type limit: int
+ :param access_level_remote_id: The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.
+ :type access_level_remote_id: str
:param cursor: The pagination cursor value.
:type cursor: str
- :param include_unmanaged: Include user's access to unmanaged resources.
- :type include_unmanaged: bool
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5357,12 +6794,14 @@ def get_user_resources_without_preload_content(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /resource-user-access-status/{resource_id}/{user_id} is deprecated.", DeprecationWarning)
- _param = self._get_user_resources_serialize(
+ _param = self._resource_user_access_status_retrieve_serialize(
+ resource_id=resource_id,
user_id=user_id,
- limit=limit,
+ access_level_remote_id=access_level_remote_id,
cursor=cursor,
- include_unmanaged=include_unmanaged,
+ page_size=page_size,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5370,7 +6809,7 @@ def get_user_resources_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceAccessUserList",
+ '200': "ResourceUserAccessStatus",
}
response_data = self.api_client.call_api(
*_param,
@@ -5379,12 +6818,13 @@ def get_user_resources_without_preload_content(
return response_data.response
- def _get_user_resources_serialize(
+ def _resource_user_access_status_retrieve_serialize(
self,
+ resource_id,
user_id,
- limit,
+ access_level_remote_id,
cursor,
- include_unmanaged,
+ page_size,
_request_auth,
_content_type,
_headers,
@@ -5406,20 +6846,22 @@ def _get_user_resources_serialize(
_body_params: Optional[bytes] = None
# process the path parameters
+ if resource_id is not None:
+ _path_params['resource_id'] = resource_id
if user_id is not None:
_path_params['user_id'] = user_id
# process the query parameters
- if limit is not None:
+ if access_level_remote_id is not None:
- _query_params.append(('limit', limit))
+ _query_params.append(('access_level_remote_id', access_level_remote_id))
if cursor is not None:
_query_params.append(('cursor', cursor))
- if include_unmanaged is not None:
+ if page_size is not None:
- _query_params.append(('include_unmanaged', include_unmanaged))
+ _query_params.append(('page_size', page_size))
# process the header parameters
# process the form parameters
@@ -5442,7 +6884,7 @@ def _get_user_resources_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/resources/users/{user_id}',
+ resource_path='/resource-user-access-status/{resource_id}/{user_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -5459,13 +6901,10 @@ def _get_user_resources_serialize(
@validate_call
- def resource_user_access_status_retrieve(
+ def set_resource_message_channels(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of the user.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.")] = None,
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ message_channel_id_list: MessageChannelIDList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5478,21 +6917,15 @@ def resource_user_access_status_retrieve(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ResourceUserAccessStatus:
- """(Deprecated) resource_user_access_status_retrieve
+ ) -> List[UUID]:
+ """set_resource_message_channels
- Get user's access status to a resource.
+ Sets the list of audit message channels attached to a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of the user. (required)
- :type user_id: UUID
- :param access_level_remote_id: The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.
- :type access_level_remote_id: str
- :param cursor: The pagination cursor value.
- :type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
- :type page_size: int
+ :param message_channel_id_list: (required)
+ :type message_channel_id_list: MessageChannelIDList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5514,14 +6947,10 @@ def resource_user_access_status_retrieve(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
- warnings.warn("GET /resource-user-access-status/{resource_id}/{user_id} is deprecated.", DeprecationWarning)
- _param = self._resource_user_access_status_retrieve_serialize(
+ _param = self._set_resource_message_channels_serialize(
resource_id=resource_id,
- user_id=user_id,
- access_level_remote_id=access_level_remote_id,
- cursor=cursor,
- page_size=page_size,
+ message_channel_id_list=message_channel_id_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5529,7 +6958,7 @@ def resource_user_access_status_retrieve(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceUserAccessStatus",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -5543,13 +6972,10 @@ def resource_user_access_status_retrieve(
@validate_call
- def resource_user_access_status_retrieve_with_http_info(
+ def set_resource_message_channels_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of the user.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.")] = None,
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ message_channel_id_list: MessageChannelIDList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5562,21 +6988,15 @@ def resource_user_access_status_retrieve_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[ResourceUserAccessStatus]:
- """(Deprecated) resource_user_access_status_retrieve
+ ) -> ApiResponse[List[UUID]]:
+ """set_resource_message_channels
- Get user's access status to a resource.
+ Sets the list of audit message channels attached to a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of the user. (required)
- :type user_id: UUID
- :param access_level_remote_id: The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.
- :type access_level_remote_id: str
- :param cursor: The pagination cursor value.
- :type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
- :type page_size: int
+ :param message_channel_id_list: (required)
+ :type message_channel_id_list: MessageChannelIDList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5598,14 +7018,10 @@ def resource_user_access_status_retrieve_with_http_info(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
- warnings.warn("GET /resource-user-access-status/{resource_id}/{user_id} is deprecated.", DeprecationWarning)
- _param = self._resource_user_access_status_retrieve_serialize(
+ _param = self._set_resource_message_channels_serialize(
resource_id=resource_id,
- user_id=user_id,
- access_level_remote_id=access_level_remote_id,
- cursor=cursor,
- page_size=page_size,
+ message_channel_id_list=message_channel_id_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5613,7 +7029,7 @@ def resource_user_access_status_retrieve_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceUserAccessStatus",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -5627,13 +7043,10 @@ def resource_user_access_status_retrieve_with_http_info(
@validate_call
- def resource_user_access_status_retrieve_without_preload_content(
+ def set_resource_message_channels_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- user_id: Annotated[UUID, Field(description="The ID of the user.")],
- access_level_remote_id: Annotated[Optional[StrictStr], Field(description="The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.")] = None,
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ message_channel_id_list: MessageChannelIDList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5647,20 +7060,14 @@ def resource_user_access_status_retrieve_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """(Deprecated) resource_user_access_status_retrieve
+ """set_resource_message_channels
- Get user's access status to a resource.
+ Sets the list of audit message channels attached to a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param user_id: The ID of the user. (required)
- :type user_id: UUID
- :param access_level_remote_id: The remote ID of the access level that you wish to query for the resource. If omitted, the default access level remote ID value (empty string) is used.
- :type access_level_remote_id: str
- :param cursor: The pagination cursor value.
- :type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
- :type page_size: int
+ :param message_channel_id_list: (required)
+ :type message_channel_id_list: MessageChannelIDList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5682,14 +7089,10 @@ def resource_user_access_status_retrieve_without_preload_content(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
- warnings.warn("GET /resource-user-access-status/{resource_id}/{user_id} is deprecated.", DeprecationWarning)
- _param = self._resource_user_access_status_retrieve_serialize(
+ _param = self._set_resource_message_channels_serialize(
resource_id=resource_id,
- user_id=user_id,
- access_level_remote_id=access_level_remote_id,
- cursor=cursor,
- page_size=page_size,
+ message_channel_id_list=message_channel_id_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5697,7 +7100,7 @@ def resource_user_access_status_retrieve_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ResourceUserAccessStatus",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -5706,13 +7109,10 @@ def resource_user_access_status_retrieve_without_preload_content(
return response_data.response
- def _resource_user_access_status_retrieve_serialize(
+ def _set_resource_message_channels_serialize(
self,
resource_id,
- user_id,
- access_level_remote_id,
- cursor,
- page_size,
+ message_channel_id_list,
_request_auth,
_content_type,
_headers,
@@ -5736,24 +7136,12 @@ def _resource_user_access_status_retrieve_serialize(
# process the path parameters
if resource_id is not None:
_path_params['resource_id'] = resource_id
- if user_id is not None:
- _path_params['user_id'] = user_id
# process the query parameters
- if access_level_remote_id is not None:
-
- _query_params.append(('access_level_remote_id', access_level_remote_id))
-
- if cursor is not None:
-
- _query_params.append(('cursor', cursor))
-
- if page_size is not None:
-
- _query_params.append(('page_size', page_size))
-
# process the header parameters
# process the form parameters
# process the body parameter
+ if message_channel_id_list is not None:
+ _body_params = message_channel_id_list
# set the HTTP header `Accept`
@@ -5764,6 +7152,19 @@ def _resource_user_access_status_retrieve_serialize(
]
)
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
# authentication setting
_auth_settings: List[str] = [
@@ -5771,8 +7172,8 @@ def _resource_user_access_status_retrieve_serialize(
]
return self.api_client.param_serialize(
- method='GET',
- resource_path='/resource-user-access-status/{resource_id}/{user_id}',
+ method='PUT',
+ resource_path='/resources/{resource_id}/message-channels',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -5789,10 +7190,10 @@ def _resource_user_access_status_retrieve_serialize(
@validate_call
- def set_resource_message_channels(
+ def set_resource_reviewer_stages(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- message_channel_id_list: MessageChannelIDList,
+ reviewer_stage_list: ReviewerStageList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5805,15 +7206,15 @@ def set_resource_message_channels(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> List[UUID]:
- """set_resource_message_channels
+ ) -> List[ReviewerStage]:
+ """set_resource_reviewer_stages
- Sets the list of audit message channels attached to a resource.
+ Sets the list of reviewer stages for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param message_channel_id_list: (required)
- :type message_channel_id_list: MessageChannelIDList
+ :param reviewer_stage_list: (required)
+ :type reviewer_stage_list: ReviewerStageList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5836,9 +7237,9 @@ def set_resource_message_channels(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_message_channels_serialize(
+ _param = self._set_resource_reviewer_stages_serialize(
resource_id=resource_id,
- message_channel_id_list=message_channel_id_list,
+ reviewer_stage_list=reviewer_stage_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5846,7 +7247,7 @@ def set_resource_message_channels(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "List[ReviewerStage]",
}
response_data = self.api_client.call_api(
*_param,
@@ -5860,10 +7261,10 @@ def set_resource_message_channels(
@validate_call
- def set_resource_message_channels_with_http_info(
+ def set_resource_reviewer_stages_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- message_channel_id_list: MessageChannelIDList,
+ reviewer_stage_list: ReviewerStageList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5876,15 +7277,15 @@ def set_resource_message_channels_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[List[UUID]]:
- """set_resource_message_channels
+ ) -> ApiResponse[List[ReviewerStage]]:
+ """set_resource_reviewer_stages
- Sets the list of audit message channels attached to a resource.
+ Sets the list of reviewer stages for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param message_channel_id_list: (required)
- :type message_channel_id_list: MessageChannelIDList
+ :param reviewer_stage_list: (required)
+ :type reviewer_stage_list: ReviewerStageList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5907,9 +7308,9 @@ def set_resource_message_channels_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_message_channels_serialize(
+ _param = self._set_resource_reviewer_stages_serialize(
resource_id=resource_id,
- message_channel_id_list=message_channel_id_list,
+ reviewer_stage_list=reviewer_stage_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5917,7 +7318,7 @@ def set_resource_message_channels_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "List[ReviewerStage]",
}
response_data = self.api_client.call_api(
*_param,
@@ -5931,10 +7332,10 @@ def set_resource_message_channels_with_http_info(
@validate_call
- def set_resource_message_channels_without_preload_content(
+ def set_resource_reviewer_stages_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- message_channel_id_list: MessageChannelIDList,
+ reviewer_stage_list: ReviewerStageList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -5948,14 +7349,14 @@ def set_resource_message_channels_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """set_resource_message_channels
+ """set_resource_reviewer_stages
- Sets the list of audit message channels attached to a resource.
+ Sets the list of reviewer stages for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param message_channel_id_list: (required)
- :type message_channel_id_list: MessageChannelIDList
+ :param reviewer_stage_list: (required)
+ :type reviewer_stage_list: ReviewerStageList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -5978,9 +7379,9 @@ def set_resource_message_channels_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_message_channels_serialize(
+ _param = self._set_resource_reviewer_stages_serialize(
resource_id=resource_id,
- message_channel_id_list=message_channel_id_list,
+ reviewer_stage_list=reviewer_stage_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -5988,7 +7389,7 @@ def set_resource_message_channels_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "List[ReviewerStage]",
}
response_data = self.api_client.call_api(
*_param,
@@ -5997,10 +7398,10 @@ def set_resource_message_channels_without_preload_content(
return response_data.response
- def _set_resource_message_channels_serialize(
+ def _set_resource_reviewer_stages_serialize(
self,
resource_id,
- message_channel_id_list,
+ reviewer_stage_list,
_request_auth,
_content_type,
_headers,
@@ -6028,8 +7429,8 @@ def _set_resource_message_channels_serialize(
# process the header parameters
# process the form parameters
# process the body parameter
- if message_channel_id_list is not None:
- _body_params = message_channel_id_list
+ if reviewer_stage_list is not None:
+ _body_params = reviewer_stage_list
# set the HTTP header `Accept`
@@ -6061,7 +7462,7 @@ def _set_resource_message_channels_serialize(
return self.api_client.param_serialize(
method='PUT',
- resource_path='/resources/{resource_id}/message-channels',
+ resource_path='/resources/{resource_id}/reviewer-stages',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -6078,10 +7479,10 @@ def _set_resource_message_channels_serialize(
@validate_call
- def set_resource_reviewer_stages(
+ def set_resource_reviewers(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- reviewer_stage_list: ReviewerStageList,
+ reviewer_id_list: ReviewerIDList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6094,15 +7495,15 @@ def set_resource_reviewer_stages(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> List[ReviewerStage]:
- """set_resource_reviewer_stages
+ ) -> List[UUID]:
+ """set_resource_reviewers
- Sets the list of reviewer stages for a resource.
+ Sets the list of reviewers for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param reviewer_stage_list: (required)
- :type reviewer_stage_list: ReviewerStageList
+ :param reviewer_id_list: (required)
+ :type reviewer_id_list: ReviewerIDList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6125,9 +7526,9 @@ def set_resource_reviewer_stages(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_reviewer_stages_serialize(
+ _param = self._set_resource_reviewers_serialize(
resource_id=resource_id,
- reviewer_stage_list=reviewer_stage_list,
+ reviewer_id_list=reviewer_id_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6135,7 +7536,7 @@ def set_resource_reviewer_stages(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[ReviewerStage]",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -6149,10 +7550,10 @@ def set_resource_reviewer_stages(
@validate_call
- def set_resource_reviewer_stages_with_http_info(
+ def set_resource_reviewers_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- reviewer_stage_list: ReviewerStageList,
+ reviewer_id_list: ReviewerIDList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6165,15 +7566,15 @@ def set_resource_reviewer_stages_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[List[ReviewerStage]]:
- """set_resource_reviewer_stages
+ ) -> ApiResponse[List[UUID]]:
+ """set_resource_reviewers
- Sets the list of reviewer stages for a resource.
+ Sets the list of reviewers for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param reviewer_stage_list: (required)
- :type reviewer_stage_list: ReviewerStageList
+ :param reviewer_id_list: (required)
+ :type reviewer_id_list: ReviewerIDList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6196,9 +7597,9 @@ def set_resource_reviewer_stages_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_reviewer_stages_serialize(
+ _param = self._set_resource_reviewers_serialize(
resource_id=resource_id,
- reviewer_stage_list=reviewer_stage_list,
+ reviewer_id_list=reviewer_id_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6206,7 +7607,7 @@ def set_resource_reviewer_stages_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[ReviewerStage]",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -6220,10 +7621,10 @@ def set_resource_reviewer_stages_with_http_info(
@validate_call
- def set_resource_reviewer_stages_without_preload_content(
+ def set_resource_reviewers_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- reviewer_stage_list: ReviewerStageList,
+ reviewer_id_list: ReviewerIDList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6237,14 +7638,14 @@ def set_resource_reviewer_stages_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """set_resource_reviewer_stages
+ """set_resource_reviewers
- Sets the list of reviewer stages for a resource.
+ Sets the list of reviewers for a resource.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param reviewer_stage_list: (required)
- :type reviewer_stage_list: ReviewerStageList
+ :param reviewer_id_list: (required)
+ :type reviewer_id_list: ReviewerIDList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6267,9 +7668,9 @@ def set_resource_reviewer_stages_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_reviewer_stages_serialize(
+ _param = self._set_resource_reviewers_serialize(
resource_id=resource_id,
- reviewer_stage_list=reviewer_stage_list,
+ reviewer_id_list=reviewer_id_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6277,7 +7678,7 @@ def set_resource_reviewer_stages_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[ReviewerStage]",
+ '200': "List[UUID]",
}
response_data = self.api_client.call_api(
*_param,
@@ -6286,10 +7687,10 @@ def set_resource_reviewer_stages_without_preload_content(
return response_data.response
- def _set_resource_reviewer_stages_serialize(
+ def _set_resource_reviewers_serialize(
self,
resource_id,
- reviewer_stage_list,
+ reviewer_id_list,
_request_auth,
_content_type,
_headers,
@@ -6317,8 +7718,8 @@ def _set_resource_reviewer_stages_serialize(
# process the header parameters
# process the form parameters
# process the body parameter
- if reviewer_stage_list is not None:
- _body_params = reviewer_stage_list
+ if reviewer_id_list is not None:
+ _body_params = reviewer_id_list
# set the HTTP header `Accept`
@@ -6350,7 +7751,7 @@ def _set_resource_reviewer_stages_serialize(
return self.api_client.param_serialize(
method='PUT',
- resource_path='/resources/{resource_id}/reviewer-stages',
+ resource_path='/resources/{resource_id}/reviewers',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -6367,10 +7768,10 @@ def _set_resource_reviewer_stages_serialize(
@validate_call
- def set_resource_reviewers(
+ def set_resource_scoped_role_permissions(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- reviewer_id_list: ReviewerIDList,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type.")],
+ scoped_role_permission_list: ScopedRolePermissionList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6383,15 +7784,15 @@ def set_resource_reviewers(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> List[UUID]:
- """set_resource_reviewers
+ ) -> ScopedRolePermissionList:
+ """set_resource_scoped_role_permissions
- Sets the list of reviewers for a resource.
+ Sets all the scoped role permissions on an OPAL_SCOPED_ROLE resource.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type. (required)
:type resource_id: UUID
- :param reviewer_id_list: (required)
- :type reviewer_id_list: ReviewerIDList
+ :param scoped_role_permission_list: (required)
+ :type scoped_role_permission_list: ScopedRolePermissionList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6414,9 +7815,9 @@ def set_resource_reviewers(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_reviewers_serialize(
+ _param = self._set_resource_scoped_role_permissions_serialize(
resource_id=resource_id,
- reviewer_id_list=reviewer_id_list,
+ scoped_role_permission_list=scoped_role_permission_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6424,7 +7825,7 @@ def set_resource_reviewers(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "ScopedRolePermissionList",
}
response_data = self.api_client.call_api(
*_param,
@@ -6438,10 +7839,10 @@ def set_resource_reviewers(
@validate_call
- def set_resource_reviewers_with_http_info(
+ def set_resource_scoped_role_permissions_with_http_info(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- reviewer_id_list: ReviewerIDList,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type.")],
+ scoped_role_permission_list: ScopedRolePermissionList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6454,15 +7855,15 @@ def set_resource_reviewers_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[List[UUID]]:
- """set_resource_reviewers
+ ) -> ApiResponse[ScopedRolePermissionList]:
+ """set_resource_scoped_role_permissions
- Sets the list of reviewers for a resource.
+ Sets all the scoped role permissions on an OPAL_SCOPED_ROLE resource.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type. (required)
:type resource_id: UUID
- :param reviewer_id_list: (required)
- :type reviewer_id_list: ReviewerIDList
+ :param scoped_role_permission_list: (required)
+ :type scoped_role_permission_list: ScopedRolePermissionList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6485,9 +7886,9 @@ def set_resource_reviewers_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_reviewers_serialize(
+ _param = self._set_resource_scoped_role_permissions_serialize(
resource_id=resource_id,
- reviewer_id_list=reviewer_id_list,
+ scoped_role_permission_list=scoped_role_permission_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6495,7 +7896,7 @@ def set_resource_reviewers_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "ScopedRolePermissionList",
}
response_data = self.api_client.call_api(
*_param,
@@ -6509,10 +7910,10 @@ def set_resource_reviewers_with_http_info(
@validate_call
- def set_resource_reviewers_without_preload_content(
+ def set_resource_scoped_role_permissions_without_preload_content(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- reviewer_id_list: ReviewerIDList,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type.")],
+ scoped_role_permission_list: ScopedRolePermissionList,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6526,14 +7927,14 @@ def set_resource_reviewers_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """set_resource_reviewers
+ """set_resource_scoped_role_permissions
- Sets the list of reviewers for a resource.
+ Sets all the scoped role permissions on an OPAL_SCOPED_ROLE resource.
- :param resource_id: The ID of the resource. (required)
+ :param resource_id: The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type. (required)
:type resource_id: UUID
- :param reviewer_id_list: (required)
- :type reviewer_id_list: ReviewerIDList
+ :param scoped_role_permission_list: (required)
+ :type scoped_role_permission_list: ScopedRolePermissionList
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6556,9 +7957,9 @@ def set_resource_reviewers_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_reviewers_serialize(
+ _param = self._set_resource_scoped_role_permissions_serialize(
resource_id=resource_id,
- reviewer_id_list=reviewer_id_list,
+ scoped_role_permission_list=scoped_role_permission_list,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6566,7 +7967,7 @@ def set_resource_reviewers_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "List[UUID]",
+ '200': "ScopedRolePermissionList",
}
response_data = self.api_client.call_api(
*_param,
@@ -6575,10 +7976,10 @@ def set_resource_reviewers_without_preload_content(
return response_data.response
- def _set_resource_reviewers_serialize(
+ def _set_resource_scoped_role_permissions_serialize(
self,
resource_id,
- reviewer_id_list,
+ scoped_role_permission_list,
_request_auth,
_content_type,
_headers,
@@ -6606,8 +8007,8 @@ def _set_resource_reviewers_serialize(
# process the header parameters
# process the form parameters
# process the body parameter
- if reviewer_id_list is not None:
- _body_params = reviewer_id_list
+ if scoped_role_permission_list is not None:
+ _body_params = scoped_role_permission_list
# set the HTTP header `Accept`
@@ -6639,7 +8040,7 @@ def _set_resource_reviewers_serialize(
return self.api_client.param_serialize(
method='PUT',
- resource_path='/resources/{resource_id}/reviewers',
+ resource_path='/resources/{resource_id}/scoped-role-permissions',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -6656,10 +8057,10 @@ def _set_resource_reviewers_serialize(
@validate_call
- def set_resource_scoped_role_permissions(
+ def set_resource_visibility(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type.")],
- scoped_role_permission_list: ScopedRolePermissionList,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ visibility_info: VisibilityInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6672,15 +8073,15 @@ def set_resource_scoped_role_permissions(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ScopedRolePermissionList:
- """set_resource_scoped_role_permissions
+ ) -> VisibilityInfo:
+ """set_resource_visibility
- Sets all the scoped role permissions on an OPAL_SCOPED_ROLE resource.
+ Sets the visibility of this resource.
- :param resource_id: The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param scoped_role_permission_list: (required)
- :type scoped_role_permission_list: ScopedRolePermissionList
+ :param visibility_info: (required)
+ :type visibility_info: VisibilityInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6703,9 +8104,9 @@ def set_resource_scoped_role_permissions(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_scoped_role_permissions_serialize(
+ _param = self._set_resource_visibility_serialize(
resource_id=resource_id,
- scoped_role_permission_list=scoped_role_permission_list,
+ visibility_info=visibility_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6713,7 +8114,7 @@ def set_resource_scoped_role_permissions(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ScopedRolePermissionList",
+ '200': "VisibilityInfo",
}
response_data = self.api_client.call_api(
*_param,
@@ -6727,10 +8128,10 @@ def set_resource_scoped_role_permissions(
@validate_call
- def set_resource_scoped_role_permissions_with_http_info(
+ def set_resource_visibility_with_http_info(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type.")],
- scoped_role_permission_list: ScopedRolePermissionList,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ visibility_info: VisibilityInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6743,15 +8144,15 @@ def set_resource_scoped_role_permissions_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[ScopedRolePermissionList]:
- """set_resource_scoped_role_permissions
+ ) -> ApiResponse[VisibilityInfo]:
+ """set_resource_visibility
- Sets all the scoped role permissions on an OPAL_SCOPED_ROLE resource.
+ Sets the visibility of this resource.
- :param resource_id: The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param scoped_role_permission_list: (required)
- :type scoped_role_permission_list: ScopedRolePermissionList
+ :param visibility_info: (required)
+ :type visibility_info: VisibilityInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6774,9 +8175,9 @@ def set_resource_scoped_role_permissions_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_scoped_role_permissions_serialize(
+ _param = self._set_resource_visibility_serialize(
resource_id=resource_id,
- scoped_role_permission_list=scoped_role_permission_list,
+ visibility_info=visibility_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6784,7 +8185,7 @@ def set_resource_scoped_role_permissions_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ScopedRolePermissionList",
+ '200': "VisibilityInfo",
}
response_data = self.api_client.call_api(
*_param,
@@ -6798,10 +8199,10 @@ def set_resource_scoped_role_permissions_with_http_info(
@validate_call
- def set_resource_scoped_role_permissions_without_preload_content(
+ def set_resource_visibility_without_preload_content(
self,
- resource_id: Annotated[UUID, Field(description="The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type.")],
- scoped_role_permission_list: ScopedRolePermissionList,
+ resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
+ visibility_info: VisibilityInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6815,14 +8216,14 @@ def set_resource_scoped_role_permissions_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """set_resource_scoped_role_permissions
+ """set_resource_visibility
- Sets all the scoped role permissions on an OPAL_SCOPED_ROLE resource.
+ Sets the visibility of this resource.
- :param resource_id: The ID of the resource whose scoped role permissions belong to. Must be of OPAL_SCOPED_ROLE resource type. (required)
+ :param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param scoped_role_permission_list: (required)
- :type scoped_role_permission_list: ScopedRolePermissionList
+ :param visibility_info: (required)
+ :type visibility_info: VisibilityInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6845,9 +8246,9 @@ def set_resource_scoped_role_permissions_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_scoped_role_permissions_serialize(
+ _param = self._set_resource_visibility_serialize(
resource_id=resource_id,
- scoped_role_permission_list=scoped_role_permission_list,
+ visibility_info=visibility_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -6855,7 +8256,7 @@ def set_resource_scoped_role_permissions_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "ScopedRolePermissionList",
+ '200': "VisibilityInfo",
}
response_data = self.api_client.call_api(
*_param,
@@ -6864,10 +8265,10 @@ def set_resource_scoped_role_permissions_without_preload_content(
return response_data.response
- def _set_resource_scoped_role_permissions_serialize(
+ def _set_resource_visibility_serialize(
self,
resource_id,
- scoped_role_permission_list,
+ visibility_info,
_request_auth,
_content_type,
_headers,
@@ -6895,8 +8296,8 @@ def _set_resource_scoped_role_permissions_serialize(
# process the header parameters
# process the form parameters
# process the body parameter
- if scoped_role_permission_list is not None:
- _body_params = scoped_role_permission_list
+ if visibility_info is not None:
+ _body_params = visibility_info
# set the HTTP header `Accept`
@@ -6928,7 +8329,7 @@ def _set_resource_scoped_role_permissions_serialize(
return self.api_client.param_serialize(
method='PUT',
- resource_path='/resources/{resource_id}/scoped-role-permissions',
+ resource_path='/resources/{resource_id}/visibility',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -6945,10 +8346,11 @@ def _set_resource_scoped_role_permissions_serialize(
@validate_call
- def set_resource_visibility(
+ def update_resource_custom_access_level(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- visibility_info: VisibilityInfo,
+ access_level_remote_id: Annotated[StrictStr, Field(description="The remote ID of the access level.")],
+ update_resource_custom_access_level_info: UpdateResourceCustomAccessLevelInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -6961,15 +8363,17 @@ def set_resource_visibility(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> VisibilityInfo:
- """set_resource_visibility
+ ) -> ResourceCustomAccessLevelResponse:
+ """update_resource_custom_access_level
- Sets the visibility of this resource.
+ Updates a custom access level identified by its remote ID. If the resource is a parent type, the update fans out to all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param visibility_info: (required)
- :type visibility_info: VisibilityInfo
+ :param access_level_remote_id: The remote ID of the access level. (required)
+ :type access_level_remote_id: str
+ :param update_resource_custom_access_level_info: (required)
+ :type update_resource_custom_access_level_info: UpdateResourceCustomAccessLevelInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -6992,9 +8396,10 @@ def set_resource_visibility(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_visibility_serialize(
+ _param = self._update_resource_custom_access_level_serialize(
resource_id=resource_id,
- visibility_info=visibility_info,
+ access_level_remote_id=access_level_remote_id,
+ update_resource_custom_access_level_info=update_resource_custom_access_level_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -7002,7 +8407,9 @@ def set_resource_visibility(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "VisibilityInfo",
+ '200': "ResourceCustomAccessLevelResponse",
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -7016,10 +8423,11 @@ def set_resource_visibility(
@validate_call
- def set_resource_visibility_with_http_info(
+ def update_resource_custom_access_level_with_http_info(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- visibility_info: VisibilityInfo,
+ access_level_remote_id: Annotated[StrictStr, Field(description="The remote ID of the access level.")],
+ update_resource_custom_access_level_info: UpdateResourceCustomAccessLevelInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -7032,15 +8440,17 @@ def set_resource_visibility_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[VisibilityInfo]:
- """set_resource_visibility
+ ) -> ApiResponse[ResourceCustomAccessLevelResponse]:
+ """update_resource_custom_access_level
- Sets the visibility of this resource.
+ Updates a custom access level identified by its remote ID. If the resource is a parent type, the update fans out to all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param visibility_info: (required)
- :type visibility_info: VisibilityInfo
+ :param access_level_remote_id: The remote ID of the access level. (required)
+ :type access_level_remote_id: str
+ :param update_resource_custom_access_level_info: (required)
+ :type update_resource_custom_access_level_info: UpdateResourceCustomAccessLevelInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -7063,9 +8473,10 @@ def set_resource_visibility_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_visibility_serialize(
+ _param = self._update_resource_custom_access_level_serialize(
resource_id=resource_id,
- visibility_info=visibility_info,
+ access_level_remote_id=access_level_remote_id,
+ update_resource_custom_access_level_info=update_resource_custom_access_level_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -7073,7 +8484,9 @@ def set_resource_visibility_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "VisibilityInfo",
+ '200': "ResourceCustomAccessLevelResponse",
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -7087,10 +8500,11 @@ def set_resource_visibility_with_http_info(
@validate_call
- def set_resource_visibility_without_preload_content(
+ def update_resource_custom_access_level_without_preload_content(
self,
resource_id: Annotated[UUID, Field(description="The ID of the resource.")],
- visibility_info: VisibilityInfo,
+ access_level_remote_id: Annotated[StrictStr, Field(description="The remote ID of the access level.")],
+ update_resource_custom_access_level_info: UpdateResourceCustomAccessLevelInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -7104,14 +8518,16 @@ def set_resource_visibility_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """set_resource_visibility
+ """update_resource_custom_access_level
- Sets the visibility of this resource.
+ Updates a custom access level identified by its remote ID. If the resource is a parent type, the update fans out to all child resources.
:param resource_id: The ID of the resource. (required)
:type resource_id: UUID
- :param visibility_info: (required)
- :type visibility_info: VisibilityInfo
+ :param access_level_remote_id: The remote ID of the access level. (required)
+ :type access_level_remote_id: str
+ :param update_resource_custom_access_level_info: (required)
+ :type update_resource_custom_access_level_info: UpdateResourceCustomAccessLevelInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -7134,9 +8550,10 @@ def set_resource_visibility_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._set_resource_visibility_serialize(
+ _param = self._update_resource_custom_access_level_serialize(
resource_id=resource_id,
- visibility_info=visibility_info,
+ access_level_remote_id=access_level_remote_id,
+ update_resource_custom_access_level_info=update_resource_custom_access_level_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -7144,7 +8561,9 @@ def set_resource_visibility_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "VisibilityInfo",
+ '200': "ResourceCustomAccessLevelResponse",
+ '400': None,
+ '404': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -7153,10 +8572,11 @@ def set_resource_visibility_without_preload_content(
return response_data.response
- def _set_resource_visibility_serialize(
+ def _update_resource_custom_access_level_serialize(
self,
resource_id,
- visibility_info,
+ access_level_remote_id,
+ update_resource_custom_access_level_info,
_request_auth,
_content_type,
_headers,
@@ -7180,12 +8600,14 @@ def _set_resource_visibility_serialize(
# process the path parameters
if resource_id is not None:
_path_params['resource_id'] = resource_id
+ if access_level_remote_id is not None:
+ _path_params['access_level_remote_id'] = access_level_remote_id
# process the query parameters
# process the header parameters
# process the form parameters
# process the body parameter
- if visibility_info is not None:
- _body_params = visibility_info
+ if update_resource_custom_access_level_info is not None:
+ _body_params = update_resource_custom_access_level_info
# set the HTTP header `Accept`
@@ -7216,8 +8638,8 @@ def _set_resource_visibility_serialize(
]
return self.api_client.param_serialize(
- method='PUT',
- resource_path='/resources/{resource_id}/visibility',
+ method='PATCH',
+ resource_path='/resources/{resource_id}/custom-access-levels/{access_level_remote_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
diff --git a/opal_security/api/uars_api.py b/opal_security/api/uars_api.py
index f3f0df1..7f804ed 100644
--- a/opal_security/api/uars_api.py
+++ b/opal_security/api/uars_api.py
@@ -60,9 +60,9 @@ def create_uar(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> UAR:
- """create_uar
+ """(Deprecated) create_uar
- Starts a User Access Review.
+ Starts a User Access Review. Deprecated in favor of `POST /campaigns`.
:param create_uar_info: The settings of the UAR. (required)
:type create_uar_info: CreateUARInfo
@@ -87,6 +87,7 @@ def create_uar(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("POST /uar is deprecated.", DeprecationWarning)
_param = self._create_uar_serialize(
create_uar_info=create_uar_info,
@@ -127,9 +128,9 @@ def create_uar_with_http_info(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> ApiResponse[UAR]:
- """create_uar
+ """(Deprecated) create_uar
- Starts a User Access Review.
+ Starts a User Access Review. Deprecated in favor of `POST /campaigns`.
:param create_uar_info: The settings of the UAR. (required)
:type create_uar_info: CreateUARInfo
@@ -154,6 +155,7 @@ def create_uar_with_http_info(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("POST /uar is deprecated.", DeprecationWarning)
_param = self._create_uar_serialize(
create_uar_info=create_uar_info,
@@ -194,9 +196,9 @@ def create_uar_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """create_uar
+ """(Deprecated) create_uar
- Starts a User Access Review.
+ Starts a User Access Review. Deprecated in favor of `POST /campaigns`.
:param create_uar_info: The settings of the UAR. (required)
:type create_uar_info: CreateUARInfo
@@ -221,6 +223,7 @@ def create_uar_without_preload_content(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("POST /uar is deprecated.", DeprecationWarning)
_param = self._create_uar_serialize(
create_uar_info=create_uar_info,
@@ -334,9 +337,9 @@ def get_uar(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> UAR:
- """get_uar
+ """(Deprecated) get_uar
- Retrieves a specific UAR.
+ Retrieves a specific UAR. Deprecated in favor of `GET /campaigns/{campaign_id}`.
:param uar_id: The ID of the UAR. (required)
:type uar_id: UUID
@@ -361,6 +364,7 @@ def get_uar(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /uar/{uar_id} is deprecated.", DeprecationWarning)
_param = self._get_uar_serialize(
uar_id=uar_id,
@@ -401,9 +405,9 @@ def get_uar_with_http_info(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> ApiResponse[UAR]:
- """get_uar
+ """(Deprecated) get_uar
- Retrieves a specific UAR.
+ Retrieves a specific UAR. Deprecated in favor of `GET /campaigns/{campaign_id}`.
:param uar_id: The ID of the UAR. (required)
:type uar_id: UUID
@@ -428,6 +432,7 @@ def get_uar_with_http_info(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /uar/{uar_id} is deprecated.", DeprecationWarning)
_param = self._get_uar_serialize(
uar_id=uar_id,
@@ -468,9 +473,9 @@ def get_uar_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_uar
+ """(Deprecated) get_uar
- Retrieves a specific UAR.
+ Retrieves a specific UAR. Deprecated in favor of `GET /campaigns/{campaign_id}`.
:param uar_id: The ID of the UAR. (required)
:type uar_id: UUID
@@ -495,6 +500,7 @@ def get_uar_without_preload_content(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /uar/{uar_id} is deprecated.", DeprecationWarning)
_param = self._get_uar_serialize(
uar_id=uar_id,
@@ -596,9 +602,9 @@ def get_uars(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> PaginatedUARsList:
- """get_uars
+ """(Deprecated) get_uars
- Returns a list of `UAR` objects.
+ Returns a list of `UAR` objects. Deprecated in favor of `GET /campaigns`.
:param cursor: The pagination cursor value.
:type cursor: str
@@ -625,6 +631,7 @@ def get_uars(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /uars is deprecated.", DeprecationWarning)
_param = self._get_uars_serialize(
cursor=cursor,
@@ -667,9 +674,9 @@ def get_uars_with_http_info(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> ApiResponse[PaginatedUARsList]:
- """get_uars
+ """(Deprecated) get_uars
- Returns a list of `UAR` objects.
+ Returns a list of `UAR` objects. Deprecated in favor of `GET /campaigns`.
:param cursor: The pagination cursor value.
:type cursor: str
@@ -696,6 +703,7 @@ def get_uars_with_http_info(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /uars is deprecated.", DeprecationWarning)
_param = self._get_uars_serialize(
cursor=cursor,
@@ -738,9 +746,9 @@ def get_uars_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_uars
+ """(Deprecated) get_uars
- Returns a list of `UAR` objects.
+ Returns a list of `UAR` objects. Deprecated in favor of `GET /campaigns`.
:param cursor: The pagination cursor value.
:type cursor: str
@@ -767,6 +775,7 @@ def get_uars_without_preload_content(
:type _host_index: int, optional
:return: Returns the result object.
""" # noqa: E501
+ warnings.warn("GET /uars is deprecated.", DeprecationWarning)
_param = self._get_uars_serialize(
cursor=cursor,
diff --git a/opal_security/api/users_api.py b/opal_security/api/users_api.py
index 9a27db4..87fbbe9 100644
--- a/opal_security/api/users_api.py
+++ b/opal_security/api/users_api.py
@@ -21,10 +21,12 @@
from typing import List, Optional
from typing_extensions import Annotated
from uuid import UUID
+from opal_security.models.invite_user_info import InviteUserInfo
from opal_security.models.paginated_remote_users_list import PaginatedRemoteUsersList
from opal_security.models.paginated_users_list import PaginatedUsersList
from opal_security.models.tags_list import TagsList
from opal_security.models.third_party_provider_enum import ThirdPartyProviderEnum
+from opal_security.models.update_user_info import UpdateUserInfo
from opal_security.models.user import User
from opal_security.api_client import ApiClient, RequestSerialized
@@ -45,14 +47,1123 @@ def __init__(self, api_client=None) -> None:
self.api_client = api_client
+ @validate_call
+ def delete_user(
+ self,
+ user_id: Annotated[UUID, Field(description="The ID of the user to delete.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> User:
+ """delete_user
+
+ Deletes a user from your organization.
+
+ :param user_id: The ID of the user to delete. (required)
+ :type user_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_user_serialize(
+ user_id=user_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "User",
+ '403': None,
+ '404': None,
+ '409': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def delete_user_with_http_info(
+ self,
+ user_id: Annotated[UUID, Field(description="The ID of the user to delete.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[User]:
+ """delete_user
+
+ Deletes a user from your organization.
+
+ :param user_id: The ID of the user to delete. (required)
+ :type user_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_user_serialize(
+ user_id=user_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "User",
+ '403': None,
+ '404': None,
+ '409': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def delete_user_without_preload_content(
+ self,
+ user_id: Annotated[UUID, Field(description="The ID of the user to delete.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """delete_user
+
+ Deletes a user from your organization.
+
+ :param user_id: The ID of the user to delete. (required)
+ :type user_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._delete_user_serialize(
+ user_id=user_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "User",
+ '403': None,
+ '404': None,
+ '409': None,
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _delete_user_serialize(
+ self,
+ user_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if user_id is not None:
+ _path_params['user_id'] = user_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='DELETE',
+ resource_path='/users/{user_id}',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
@validate_call
def get_remote_users(
self,
- third_party_provider: Annotated[Optional[List[ThirdPartyProviderEnum]], Field(description="Filter remote users by their third party provider.")] = None,
- user_id: Annotated[Optional[List[UUID]], Field(description="Filter remote users by their user ID.")] = None,
- remote_id: Annotated[Optional[List[StrictStr]], Field(description="Filter remote users by their remote ID.")] = None,
+ third_party_provider: Annotated[Optional[List[ThirdPartyProviderEnum]], Field(description="Filter remote users by their third party provider.")] = None,
+ user_id: Annotated[Optional[List[UUID]], Field(description="Filter remote users by their user ID.")] = None,
+ remote_id: Annotated[Optional[List[StrictStr]], Field(description="Filter remote users by their remote ID.")] = None,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> PaginatedRemoteUsersList:
+ """get_remote_users
+
+ Returns a list of remote users for your organization.
+
+ :param third_party_provider: Filter remote users by their third party provider.
+ :type third_party_provider: List[ThirdPartyProviderEnum]
+ :param user_id: Filter remote users by their user ID.
+ :type user_id: List[UUID]
+ :param remote_id: Filter remote users by their remote ID.
+ :type remote_id: List[str]
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_remote_users_serialize(
+ third_party_provider=third_party_provider,
+ user_id=user_id,
+ remote_id=remote_id,
+ cursor=cursor,
+ page_size=page_size,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedRemoteUsersList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_remote_users_with_http_info(
+ self,
+ third_party_provider: Annotated[Optional[List[ThirdPartyProviderEnum]], Field(description="Filter remote users by their third party provider.")] = None,
+ user_id: Annotated[Optional[List[UUID]], Field(description="Filter remote users by their user ID.")] = None,
+ remote_id: Annotated[Optional[List[StrictStr]], Field(description="Filter remote users by their remote ID.")] = None,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[PaginatedRemoteUsersList]:
+ """get_remote_users
+
+ Returns a list of remote users for your organization.
+
+ :param third_party_provider: Filter remote users by their third party provider.
+ :type third_party_provider: List[ThirdPartyProviderEnum]
+ :param user_id: Filter remote users by their user ID.
+ :type user_id: List[UUID]
+ :param remote_id: Filter remote users by their remote ID.
+ :type remote_id: List[str]
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_remote_users_serialize(
+ third_party_provider=third_party_provider,
+ user_id=user_id,
+ remote_id=remote_id,
+ cursor=cursor,
+ page_size=page_size,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedRemoteUsersList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_remote_users_without_preload_content(
+ self,
+ third_party_provider: Annotated[Optional[List[ThirdPartyProviderEnum]], Field(description="Filter remote users by their third party provider.")] = None,
+ user_id: Annotated[Optional[List[UUID]], Field(description="Filter remote users by their user ID.")] = None,
+ remote_id: Annotated[Optional[List[StrictStr]], Field(description="Filter remote users by their remote ID.")] = None,
+ cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
+ page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """get_remote_users
+
+ Returns a list of remote users for your organization.
+
+ :param third_party_provider: Filter remote users by their third party provider.
+ :type third_party_provider: List[ThirdPartyProviderEnum]
+ :param user_id: Filter remote users by their user ID.
+ :type user_id: List[UUID]
+ :param remote_id: Filter remote users by their remote ID.
+ :type remote_id: List[str]
+ :param cursor: The pagination cursor value.
+ :type cursor: str
+ :param page_size: Number of results to return per page. Default is 200.
+ :type page_size: int
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_remote_users_serialize(
+ third_party_provider=third_party_provider,
+ user_id=user_id,
+ remote_id=remote_id,
+ cursor=cursor,
+ page_size=page_size,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "PaginatedRemoteUsersList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_remote_users_serialize(
+ self,
+ third_party_provider,
+ user_id,
+ remote_id,
+ cursor,
+ page_size,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ 'third_party_provider': 'multi',
+ 'user_id': 'multi',
+ 'remote_id': 'multi',
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ if third_party_provider is not None:
+
+ _query_params.append(('third_party_provider', third_party_provider))
+
+ if user_id is not None:
+
+ _query_params.append(('user_id', user_id))
+
+ if remote_id is not None:
+
+ _query_params.append(('remote_id', remote_id))
+
+ if cursor is not None:
+
+ _query_params.append(('cursor', cursor))
+
+ if page_size is not None:
+
+ _query_params.append(('page_size', page_size))
+
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/users/remote_users',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_user_tags(
+ self,
+ user_id: Annotated[UUID, Field(description="The ID of the user whose tags to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> TagsList:
+ """get_user_tags
+
+ Returns all tags applied to the user.
+
+ :param user_id: The ID of the user whose tags to return. (required)
+ :type user_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_user_tags_serialize(
+ user_id=user_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "TagsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_user_tags_with_http_info(
+ self,
+ user_id: Annotated[UUID, Field(description="The ID of the user whose tags to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[TagsList]:
+ """get_user_tags
+
+ Returns all tags applied to the user.
+
+ :param user_id: The ID of the user whose tags to return. (required)
+ :type user_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_user_tags_serialize(
+ user_id=user_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "TagsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_user_tags_without_preload_content(
+ self,
+ user_id: Annotated[UUID, Field(description="The ID of the user whose tags to return.")],
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """get_user_tags
+
+ Returns all tags applied to the user.
+
+ :param user_id: The ID of the user whose tags to return. (required)
+ :type user_id: UUID
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_user_tags_serialize(
+ user_id=user_id,
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "TagsList",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_user_tags_serialize(
+ self,
+ user_id,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ if user_id is not None:
+ _path_params['user_id'] = user_id
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/users/{user_id}/tags',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_user_whoami(
+ self,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> User:
+ """get_user_whoami
+
+ Returns the user that the provided API token authenticates as.
+
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_user_whoami_serialize(
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "User",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ ).data
+
+
+ @validate_call
+ def get_user_whoami_with_http_info(
+ self,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> ApiResponse[User]:
+ """get_user_whoami
+
+ Returns the user that the provided API token authenticates as.
+
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_user_whoami_serialize(
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "User",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ response_data.read()
+ return self.api_client.response_deserialize(
+ response_data=response_data,
+ response_types_map=_response_types_map,
+ )
+
+
+ @validate_call
+ def get_user_whoami_without_preload_content(
+ self,
+ _request_timeout: Union[
+ None,
+ Annotated[StrictFloat, Field(gt=0)],
+ Tuple[
+ Annotated[StrictFloat, Field(gt=0)],
+ Annotated[StrictFloat, Field(gt=0)]
+ ]
+ ] = None,
+ _request_auth: Optional[Dict[StrictStr, Any]] = None,
+ _content_type: Optional[StrictStr] = None,
+ _headers: Optional[Dict[StrictStr, Any]] = None,
+ _host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
+ ) -> RESTResponseType:
+ """get_user_whoami
+
+ Returns the user that the provided API token authenticates as.
+
+ :param _request_timeout: timeout setting for this request. If one
+ number provided, it will be total request
+ timeout. It can also be a pair (tuple) of
+ (connection, read) timeouts.
+ :type _request_timeout: int, tuple(int, int), optional
+ :param _request_auth: set to override the auth_settings for an a single
+ request; this effectively ignores the
+ authentication in the spec for a single request.
+ :type _request_auth: dict, optional
+ :param _content_type: force content-type for the request.
+ :type _content_type: str, Optional
+ :param _headers: set to override the headers for a single
+ request; this effectively ignores the headers
+ in the spec for a single request.
+ :type _headers: dict, optional
+ :param _host_index: set to override the host_index for a single
+ request; this effectively ignores the host_index
+ in the spec for a single request.
+ :type _host_index: int, optional
+ :return: Returns the result object.
+ """ # noqa: E501
+
+ _param = self._get_user_whoami_serialize(
+ _request_auth=_request_auth,
+ _content_type=_content_type,
+ _headers=_headers,
+ _host_index=_host_index
+ )
+
+ _response_types_map: Dict[str, Optional[str]] = {
+ '200': "User",
+ }
+ response_data = self.api_client.call_api(
+ *_param,
+ _request_timeout=_request_timeout
+ )
+ return response_data.response
+
+
+ def _get_user_whoami_serialize(
+ self,
+ _request_auth,
+ _content_type,
+ _headers,
+ _host_index,
+ ) -> RequestSerialized:
+
+ _host = None
+
+ _collection_formats: Dict[str, str] = {
+ }
+
+ _path_params: Dict[str, str] = {}
+ _query_params: List[Tuple[str, str]] = []
+ _header_params: Dict[str, Optional[str]] = _headers or {}
+ _form_params: List[Tuple[str, str]] = []
+ _files: Dict[
+ str, Union[str, bytes, List[str], List[bytes], List[Tuple[str, bytes]]]
+ ] = {}
+ _body_params: Optional[bytes] = None
+
+ # process the path parameters
+ # process the query parameters
+ # process the header parameters
+ # process the form parameters
+ # process the body parameter
+
+
+ # set the HTTP header `Accept`
+ if 'Accept' not in _header_params:
+ _header_params['Accept'] = self.api_client.select_header_accept(
+ [
+ 'application/json'
+ ]
+ )
+
+
+ # authentication setting
+ _auth_settings: List[str] = [
+ 'BearerAuth'
+ ]
+
+ return self.api_client.param_serialize(
+ method='GET',
+ resource_path='/users/whoami',
+ path_params=_path_params,
+ query_params=_query_params,
+ header_params=_header_params,
+ body=_body_params,
+ post_params=_form_params,
+ files=_files,
+ auth_settings=_auth_settings,
+ collection_formats=_collection_formats,
+ _host=_host,
+ _request_auth=_request_auth
+ )
+
+
+
+
+ @validate_call
+ def get_users(
+ self,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only users that have any of these tags applied.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -65,21 +1176,17 @@ def get_remote_users(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> PaginatedRemoteUsersList:
- """get_remote_users
+ ) -> PaginatedUsersList:
+ """get_users
- Returns a list of remote users for your organization.
+ Returns a list of users for your organization.
- :param third_party_provider: Filter remote users by their third party provider.
- :type third_party_provider: List[ThirdPartyProviderEnum]
- :param user_id: Filter remote users by their user ID.
- :type user_id: List[UUID]
- :param remote_id: Filter remote users by their remote ID.
- :type remote_id: List[str]
:param cursor: The pagination cursor value.
:type cursor: str
:param page_size: Number of results to return per page. Default is 200.
:type page_size: int
+ :param tag_ids: The IDs of the tags to filter by. Returns only users that have any of these tags applied.
+ :type tag_ids: List[UUID]
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -102,12 +1209,10 @@ def get_remote_users(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_remote_users_serialize(
- third_party_provider=third_party_provider,
- user_id=user_id,
- remote_id=remote_id,
+ _param = self._get_users_serialize(
cursor=cursor,
page_size=page_size,
+ tag_ids=tag_ids,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -115,7 +1220,7 @@ def get_remote_users(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedRemoteUsersList",
+ '200': "PaginatedUsersList",
}
response_data = self.api_client.call_api(
*_param,
@@ -129,13 +1234,11 @@ def get_remote_users(
@validate_call
- def get_remote_users_with_http_info(
+ def get_users_with_http_info(
self,
- third_party_provider: Annotated[Optional[List[ThirdPartyProviderEnum]], Field(description="Filter remote users by their third party provider.")] = None,
- user_id: Annotated[Optional[List[UUID]], Field(description="Filter remote users by their user ID.")] = None,
- remote_id: Annotated[Optional[List[StrictStr]], Field(description="Filter remote users by their remote ID.")] = None,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only users that have any of these tags applied.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -148,21 +1251,17 @@ def get_remote_users_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[PaginatedRemoteUsersList]:
- """get_remote_users
+ ) -> ApiResponse[PaginatedUsersList]:
+ """get_users
- Returns a list of remote users for your organization.
+ Returns a list of users for your organization.
- :param third_party_provider: Filter remote users by their third party provider.
- :type third_party_provider: List[ThirdPartyProviderEnum]
- :param user_id: Filter remote users by their user ID.
- :type user_id: List[UUID]
- :param remote_id: Filter remote users by their remote ID.
- :type remote_id: List[str]
:param cursor: The pagination cursor value.
:type cursor: str
:param page_size: Number of results to return per page. Default is 200.
:type page_size: int
+ :param tag_ids: The IDs of the tags to filter by. Returns only users that have any of these tags applied.
+ :type tag_ids: List[UUID]
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -185,12 +1284,10 @@ def get_remote_users_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_remote_users_serialize(
- third_party_provider=third_party_provider,
- user_id=user_id,
- remote_id=remote_id,
+ _param = self._get_users_serialize(
cursor=cursor,
page_size=page_size,
+ tag_ids=tag_ids,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -198,7 +1295,7 @@ def get_remote_users_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedRemoteUsersList",
+ '200': "PaginatedUsersList",
}
response_data = self.api_client.call_api(
*_param,
@@ -212,13 +1309,11 @@ def get_remote_users_with_http_info(
@validate_call
- def get_remote_users_without_preload_content(
+ def get_users_without_preload_content(
self,
- third_party_provider: Annotated[Optional[List[ThirdPartyProviderEnum]], Field(description="Filter remote users by their third party provider.")] = None,
- user_id: Annotated[Optional[List[UUID]], Field(description="Filter remote users by their user ID.")] = None,
- remote_id: Annotated[Optional[List[StrictStr]], Field(description="Filter remote users by their remote ID.")] = None,
cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
+ tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only users that have any of these tags applied.")] = None,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -232,20 +1327,16 @@ def get_remote_users_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_remote_users
+ """get_users
- Returns a list of remote users for your organization.
+ Returns a list of users for your organization.
- :param third_party_provider: Filter remote users by their third party provider.
- :type third_party_provider: List[ThirdPartyProviderEnum]
- :param user_id: Filter remote users by their user ID.
- :type user_id: List[UUID]
- :param remote_id: Filter remote users by their remote ID.
- :type remote_id: List[str]
:param cursor: The pagination cursor value.
:type cursor: str
:param page_size: Number of results to return per page. Default is 200.
:type page_size: int
+ :param tag_ids: The IDs of the tags to filter by. Returns only users that have any of these tags applied.
+ :type tag_ids: List[UUID]
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -268,12 +1359,10 @@ def get_remote_users_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_remote_users_serialize(
- third_party_provider=third_party_provider,
- user_id=user_id,
- remote_id=remote_id,
+ _param = self._get_users_serialize(
cursor=cursor,
page_size=page_size,
+ tag_ids=tag_ids,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -281,7 +1370,7 @@ def get_remote_users_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedRemoteUsersList",
+ '200': "PaginatedUsersList",
}
response_data = self.api_client.call_api(
*_param,
@@ -290,13 +1379,11 @@ def get_remote_users_without_preload_content(
return response_data.response
- def _get_remote_users_serialize(
+ def _get_users_serialize(
self,
- third_party_provider,
- user_id,
- remote_id,
cursor,
page_size,
+ tag_ids,
_request_auth,
_content_type,
_headers,
@@ -306,9 +1393,7 @@ def _get_remote_users_serialize(
_host = None
_collection_formats: Dict[str, str] = {
- 'third_party_provider': 'multi',
- 'user_id': 'multi',
- 'remote_id': 'multi',
+ 'tag_ids': 'multi',
}
_path_params: Dict[str, str] = {}
@@ -322,18 +1407,6 @@ def _get_remote_users_serialize(
# process the path parameters
# process the query parameters
- if third_party_provider is not None:
-
- _query_params.append(('third_party_provider', third_party_provider))
-
- if user_id is not None:
-
- _query_params.append(('user_id', user_id))
-
- if remote_id is not None:
-
- _query_params.append(('remote_id', remote_id))
-
if cursor is not None:
_query_params.append(('cursor', cursor))
@@ -342,6 +1415,10 @@ def _get_remote_users_serialize(
_query_params.append(('page_size', page_size))
+ if tag_ids is not None:
+
+ _query_params.append(('tag_ids', tag_ids))
+
# process the header parameters
# process the form parameters
# process the body parameter
@@ -363,7 +1440,7 @@ def _get_remote_users_serialize(
return self.api_client.param_serialize(
method='GET',
- resource_path='/users/remote_users',
+ resource_path='/users',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -380,9 +1457,9 @@ def _get_remote_users_serialize(
@validate_call
- def get_user_tags(
+ def invite_user(
self,
- user_id: Annotated[UUID, Field(description="The ID of the user whose tags to return.")],
+ invite_user_info: InviteUserInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -395,13 +1472,13 @@ def get_user_tags(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> TagsList:
- """get_user_tags
+ ) -> User:
+ """invite_user
- Returns all tags applied to the user.
+ Invites a user to your organization.
- :param user_id: The ID of the user whose tags to return. (required)
- :type user_id: UUID
+ :param invite_user_info: (required)
+ :type invite_user_info: InviteUserInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -424,8 +1501,8 @@ def get_user_tags(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_user_tags_serialize(
- user_id=user_id,
+ _param = self._invite_user_serialize(
+ invite_user_info=invite_user_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -433,7 +1510,10 @@ def get_user_tags(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "TagsList",
+ '200': "User",
+ '400': None,
+ '403': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -447,9 +1527,9 @@ def get_user_tags(
@validate_call
- def get_user_tags_with_http_info(
+ def invite_user_with_http_info(
self,
- user_id: Annotated[UUID, Field(description="The ID of the user whose tags to return.")],
+ invite_user_info: InviteUserInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -462,13 +1542,13 @@ def get_user_tags_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[TagsList]:
- """get_user_tags
+ ) -> ApiResponse[User]:
+ """invite_user
- Returns all tags applied to the user.
+ Invites a user to your organization.
- :param user_id: The ID of the user whose tags to return. (required)
- :type user_id: UUID
+ :param invite_user_info: (required)
+ :type invite_user_info: InviteUserInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -491,8 +1571,8 @@ def get_user_tags_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_user_tags_serialize(
- user_id=user_id,
+ _param = self._invite_user_serialize(
+ invite_user_info=invite_user_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -500,7 +1580,10 @@ def get_user_tags_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "TagsList",
+ '200': "User",
+ '400': None,
+ '403': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -514,9 +1597,9 @@ def get_user_tags_with_http_info(
@validate_call
- def get_user_tags_without_preload_content(
+ def invite_user_without_preload_content(
self,
- user_id: Annotated[UUID, Field(description="The ID of the user whose tags to return.")],
+ invite_user_info: InviteUserInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -530,12 +1613,12 @@ def get_user_tags_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_user_tags
+ """invite_user
- Returns all tags applied to the user.
+ Invites a user to your organization.
- :param user_id: The ID of the user whose tags to return. (required)
- :type user_id: UUID
+ :param invite_user_info: (required)
+ :type invite_user_info: InviteUserInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -558,8 +1641,8 @@ def get_user_tags_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_user_tags_serialize(
- user_id=user_id,
+ _param = self._invite_user_serialize(
+ invite_user_info=invite_user_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -567,7 +1650,10 @@ def get_user_tags_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "TagsList",
+ '200': "User",
+ '400': None,
+ '403': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -576,9 +1662,9 @@ def get_user_tags_without_preload_content(
return response_data.response
- def _get_user_tags_serialize(
+ def _invite_user_serialize(
self,
- user_id,
+ invite_user_info,
_request_auth,
_content_type,
_headers,
@@ -600,12 +1686,12 @@ def _get_user_tags_serialize(
_body_params: Optional[bytes] = None
# process the path parameters
- if user_id is not None:
- _path_params['user_id'] = user_id
# process the query parameters
# process the header parameters
# process the form parameters
# process the body parameter
+ if invite_user_info is not None:
+ _body_params = invite_user_info
# set the HTTP header `Accept`
@@ -616,6 +1702,19 @@ def _get_user_tags_serialize(
]
)
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
# authentication setting
_auth_settings: List[str] = [
@@ -623,8 +1722,8 @@ def _get_user_tags_serialize(
]
return self.api_client.param_serialize(
- method='GET',
- resource_path='/users/{user_id}/tags',
+ method='POST',
+ resource_path='/users',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
@@ -641,11 +1740,10 @@ def _get_user_tags_serialize(
@validate_call
- def get_users(
+ def update_user(
self,
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
- tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only users that have any of these tags applied.")] = None,
+ user_id: Annotated[UUID, Field(description="The ID of the user to update.")],
+ update_user_info: UpdateUserInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -658,17 +1756,15 @@ def get_users(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> PaginatedUsersList:
- """get_users
+ ) -> User:
+ """update_user
- Returns a list of users for your organization.
+ Updates a user's position or manager.
- :param cursor: The pagination cursor value.
- :type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
- :type page_size: int
- :param tag_ids: The IDs of the tags to filter by. Returns only users that have any of these tags applied.
- :type tag_ids: List[UUID]
+ :param user_id: The ID of the user to update. (required)
+ :type user_id: UUID
+ :param update_user_info: (required)
+ :type update_user_info: UpdateUserInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -691,10 +1787,9 @@ def get_users(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_users_serialize(
- cursor=cursor,
- page_size=page_size,
- tag_ids=tag_ids,
+ _param = self._update_user_serialize(
+ user_id=user_id,
+ update_user_info=update_user_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -702,7 +1797,11 @@ def get_users(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedUsersList",
+ '200': "User",
+ '400': None,
+ '403': None,
+ '404': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -716,11 +1815,10 @@ def get_users(
@validate_call
- def get_users_with_http_info(
+ def update_user_with_http_info(
self,
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
- tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only users that have any of these tags applied.")] = None,
+ user_id: Annotated[UUID, Field(description="The ID of the user to update.")],
+ update_user_info: UpdateUserInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -733,17 +1831,15 @@ def get_users_with_http_info(
_content_type: Optional[StrictStr] = None,
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
- ) -> ApiResponse[PaginatedUsersList]:
- """get_users
+ ) -> ApiResponse[User]:
+ """update_user
- Returns a list of users for your organization.
+ Updates a user's position or manager.
- :param cursor: The pagination cursor value.
- :type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
- :type page_size: int
- :param tag_ids: The IDs of the tags to filter by. Returns only users that have any of these tags applied.
- :type tag_ids: List[UUID]
+ :param user_id: The ID of the user to update. (required)
+ :type user_id: UUID
+ :param update_user_info: (required)
+ :type update_user_info: UpdateUserInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -766,10 +1862,9 @@ def get_users_with_http_info(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_users_serialize(
- cursor=cursor,
- page_size=page_size,
- tag_ids=tag_ids,
+ _param = self._update_user_serialize(
+ user_id=user_id,
+ update_user_info=update_user_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -777,7 +1872,11 @@ def get_users_with_http_info(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedUsersList",
+ '200': "User",
+ '400': None,
+ '403': None,
+ '404': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -791,11 +1890,10 @@ def get_users_with_http_info(
@validate_call
- def get_users_without_preload_content(
+ def update_user_without_preload_content(
self,
- cursor: Annotated[Optional[StrictStr], Field(description="The pagination cursor value.")] = None,
- page_size: Annotated[Optional[Annotated[int, Field(le=1000, strict=True)]], Field(description="Number of results to return per page. Default is 200.")] = None,
- tag_ids: Annotated[Optional[List[UUID]], Field(description="The IDs of the tags to filter by. Returns only users that have any of these tags applied.")] = None,
+ user_id: Annotated[UUID, Field(description="The ID of the user to update.")],
+ update_user_info: UpdateUserInfo,
_request_timeout: Union[
None,
Annotated[StrictFloat, Field(gt=0)],
@@ -809,16 +1907,14 @@ def get_users_without_preload_content(
_headers: Optional[Dict[StrictStr, Any]] = None,
_host_index: Annotated[StrictInt, Field(ge=0, le=0)] = 0,
) -> RESTResponseType:
- """get_users
+ """update_user
- Returns a list of users for your organization.
+ Updates a user's position or manager.
- :param cursor: The pagination cursor value.
- :type cursor: str
- :param page_size: Number of results to return per page. Default is 200.
- :type page_size: int
- :param tag_ids: The IDs of the tags to filter by. Returns only users that have any of these tags applied.
- :type tag_ids: List[UUID]
+ :param user_id: The ID of the user to update. (required)
+ :type user_id: UUID
+ :param update_user_info: (required)
+ :type update_user_info: UpdateUserInfo
:param _request_timeout: timeout setting for this request. If one
number provided, it will be total request
timeout. It can also be a pair (tuple) of
@@ -841,10 +1937,9 @@ def get_users_without_preload_content(
:return: Returns the result object.
""" # noqa: E501
- _param = self._get_users_serialize(
- cursor=cursor,
- page_size=page_size,
- tag_ids=tag_ids,
+ _param = self._update_user_serialize(
+ user_id=user_id,
+ update_user_info=update_user_info,
_request_auth=_request_auth,
_content_type=_content_type,
_headers=_headers,
@@ -852,7 +1947,11 @@ def get_users_without_preload_content(
)
_response_types_map: Dict[str, Optional[str]] = {
- '200': "PaginatedUsersList",
+ '200': "User",
+ '400': None,
+ '403': None,
+ '404': None,
+ '409': None,
}
response_data = self.api_client.call_api(
*_param,
@@ -861,11 +1960,10 @@ def get_users_without_preload_content(
return response_data.response
- def _get_users_serialize(
+ def _update_user_serialize(
self,
- cursor,
- page_size,
- tag_ids,
+ user_id,
+ update_user_info,
_request_auth,
_content_type,
_headers,
@@ -875,7 +1973,6 @@ def _get_users_serialize(
_host = None
_collection_formats: Dict[str, str] = {
- 'tag_ids': 'multi',
}
_path_params: Dict[str, str] = {}
@@ -888,22 +1985,14 @@ def _get_users_serialize(
_body_params: Optional[bytes] = None
# process the path parameters
+ if user_id is not None:
+ _path_params['user_id'] = user_id
# process the query parameters
- if cursor is not None:
-
- _query_params.append(('cursor', cursor))
-
- if page_size is not None:
-
- _query_params.append(('page_size', page_size))
-
- if tag_ids is not None:
-
- _query_params.append(('tag_ids', tag_ids))
-
# process the header parameters
# process the form parameters
# process the body parameter
+ if update_user_info is not None:
+ _body_params = update_user_info
# set the HTTP header `Accept`
@@ -914,6 +2003,19 @@ def _get_users_serialize(
]
)
+ # set the HTTP header `Content-Type`
+ if _content_type:
+ _header_params['Content-Type'] = _content_type
+ else:
+ _default_content_type = (
+ self.api_client.select_header_content_type(
+ [
+ 'application/json'
+ ]
+ )
+ )
+ if _default_content_type is not None:
+ _header_params['Content-Type'] = _default_content_type
# authentication setting
_auth_settings: List[str] = [
@@ -921,8 +2023,8 @@ def _get_users_serialize(
]
return self.api_client.param_serialize(
- method='GET',
- resource_path='/users',
+ method='PATCH',
+ resource_path='/users/{user_id}',
path_params=_path_params,
query_params=_query_params,
header_params=_header_params,
diff --git a/opal_security/models/__init__.py b/opal_security/models/__init__.py
index e39bbb8..e88a54b 100644
--- a/opal_security/models/__init__.py
+++ b/opal_security/models/__init__.py
@@ -39,9 +39,23 @@
from opal_security.models.bundle import Bundle
from opal_security.models.bundle_group import BundleGroup
from opal_security.models.bundle_resource import BundleResource
+from opal_security.models.campaign import Campaign
+from opal_security.models.campaign_configuration import CampaignConfiguration
+from opal_security.models.campaign_group_asset_visibility_policy_enum import CampaignGroupAssetVisibilityPolicyEnum
+from opal_security.models.campaign_item import CampaignItem
+from opal_security.models.campaign_item_admin_override import CampaignItemAdminOverride
+from opal_security.models.campaign_item_review import CampaignItemReview
+from opal_security.models.campaign_item_review_decision_enum import CampaignItemReviewDecisionEnum
+from opal_security.models.campaign_item_reviewer_assignment_source_enum import CampaignItemReviewerAssignmentSourceEnum
+from opal_security.models.campaign_item_status_enum import CampaignItemStatusEnum
+from opal_security.models.campaign_item_target_type_enum import CampaignItemTargetTypeEnum
+from opal_security.models.campaign_revoke_on_enum import CampaignRevokeOnEnum
+from opal_security.models.campaign_status_enum import CampaignStatusEnum
from opal_security.models.condition import Condition
from opal_security.models.configuration_template import ConfigurationTemplate
from opal_security.models.create_bundle_info import CreateBundleInfo
+from opal_security.models.create_campaign_configuration_info import CreateCampaignConfigurationInfo
+from opal_security.models.create_campaign_info import CreateCampaignInfo
from opal_security.models.create_configuration_template_info import CreateConfigurationTemplateInfo
from opal_security.models.create_delegation_request import CreateDelegationRequest
from opal_security.models.create_event_stream_info import CreateEventStreamInfo
@@ -52,6 +66,8 @@
from opal_security.models.create_message_channel_info import CreateMessageChannelInfo
from opal_security.models.create_on_call_schedule_info import CreateOnCallScheduleInfo
from opal_security.models.create_owner_info import CreateOwnerInfo
+from opal_security.models.create_paladin_context_source_info import CreatePaladinContextSourceInfo
+from opal_security.models.create_paladin_info import CreatePaladinInfo
from opal_security.models.create_request200_response import CreateRequest200Response
from opal_security.models.create_request_comment_request import CreateRequestCommentRequest
from opal_security.models.create_request_configuration_info_list import CreateRequestConfigurationInfoList
@@ -60,11 +76,14 @@
from opal_security.models.create_request_info_groups_inner import CreateRequestInfoGroupsInner
from opal_security.models.create_request_info_resources_inner import CreateRequestInfoResourcesInner
from opal_security.models.create_request_info_support_ticket import CreateRequestInfoSupportTicket
+from opal_security.models.create_request_template_info import CreateRequestTemplateInfo
+from opal_security.models.create_resource_custom_access_level_info import CreateResourceCustomAccessLevelInfo
from opal_security.models.create_resource_info import CreateResourceInfo
from opal_security.models.create_tag_info import CreateTagInfo
from opal_security.models.create_uar_info import CreateUARInfo
from opal_security.models.delegation import Delegation
from opal_security.models.deny_request_request import DenyRequestRequest
+from opal_security.models.entity_admin_filter import EntityAdminFilter
from opal_security.models.entity_item_type_enum import EntityItemTypeEnum
from opal_security.models.entity_name_filter import EntityNameFilter
from opal_security.models.entity_tag_filter import EntityTagFilter
@@ -77,6 +96,7 @@
from opal_security.models.get_resource_user200_response import GetResourceUser200Response
from opal_security.models.group import Group
from opal_security.models.group_access_level import GroupAccessLevel
+from opal_security.models.group_access_level_list import GroupAccessLevelList
from opal_security.models.group_binding import GroupBinding
from opal_security.models.group_binding_group import GroupBindingGroup
from opal_security.models.group_containing_group import GroupContainingGroup
@@ -87,9 +107,12 @@
from opal_security.models.group_remote_info_azure_ad_microsoft365_group import GroupRemoteInfoAzureAdMicrosoft365Group
from opal_security.models.group_remote_info_azure_ad_security_group import GroupRemoteInfoAzureAdSecurityGroup
from opal_security.models.group_remote_info_clickhouse_role import GroupRemoteInfoClickhouseRole
+from opal_security.models.group_remote_info_confluence_group import GroupRemoteInfoConfluenceGroup
from opal_security.models.group_remote_info_connector_group import GroupRemoteInfoConnectorGroup
from opal_security.models.group_remote_info_databricks_account_group import GroupRemoteInfoDatabricksAccountGroup
from opal_security.models.group_remote_info_devin_group import GroupRemoteInfoDevinGroup
+from opal_security.models.group_remote_info_docusign_group import GroupRemoteInfoDocusignGroup
+from opal_security.models.group_remote_info_docusign_signing_group import GroupRemoteInfoDocusignSigningGroup
from opal_security.models.group_remote_info_duo_group import GroupRemoteInfoDuoGroup
from opal_security.models.group_remote_info_github_enterprise_team import GroupRemoteInfoGithubEnterpriseTeam
from opal_security.models.group_remote_info_github_team import GroupRemoteInfoGithubTeam
@@ -98,19 +121,23 @@
from opal_security.models.group_remote_info_grafana_team import GroupRemoteInfoGrafanaTeam
from opal_security.models.group_remote_info_hubspot_team import GroupRemoteInfoHubspotTeam
from opal_security.models.group_remote_info_incidentio_on_call_schedule import GroupRemoteInfoIncidentioOnCallSchedule
+from opal_security.models.group_remote_info_jira_group import GroupRemoteInfoJiraGroup
from opal_security.models.group_remote_info_ldap_group import GroupRemoteInfoLdapGroup
+from opal_security.models.group_remote_info_linear_team import GroupRemoteInfoLinearTeam
from opal_security.models.group_remote_info_okta_group import GroupRemoteInfoOktaGroup
from opal_security.models.group_remote_info_okta_group_rule import GroupRemoteInfoOktaGroupRule
from opal_security.models.group_remote_info_pagerduty_on_call_schedule import GroupRemoteInfoPagerdutyOnCallSchedule
from opal_security.models.group_remote_info_rootly_on_call_schedule import GroupRemoteInfoRootlyOnCallSchedule
from opal_security.models.group_remote_info_slack_user_group import GroupRemoteInfoSlackUserGroup
from opal_security.models.group_remote_info_snowflake_role import GroupRemoteInfoSnowflakeRole
+from opal_security.models.group_remote_info_tableau_group import GroupRemoteInfoTableauGroup
from opal_security.models.group_remote_info_tailscale_group import GroupRemoteInfoTailscaleGroup
from opal_security.models.group_remote_info_twingate_group import GroupRemoteInfoTwingateGroup
from opal_security.models.group_remote_info_twingate_group_synced import GroupRemoteInfoTwingateGroupSynced
from opal_security.models.group_remote_info_workday_user_security_group import GroupRemoteInfoWorkdayUserSecurityGroup
from opal_security.models.group_remote_info_zendesk_group import GroupRemoteInfoZendeskGroup
from opal_security.models.group_remote_info_zendesk_organization import GroupRemoteInfoZendeskOrganization
+from opal_security.models.group_remote_info_zoom_group import GroupRemoteInfoZoomGroup
from opal_security.models.group_resource import GroupResource
from opal_security.models.group_resource_list import GroupResourceList
from opal_security.models.group_type_enum import GroupTypeEnum
@@ -119,6 +146,8 @@
from opal_security.models.group_with_access_level import GroupWithAccessLevel
from opal_security.models.idp_group_mapping import IdpGroupMapping
from opal_security.models.idp_group_mapping_list import IdpGroupMappingList
+from opal_security.models.idp_status_filter import IdpStatusFilter
+from opal_security.models.invite_user_info import InviteUserInfo
from opal_security.models.message_channel import MessageChannel
from opal_security.models.message_channel_id_list import MessageChannelIDList
from opal_security.models.message_channel_list import MessageChannelList
@@ -127,11 +156,18 @@
from opal_security.models.on_call_schedule_id_list import OnCallScheduleIDList
from opal_security.models.on_call_schedule_list import OnCallScheduleList
from opal_security.models.on_call_schedule_provider_enum import OnCallScheduleProviderEnum
+from opal_security.models.opal_access_path_edge_filter import OpalAccessPathEdgeFilter
+from opal_security.models.opal_access_path_query import OpalAccessPathQuery
+from opal_security.models.opal_access_path_query_body import OpalAccessPathQueryBody
+from opal_security.models.opal_access_path_query_results import OpalAccessPathQueryResults
+from opal_security.models.opal_access_path_result_edge import OpalAccessPathResultEdge
+from opal_security.models.opal_access_path_result_node import OpalAccessPathResultNode
from opal_security.models.opal_node_query import OpalNodeQuery
from opal_security.models.opal_node_query_body import OpalNodeQueryBody
from opal_security.models.opal_node_query_results import OpalNodeQueryResults
from opal_security.models.opal_query_result_edge import OpalQueryResultEdge
from opal_security.models.opal_query_result_node import OpalQueryResultNode
+from opal_security.models.opal_query_results import OpalQueryResults
from opal_security.models.owner import Owner
from opal_security.models.page_info import PageInfo
from opal_security.models.paginated_access_rules_list import PaginatedAccessRulesList
@@ -139,6 +175,8 @@
from opal_security.models.paginated_bundle_group_list import PaginatedBundleGroupList
from opal_security.models.paginated_bundle_list import PaginatedBundleList
from opal_security.models.paginated_bundle_resource_list import PaginatedBundleResourceList
+from opal_security.models.paginated_campaign_items_list import PaginatedCampaignItemsList
+from opal_security.models.paginated_campaigns_list import PaginatedCampaignsList
from opal_security.models.paginated_configuration_template_list import PaginatedConfigurationTemplateList
from opal_security.models.paginated_delegations_list import PaginatedDelegationsList
from opal_security.models.paginated_event_list import PaginatedEventList
@@ -146,14 +184,24 @@
from opal_security.models.paginated_groups_list import PaginatedGroupsList
from opal_security.models.paginated_owners_list import PaginatedOwnersList
from opal_security.models.paginated_remote_users_list import PaginatedRemoteUsersList
+from opal_security.models.paginated_request_template_list import PaginatedRequestTemplateList
from opal_security.models.paginated_resources_list import PaginatedResourcesList
from opal_security.models.paginated_tags_list import PaginatedTagsList
from opal_security.models.paginated_tokens_list import PaginatedTokensList
from opal_security.models.paginated_uars_list import PaginatedUARsList
from opal_security.models.paginated_users_list import PaginatedUsersList
+from opal_security.models.paginated_viewer_campaign_items_list import PaginatedViewerCampaignItemsList
+from opal_security.models.paladin import Paladin
+from opal_security.models.paladin_connector import PaladinConnector
+from opal_security.models.paladin_context_source import PaladinContextSource
+from opal_security.models.paladin_context_source_kind import PaladinContextSourceKind
+from opal_security.models.paladin_context_source_list import PaladinContextSourceList
+from opal_security.models.paladin_context_source_provider import PaladinContextSourceProvider
+from opal_security.models.paladin_list import PaladinList
from opal_security.models.propagation_status import PropagationStatus
from opal_security.models.propagation_status_enum import PropagationStatusEnum
from opal_security.models.rds_engine_enum import RDSEngineEnum
+from opal_security.models.remind_request200_response import RemindRequest200Response
from opal_security.models.remote_user import RemoteUser
from opal_security.models.request import Request
from opal_security.models.request_approval_enum import RequestApprovalEnum
@@ -170,14 +218,25 @@
from opal_security.models.request_reviewer_stages import RequestReviewerStages
from opal_security.models.request_stage import RequestStage
from opal_security.models.request_status_enum import RequestStatusEnum
+from opal_security.models.request_template import RequestTemplate
+from opal_security.models.request_template_custom_field import RequestTemplateCustomField
+from opal_security.models.request_template_custom_field_callout_metadata import RequestTemplateCustomFieldCalloutMetadata
+from opal_security.models.request_template_custom_field_input import RequestTemplateCustomFieldInput
+from opal_security.models.request_template_custom_field_metadata import RequestTemplateCustomFieldMetadata
+from opal_security.models.request_template_custom_field_multi_choice_metadata import RequestTemplateCustomFieldMultiChoiceMetadata
from opal_security.models.request_template_custom_field_type_enum import RequestTemplateCustomFieldTypeEnum
from opal_security.models.requested_item import RequestedItem
from opal_security.models.resource import Resource
from opal_security.models.resource_access_level import ResourceAccessLevel
+from opal_security.models.resource_access_level_list import ResourceAccessLevelList
from opal_security.models.resource_access_user import ResourceAccessUser
from opal_security.models.resource_access_user_list import ResourceAccessUserList
+from opal_security.models.resource_custom_access_level_list import ResourceCustomAccessLevelList
+from opal_security.models.resource_custom_access_level_response import ResourceCustomAccessLevelResponse
from opal_security.models.resource_nhi import ResourceNHI
from opal_security.models.resource_remote_info import ResourceRemoteInfo
+from opal_security.models.resource_remote_info_alicloud_ecs_instance import ResourceRemoteInfoAlicloudEcsInstance
+from opal_security.models.resource_remote_info_alicloud_ram_role import ResourceRemoteInfoAlicloudRamRole
from opal_security.models.resource_remote_info_anthropic_workspace import ResourceRemoteInfoAnthropicWorkspace
from opal_security.models.resource_remote_info_aws_account import ResourceRemoteInfoAwsAccount
from opal_security.models.resource_remote_info_aws_ec2_instance import ResourceRemoteInfoAwsEc2Instance
@@ -210,8 +269,10 @@
from opal_security.models.resource_remote_info_datastax_astra_role import ResourceRemoteInfoDatastaxAstraRole
from opal_security.models.resource_remote_info_devin_organization import ResourceRemoteInfoDevinOrganization
from opal_security.models.resource_remote_info_devin_role import ResourceRemoteInfoDevinRole
+from opal_security.models.resource_remote_info_docusign_permission_profile import ResourceRemoteInfoDocusignPermissionProfile
from opal_security.models.resource_remote_info_gcp_big_query_dataset import ResourceRemoteInfoGcpBigQueryDataset
from opal_security.models.resource_remote_info_gcp_big_query_table import ResourceRemoteInfoGcpBigQueryTable
+from opal_security.models.resource_remote_info_gcp_billing_account import ResourceRemoteInfoGcpBillingAccount
from opal_security.models.resource_remote_info_gcp_bucket import ResourceRemoteInfoGcpBucket
from opal_security.models.resource_remote_info_gcp_compute_instance import ResourceRemoteInfoGcpComputeInstance
from opal_security.models.resource_remote_info_gcp_folder import ResourceRemoteInfoGcpFolder
@@ -231,6 +292,8 @@
from opal_security.models.resource_remote_info_grafana_role import ResourceRemoteInfoGrafanaRole
from opal_security.models.resource_remote_info_hubspot_role import ResourceRemoteInfoHubspotRole
from opal_security.models.resource_remote_info_ilevel_advanced_role import ResourceRemoteInfoIlevelAdvancedRole
+from opal_security.models.resource_remote_info_linear_organization import ResourceRemoteInfoLinearOrganization
+from opal_security.models.resource_remote_info_linear_project import ResourceRemoteInfoLinearProject
from opal_security.models.resource_remote_info_netsuite_role import ResourceRemoteInfoNetsuiteRole
from opal_security.models.resource_remote_info_okta_app import ResourceRemoteInfoOktaApp
from opal_security.models.resource_remote_info_okta_custom_role import ResourceRemoteInfoOktaCustomRole
@@ -250,6 +313,8 @@
from opal_security.models.resource_remote_info_twingate_resource import ResourceRemoteInfoTwingateResource
from opal_security.models.resource_remote_info_workday_role import ResourceRemoteInfoWorkdayRole
from opal_security.models.resource_remote_info_zendesk_role import ResourceRemoteInfoZendeskRole
+from opal_security.models.resource_remote_info_zoom_license import ResourceRemoteInfoZoomLicense
+from opal_security.models.resource_remote_info_zoom_role import ResourceRemoteInfoZoomRole
from opal_security.models.resource_type_enum import ResourceTypeEnum
from opal_security.models.resource_user import ResourceUser
from opal_security.models.resource_user_access_status import ResourceUserAccessStatus
@@ -265,10 +330,13 @@
from opal_security.models.rule_clauses import RuleClauses
from opal_security.models.rule_conjunction import RuleConjunction
from opal_security.models.rule_disjunction import RuleDisjunction
+from opal_security.models.run_opal_query_request import RunOpalQueryRequest
from opal_security.models.scoped_role_permission import ScopedRolePermission
from opal_security.models.scoped_role_permission_list import ScopedRolePermissionList
from opal_security.models.session import Session
from opal_security.models.sessions_list import SessionsList
+from opal_security.models.sort_direction_enum import SortDirectionEnum
+from opal_security.models.stop_campaign_request import StopCampaignRequest
from opal_security.models.string_match_type import StringMatchType
from opal_security.models.sub_event import SubEvent
from opal_security.models.sync_error import SyncError
@@ -286,6 +354,8 @@
from opal_security.models.uar_reviewer_assignment_policy_enum import UARReviewerAssignmentPolicyEnum
from opal_security.models.uar_scope import UARScope
from opal_security.models.update_access_rule_info import UpdateAccessRuleInfo
+from opal_security.models.update_campaign_configuration_info import UpdateCampaignConfigurationInfo
+from opal_security.models.update_campaign_info import UpdateCampaignInfo
from opal_security.models.update_configuration_template_info import UpdateConfigurationTemplateInfo
from opal_security.models.update_event_stream_info import UpdateEventStreamInfo
from opal_security.models.update_group_binding_info import UpdateGroupBindingInfo
@@ -298,14 +368,23 @@
from opal_security.models.update_idp_group_mappings_request_mappings_inner import UpdateIdpGroupMappingsRequestMappingsInner
from opal_security.models.update_owner_info import UpdateOwnerInfo
from opal_security.models.update_owner_info_list import UpdateOwnerInfoList
+from opal_security.models.update_paladin_info import UpdatePaladinInfo
+from opal_security.models.update_request_template_info import UpdateRequestTemplateInfo
+from opal_security.models.update_resource_custom_access_level_info import UpdateResourceCustomAccessLevelInfo
from opal_security.models.update_resource_info import UpdateResourceInfo
from opal_security.models.update_resource_info_list import UpdateResourceInfoList
from opal_security.models.update_resource_user_request import UpdateResourceUserRequest
+from opal_security.models.update_user_info import UpdateUserInfo
from opal_security.models.user import User
from opal_security.models.user_attribute_selector import UserAttributeSelector
from opal_security.models.user_hr_idp_status_enum import UserHrIdpStatusEnum
from opal_security.models.user_id_list import UserIDList
from opal_security.models.user_list import UserList
+from opal_security.models.user_product_role_enum import UserProductRoleEnum
+from opal_security.models.viewer_campaign_item import ViewerCampaignItem
+from opal_security.models.viewer_campaign_item_review_decision_enum import ViewerCampaignItemReviewDecisionEnum
+from opal_security.models.viewer_campaign_item_sort_field_enum import ViewerCampaignItemSortFieldEnum
+from opal_security.models.viewer_campaign_item_status_enum import ViewerCampaignItemStatusEnum
from opal_security.models.visibility_info import VisibilityInfo
from opal_security.models.visibility_type_enum import VisibilityTypeEnum
from opal_security.models.webhook_api_key_credential import WebhookApiKeyCredential
diff --git a/opal_security/models/access_entity_filters.py b/opal_security/models/access_entity_filters.py
index 95f78e5..5402e05 100644
--- a/opal_security/models/access_entity_filters.py
+++ b/opal_security/models/access_entity_filters.py
@@ -21,9 +21,11 @@
from pydantic import BaseModel, ConfigDict, Field, StrictStr, field_validator
from typing import Any, ClassVar, Dict, List, Optional
from uuid import UUID
+from opal_security.models.entity_admin_filter import EntityAdminFilter
from opal_security.models.entity_item_type_enum import EntityItemTypeEnum
from opal_security.models.entity_name_filter import EntityNameFilter
from opal_security.models.entity_tag_filter import EntityTagFilter
+from opal_security.models.idp_status_filter import IdpStatusFilter
from typing import Optional, Set
from typing_extensions import Self
@@ -35,6 +37,8 @@ class AccessEntityFilters(BaseModel):
entity_item_types: Optional[List[EntityItemTypeEnum]] = Field(default=None, description="Filter by entity item types.", alias="entityItemTypes")
entity_name: Optional[EntityNameFilter] = Field(default=None, alias="entityName")
entity_tag: Optional[EntityTagFilter] = Field(default=None, alias="entityTag")
+ hr_idp_status: Optional[IdpStatusFilter] = Field(default=None, alias="hrIdpStatus")
+ entity_admin_owner: Optional[EntityAdminFilter] = Field(default=None, alias="entityAdminOwner")
entity_ids: Optional[List[UUID]] = Field(default=None, description="Filter by specific entity UUIDs.", alias="entityIDs")
imported_from_app: Optional[List[UUID]] = Field(default=None, description="Filter by app IDs from which returned nodes will be imported from.", alias="importedFromApp")
role_remote_ids: Optional[List[StrictStr]] = Field(default=None, description="Filter by role remote IDs. Can only be applied within a hasAccessTo clause.", alias="roleRemoteIds")
@@ -43,7 +47,7 @@ class AccessEntityFilters(BaseModel):
any_of: Optional[List[AccessEntityFilters]] = Field(default=None, description="A list of nested filters where at least one must match (logical OR). Each item has the same shape as this object. ", alias="anyOf")
var_not: Optional[Dict[str, Any]] = Field(default=None, description="Excludes entities matching the embedded filter (logical NOT). Pass a filter object with the same shape as this one — typically a single scalar field, like `{not: {entityTypes: [\"RESOURCE\"]}}` to exclude resources. ", alias="not")
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["entityTypes", "entityItemTypes", "entityName", "entityTag", "entityIDs", "importedFromApp", "roleRemoteIds", "roleNames", "allOf", "anyOf", "not"]
+ __properties: ClassVar[List[str]] = ["entityTypes", "entityItemTypes", "entityName", "entityTag", "hrIdpStatus", "entityAdminOwner", "entityIDs", "importedFromApp", "roleRemoteIds", "roleNames", "allOf", "anyOf", "not"]
@field_validator('entity_types')
def entity_types_validate_enum(cls, value):
@@ -103,6 +107,12 @@ def to_dict(self) -> Dict[str, Any]:
# override the default output from pydantic by calling `to_dict()` of entity_tag
if self.entity_tag:
_dict['entityTag'] = self.entity_tag.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of hr_idp_status
+ if self.hr_idp_status:
+ _dict['hrIdpStatus'] = self.hr_idp_status.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of entity_admin_owner
+ if self.entity_admin_owner:
+ _dict['entityAdminOwner'] = self.entity_admin_owner.to_dict()
# override the default output from pydantic by calling `to_dict()` of each item in all_of (list)
_items = []
if self.all_of:
@@ -138,6 +148,8 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"entityItemTypes": obj.get("entityItemTypes"),
"entityName": EntityNameFilter.from_dict(obj["entityName"]) if obj.get("entityName") is not None else None,
"entityTag": EntityTagFilter.from_dict(obj["entityTag"]) if obj.get("entityTag") is not None else None,
+ "hrIdpStatus": IdpStatusFilter.from_dict(obj["hrIdpStatus"]) if obj.get("hrIdpStatus") is not None else None,
+ "entityAdminOwner": EntityAdminFilter.from_dict(obj["entityAdminOwner"]) if obj.get("entityAdminOwner") is not None else None,
"entityIDs": obj.get("entityIDs"),
"importedFromApp": obj.get("importedFromApp"),
"roleRemoteIds": obj.get("roleRemoteIds"),
diff --git a/opal_security/models/add_group_resource_request.py b/opal_security/models/add_group_resource_request.py
index 77dfb0c..a5a69c2 100644
--- a/opal_security/models/add_group_resource_request.py
+++ b/opal_security/models/add_group_resource_request.py
@@ -29,7 +29,7 @@ class AddGroupResourceRequest(BaseModel):
AddGroupResourceRequest
""" # noqa: E501
access_level_remote_id: Optional[StrictStr] = Field(default=None, description="The remote ID of the access level to grant to this user. If omitted, the default access level remote ID value (empty string) is used.")
- duration_minutes: Optional[Annotated[int, Field(le=525960, strict=True, ge=0)]] = Field(default=None, description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")
+ duration_minutes: Optional[Annotated[int, Field(le=153722867, strict=True, ge=0)]] = Field(default=None, description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")
additional_properties: Dict[str, Any] = {}
__properties: ClassVar[List[str]] = ["access_level_remote_id", "duration_minutes"]
diff --git a/opal_security/models/add_resource_nhi_request.py b/opal_security/models/add_resource_nhi_request.py
index 2a1b55b..b71dede 100644
--- a/opal_security/models/add_resource_nhi_request.py
+++ b/opal_security/models/add_resource_nhi_request.py
@@ -28,7 +28,7 @@ class AddResourceNhiRequest(BaseModel):
"""
AddResourceNhiRequest
""" # noqa: E501
- duration_minutes: Annotated[int, Field(le=525960, strict=True)] = Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")
+ duration_minutes: Annotated[int, Field(le=153722867, strict=True)] = Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")
access_level_remote_id: Optional[StrictStr] = Field(default=None, description="The remote ID of the access level to grant. If omitted, the default access level remote ID value (empty string) is used.")
additional_properties: Dict[str, Any] = {}
__properties: ClassVar[List[str]] = ["duration_minutes", "access_level_remote_id"]
diff --git a/opal_security/models/add_resource_user_request.py b/opal_security/models/add_resource_user_request.py
index 0d395c4..7004c90 100644
--- a/opal_security/models/add_resource_user_request.py
+++ b/opal_security/models/add_resource_user_request.py
@@ -28,7 +28,7 @@ class AddResourceUserRequest(BaseModel):
"""
AddResourceUserRequest
""" # noqa: E501
- duration_minutes: Annotated[int, Field(le=525960, strict=True)] = Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")
+ duration_minutes: Annotated[int, Field(le=153722867, strict=True)] = Field(description="The duration for which the resource can be accessed (in minutes). Use 0 to set to indefinite.")
access_level_remote_id: Optional[StrictStr] = Field(default=None, description="The remote ID of the access level to grant to this user. If omitted, the default access level remote ID value (empty string) is used.")
additional_properties: Dict[str, Any] = {}
__properties: ClassVar[List[str]] = ["duration_minutes", "access_level_remote_id"]
diff --git a/opal_security/models/app_type_enum.py b/opal_security/models/app_type_enum.py
index 7031cd2..48da454 100644
--- a/opal_security/models/app_type_enum.py
+++ b/opal_security/models/app_type_enum.py
@@ -36,10 +36,13 @@ class AppTypeEnum(str, Enum):
COUPA = 'COUPA'
CURSOR = 'CURSOR'
CUSTOM = 'CUSTOM'
+ CONFLUENCE = 'CONFLUENCE'
CUSTOM_CONNECTOR = 'CUSTOM_CONNECTOR'
DATABRICKS = 'DATABRICKS'
DATASTAX_ASTRA = 'DATASTAX_ASTRA'
+ ALICLOUD = 'ALICLOUD'
DEVIN = 'DEVIN'
+ DOCUSIGN = 'DOCUSIGN'
DUO = 'DUO'
GCP = 'GCP'
GIT_HUB = 'GIT_HUB'
@@ -50,7 +53,9 @@ class AppTypeEnum(str, Enum):
HUBSPOT = 'HUBSPOT'
ILEVEL = 'ILEVEL'
INCIDENTIO = 'INCIDENTIO'
+ JIRA = 'JIRA'
LDAP = 'LDAP'
+ LINEAR = 'LINEAR'
MARIADB = 'MARIADB'
MONGO = 'MONGO'
MONGO_ATLAS = 'MONGO_ATLAS'
@@ -68,12 +73,14 @@ class AppTypeEnum(str, Enum):
SALESFORCE = 'SALESFORCE'
SNOWFLAKE = 'SNOWFLAKE'
SLACK = 'SLACK'
+ TABLEAU = 'TABLEAU'
TAILSCALE = 'TAILSCALE'
TELEPORT = 'TELEPORT'
TWINGATE = 'TWINGATE'
VAULT = 'VAULT'
WORKDAY = 'WORKDAY'
ZENDESK = 'ZENDESK'
+ ZOOM = 'ZOOM'
@classmethod
def from_json(cls, json_str: str) -> Self:
diff --git a/opal_security/models/campaign.py b/opal_security/models/campaign.py
new file mode 100644
index 0000000..6052422
--- /dev/null
+++ b/opal_security/models/campaign.py
@@ -0,0 +1,134 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.campaign_configuration import CampaignConfiguration
+from opal_security.models.campaign_status_enum import CampaignStatusEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class Campaign(BaseModel):
+ """
+ An access review campaign.
+ """ # noqa: E501
+ campaign_id: UUID = Field(description="The ID of the campaign.")
+ name: StrictStr = Field(description="The name of the campaign.")
+ status: CampaignStatusEnum
+ is_template: StrictBool = Field(description="Whether this campaign is a recurring schedule template. Templates spawn draft campaigns on schedule rather than being reviewed directly.")
+ created_at: datetime = Field(description="The creation time of the campaign.")
+ updated_at: datetime = Field(description="The last updated time of the campaign.")
+ created_by_user_id: UUID = Field(description="The ID of the user who created the campaign.")
+ configuration: Optional[CampaignConfiguration] = Field(default=None, description="The campaign's configuration, if set.")
+ started_at: Optional[datetime] = Field(default=None, description="The time the campaign was started, if started.")
+ started_by_user_id: Optional[UUID] = Field(default=None, description="The ID of the user who started the campaign, if started.")
+ stopped_at: Optional[datetime] = Field(default=None, description="The time the campaign was manually stopped, if stopped.")
+ stopped_by_user_id: Optional[UUID] = Field(default=None, description="The ID of the user who stopped the campaign, if stopped.")
+ ended_at: Optional[datetime] = Field(default=None, description="The time the campaign reached its scheduled end, if ended.")
+ ended_by_user_id: Optional[UUID] = Field(default=None, description="The ID of the user who ended the campaign, if ended.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["campaign_id", "name", "status", "is_template", "created_at", "updated_at", "created_by_user_id", "configuration", "started_at", "started_by_user_id", "stopped_at", "stopped_by_user_id", "ended_at", "ended_by_user_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of Campaign from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of configuration
+ if self.configuration:
+ _dict['configuration'] = self.configuration.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of Campaign from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "campaign_id": obj.get("campaign_id"),
+ "name": obj.get("name"),
+ "status": obj.get("status"),
+ "is_template": obj.get("is_template"),
+ "created_at": obj.get("created_at"),
+ "updated_at": obj.get("updated_at"),
+ "created_by_user_id": obj.get("created_by_user_id"),
+ "configuration": CampaignConfiguration.from_dict(obj["configuration"]) if obj.get("configuration") is not None else None,
+ "started_at": obj.get("started_at"),
+ "started_by_user_id": obj.get("started_by_user_id"),
+ "stopped_at": obj.get("stopped_at"),
+ "stopped_by_user_id": obj.get("stopped_by_user_id"),
+ "ended_at": obj.get("ended_at"),
+ "ended_by_user_id": obj.get("ended_by_user_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/campaign_configuration.py b/opal_security/models/campaign_configuration.py
new file mode 100644
index 0000000..11a319b
--- /dev/null
+++ b/opal_security/models/campaign_configuration.py
@@ -0,0 +1,154 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.campaign_group_asset_visibility_policy_enum import CampaignGroupAssetVisibilityPolicyEnum
+from opal_security.models.campaign_revoke_on_enum import CampaignRevokeOnEnum
+from opal_security.models.opal_access_path_query_body import OpalAccessPathQueryBody
+from opal_security.models.uar_reviewer_assignment_policy_enum import UARReviewerAssignmentPolicyEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CampaignConfiguration(BaseModel):
+ """
+ Configuration for an access review campaign.
+ """ # noqa: E501
+ configuration_id: UUID = Field(description="The ID of the campaign configuration.")
+ created_at: datetime = Field(description="The creation time of the configuration.")
+ updated_at: datetime = Field(description="The last updated time of the configuration.")
+ query: Optional[OpalAccessPathQueryBody] = Field(default=None, description="Access-path query defining the scope of access to review. Uses the same principalFilter / entitlementFilter shape as ACCESS_PATH OpalQuery.")
+ reviewer_assignment_policy: UARReviewerAssignmentPolicyEnum
+ allow_self_review: StrictBool = Field(description="Whether reviewers can review their own access.")
+ send_reviewer_assignment_notification: StrictBool = Field(description="Whether to notify reviewers upon assignment.")
+ allow_reviewer_reassignment: StrictBool = Field(description="Whether reviewers may reassign their reviews to another user.")
+ start_date: Optional[datetime] = Field(default=None, description="Scheduled start date of the campaign.")
+ end_date: Optional[datetime] = Field(default=None, description="Scheduled end date of the campaign.")
+ timezone: StrictStr = Field(description="IANA timezone used to interpret campaign deadlines (e.g. America/Los_Angeles).")
+ revoke_on: CampaignRevokeOnEnum
+ reminder_schedule: Optional[List[StrictInt]] = Field(default=None, description="Days before end date to send reminder notifications.")
+ reminder_include_manager: StrictBool = Field(description="Whether to include the reviewer's manager in reminders.")
+ require_reason_on_denial: StrictBool = Field(description="Whether reviewers must provide a reason when denying (revoking) access.")
+ hide_ai_suggestions: StrictBool = Field(description="Whether AI suggestions are hidden from reviewers.")
+ custom_start_message: Optional[StrictStr] = Field(default=None, description="Optional custom message included when notifying reviewers that the campaign started.")
+ group_asset_visibility_policy: CampaignGroupAssetVisibilityPolicyEnum
+ is_template: StrictBool = Field(description="Whether this configuration is a recurring schedule template.")
+ cron_expression: Optional[StrictStr] = Field(default=None, description="Cron expression driving the recurring schedule. Null for one-off campaigns.")
+ next_scheduled_run: Optional[datetime] = Field(default=None, description="Next time a draft will be generated from this template.")
+ last_scheduled_run: Optional[datetime] = Field(default=None, description="Most recent time a draft was generated from this template.")
+ recurring_duration_days: Optional[StrictInt] = Field(default=None, description="Deadline window in days applied to each draft generated from this template.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["configuration_id", "created_at", "updated_at", "query", "reviewer_assignment_policy", "allow_self_review", "send_reviewer_assignment_notification", "allow_reviewer_reassignment", "start_date", "end_date", "timezone", "revoke_on", "reminder_schedule", "reminder_include_manager", "require_reason_on_denial", "hide_ai_suggestions", "custom_start_message", "group_asset_visibility_policy", "is_template", "cron_expression", "next_scheduled_run", "last_scheduled_run", "recurring_duration_days"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CampaignConfiguration from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of query
+ if self.query:
+ _dict['query'] = self.query.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CampaignConfiguration from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "configuration_id": obj.get("configuration_id"),
+ "created_at": obj.get("created_at"),
+ "updated_at": obj.get("updated_at"),
+ "query": OpalAccessPathQueryBody.from_dict(obj["query"]) if obj.get("query") is not None else None,
+ "reviewer_assignment_policy": obj.get("reviewer_assignment_policy"),
+ "allow_self_review": obj.get("allow_self_review"),
+ "send_reviewer_assignment_notification": obj.get("send_reviewer_assignment_notification"),
+ "allow_reviewer_reassignment": obj.get("allow_reviewer_reassignment"),
+ "start_date": obj.get("start_date"),
+ "end_date": obj.get("end_date"),
+ "timezone": obj.get("timezone"),
+ "revoke_on": obj.get("revoke_on"),
+ "reminder_schedule": obj.get("reminder_schedule"),
+ "reminder_include_manager": obj.get("reminder_include_manager"),
+ "require_reason_on_denial": obj.get("require_reason_on_denial"),
+ "hide_ai_suggestions": obj.get("hide_ai_suggestions"),
+ "custom_start_message": obj.get("custom_start_message"),
+ "group_asset_visibility_policy": obj.get("group_asset_visibility_policy"),
+ "is_template": obj.get("is_template"),
+ "cron_expression": obj.get("cron_expression"),
+ "next_scheduled_run": obj.get("next_scheduled_run"),
+ "last_scheduled_run": obj.get("last_scheduled_run"),
+ "recurring_duration_days": obj.get("recurring_duration_days")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/campaign_group_asset_visibility_policy_enum.py b/opal_security/models/campaign_group_asset_visibility_policy_enum.py
new file mode 100644
index 0000000..68deed0
--- /dev/null
+++ b/opal_security/models/campaign_group_asset_visibility_policy_enum.py
@@ -0,0 +1,39 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class CampaignGroupAssetVisibilityPolicyEnum(str, Enum):
+ """
+ Controls what group assets reviewers can see during the campaign.
+ """
+
+ """
+ allowed enum values
+ """
+ STRICT = 'STRICT'
+ VIEW_VISIBLE_AND_ASSIGNED = 'VIEW_VISIBLE_AND_ASSIGNED'
+ VIEW_ALL = 'VIEW_ALL'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of CampaignGroupAssetVisibilityPolicyEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/campaign_item.py b/opal_security/models/campaign_item.py
new file mode 100644
index 0000000..1de76be
--- /dev/null
+++ b/opal_security/models/campaign_item.py
@@ -0,0 +1,150 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.campaign_item_admin_override import CampaignItemAdminOverride
+from opal_security.models.campaign_item_review import CampaignItemReview
+from opal_security.models.campaign_item_status_enum import CampaignItemStatusEnum
+from opal_security.models.campaign_item_target_type_enum import CampaignItemTargetTypeEnum
+from opal_security.models.entity_type_enum import EntityTypeEnum
+from opal_security.models.resource_access_level import ResourceAccessLevel
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CampaignItem(BaseModel):
+ """
+ A campaign review item — one direct access edge under review, matching a row on the admin Reviews tab.
+ """ # noqa: E501
+ campaign_item_id: UUID = Field(description="The ID of the campaign item.")
+ campaign_id: UUID = Field(description="The ID of the parent campaign.")
+ target_type: CampaignItemTargetTypeEnum
+ role_assignment_id: UUID = Field(description="The role assignment ID this item reviews (`target_id` when `target_type` is ROLE_ASSIGNMENT). ")
+ status: CampaignItemStatusEnum
+ created_at: datetime = Field(description="When the item was created (snapshotted into the campaign).")
+ is_target_deleted: StrictBool = Field(description="True when the underlying role assignment is soft-deleted.")
+ principal_id: Optional[UUID] = Field(default=None, description="Principal ID from the role assignment. Null if the RA is missing.")
+ principal_type: Optional[EntityTypeEnum] = Field(default=None, description="Principal entity type. Null if the RA is missing.")
+ entity_id: Optional[UUID] = Field(default=None, description="Entitlement entity ID. Null if the RA is missing.")
+ entity_type: Optional[EntityTypeEnum] = Field(default=None, description="Entitlement entity type. Null if the RA is missing.")
+ access_level: Optional[ResourceAccessLevel] = Field(default=None, description="Access level on the role assignment, if any.")
+ access_level_name: Optional[StrictStr] = Field(default=None, description="Denormalized access level name stored on the campaign item.")
+ reviews: List[CampaignItemReview] = Field(description="Reviewer assignments and decisions for this item.")
+ admin_override: Optional[CampaignItemAdminOverride] = Field(default=None, description="Admin override, if any.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["campaign_item_id", "campaign_id", "target_type", "role_assignment_id", "status", "created_at", "is_target_deleted", "principal_id", "principal_type", "entity_id", "entity_type", "access_level", "access_level_name", "reviews", "admin_override"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CampaignItem from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of access_level
+ if self.access_level:
+ _dict['access_level'] = self.access_level.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of each item in reviews (list)
+ _items = []
+ if self.reviews:
+ for _item_reviews in self.reviews:
+ if _item_reviews:
+ _items.append(_item_reviews.to_dict())
+ _dict['reviews'] = _items
+ # override the default output from pydantic by calling `to_dict()` of admin_override
+ if self.admin_override:
+ _dict['admin_override'] = self.admin_override.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CampaignItem from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "campaign_item_id": obj.get("campaign_item_id"),
+ "campaign_id": obj.get("campaign_id"),
+ "target_type": obj.get("target_type"),
+ "role_assignment_id": obj.get("role_assignment_id"),
+ "status": obj.get("status"),
+ "created_at": obj.get("created_at"),
+ "is_target_deleted": obj.get("is_target_deleted"),
+ "principal_id": obj.get("principal_id"),
+ "principal_type": obj.get("principal_type"),
+ "entity_id": obj.get("entity_id"),
+ "entity_type": obj.get("entity_type"),
+ "access_level": ResourceAccessLevel.from_dict(obj["access_level"]) if obj.get("access_level") is not None else None,
+ "access_level_name": obj.get("access_level_name"),
+ "reviews": [CampaignItemReview.from_dict(_item) for _item in obj["reviews"]] if obj.get("reviews") is not None else None,
+ "admin_override": CampaignItemAdminOverride.from_dict(obj["admin_override"]) if obj.get("admin_override") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/campaign_item_admin_override.py b/opal_security/models/campaign_item_admin_override.py
new file mode 100644
index 0000000..17ca804
--- /dev/null
+++ b/opal_security/models/campaign_item_admin_override.py
@@ -0,0 +1,108 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field
+from typing import Any, ClassVar, Dict, List
+from uuid import UUID
+from opal_security.models.campaign_item_review_decision_enum import CampaignItemReviewDecisionEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CampaignItemAdminOverride(BaseModel):
+ """
+ Admin override applied to a campaign item. When set, it takes precedence over reviewer decisions for status and end-campaign remediations.
+ """ # noqa: E501
+ actor_user_id: UUID = Field(description="The admin who applied the override.")
+ decision: CampaignItemReviewDecisionEnum
+ decided_at: datetime = Field(description="When the override was applied.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["actor_user_id", "decision", "decided_at"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CampaignItemAdminOverride from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CampaignItemAdminOverride from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "actor_user_id": obj.get("actor_user_id"),
+ "decision": obj.get("decision"),
+ "decided_at": obj.get("decided_at")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/campaign_item_review.py b/opal_security/models/campaign_item_review.py
new file mode 100644
index 0000000..42f0e15
--- /dev/null
+++ b/opal_security/models/campaign_item_review.py
@@ -0,0 +1,119 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.campaign_item_review_decision_enum import CampaignItemReviewDecisionEnum
+from opal_security.models.campaign_item_reviewer_assignment_source_enum import CampaignItemReviewerAssignmentSourceEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CampaignItemReview(BaseModel):
+ """
+ A single reviewer's assignment and decision for a campaign item.
+ """ # noqa: E501
+ campaign_item_review_id: UUID = Field(description="The ID of the campaign item review.")
+ campaign_item_id: UUID = Field(description="The ID of the campaign item.")
+ reviewer_user_id: UUID = Field(description="The ID of the assigned reviewer.")
+ assignment_source: CampaignItemReviewerAssignmentSourceEnum
+ decision: Optional[CampaignItemReviewDecisionEnum] = Field(default=None, description="The reviewer's decision. Null when the reviewer has not yet submitted. ")
+ note: Optional[StrictStr] = Field(default=None, description="Optional note from the reviewer.")
+ updated_access_level_remote_id: Optional[StrictStr] = Field(default=None, description="Target access level remote ID when decision is CHANGE_ROLE.")
+ decided_at: Optional[datetime] = Field(default=None, description="When the decision was finalized.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["campaign_item_review_id", "campaign_item_id", "reviewer_user_id", "assignment_source", "decision", "note", "updated_access_level_remote_id", "decided_at"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CampaignItemReview from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CampaignItemReview from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "campaign_item_review_id": obj.get("campaign_item_review_id"),
+ "campaign_item_id": obj.get("campaign_item_id"),
+ "reviewer_user_id": obj.get("reviewer_user_id"),
+ "assignment_source": obj.get("assignment_source"),
+ "decision": obj.get("decision"),
+ "note": obj.get("note"),
+ "updated_access_level_remote_id": obj.get("updated_access_level_remote_id"),
+ "decided_at": obj.get("decided_at")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/campaign_item_review_decision_enum.py b/opal_security/models/campaign_item_review_decision_enum.py
new file mode 100644
index 0000000..6c7874e
--- /dev/null
+++ b/opal_security/models/campaign_item_review_decision_enum.py
@@ -0,0 +1,44 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class CampaignItemReviewDecisionEnum(str, Enum):
+ """
+ Decision recorded on a campaign item review row.
+ """
+
+ """
+ allowed enum values
+ """
+ APPROVED = 'APPROVED'
+ REVOKED = 'REVOKED'
+ CHANGE_ROLE = 'CHANGE_ROLE'
+ ADMIN_REVOKED = 'ADMIN_REVOKED'
+ NO_ACTION = 'NO_ACTION'
+ REASSIGNED = 'REASSIGNED'
+ ADMIN_OVERRIDE_APPROVED = 'ADMIN_OVERRIDE_APPROVED'
+ ADMIN_OVERRIDE_REVOKED = 'ADMIN_OVERRIDE_REVOKED'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of CampaignItemReviewDecisionEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/campaign_item_reviewer_assignment_source_enum.py b/opal_security/models/campaign_item_reviewer_assignment_source_enum.py
new file mode 100644
index 0000000..9f1f055
--- /dev/null
+++ b/opal_security/models/campaign_item_reviewer_assignment_source_enum.py
@@ -0,0 +1,39 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class CampaignItemReviewerAssignmentSourceEnum(str, Enum):
+ """
+ How a reviewer was assigned to a campaign item.
+ """
+
+ """
+ allowed enum values
+ """
+ MANUAL = 'MANUAL'
+ PRINCIPAL_MANAGER = 'PRINCIPAL_MANAGER'
+ ASSET_ADMIN_OWNER = 'ASSET_ADMIN_OWNER'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of CampaignItemReviewerAssignmentSourceEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/campaign_item_status_enum.py b/opal_security/models/campaign_item_status_enum.py
new file mode 100644
index 0000000..3a81988
--- /dev/null
+++ b/opal_security/models/campaign_item_status_enum.py
@@ -0,0 +1,43 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class CampaignItemStatusEnum(str, Enum):
+ """
+ Derived aggregate status for a campaign item. Matches the admin Reviews tab Status column labels (undecided items on a stopped campaign are PENDING, not a separate stopped status).
+ """
+
+ """
+ allowed enum values
+ """
+ PENDING = 'PENDING'
+ COMPLETED = 'COMPLETED'
+ APPROVED = 'APPROVED'
+ REVOKED = 'REVOKED'
+ NO_ACTION = 'NO_ACTION'
+ CHANGED_ROLE = 'CHANGED_ROLE'
+ ADMIN_REVOKED = 'ADMIN_REVOKED'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of CampaignItemStatusEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/campaign_item_target_type_enum.py b/opal_security/models/campaign_item_target_type_enum.py
new file mode 100644
index 0000000..ab338ef
--- /dev/null
+++ b/opal_security/models/campaign_item_target_type_enum.py
@@ -0,0 +1,37 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class CampaignItemTargetTypeEnum(str, Enum):
+ """
+ Type of access edge the campaign item reviews.
+ """
+
+ """
+ allowed enum values
+ """
+ ROLE_ASSIGNMENT = 'ROLE_ASSIGNMENT'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of CampaignItemTargetTypeEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/campaign_revoke_on_enum.py b/opal_security/models/campaign_revoke_on_enum.py
new file mode 100644
index 0000000..0c9273c
--- /dev/null
+++ b/opal_security/models/campaign_revoke_on_enum.py
@@ -0,0 +1,39 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class CampaignRevokeOnEnum(str, Enum):
+ """
+ When access decisions take effect during a campaign.
+ """
+
+ """
+ allowed enum values
+ """
+ ACTION = 'ACTION'
+ END = 'END'
+ NONE = 'NONE'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of CampaignRevokeOnEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/campaign_status_enum.py b/opal_security/models/campaign_status_enum.py
new file mode 100644
index 0000000..c3ce7a6
--- /dev/null
+++ b/opal_security/models/campaign_status_enum.py
@@ -0,0 +1,41 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class CampaignStatusEnum(str, Enum):
+ """
+ The current status of a campaign.
+ """
+
+ """
+ allowed enum values
+ """
+ DRAFT = 'DRAFT'
+ ONGOING = 'ONGOING'
+ COMPLETED = 'COMPLETED'
+ STOPPED = 'STOPPED'
+ ENDED = 'ENDED'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of CampaignStatusEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/create_campaign_configuration_info.py b/opal_security/models/create_campaign_configuration_info.py
new file mode 100644
index 0000000..1530dd9
--- /dev/null
+++ b/opal_security/models/create_campaign_configuration_info.py
@@ -0,0 +1,146 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.campaign_group_asset_visibility_policy_enum import CampaignGroupAssetVisibilityPolicyEnum
+from opal_security.models.campaign_revoke_on_enum import CampaignRevokeOnEnum
+from opal_security.models.opal_access_path_query_body import OpalAccessPathQueryBody
+from opal_security.models.uar_reviewer_assignment_policy_enum import UARReviewerAssignmentPolicyEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CreateCampaignConfigurationInfo(BaseModel):
+ """
+ Configuration to apply when creating a campaign. `query` is required; other omitted fields use defaults.
+ """ # noqa: E501
+ query: OpalAccessPathQueryBody = Field(description="Access-path query defining the scope of access to review. Required. Uses the same principalFilter / entitlementFilter shape as ACCESS_PATH OpalQuery. Must include at least one of principalFilter or entitlementFilter. Campaign scope only supports direct access edges: `edgeFilter.directOnly` defaults to `true`, is always stored as `true`, and passing `false` returns 400. ")
+ reviewer_assignment_policy: Optional[UARReviewerAssignmentPolicyEnum] = None
+ allow_self_review: Optional[StrictBool] = Field(default=None, description="Whether reviewers can review their own access.")
+ send_reviewer_assignment_notification: Optional[StrictBool] = Field(default=None, description="Whether to notify reviewers upon assignment.")
+ allow_reviewer_reassignment: Optional[StrictBool] = Field(default=None, description="Whether reviewers may reassign their reviews to another user.")
+ start_date: Optional[datetime] = Field(default=None, description="Scheduled start date of the campaign.")
+ end_date: Optional[datetime] = Field(default=None, description="Scheduled end date of the campaign.")
+ timezone: Optional[StrictStr] = Field(default=None, description="IANA timezone used to interpret campaign deadlines (e.g. America/Los_Angeles).")
+ revoke_on: Optional[CampaignRevokeOnEnum] = None
+ reminder_schedule: Optional[List[StrictInt]] = Field(default=None, description="Days before end date to send reminder notifications.")
+ reminder_include_manager: Optional[StrictBool] = Field(default=None, description="Whether to include the reviewer's manager in reminders.")
+ require_reason_on_denial: Optional[StrictBool] = Field(default=None, description="Whether reviewers must provide a reason when denying (revoking) access.")
+ hide_ai_suggestions: Optional[StrictBool] = Field(default=None, description="Whether AI suggestions are hidden from reviewers.")
+ custom_start_message: Optional[StrictStr] = Field(default=None, description="Optional custom message included when notifying reviewers that the campaign started.")
+ group_asset_visibility_policy: Optional[CampaignGroupAssetVisibilityPolicyEnum] = None
+ is_template: Optional[StrictBool] = Field(default=None, description="Whether this configuration is a recurring schedule template.")
+ cron_expression: Optional[StrictStr] = Field(default=None, description="Cron expression driving the recurring schedule. Null for one-off campaigns.")
+ recurring_duration_days: Optional[StrictInt] = Field(default=None, description="Deadline window in days applied to each draft generated from this template.")
+ excluded_role_assignment_ids: Optional[List[UUID]] = Field(default=None, description="Role assignment IDs to exclude from the campaign scope during population.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["query", "reviewer_assignment_policy", "allow_self_review", "send_reviewer_assignment_notification", "allow_reviewer_reassignment", "start_date", "end_date", "timezone", "revoke_on", "reminder_schedule", "reminder_include_manager", "require_reason_on_denial", "hide_ai_suggestions", "custom_start_message", "group_asset_visibility_policy", "is_template", "cron_expression", "recurring_duration_days", "excluded_role_assignment_ids"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CreateCampaignConfigurationInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of query
+ if self.query:
+ _dict['query'] = self.query.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CreateCampaignConfigurationInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "query": OpalAccessPathQueryBody.from_dict(obj["query"]) if obj.get("query") is not None else None,
+ "reviewer_assignment_policy": obj.get("reviewer_assignment_policy"),
+ "allow_self_review": obj.get("allow_self_review"),
+ "send_reviewer_assignment_notification": obj.get("send_reviewer_assignment_notification"),
+ "allow_reviewer_reassignment": obj.get("allow_reviewer_reassignment"),
+ "start_date": obj.get("start_date"),
+ "end_date": obj.get("end_date"),
+ "timezone": obj.get("timezone"),
+ "revoke_on": obj.get("revoke_on"),
+ "reminder_schedule": obj.get("reminder_schedule"),
+ "reminder_include_manager": obj.get("reminder_include_manager"),
+ "require_reason_on_denial": obj.get("require_reason_on_denial"),
+ "hide_ai_suggestions": obj.get("hide_ai_suggestions"),
+ "custom_start_message": obj.get("custom_start_message"),
+ "group_asset_visibility_policy": obj.get("group_asset_visibility_policy"),
+ "is_template": obj.get("is_template"),
+ "cron_expression": obj.get("cron_expression"),
+ "recurring_duration_days": obj.get("recurring_duration_days"),
+ "excluded_role_assignment_ids": obj.get("excluded_role_assignment_ids")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/create_campaign_info.py b/opal_security/models/create_campaign_info.py
new file mode 100644
index 0000000..ac3bc43
--- /dev/null
+++ b/opal_security/models/create_campaign_info.py
@@ -0,0 +1,107 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from opal_security.models.create_campaign_configuration_info import CreateCampaignConfigurationInfo
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CreateCampaignInfo(BaseModel):
+ """
+ # CreateCampaignInfo Object ### Description The `CreateCampaignInfo` object is used to create a campaign. ### Usage Example Use in the `POST Campaigns` endpoint.
+ """ # noqa: E501
+ name: StrictStr = Field(description="The name of the campaign.")
+ configuration: CreateCampaignConfigurationInfo = Field(description="Configuration for the campaign. Required; must include a query. Other omitted fields use defaults.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["name", "configuration"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CreateCampaignInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of configuration
+ if self.configuration:
+ _dict['configuration'] = self.configuration.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CreateCampaignInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "name": obj.get("name"),
+ "configuration": CreateCampaignConfigurationInfo.from_dict(obj["configuration"]) if obj.get("configuration") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/create_group_info.py b/opal_security/models/create_group_info.py
index cd7480a..7dd715d 100644
--- a/opal_security/models/create_group_info.py
+++ b/opal_security/models/create_group_info.py
@@ -18,7 +18,7 @@
import re # noqa: F401
import json
-from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
from typing import Any, ClassVar, Dict, List, Optional
from typing_extensions import Annotated
from uuid import UUID
@@ -41,8 +41,13 @@ class CreateGroupInfo(BaseModel):
metadata: Optional[StrictStr] = Field(default=None, description="Deprecated - use remote_info instead. JSON metadata about the remote group. Include only for items linked to remote systems. See [this guide](https://docs.opal.dev/reference/end-system-objects) for details on how to specify this field. The required format is dependent on group_type and should have the following schema: ```json { \"$schema\": \"http://json-schema.org/draft-04/schema#\", \"title\": \"Group Metadata\", \"properties\": { \"ad_group\": { \"properties\": { \"object_guid\": { \"type\": \"string\" } }, \"required\": [\"object_guid\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Active Directory Group\" }, \"duo_group\": { \"properties\": { \"group_id\": { \"type\": \"string\" } }, \"required\": [\"group_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Duo Group\" }, \"git_hub_team\": { \"properties\": { \"org_name\": { \"type\": \"string\" }, \"team_slug\": { \"type\": \"string\" } }, \"required\": [\"org_name\", \"team_slug\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GitHub Team\" }, \"google_groups_group\": { \"properties\": { \"group_id\": { \"type\": \"string\" } }, \"required\": [\"group_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Google Groups Group\" }, \"ldap_group\": { \"properties\": { \"group_uid\": { \"type\": \"string\" } }, \"required\": [\"group_uid\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"LDAP Group\" }, \"okta_directory_group\": { \"properties\": { \"group_id\": { \"type\": \"string\" } }, \"required\": [\"group_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Okta Directory Group\" } }, \"additionalProperties\": false, \"minProperties\": 1, \"maxProperties\": 1, \"type\": \"object\" } ```")
custom_request_notification: Optional[Annotated[str, Field(strict=True, max_length=800)]] = Field(default=None, description="Custom request notification sent upon request approval.")
risk_sensitivity_override: Optional[RiskSensitivityEnum] = None
+ match_remote_name: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the group's name should be synced from the end system. When true, the name is overwritten with the remote name on each sync, so a `name` provided together with this field set to true will be replaced at the next sync. Defaults to false.")
+ match_remote_description: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the group's description should be synced from the end system. When true, the description is overwritten with the remote description on each sync, so a `description` provided together with this field set to true will be replaced at the next sync. Defaults to false.")
+ handle: Optional[StrictStr] = Field(default=None, description="Slack user group mention name, without the @. Optional; Slack assigns one if omitted.")
+ team_id: Optional[StrictStr] = Field(default=None, description="Slack workspace ID. Required when the Slack connection spans multiple workspaces.")
+ initial_user_ids: Optional[List[UUID]] = Field(default=None, description="Opal user IDs to add as the group's initial members. Required when creating a Slack user group.")
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["name", "description", "group_type", "app_id", "remote_info", "remote_group_id", "metadata", "custom_request_notification", "risk_sensitivity_override"]
+ __properties: ClassVar[List[str]] = ["name", "description", "group_type", "app_id", "remote_info", "remote_group_id", "metadata", "custom_request_notification", "risk_sensitivity_override", "match_remote_name", "match_remote_description", "handle", "team_id", "initial_user_ids"]
model_config = ConfigDict(
populate_by_name=True,
@@ -113,7 +118,12 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"remote_group_id": obj.get("remote_group_id"),
"metadata": obj.get("metadata"),
"custom_request_notification": obj.get("custom_request_notification"),
- "risk_sensitivity_override": obj.get("risk_sensitivity_override")
+ "risk_sensitivity_override": obj.get("risk_sensitivity_override"),
+ "match_remote_name": obj.get("match_remote_name"),
+ "match_remote_description": obj.get("match_remote_description"),
+ "handle": obj.get("handle"),
+ "team_id": obj.get("team_id"),
+ "initial_user_ids": obj.get("initial_user_ids")
})
# store additional fields in additional_properties
for _key in obj.keys():
diff --git a/opal_security/models/create_paladin_context_source_info.py b/opal_security/models/create_paladin_context_source_info.py
new file mode 100644
index 0000000..3b31ff9
--- /dev/null
+++ b/opal_security/models/create_paladin_context_source_info.py
@@ -0,0 +1,111 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.paladin_context_source_kind import PaladinContextSourceKind
+from opal_security.models.paladin_context_source_provider import PaladinContextSourceProvider
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CreatePaladinContextSourceInfo(BaseModel):
+ """
+ Information for adding a context source to a Paladin.
+ """ # noqa: E501
+ source_kind: PaladinContextSourceKind
+ third_party_provider: PaladinContextSourceProvider
+ remote_id: StrictStr = Field(description="The provider's identifier for the source. The Slack channel ID for a channel, or the Notion/Confluence page ID for a document.")
+ name: Optional[StrictStr] = Field(default=None, description="An optional human-readable name for the source.")
+ url: Optional[StrictStr] = Field(default=None, description="An optional link to the source.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["source_kind", "third_party_provider", "remote_id", "name", "url"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CreatePaladinContextSourceInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CreatePaladinContextSourceInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "source_kind": obj.get("source_kind"),
+ "third_party_provider": obj.get("third_party_provider"),
+ "remote_id": obj.get("remote_id"),
+ "name": obj.get("name"),
+ "url": obj.get("url")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/create_paladin_info.py b/opal_security/models/create_paladin_info.py
new file mode 100644
index 0000000..3b982e6
--- /dev/null
+++ b/opal_security/models/create_paladin_info.py
@@ -0,0 +1,113 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.paladin_connector import PaladinConnector
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CreatePaladinInfo(BaseModel):
+ """
+ Information for creating a Paladin.
+ """ # noqa: E501
+ name: StrictStr = Field(description="The name of the Paladin.")
+ owner_id: UUID = Field(description="The ID of the owner of the Paladin.")
+ monitor_mode: Optional[StrictBool] = Field(default=True, description="When true, the Paladin reasons about requests but takes no action. Defaults to true.")
+ admin_view_only: Optional[StrictBool] = Field(default=False, description="When true, recommendations are visible only to admins. Only meaningful when monitor_mode is true. Defaults to false.")
+ enabled_connectors: Optional[List[PaladinConnector]] = Field(default=None, description="The connectors the Paladin is allowed to use.")
+ instructions: Optional[StrictStr] = Field(default=None, description="The free-form instructions that guide the Paladin's decisions. Optional; if omitted the Paladin is created without instructions.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["name", "owner_id", "monitor_mode", "admin_view_only", "enabled_connectors", "instructions"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CreatePaladinInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CreatePaladinInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "name": obj.get("name"),
+ "owner_id": obj.get("owner_id"),
+ "monitor_mode": obj.get("monitor_mode") if obj.get("monitor_mode") is not None else True,
+ "admin_view_only": obj.get("admin_view_only") if obj.get("admin_view_only") is not None else False,
+ "enabled_connectors": obj.get("enabled_connectors"),
+ "instructions": obj.get("instructions")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/create_request_template_info.py b/opal_security/models/create_request_template_info.py
new file mode 100644
index 0000000..0c2bf79
--- /dev/null
+++ b/opal_security/models/create_request_template_info.py
@@ -0,0 +1,111 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.request_template_custom_field_input import RequestTemplateCustomFieldInput
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CreateRequestTemplateInfo(BaseModel):
+ """
+ Information for creating a request template.
+ """ # noqa: E501
+ name: StrictStr = Field(description="The name of the request template.")
+ custom_fields: Optional[List[RequestTemplateCustomFieldInput]] = Field(default=None, description="The fields to put on the template, in the order they are shown.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["name", "custom_fields"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CreateRequestTemplateInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in custom_fields (list)
+ _items = []
+ if self.custom_fields:
+ for _item_custom_fields in self.custom_fields:
+ if _item_custom_fields:
+ _items.append(_item_custom_fields.to_dict())
+ _dict['custom_fields'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CreateRequestTemplateInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "name": obj.get("name"),
+ "custom_fields": [RequestTemplateCustomFieldInput.from_dict(_item) for _item in obj["custom_fields"]] if obj.get("custom_fields") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/create_resource_custom_access_level_info.py b/opal_security/models/create_resource_custom_access_level_info.py
new file mode 100644
index 0000000..f27c5a0
--- /dev/null
+++ b/opal_security/models/create_resource_custom_access_level_info.py
@@ -0,0 +1,111 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.resource_access_level import ResourceAccessLevel
+from typing import Optional, Set
+from typing_extensions import Self
+
+class CreateResourceCustomAccessLevelInfo(BaseModel):
+ """
+ Info for creating a custom access level.
+ """ # noqa: E501
+ access_level: ResourceAccessLevel
+ policy: Optional[StrictStr] = Field(default=None, description="The policy document.")
+ requestable_by_default: Optional[StrictBool] = Field(default=None, description="Whether the role is requestable. Defaults to false.")
+ stackable_sensitivity_index: Optional[StrictInt] = Field(default=None, description="The sensitivity index. Null to leave unranked.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["access_level", "policy", "requestable_by_default", "stackable_sensitivity_index"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of CreateResourceCustomAccessLevelInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of access_level
+ if self.access_level:
+ _dict['access_level'] = self.access_level.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of CreateResourceCustomAccessLevelInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "access_level": ResourceAccessLevel.from_dict(obj["access_level"]) if obj.get("access_level") is not None else None,
+ "policy": obj.get("policy"),
+ "requestable_by_default": obj.get("requestable_by_default"),
+ "stackable_sensitivity_index": obj.get("stackable_sensitivity_index")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/create_resource_info.py b/opal_security/models/create_resource_info.py
index 4d8c535..16654bb 100644
--- a/opal_security/models/create_resource_info.py
+++ b/opal_security/models/create_resource_info.py
@@ -18,7 +18,7 @@
import re # noqa: F401
import json
-from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
from typing import Any, ClassVar, Dict, List, Optional
from typing_extensions import Annotated
from uuid import UUID
@@ -41,8 +41,10 @@ class CreateResourceInfo(BaseModel):
metadata: Optional[StrictStr] = Field(default=None, description="Deprecated - use remote_info instead. JSON metadata about the remote resource. Include only for items linked to remote systems. See [this guide](https://docs.opal.dev/reference/end-system-objects) for details on how to specify this field. The required format is dependent on resource_type and should have the following schema: ```json { \"$schema\": \"http://json-schema.org/draft-04/schema#\", \"title\": \"Resource Metadata\", \"properties\": { \"aws_ec2_instance\": { \"properties\": { \"instance_id\": { \"type\": \"string\" }, \"region\": { \"type\": \"string\" } }, \"required\": [\"instance_id\", \"region\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"AWS EC2 Instance\" }, \"aws_eks_cluster\": { \"properties\": { \"cluster_name\": { \"type\": \"string\" }, \"cluster_region\": { \"type\": \"string\" }, \"cluster_arn\": { \"type\": \"string\" } }, \"required\": [\"cluster_name\", \"cluster_region\", \"cluster_arn\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"AWS EKS Cluster\" }, \"aws_rds_instance\": { \"properties\": { \"instance_id\": { \"type\": \"string\" }, \"engine\": { \"type\": \"string\" }, \"region\": { \"type\": \"string\" }, \"resource_id\": { \"type\": \"string\" }, \"database_name\": { \"type\": \"string\" } }, \"required\": [ \"instance_id\", \"engine\", \"region\", \"resource_id\", \"database_name\" ], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"AWS RDS Instance\" }, \"aws_role\": { \"properties\": { \"arn\": { \"type\": \"string\" }, \"name\": { \"type\": \"string\" } }, \"required\": [\"arn\", \"name\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"AWS Role\" }, \"gcp_bucket\": { \"properties\": { \"bucket_id\": { \"type\": \"string\" } }, \"required\": [\"bucket_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP Bucket\" }, \"gcp_compute_instance\": { \"properties\": { \"instance_id\": { \"type\": \"string\" }, \"project_id\": { \"type\": \"string\" }, \"zone\": { \"type\": \"string\" } }, \"required\": [\"instance_id\", \"project_id\", \"zone\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP Compute Instance\" }, \"gcp_folder\": { \"properties\": { \"folder_id\": { \"type\": \"string\" } }, \"required\": [\"folder_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP Folder\" }, \"gcp_gke_cluster\": { \"properties\": { \"cluster_name\": { \"type\": \"string\" } }, \"required\": [\"cluster_name\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP GKE Cluster\" }, \"gcp_project\": { \"properties\": { \"project_id\": { \"type\": \"string\" } }, \"required\": [\"project_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP Project\" }, \"gcp_sql_instance\": { \"properties\": { \"instance_id\": { \"type\": \"string\" }, \"project_id\": { \"type\": \"string\" } }, \"required\": [\"instance_id\", \"project_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GCP SQL Instance\" }, \"git_hub_repo\": { \"properties\": { \"org_name\": { \"type\": \"string\" }, \"repo_name\": { \"type\": \"string\" } }, \"required\": [\"org_name\", \"repo_name\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"GitHub Repo\" }, \"okta_directory_app\": { \"properties\": { \"app_id\": { \"type\": \"string\" }, \"logo_url\": { \"type\": \"string\" } }, \"required\": [\"app_id\", \"logo_url\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Okta Directory App\" }, \"okta_directory_role\": { \"properties\": { \"role_type\": { \"type\": \"string\" }, \"role_id\": { \"type\": \"string\" } }, \"required\": [\"role_type\", \"role_id\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Okta Directory Role\" }, \"salesforce_profile\": { \"properties\": { \"user_license\": { \"type\": \"string\" } }, \"required\": [\"user_license\"], \"additionalProperties\": false, \"type\": \"object\", \"title\": \"Salesforce Profile\" } }, \"additionalProperties\": false, \"minProperties\": 1, \"maxProperties\": 1, \"type\": \"object\" } ```")
custom_request_notification: Optional[Annotated[str, Field(strict=True, max_length=800)]] = Field(default=None, description="Custom request notification sent upon request approval.")
risk_sensitivity_override: Optional[RiskSensitivityEnum] = None
+ match_remote_name: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the resource's name should be synced from the end system. When true, the name is overwritten with the remote name on each sync, so a `name` provided together with this field set to true will be replaced at the next sync. Defaults to false.")
+ match_remote_description: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the resource's description should be synced from the end system. When true, the description is overwritten with the remote description on each sync, so a `description` provided together with this field set to true will be replaced at the next sync. Defaults to false.")
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["name", "description", "resource_type", "app_id", "remote_info", "remote_resource_id", "metadata", "custom_request_notification", "risk_sensitivity_override"]
+ __properties: ClassVar[List[str]] = ["name", "description", "resource_type", "app_id", "remote_info", "remote_resource_id", "metadata", "custom_request_notification", "risk_sensitivity_override", "match_remote_name", "match_remote_description"]
model_config = ConfigDict(
populate_by_name=True,
@@ -113,7 +115,9 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"remote_resource_id": obj.get("remote_resource_id"),
"metadata": obj.get("metadata"),
"custom_request_notification": obj.get("custom_request_notification"),
- "risk_sensitivity_override": obj.get("risk_sensitivity_override")
+ "risk_sensitivity_override": obj.get("risk_sensitivity_override"),
+ "match_remote_name": obj.get("match_remote_name"),
+ "match_remote_description": obj.get("match_remote_description")
})
# store additional fields in additional_properties
for _key in obj.keys():
diff --git a/opal_security/models/entity_admin_filter.py b/opal_security/models/entity_admin_filter.py
new file mode 100644
index 0000000..17d291f
--- /dev/null
+++ b/opal_security/models/entity_admin_filter.py
@@ -0,0 +1,104 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from typing import Optional, Set
+from typing_extensions import Self
+
+class EntityAdminFilter(BaseModel):
+ """
+ Filters GROUP and RESOURCE entities by their admin owner. USER entities never match, in either polarity. `not` inverts the match within the resource/group domain (self-negating, like IdpStatusFilter): omit it (or false) to include entities owned by the given owners, set it true to exclude them.
+ """ # noqa: E501
+ owner_ids: List[UUID] = Field(description="The owner (group) UUIDs to match entities against.", alias="ownerIDs")
+ var_not: Optional[StrictBool] = Field(default=None, description="Invert the match — return resources/groups NOT owned by the given owners.", alias="not")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["ownerIDs", "not"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of EntityAdminFilter from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of EntityAdminFilter from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "ownerIDs": obj.get("ownerIDs"),
+ "not": obj.get("not")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/entity_item_type_enum.py b/opal_security/models/entity_item_type_enum.py
index 417c0a9..88aeb71 100644
--- a/opal_security/models/entity_item_type_enum.py
+++ b/opal_security/models/entity_item_type_enum.py
@@ -85,6 +85,7 @@ class EntityItemTypeEnum(str, Enum):
GCP_CLOUD_SQL_POSTGRES_INSTANCE = 'GCP_CLOUD_SQL_POSTGRES_INSTANCE'
GCP_CLOUD_SQL_MYSQL_INSTANCE = 'GCP_CLOUD_SQL_MYSQL_INSTANCE'
GCP_SERVICE_ACCOUNT = 'GCP_SERVICE_ACCOUNT'
+ GCP_BILLING_ACCOUNT = 'GCP_BILLING_ACCOUNT'
GIT_HUB_REPO = 'GIT_HUB_REPO'
GIT_HUB_ORG_ROLE = 'GIT_HUB_ORG_ROLE'
GIT_LAB_PROJECT = 'GIT_LAB_PROJECT'
diff --git a/opal_security/models/group.py b/opal_security/models/group.py
index 9e734d1..7e79bb4 100644
--- a/opal_security/models/group.py
+++ b/opal_security/models/group.py
@@ -62,9 +62,11 @@ class Group(BaseModel):
custom_request_notification: Optional[Annotated[str, Field(strict=True, max_length=800)]] = Field(default=None, description="Custom request notification sent to the requester when the request is approved.")
risk_sensitivity: Optional[RiskSensitivityEnum] = Field(default=None, description="The risk sensitivity level for the group. When an override is set, this field will match that.")
risk_sensitivity_override: Optional[RiskSensitivityEnum] = None
+ match_remote_name: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the group's name is synced from the end system. When true, the name is overwritten with the remote name on each sync. Defaults to false.")
+ match_remote_description: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the group's description is synced from the end system. When true, the description is overwritten with the remote description on each sync. Defaults to false.")
last_successful_sync: Optional[SyncTask] = Field(default=None, description="Information about the last successful sync of this group.")
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["group_id", "app_id", "name", "description", "admin_owner_id", "group_leader_user_ids", "remote_id", "remote_name", "group_type", "max_duration", "recommended_duration", "extensions_duration_in_minutes", "require_manager_approval", "require_support_ticket", "require_mfa_to_approve", "require_mfa_to_request", "auto_approval", "request_template_id", "configuration_template_id", "group_binding_id", "is_requestable", "request_configurations", "request_configuration_list", "metadata", "remote_info", "custom_request_notification", "risk_sensitivity", "risk_sensitivity_override", "last_successful_sync"]
+ __properties: ClassVar[List[str]] = ["group_id", "app_id", "name", "description", "admin_owner_id", "group_leader_user_ids", "remote_id", "remote_name", "group_type", "max_duration", "recommended_duration", "extensions_duration_in_minutes", "require_manager_approval", "require_support_ticket", "require_mfa_to_approve", "require_mfa_to_request", "auto_approval", "request_template_id", "configuration_template_id", "group_binding_id", "is_requestable", "request_configurations", "request_configuration_list", "metadata", "remote_info", "custom_request_notification", "risk_sensitivity", "risk_sensitivity_override", "match_remote_name", "match_remote_description", "last_successful_sync"]
model_config = ConfigDict(
populate_by_name=True,
@@ -176,6 +178,8 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"custom_request_notification": obj.get("custom_request_notification"),
"risk_sensitivity": obj.get("risk_sensitivity"),
"risk_sensitivity_override": obj.get("risk_sensitivity_override"),
+ "match_remote_name": obj.get("match_remote_name"),
+ "match_remote_description": obj.get("match_remote_description"),
"last_successful_sync": SyncTask.from_dict(obj["last_successful_sync"]) if obj.get("last_successful_sync") is not None else None
})
# store additional fields in additional_properties
diff --git a/opal_security/models/group_access_level_list.py b/opal_security/models/group_access_level_list.py
new file mode 100644
index 0000000..22e5f88
--- /dev/null
+++ b/opal_security/models/group_access_level_list.py
@@ -0,0 +1,109 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.group_access_level import GroupAccessLevel
+from typing import Optional, Set
+from typing_extensions import Self
+
+class GroupAccessLevelList(BaseModel):
+ """
+ A list of access levels defined for a group.
+ """ # noqa: E501
+ results: Optional[List[GroupAccessLevel]] = None
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["results"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of GroupAccessLevelList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in results (list)
+ _items = []
+ if self.results:
+ for _item_results in self.results:
+ if _item_results:
+ _items.append(_item_results.to_dict())
+ _dict['results'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of GroupAccessLevelList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "results": [GroupAccessLevel.from_dict(_item) for _item in obj["results"]] if obj.get("results") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/group_containing_group.py b/opal_security/models/group_containing_group.py
index a2e48e1..509fab0 100644
--- a/opal_security/models/group_containing_group.py
+++ b/opal_security/models/group_containing_group.py
@@ -30,7 +30,7 @@ class GroupContainingGroup(BaseModel):
# GroupContainingGroup Object ### Description The `GroupContainingGroup` object is used to represent a relationship between a group and a group.
""" # noqa: E501
containing_group_id: UUID = Field(description="The groupID of the containing group.")
- duration_minutes: Optional[Annotated[int, Field(le=525960, strict=True)]] = Field(default=None, description="The updated duration for which the group can be accessed (in minutes). Use 0 for indefinite.")
+ duration_minutes: Optional[Annotated[int, Field(le=153722867, strict=True)]] = Field(default=None, description="The updated duration for which the group can be accessed (in minutes). Use 0 for indefinite.")
access_level_remote_id: Optional[StrictStr] = Field(default=None, description="The updated remote ID of the access level granted to this group.")
additional_properties: Dict[str, Any] = {}
__properties: ClassVar[List[str]] = ["containing_group_id", "duration_minutes", "access_level_remote_id"]
diff --git a/opal_security/models/group_remote_info.py b/opal_security/models/group_remote_info.py
index 253a55c..c6fb6de 100644
--- a/opal_security/models/group_remote_info.py
+++ b/opal_security/models/group_remote_info.py
@@ -25,9 +25,12 @@
from opal_security.models.group_remote_info_azure_ad_microsoft365_group import GroupRemoteInfoAzureAdMicrosoft365Group
from opal_security.models.group_remote_info_azure_ad_security_group import GroupRemoteInfoAzureAdSecurityGroup
from opal_security.models.group_remote_info_clickhouse_role import GroupRemoteInfoClickhouseRole
+from opal_security.models.group_remote_info_confluence_group import GroupRemoteInfoConfluenceGroup
from opal_security.models.group_remote_info_connector_group import GroupRemoteInfoConnectorGroup
from opal_security.models.group_remote_info_databricks_account_group import GroupRemoteInfoDatabricksAccountGroup
from opal_security.models.group_remote_info_devin_group import GroupRemoteInfoDevinGroup
+from opal_security.models.group_remote_info_docusign_group import GroupRemoteInfoDocusignGroup
+from opal_security.models.group_remote_info_docusign_signing_group import GroupRemoteInfoDocusignSigningGroup
from opal_security.models.group_remote_info_duo_group import GroupRemoteInfoDuoGroup
from opal_security.models.group_remote_info_github_enterprise_team import GroupRemoteInfoGithubEnterpriseTeam
from opal_security.models.group_remote_info_github_team import GroupRemoteInfoGithubTeam
@@ -36,19 +39,23 @@
from opal_security.models.group_remote_info_grafana_team import GroupRemoteInfoGrafanaTeam
from opal_security.models.group_remote_info_hubspot_team import GroupRemoteInfoHubspotTeam
from opal_security.models.group_remote_info_incidentio_on_call_schedule import GroupRemoteInfoIncidentioOnCallSchedule
+from opal_security.models.group_remote_info_jira_group import GroupRemoteInfoJiraGroup
from opal_security.models.group_remote_info_ldap_group import GroupRemoteInfoLdapGroup
+from opal_security.models.group_remote_info_linear_team import GroupRemoteInfoLinearTeam
from opal_security.models.group_remote_info_okta_group import GroupRemoteInfoOktaGroup
from opal_security.models.group_remote_info_okta_group_rule import GroupRemoteInfoOktaGroupRule
from opal_security.models.group_remote_info_pagerduty_on_call_schedule import GroupRemoteInfoPagerdutyOnCallSchedule
from opal_security.models.group_remote_info_rootly_on_call_schedule import GroupRemoteInfoRootlyOnCallSchedule
from opal_security.models.group_remote_info_slack_user_group import GroupRemoteInfoSlackUserGroup
from opal_security.models.group_remote_info_snowflake_role import GroupRemoteInfoSnowflakeRole
+from opal_security.models.group_remote_info_tableau_group import GroupRemoteInfoTableauGroup
from opal_security.models.group_remote_info_tailscale_group import GroupRemoteInfoTailscaleGroup
from opal_security.models.group_remote_info_twingate_group import GroupRemoteInfoTwingateGroup
from opal_security.models.group_remote_info_twingate_group_synced import GroupRemoteInfoTwingateGroupSynced
from opal_security.models.group_remote_info_workday_user_security_group import GroupRemoteInfoWorkdayUserSecurityGroup
from opal_security.models.group_remote_info_zendesk_group import GroupRemoteInfoZendeskGroup
from opal_security.models.group_remote_info_zendesk_organization import GroupRemoteInfoZendeskOrganization
+from opal_security.models.group_remote_info_zoom_group import GroupRemoteInfoZoomGroup
from typing import Optional, Set
from typing_extensions import Self
@@ -85,8 +92,15 @@ class GroupRemoteInfo(BaseModel):
slack_user_group: Optional[GroupRemoteInfoSlackUserGroup] = None
zendesk_organization: Optional[GroupRemoteInfoZendeskOrganization] = None
hubspot_team: Optional[GroupRemoteInfoHubspotTeam] = None
+ tableau_group: Optional[GroupRemoteInfoTableauGroup] = None
+ confluence_group: Optional[GroupRemoteInfoConfluenceGroup] = None
+ jira_group: Optional[GroupRemoteInfoJiraGroup] = None
+ docusign_group: Optional[GroupRemoteInfoDocusignGroup] = None
+ zoom_group: Optional[GroupRemoteInfoZoomGroup] = None
+ docusign_signing_group: Optional[GroupRemoteInfoDocusignSigningGroup] = None
+ linear_team: Optional[GroupRemoteInfoLinearTeam] = None
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["active_directory_group", "tailscale_group", "twingate_group", "twingate_group_synced", "aws_sso_group", "databricks_account_group", "connector_group", "github_team", "github_enterprise_team", "gitlab_group", "google_group", "ldap_group", "okta_group", "duo_group", "azure_ad_security_group", "azure_ad_microsoft_365_group", "snowflake_role", "okta_group_rule", "workday_user_security_group", "pagerduty_on_call_schedule", "incidentio_on_call_schedule", "rootly_on_call_schedule", "devin_group", "clickhouse_role", "grafana_team", "zendesk_group", "slack_user_group", "zendesk_organization", "hubspot_team"]
+ __properties: ClassVar[List[str]] = ["active_directory_group", "tailscale_group", "twingate_group", "twingate_group_synced", "aws_sso_group", "databricks_account_group", "connector_group", "github_team", "github_enterprise_team", "gitlab_group", "google_group", "ldap_group", "okta_group", "duo_group", "azure_ad_security_group", "azure_ad_microsoft_365_group", "snowflake_role", "okta_group_rule", "workday_user_security_group", "pagerduty_on_call_schedule", "incidentio_on_call_schedule", "rootly_on_call_schedule", "devin_group", "clickhouse_role", "grafana_team", "zendesk_group", "slack_user_group", "zendesk_organization", "hubspot_team", "tableau_group", "confluence_group", "jira_group", "docusign_group", "zoom_group", "docusign_signing_group", "linear_team"]
model_config = ConfigDict(
populate_by_name=True,
@@ -216,6 +230,27 @@ def to_dict(self) -> Dict[str, Any]:
# override the default output from pydantic by calling `to_dict()` of hubspot_team
if self.hubspot_team:
_dict['hubspot_team'] = self.hubspot_team.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of tableau_group
+ if self.tableau_group:
+ _dict['tableau_group'] = self.tableau_group.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of confluence_group
+ if self.confluence_group:
+ _dict['confluence_group'] = self.confluence_group.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of jira_group
+ if self.jira_group:
+ _dict['jira_group'] = self.jira_group.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of docusign_group
+ if self.docusign_group:
+ _dict['docusign_group'] = self.docusign_group.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of zoom_group
+ if self.zoom_group:
+ _dict['zoom_group'] = self.zoom_group.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of docusign_signing_group
+ if self.docusign_signing_group:
+ _dict['docusign_signing_group'] = self.docusign_signing_group.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of linear_team
+ if self.linear_team:
+ _dict['linear_team'] = self.linear_team.to_dict()
# puts key-value pairs in additional_properties in the top level
if self.additional_properties is not None:
for _key, _value in self.additional_properties.items():
@@ -261,7 +296,14 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"zendesk_group": GroupRemoteInfoZendeskGroup.from_dict(obj["zendesk_group"]) if obj.get("zendesk_group") is not None else None,
"slack_user_group": GroupRemoteInfoSlackUserGroup.from_dict(obj["slack_user_group"]) if obj.get("slack_user_group") is not None else None,
"zendesk_organization": GroupRemoteInfoZendeskOrganization.from_dict(obj["zendesk_organization"]) if obj.get("zendesk_organization") is not None else None,
- "hubspot_team": GroupRemoteInfoHubspotTeam.from_dict(obj["hubspot_team"]) if obj.get("hubspot_team") is not None else None
+ "hubspot_team": GroupRemoteInfoHubspotTeam.from_dict(obj["hubspot_team"]) if obj.get("hubspot_team") is not None else None,
+ "tableau_group": GroupRemoteInfoTableauGroup.from_dict(obj["tableau_group"]) if obj.get("tableau_group") is not None else None,
+ "confluence_group": GroupRemoteInfoConfluenceGroup.from_dict(obj["confluence_group"]) if obj.get("confluence_group") is not None else None,
+ "jira_group": GroupRemoteInfoJiraGroup.from_dict(obj["jira_group"]) if obj.get("jira_group") is not None else None,
+ "docusign_group": GroupRemoteInfoDocusignGroup.from_dict(obj["docusign_group"]) if obj.get("docusign_group") is not None else None,
+ "zoom_group": GroupRemoteInfoZoomGroup.from_dict(obj["zoom_group"]) if obj.get("zoom_group") is not None else None,
+ "docusign_signing_group": GroupRemoteInfoDocusignSigningGroup.from_dict(obj["docusign_signing_group"]) if obj.get("docusign_signing_group") is not None else None,
+ "linear_team": GroupRemoteInfoLinearTeam.from_dict(obj["linear_team"]) if obj.get("linear_team") is not None else None
})
# store additional fields in additional_properties
for _key in obj.keys():
diff --git a/opal_security/models/group_remote_info_confluence_group.py b/opal_security/models/group_remote_info_confluence_group.py
new file mode 100644
index 0000000..e777853
--- /dev/null
+++ b/opal_security/models/group_remote_info_confluence_group.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class GroupRemoteInfoConfluenceGroup(BaseModel):
+ """
+ Remote info for Confluence group.
+ """ # noqa: E501
+ group_id: StrictStr = Field(description="The ID of the Confluence group.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["group_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoConfluenceGroup from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoConfluenceGroup from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "group_id": obj.get("group_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/group_remote_info_docusign_group.py b/opal_security/models/group_remote_info_docusign_group.py
new file mode 100644
index 0000000..2c1696d
--- /dev/null
+++ b/opal_security/models/group_remote_info_docusign_group.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class GroupRemoteInfoDocusignGroup(BaseModel):
+ """
+ Remote info for Docusign group.
+ """ # noqa: E501
+ group_id: StrictStr = Field(description="The ID of the Docusign group.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["group_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoDocusignGroup from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoDocusignGroup from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "group_id": obj.get("group_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/group_remote_info_docusign_signing_group.py b/opal_security/models/group_remote_info_docusign_signing_group.py
new file mode 100644
index 0000000..8e6cbc8
--- /dev/null
+++ b/opal_security/models/group_remote_info_docusign_signing_group.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class GroupRemoteInfoDocusignSigningGroup(BaseModel):
+ """
+ Remote info for Docusign signing group.
+ """ # noqa: E501
+ signing_group_id: StrictStr = Field(description="The ID of the Docusign signing group.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["signing_group_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoDocusignSigningGroup from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoDocusignSigningGroup from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "signing_group_id": obj.get("signing_group_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/group_remote_info_jira_group.py b/opal_security/models/group_remote_info_jira_group.py
new file mode 100644
index 0000000..068359e
--- /dev/null
+++ b/opal_security/models/group_remote_info_jira_group.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class GroupRemoteInfoJiraGroup(BaseModel):
+ """
+ Remote info for Jira group.
+ """ # noqa: E501
+ group_id: StrictStr = Field(description="The ID of the Jira group.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["group_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoJiraGroup from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoJiraGroup from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "group_id": obj.get("group_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/group_remote_info_linear_team.py b/opal_security/models/group_remote_info_linear_team.py
new file mode 100644
index 0000000..3b99a0b
--- /dev/null
+++ b/opal_security/models/group_remote_info_linear_team.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class GroupRemoteInfoLinearTeam(BaseModel):
+ """
+ Remote info for Linear team.
+ """ # noqa: E501
+ team_id: StrictStr = Field(description="The ID of the Linear team.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["team_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoLinearTeam from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoLinearTeam from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "team_id": obj.get("team_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/group_remote_info_tableau_group.py b/opal_security/models/group_remote_info_tableau_group.py
new file mode 100644
index 0000000..cd3dd5f
--- /dev/null
+++ b/opal_security/models/group_remote_info_tableau_group.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class GroupRemoteInfoTableauGroup(BaseModel):
+ """
+ Remote info for Tableau group.
+ """ # noqa: E501
+ group_id: StrictStr = Field(description="The ID of the Tableau group.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["group_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoTableauGroup from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoTableauGroup from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "group_id": obj.get("group_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/group_remote_info_zoom_group.py b/opal_security/models/group_remote_info_zoom_group.py
new file mode 100644
index 0000000..57847d8
--- /dev/null
+++ b/opal_security/models/group_remote_info_zoom_group.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class GroupRemoteInfoZoomGroup(BaseModel):
+ """
+ Remote info for Zoom group.
+ """ # noqa: E501
+ group_id: StrictStr = Field(description="The ID of the Zoom group.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["group_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoZoomGroup from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of GroupRemoteInfoZoomGroup from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "group_id": obj.get("group_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/group_type_enum.py b/opal_security/models/group_type_enum.py
index 64a2bc4..d5de885 100644
--- a/opal_security/models/group_type_enum.py
+++ b/opal_security/models/group_type_enum.py
@@ -59,6 +59,12 @@ class GroupTypeEnum(str, Enum):
ZENDESK_GROUP = 'ZENDESK_GROUP'
ZENDESK_ORGANIZATION = 'ZENDESK_ORGANIZATION'
HUBSPOT_TEAM = 'HUBSPOT_TEAM'
+ TABLEAU_GROUP = 'TABLEAU_GROUP'
+ CONFLUENCE_GROUP = 'CONFLUENCE_GROUP'
+ JIRA_GROUP = 'JIRA_GROUP'
+ DOCUSIGN_GROUP = 'DOCUSIGN_GROUP'
+ ZOOM_GROUP = 'ZOOM_GROUP'
+ LINEAR_TEAM = 'LINEAR_TEAM'
@classmethod
def from_json(cls, json_str: str) -> Self:
diff --git a/opal_security/models/idp_status_filter.py b/opal_security/models/idp_status_filter.py
new file mode 100644
index 0000000..bf62123
--- /dev/null
+++ b/opal_security/models/idp_status_filter.py
@@ -0,0 +1,104 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.user_hr_idp_status_enum import UserHrIdpStatusEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class IdpStatusFilter(BaseModel):
+ """
+ Filters USER entities by their HR/IDP lifecycle status. Only applies to USER entities; GROUP and RESOURCE entities never match, in either polarity. `statuses` combine with OR. `not` inverts the match within the user domain (e.g. \"IDP status is NOT active\"), so it still returns only users rather than sweeping in groups/resources.
+ """ # noqa: E501
+ statuses: Optional[List[UserHrIdpStatusEnum]] = Field(default=None, description="Match users whose HR/IDP status is one of these values.")
+ var_not: Optional[StrictBool] = Field(default=None, description="Invert the match within the user domain (e.g. \"IDP status is NOT active\").", alias="not")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["statuses", "not"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of IdpStatusFilter from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of IdpStatusFilter from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "statuses": obj.get("statuses"),
+ "not": obj.get("not")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/invite_user_info.py b/opal_security/models/invite_user_info.py
new file mode 100644
index 0000000..cff3b7a
--- /dev/null
+++ b/opal_security/models/invite_user_info.py
@@ -0,0 +1,108 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, StrictStr
+from typing import Any, ClassVar, Dict, List
+from opal_security.models.user_product_role_enum import UserProductRoleEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class InviteUserInfo(BaseModel):
+ """
+ The information required to invite a user.
+ """ # noqa: E501
+ email: StrictStr
+ first_name: StrictStr
+ last_name: StrictStr
+ role: UserProductRoleEnum
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["email", "first_name", "last_name", "role"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of InviteUserInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of InviteUserInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "email": obj.get("email"),
+ "first_name": obj.get("first_name"),
+ "last_name": obj.get("last_name"),
+ "role": obj.get("role")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/opal_access_path_edge_filter.py b/opal_security/models/opal_access_path_edge_filter.py
new file mode 100644
index 0000000..65ad889
--- /dev/null
+++ b/opal_security/models/opal_access_path_edge_filter.py
@@ -0,0 +1,113 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr, field_validator
+from typing import Any, ClassVar, Dict, List, Optional
+from typing import Optional, Set
+from typing_extensions import Self
+
+class OpalAccessPathEdgeFilter(BaseModel):
+ """
+ Constraints on the access path edges themselves.
+ """ # noqa: E501
+ direct_only: Optional[StrictBool] = Field(default=None, description="When true, only return direct (depth-1) principal-to-entitlement edges.", alias="directOnly")
+ access_duration_type: Optional[StrictStr] = Field(default=None, description="Constrain results by whether the terminal access expires.", alias="accessDurationType")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["directOnly", "accessDurationType"]
+
+ @field_validator('access_duration_type')
+ def access_duration_type_validate_enum(cls, value):
+ """Validates the enum"""
+ if value is None:
+ return value
+
+ if value not in set(['EXPIRING_ONLY', 'PERMANENT_ONLY']):
+ raise ValueError("must be one of enum values ('EXPIRING_ONLY', 'PERMANENT_ONLY')")
+ return value
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of OpalAccessPathEdgeFilter from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of OpalAccessPathEdgeFilter from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "directOnly": obj.get("directOnly"),
+ "accessDurationType": obj.get("accessDurationType")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/opal_access_path_query.py b/opal_security/models/opal_access_path_query.py
new file mode 100644
index 0000000..9e52d88
--- /dev/null
+++ b/opal_security/models/opal_access_path_query.py
@@ -0,0 +1,120 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictInt, StrictStr, field_validator
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.opal_access_path_query_body import OpalAccessPathQueryBody
+from typing import Optional, Set
+from typing_extensions import Self
+
+class OpalAccessPathQuery(BaseModel):
+ """
+ Use an Access Path query to retrieve the access edges between principals (users or groups) and their entitlements (resources or groups). You can filter by principal type, entitlement type, access level, and edge characteristics such as depth or expiration. Results are paginated and returned as a list of access path edges.
+ """ # noqa: E501
+ type: StrictStr
+ query: Optional[OpalAccessPathQueryBody] = None
+ first: Optional[StrictInt] = Field(default=None, description="Maximum number of results to return. Defaults to 200.")
+ after: Optional[StrictStr] = Field(default=None, description="Opaque cursor from a previous ACCESS_PATH response to fetch the next page of results.")
+ include_count: Optional[StrictBool] = Field(default=None, description="When true, populate totalCount in the response. Defaults to false.", alias="includeCount")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["type", "query", "first", "after", "includeCount"]
+
+ @field_validator('type')
+ def type_validate_enum(cls, value):
+ """Validates the enum"""
+ if value not in set(['ACCESS_PATH']):
+ raise ValueError("must be one of enum values ('ACCESS_PATH')")
+ return value
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of OpalAccessPathQuery from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of query
+ if self.query:
+ _dict['query'] = self.query.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of OpalAccessPathQuery from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "type": obj.get("type"),
+ "query": OpalAccessPathQueryBody.from_dict(obj["query"]) if obj.get("query") is not None else None,
+ "first": obj.get("first"),
+ "after": obj.get("after"),
+ "includeCount": obj.get("includeCount")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/opal_access_path_query_body.py b/opal_security/models/opal_access_path_query_body.py
new file mode 100644
index 0000000..bac79b4
--- /dev/null
+++ b/opal_security/models/opal_access_path_query_body.py
@@ -0,0 +1,131 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.access_entity_filters import AccessEntityFilters
+from opal_security.models.access_relationship_filters import AccessRelationshipFilters
+from opal_security.models.opal_access_path_edge_filter import OpalAccessPathEdgeFilter
+from typing import Optional, Set
+from typing_extensions import Self
+
+class OpalAccessPathQueryBody(BaseModel):
+ """
+ Edge-query filters for an ACCESS_PATH OpalQuery. At least one of principalFilter or entitlementFilter is required.
+ """ # noqa: E501
+ principal_filter: Optional[AccessEntityFilters] = Field(default=None, alias="principalFilter")
+ entitlement_filter: Optional[AccessEntityFilters] = Field(default=None, alias="entitlementFilter")
+ principal_access_filters: Optional[AccessRelationshipFilters] = Field(default=None, description="Advanced access filter on the principal side of each path. Restricts results to principals that additionally satisfy these access-edge constraints: `hasAccessTo` keeps only principals that also have access to a matching entity; `isAccessibleBy` keeps only principals that are also accessible by a matching entity. Only takes effect when `principalFilter` is also supplied (it refines that filter); on its own it has no effect. ", alias="principalAccessFilters")
+ entitlement_access_filters: Optional[AccessRelationshipFilters] = Field(default=None, description="Advanced access filter on the entitlement side of each path. Restricts results to entitlements that additionally satisfy these access-edge constraints: `hasAccessTo` keeps only entitlements that also have access to a matching entity; `isAccessibleBy` keeps only entitlements that are also accessible by a matching entity. Only takes effect when `entitlementFilter` is also supplied (it refines that filter); on its own it has no effect. ", alias="entitlementAccessFilters")
+ access_level_remote_ids: Optional[List[StrictStr]] = Field(default=None, description="Filter by access-level remote IDs on the terminal edge.", alias="accessLevelRemoteIds")
+ access_level_names: Optional[List[StrictStr]] = Field(default=None, description="Filter by access-level display names on the terminal edge.", alias="accessLevelNames")
+ edge_filter: Optional[OpalAccessPathEdgeFilter] = Field(default=None, alias="edgeFilter")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["principalFilter", "entitlementFilter", "principalAccessFilters", "entitlementAccessFilters", "accessLevelRemoteIds", "accessLevelNames", "edgeFilter"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of OpalAccessPathQueryBody from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of principal_filter
+ if self.principal_filter:
+ _dict['principalFilter'] = self.principal_filter.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of entitlement_filter
+ if self.entitlement_filter:
+ _dict['entitlementFilter'] = self.entitlement_filter.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of principal_access_filters
+ if self.principal_access_filters:
+ _dict['principalAccessFilters'] = self.principal_access_filters.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of entitlement_access_filters
+ if self.entitlement_access_filters:
+ _dict['entitlementAccessFilters'] = self.entitlement_access_filters.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of edge_filter
+ if self.edge_filter:
+ _dict['edgeFilter'] = self.edge_filter.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of OpalAccessPathQueryBody from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "principalFilter": AccessEntityFilters.from_dict(obj["principalFilter"]) if obj.get("principalFilter") is not None else None,
+ "entitlementFilter": AccessEntityFilters.from_dict(obj["entitlementFilter"]) if obj.get("entitlementFilter") is not None else None,
+ "principalAccessFilters": AccessRelationshipFilters.from_dict(obj["principalAccessFilters"]) if obj.get("principalAccessFilters") is not None else None,
+ "entitlementAccessFilters": AccessRelationshipFilters.from_dict(obj["entitlementAccessFilters"]) if obj.get("entitlementAccessFilters") is not None else None,
+ "accessLevelRemoteIds": obj.get("accessLevelRemoteIds"),
+ "accessLevelNames": obj.get("accessLevelNames"),
+ "edgeFilter": OpalAccessPathEdgeFilter.from_dict(obj["edgeFilter"]) if obj.get("edgeFilter") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/opal_access_path_query_results.py b/opal_security/models/opal_access_path_query_results.py
new file mode 100644
index 0000000..4eb2e52
--- /dev/null
+++ b/opal_security/models/opal_access_path_query_results.py
@@ -0,0 +1,126 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictInt, StrictStr, field_validator
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.opal_access_path_result_edge import OpalAccessPathResultEdge
+from opal_security.models.page_info import PageInfo
+from typing import Optional, Set
+from typing_extensions import Self
+
+class OpalAccessPathQueryResults(BaseModel):
+ """
+ Paginated results of an ACCESS_PATH-type OpalQuery — one edge per matched principal-to-entitlement access path.
+ """ # noqa: E501
+ type: StrictStr
+ edges: List[OpalAccessPathResultEdge] = Field(description="List of matched access paths.")
+ page_info: PageInfo = Field(alias="pageInfo")
+ total_count: Optional[StrictInt] = Field(default=None, description="Exact total number of matching paths when includeCount was true on the request; otherwise null.", alias="totalCount")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["type", "edges", "pageInfo", "totalCount"]
+
+ @field_validator('type')
+ def type_validate_enum(cls, value):
+ """Validates the enum"""
+ if value not in set(['ACCESS_PATH']):
+ raise ValueError("must be one of enum values ('ACCESS_PATH')")
+ return value
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of OpalAccessPathQueryResults from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in edges (list)
+ _items = []
+ if self.edges:
+ for _item_edges in self.edges:
+ if _item_edges:
+ _items.append(_item_edges.to_dict())
+ _dict['edges'] = _items
+ # override the default output from pydantic by calling `to_dict()` of page_info
+ if self.page_info:
+ _dict['pageInfo'] = self.page_info.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of OpalAccessPathQueryResults from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "type": obj.get("type"),
+ "edges": [OpalAccessPathResultEdge.from_dict(_item) for _item in obj["edges"]] if obj.get("edges") is not None else None,
+ "pageInfo": PageInfo.from_dict(obj["pageInfo"]) if obj.get("pageInfo") is not None else None,
+ "totalCount": obj.get("totalCount")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/opal_access_path_result_edge.py b/opal_security/models/opal_access_path_result_edge.py
new file mode 100644
index 0000000..311dd6c
--- /dev/null
+++ b/opal_security/models/opal_access_path_result_edge.py
@@ -0,0 +1,107 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from opal_security.models.opal_access_path_result_node import OpalAccessPathResultNode
+from typing import Optional, Set
+from typing_extensions import Self
+
+class OpalAccessPathResultEdge(BaseModel):
+ """
+ A single ACCESS_PATH result edge containing the matched path and its pagination cursor.
+ """ # noqa: E501
+ node: OpalAccessPathResultNode
+ cursor: StrictStr = Field(description="Opaque cursor for this path, used for pagination.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["node", "cursor"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of OpalAccessPathResultEdge from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of node
+ if self.node:
+ _dict['node'] = self.node.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of OpalAccessPathResultEdge from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "node": OpalAccessPathResultNode.from_dict(obj["node"]) if obj.get("node") is not None else None,
+ "cursor": obj.get("cursor")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/opal_access_path_result_node.py b/opal_security/models/opal_access_path_result_node.py
new file mode 100644
index 0000000..1136282
--- /dev/null
+++ b/opal_security/models/opal_access_path_result_node.py
@@ -0,0 +1,115 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from typing import Optional, Set
+from typing_extensions import Self
+
+class OpalAccessPathResultNode(BaseModel):
+ """
+ A matched access path from an ACCESS_PATH OpalQuery.
+ """ # noqa: E501
+ principal_id: UUID = Field(description="The principal entity ID.", alias="principalId")
+ entitlement_id: UUID = Field(description="The entitlement entity ID.", alias="entitlementId")
+ access_level_remote_id: Optional[StrictStr] = Field(default=None, description="Remote ID of the terminal access level.", alias="accessLevelRemoteId")
+ access_level_name: Optional[StrictStr] = Field(default=None, description="Display name of the terminal access level.", alias="accessLevelName")
+ expiration: Optional[datetime] = Field(default=None, description="Expiration of the terminal access, if any.")
+ depth: StrictInt = Field(description="Number of hops from principal to entitlement (path length - 1).")
+ path: List[UUID] = Field(description="Entity IDs along the path from principal to entitlement.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["principalId", "entitlementId", "accessLevelRemoteId", "accessLevelName", "expiration", "depth", "path"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of OpalAccessPathResultNode from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of OpalAccessPathResultNode from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "principalId": obj.get("principalId"),
+ "entitlementId": obj.get("entitlementId"),
+ "accessLevelRemoteId": obj.get("accessLevelRemoteId"),
+ "accessLevelName": obj.get("accessLevelName"),
+ "expiration": obj.get("expiration"),
+ "depth": obj.get("depth"),
+ "path": obj.get("path")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/opal_node_query.py b/opal_security/models/opal_node_query.py
index 35b278b..751f5c3 100644
--- a/opal_security/models/opal_node_query.py
+++ b/opal_security/models/opal_node_query.py
@@ -26,7 +26,7 @@
class OpalNodeQuery(BaseModel):
"""
- Request body for a NODE-type OpalQuery. Returns entities (users, resources, groups) matching the given filters.
+ Use a Node query to retrieve entities — users, resources, or groups — that match a set of filters. You can filter by entity type, tags, and access relationships. Results are paginated and returned as a list of entity edges.
""" # noqa: E501
type: StrictStr
query: Optional[OpalNodeQueryBody] = None
diff --git a/opal_security/models/opal_query_results.py b/opal_security/models/opal_query_results.py
new file mode 100644
index 0000000..9f78fc7
--- /dev/null
+++ b/opal_security/models/opal_query_results.py
@@ -0,0 +1,141 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+import pprint
+from pydantic import BaseModel, ConfigDict, Field, StrictStr, ValidationError, field_validator
+from typing import Any, List, Optional
+from opal_security.models.opal_access_path_query_results import OpalAccessPathQueryResults
+from opal_security.models.opal_node_query_results import OpalNodeQueryResults
+from pydantic import StrictStr, Field
+from typing import Union, List, Set, Optional, Dict
+from typing_extensions import Literal, Self
+
+OPALQUERYRESULTS_ONE_OF_SCHEMAS = ["OpalAccessPathQueryResults", "OpalNodeQueryResults"]
+
+class OpalQueryResults(BaseModel):
+ """
+ Paginated results of an OpalQuery. The `type` field discriminates which result schema applies and mirrors the `type` field on the request.
+ """
+ # data type: OpalNodeQueryResults
+ oneof_schema_1_validator: Optional[OpalNodeQueryResults] = None
+ # data type: OpalAccessPathQueryResults
+ oneof_schema_2_validator: Optional[OpalAccessPathQueryResults] = None
+ actual_instance: Optional[Union[OpalAccessPathQueryResults, OpalNodeQueryResults]] = None
+ one_of_schemas: Set[str] = { "OpalAccessPathQueryResults", "OpalNodeQueryResults" }
+
+ model_config = ConfigDict(
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ discriminator_value_class_map: Dict[str, str] = {
+ }
+
+ def __init__(self, *args, **kwargs) -> None:
+ if args:
+ if len(args) > 1:
+ raise ValueError("If a position argument is used, only 1 is allowed to set `actual_instance`")
+ if kwargs:
+ raise ValueError("If a position argument is used, keyword arguments cannot be used.")
+ super().__init__(actual_instance=args[0])
+ else:
+ super().__init__(**kwargs)
+
+ @field_validator('actual_instance')
+ def actual_instance_must_validate_oneof(cls, v):
+ instance = OpalQueryResults.model_construct()
+ error_messages = []
+ match = 0
+ # validate data type: OpalNodeQueryResults
+ if not isinstance(v, OpalNodeQueryResults):
+ error_messages.append(f"Error! Input type `{type(v)}` is not `OpalNodeQueryResults`")
+ else:
+ match += 1
+ # validate data type: OpalAccessPathQueryResults
+ if not isinstance(v, OpalAccessPathQueryResults):
+ error_messages.append(f"Error! Input type `{type(v)}` is not `OpalAccessPathQueryResults`")
+ else:
+ match += 1
+ if match > 1:
+ # more than 1 match
+ raise ValueError("Multiple matches found when setting `actual_instance` in OpalQueryResults with oneOf schemas: OpalAccessPathQueryResults, OpalNodeQueryResults. Details: " + ", ".join(error_messages))
+ elif match == 0:
+ # no match
+ raise ValueError("No match found when setting `actual_instance` in OpalQueryResults with oneOf schemas: OpalAccessPathQueryResults, OpalNodeQueryResults. Details: " + ", ".join(error_messages))
+ else:
+ return v
+
+ @classmethod
+ def from_dict(cls, obj: Union[str, Dict[str, Any]]) -> Self:
+ return cls.from_json(json.dumps(obj))
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Returns the object represented by the json string"""
+ instance = cls.model_construct()
+ error_messages = []
+ match = 0
+
+ # deserialize data into OpalNodeQueryResults
+ try:
+ instance.actual_instance = OpalNodeQueryResults.from_json(json_str)
+ match += 1
+ except (ValidationError, ValueError) as e:
+ error_messages.append(str(e))
+ # deserialize data into OpalAccessPathQueryResults
+ try:
+ instance.actual_instance = OpalAccessPathQueryResults.from_json(json_str)
+ match += 1
+ except (ValidationError, ValueError) as e:
+ error_messages.append(str(e))
+
+ if match > 1:
+ # more than 1 match
+ raise ValueError("Multiple matches found when deserializing the JSON string into OpalQueryResults with oneOf schemas: OpalAccessPathQueryResults, OpalNodeQueryResults. Details: " + ", ".join(error_messages))
+ elif match == 0:
+ # no match
+ raise ValueError("No match found when deserializing the JSON string into OpalQueryResults with oneOf schemas: OpalAccessPathQueryResults, OpalNodeQueryResults. Details: " + ", ".join(error_messages))
+ else:
+ return instance
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the actual instance"""
+ if self.actual_instance is None:
+ return "null"
+
+ if hasattr(self.actual_instance, "to_json") and callable(self.actual_instance.to_json):
+ return self.actual_instance.to_json()
+ else:
+ return json.dumps(self.actual_instance)
+
+ def to_dict(self) -> Optional[Union[Dict[str, Any], OpalAccessPathQueryResults, OpalNodeQueryResults]]:
+ """Returns the dict representation of the actual instance"""
+ if self.actual_instance is None:
+ return None
+
+ if hasattr(self.actual_instance, "to_dict") and callable(self.actual_instance.to_dict):
+ return self.actual_instance.to_dict()
+ else:
+ # primitive type
+ return self.actual_instance
+
+ def to_str(self) -> str:
+ """Returns the string representation of the actual instance"""
+ return pprint.pformat(self.model_dump())
+
+
diff --git a/opal_security/models/paginated_campaign_items_list.py b/opal_security/models/paginated_campaign_items_list.py
new file mode 100644
index 0000000..76a76d4
--- /dev/null
+++ b/opal_security/models/paginated_campaign_items_list.py
@@ -0,0 +1,115 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.campaign_item import CampaignItem
+from typing import Optional, Set
+from typing_extensions import Self
+
+class PaginatedCampaignItemsList(BaseModel):
+ """
+ A paginated list of campaign items.
+ """ # noqa: E501
+ next: Optional[StrictStr] = Field(default=None, description="The cursor with which to continue pagination if additional result pages exist.")
+ previous: Optional[StrictStr] = Field(default=None, description="The cursor used to obtain the current result page.")
+ results: List[CampaignItem]
+ total_count: StrictInt = Field(description="Total number of items matching the filter (across all pages).")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["next", "previous", "results", "total_count"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of PaginatedCampaignItemsList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in results (list)
+ _items = []
+ if self.results:
+ for _item_results in self.results:
+ if _item_results:
+ _items.append(_item_results.to_dict())
+ _dict['results'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of PaginatedCampaignItemsList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "next": obj.get("next"),
+ "previous": obj.get("previous"),
+ "results": [CampaignItem.from_dict(_item) for _item in obj["results"]] if obj.get("results") is not None else None,
+ "total_count": obj.get("total_count")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/paginated_campaigns_list.py b/opal_security/models/paginated_campaigns_list.py
new file mode 100644
index 0000000..6bbb552
--- /dev/null
+++ b/opal_security/models/paginated_campaigns_list.py
@@ -0,0 +1,113 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.campaign import Campaign
+from typing import Optional, Set
+from typing_extensions import Self
+
+class PaginatedCampaignsList(BaseModel):
+ """
+ A list of campaigns.
+ """ # noqa: E501
+ next: Optional[StrictStr] = Field(default=None, description="The cursor with which to continue pagination if additional result pages exist.")
+ previous: Optional[StrictStr] = Field(default=None, description="The cursor used to obtain the current result page.")
+ results: List[Campaign]
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["next", "previous", "results"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of PaginatedCampaignsList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in results (list)
+ _items = []
+ if self.results:
+ for _item_results in self.results:
+ if _item_results:
+ _items.append(_item_results.to_dict())
+ _dict['results'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of PaginatedCampaignsList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "next": obj.get("next"),
+ "previous": obj.get("previous"),
+ "results": [Campaign.from_dict(_item) for _item in obj["results"]] if obj.get("results") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/paginated_request_template_list.py b/opal_security/models/paginated_request_template_list.py
new file mode 100644
index 0000000..276880f
--- /dev/null
+++ b/opal_security/models/paginated_request_template_list.py
@@ -0,0 +1,113 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.request_template import RequestTemplate
+from typing import Optional, Set
+from typing_extensions import Self
+
+class PaginatedRequestTemplateList(BaseModel):
+ """
+ PaginatedRequestTemplateList
+ """ # noqa: E501
+ next: Optional[StrictStr] = Field(default=None, description="The cursor with which to continue pagination if additional result pages exist.")
+ previous: Optional[StrictStr] = Field(default=None, description="The cursor used to obtain the current result page.")
+ results: Optional[List[RequestTemplate]] = None
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["next", "previous", "results"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of PaginatedRequestTemplateList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in results (list)
+ _items = []
+ if self.results:
+ for _item_results in self.results:
+ if _item_results:
+ _items.append(_item_results.to_dict())
+ _dict['results'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of PaginatedRequestTemplateList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "next": obj.get("next"),
+ "previous": obj.get("previous"),
+ "results": [RequestTemplate.from_dict(_item) for _item in obj["results"]] if obj.get("results") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/paginated_viewer_campaign_items_list.py b/opal_security/models/paginated_viewer_campaign_items_list.py
new file mode 100644
index 0000000..76a79c0
--- /dev/null
+++ b/opal_security/models/paginated_viewer_campaign_items_list.py
@@ -0,0 +1,115 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.viewer_campaign_item import ViewerCampaignItem
+from typing import Optional, Set
+from typing_extensions import Self
+
+class PaginatedViewerCampaignItemsList(BaseModel):
+ """
+ A paginated list of viewer campaign items.
+ """ # noqa: E501
+ next: Optional[StrictStr] = Field(default=None, description="The cursor with which to continue pagination if additional result pages exist. ")
+ previous: Optional[StrictStr] = Field(default=None, description="The cursor used to obtain the current result page.")
+ results: List[ViewerCampaignItem]
+ total_count: StrictInt = Field(description="Total number of items matching the filter (across all pages).")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["next", "previous", "results", "total_count"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of PaginatedViewerCampaignItemsList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in results (list)
+ _items = []
+ if self.results:
+ for _item_results in self.results:
+ if _item_results:
+ _items.append(_item_results.to_dict())
+ _dict['results'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of PaginatedViewerCampaignItemsList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "next": obj.get("next"),
+ "previous": obj.get("previous"),
+ "results": [ViewerCampaignItem.from_dict(_item) for _item in obj["results"]] if obj.get("results") is not None else None,
+ "total_count": obj.get("total_count")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/paladin.py b/opal_security/models/paladin.py
new file mode 100644
index 0000000..456a5f6
--- /dev/null
+++ b/opal_security/models/paladin.py
@@ -0,0 +1,115 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
+from typing import Any, ClassVar, Dict, List
+from uuid import UUID
+from opal_security.models.paladin_connector import PaladinConnector
+from typing import Optional, Set
+from typing_extensions import Self
+
+class Paladin(BaseModel):
+ """
+ # Paladin Object ### Description The `Paladin` object represents a Paladin, Opal's AI access-request reviewer.
+ """ # noqa: E501
+ paladin_id: UUID = Field(description="The ID of the Paladin. Use this value as a reviewer in a request configuration's service_user_ids.")
+ name: StrictStr = Field(description="The name of the Paladin.")
+ owner_id: UUID = Field(description="The ID of the owner of the Paladin.")
+ monitor_mode: StrictBool = Field(description="When true, the Paladin reasons about requests but takes no action. Shown as \"Monitor mode\" in the UI.")
+ admin_view_only: StrictBool = Field(description="When true, the Paladin's recommendations are visible only to admins. Only meaningful when monitor_mode is true.")
+ enabled_connectors: List[PaladinConnector] = Field(description="The connectors the Paladin is allowed to use.")
+ instructions: StrictStr = Field(description="The free-form instructions that guide the Paladin's decisions.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["paladin_id", "name", "owner_id", "monitor_mode", "admin_view_only", "enabled_connectors", "instructions"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of Paladin from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of Paladin from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "paladin_id": obj.get("paladin_id"),
+ "name": obj.get("name"),
+ "owner_id": obj.get("owner_id"),
+ "monitor_mode": obj.get("monitor_mode"),
+ "admin_view_only": obj.get("admin_view_only"),
+ "enabled_connectors": obj.get("enabled_connectors"),
+ "instructions": obj.get("instructions")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/paladin_connector.py b/opal_security/models/paladin_connector.py
new file mode 100644
index 0000000..d2687e4
--- /dev/null
+++ b/opal_security/models/paladin_connector.py
@@ -0,0 +1,47 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class PaladinConnector(str, Enum):
+ """
+ A connector a Paladin is allowed to use.
+ """
+
+ """
+ allowed enum values
+ """
+ NOTION = 'NOTION'
+ JIRA = 'JIRA'
+ LINEAR = 'LINEAR'
+ SERVICE_NOW = 'SERVICE_NOW'
+ NOTION_TICKETS = 'NOTION_TICKETS'
+ FRESH_SERVICE = 'FRESH_SERVICE'
+ SHORTCUT = 'SHORTCUT'
+ SLACK = 'SLACK'
+ PAGER_DUTY = 'PAGER_DUTY'
+ CONFLUENCE = 'CONFLUENCE'
+ FLEET_DM = 'FLEET_DM'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of PaladinConnector from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/paladin_context_source.py b/opal_security/models/paladin_context_source.py
new file mode 100644
index 0000000..e9f9c88
--- /dev/null
+++ b/opal_security/models/paladin_context_source.py
@@ -0,0 +1,116 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from uuid import UUID
+from opal_security.models.paladin_context_source_kind import PaladinContextSourceKind
+from opal_security.models.paladin_context_source_provider import PaladinContextSourceProvider
+from typing import Optional, Set
+from typing_extensions import Self
+
+class PaladinContextSource(BaseModel):
+ """
+ # PaladinContextSource Object ### Description A context source (a Slack channel or a document) that a Paladin is configured to read during access-request review.
+ """ # noqa: E501
+ id: UUID = Field(description="The ID of the context source.")
+ paladin_id: UUID = Field(description="The ID of the Paladin this source belongs to.")
+ source_kind: PaladinContextSourceKind
+ third_party_provider: PaladinContextSourceProvider
+ remote_id: StrictStr = Field(description="The provider's identifier for the source. The Slack channel ID for a channel, or the Notion/Confluence page ID for a document.")
+ name: StrictStr = Field(description="A human-readable name for the source.")
+ url: StrictStr = Field(description="A link to the source.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["id", "paladin_id", "source_kind", "third_party_provider", "remote_id", "name", "url"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of PaladinContextSource from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of PaladinContextSource from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "id": obj.get("id"),
+ "paladin_id": obj.get("paladin_id"),
+ "source_kind": obj.get("source_kind"),
+ "third_party_provider": obj.get("third_party_provider"),
+ "remote_id": obj.get("remote_id"),
+ "name": obj.get("name"),
+ "url": obj.get("url")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/paladin_context_source_kind.py b/opal_security/models/paladin_context_source_kind.py
new file mode 100644
index 0000000..1c1b4a9
--- /dev/null
+++ b/opal_security/models/paladin_context_source_kind.py
@@ -0,0 +1,38 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class PaladinContextSourceKind(str, Enum):
+ """
+ The kind of source a Paladin can read. A SLACK_CHANNEL is a Slack channel; a DOCUMENT is a Notion or Confluence page.
+ """
+
+ """
+ allowed enum values
+ """
+ SLACK_CHANNEL = 'SLACK_CHANNEL'
+ DOCUMENT = 'DOCUMENT'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of PaladinContextSourceKind from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/paladin_context_source_list.py b/opal_security/models/paladin_context_source_list.py
new file mode 100644
index 0000000..fd25ffb
--- /dev/null
+++ b/opal_security/models/paladin_context_source_list.py
@@ -0,0 +1,109 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict
+from typing import Any, ClassVar, Dict, List
+from opal_security.models.paladin_context_source import PaladinContextSource
+from typing import Optional, Set
+from typing_extensions import Self
+
+class PaladinContextSourceList(BaseModel):
+ """
+ # PaladinContextSourceList Object ### Description A list of `PaladinContextSource` objects.
+ """ # noqa: E501
+ results: List[PaladinContextSource]
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["results"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of PaladinContextSourceList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in results (list)
+ _items = []
+ if self.results:
+ for _item_results in self.results:
+ if _item_results:
+ _items.append(_item_results.to_dict())
+ _dict['results'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of PaladinContextSourceList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "results": [PaladinContextSource.from_dict(_item) for _item in obj["results"]] if obj.get("results") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/paladin_context_source_provider.py b/opal_security/models/paladin_context_source_provider.py
new file mode 100644
index 0000000..31a469a
--- /dev/null
+++ b/opal_security/models/paladin_context_source_provider.py
@@ -0,0 +1,39 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class PaladinContextSourceProvider(str, Enum):
+ """
+ The integration a Paladin context source comes from.
+ """
+
+ """
+ allowed enum values
+ """
+ SLACK = 'SLACK'
+ NOTION = 'NOTION'
+ CONFLUENCE = 'CONFLUENCE'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of PaladinContextSourceProvider from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/paladin_list.py b/opal_security/models/paladin_list.py
new file mode 100644
index 0000000..ade820b
--- /dev/null
+++ b/opal_security/models/paladin_list.py
@@ -0,0 +1,109 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict
+from typing import Any, ClassVar, Dict, List
+from opal_security.models.paladin import Paladin
+from typing import Optional, Set
+from typing_extensions import Self
+
+class PaladinList(BaseModel):
+ """
+ # PaladinList Object ### Description A list of `Paladin` objects.
+ """ # noqa: E501
+ results: List[Paladin]
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["results"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of PaladinList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in results (list)
+ _items = []
+ if self.results:
+ for _item_results in self.results:
+ if _item_results:
+ _items.append(_item_results.to_dict())
+ _dict['results'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of PaladinList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "results": [Paladin.from_dict(_item) for _item in obj["results"]] if obj.get("results") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/propagation_status_enum.py b/opal_security/models/propagation_status_enum.py
index 0a98d55..af0424b 100644
--- a/opal_security/models/propagation_status_enum.py
+++ b/opal_security/models/propagation_status_enum.py
@@ -48,6 +48,8 @@ class PropagationStatusEnum(str, Enum):
ERR_DRY_RUN_MODE_ENABLED = 'ERR_DRY_RUN_MODE_ENABLED'
ERR_HR_IDP_PROVIDER_NOT_LINKED = 'ERR_HR_IDP_PROVIDER_NOT_LINKED'
ERR_REMOTE_UNRECOVERABLE_ERROR = 'ERR_REMOTE_UNRECOVERABLE_ERROR'
+ ERR_REMOTE_TICKET_NOT_FOUND = 'ERR_REMOTE_TICKET_NOT_FOUND'
+ ERR_CONNECTION_VALIDATION_FAILED = 'ERR_CONNECTION_VALIDATION_FAILED'
@classmethod
def from_json(cls, json_str: str) -> Self:
diff --git a/opal_security/models/remind_request200_response.py b/opal_security/models/remind_request200_response.py
new file mode 100644
index 0000000..bb0eb3e
--- /dev/null
+++ b/opal_security/models/remind_request200_response.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, StrictBool
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class RemindRequest200Response(BaseModel):
+ """
+ RemindRequest200Response
+ """ # noqa: E501
+ success: StrictBool
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["success"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of RemindRequest200Response from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of RemindRequest200Response from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "success": obj.get("success")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/request_configuration.py b/opal_security/models/request_configuration.py
index d8853e9..15cf5a7 100644
--- a/opal_security/models/request_configuration.py
+++ b/opal_security/models/request_configuration.py
@@ -34,7 +34,7 @@ class RequestConfiguration(BaseModel):
allow_requests: StrictBool = Field(description="A bool representing whether or not to allow requests for this resource.")
auto_approval: StrictBool = Field(description="A bool representing whether or not to automatically approve requests for this resource.")
require_mfa_to_request: StrictBool = Field(description="A bool representing whether or not to require MFA for requesting access to this resource.")
- max_duration_minutes: Optional[StrictInt] = Field(default=None, description="The maximum duration for which the resource can be requested (in minutes).")
+ max_duration_minutes: Optional[StrictInt] = Field(default=None, description="The maximum duration for which the resource can be requested (in minutes). Capped at 1 year (525600) unless a longer maximum has been enabled for your organization. Use -1 for an indefinite duration.")
recommended_duration_minutes: Optional[StrictInt] = Field(default=None, description="The recommended duration for which the resource should be requested (in minutes). -1 represents an indefinite duration.")
require_support_ticket: StrictBool = Field(description="A bool representing whether or not access requests to the resource require an access ticket.")
extensions_duration_in_minutes: Optional[StrictInt] = Field(default=None, description="The duration for which access can be extended (in minutes). Set to 0 to disable extensions. When > 0, extensions are enabled for the specified duration.")
diff --git a/opal_security/models/request_template.py b/opal_security/models/request_template.py
new file mode 100644
index 0000000..0b9ec98
--- /dev/null
+++ b/opal_security/models/request_template.py
@@ -0,0 +1,114 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.request_template_custom_field import RequestTemplateCustomField
+from typing import Optional, Set
+from typing_extensions import Self
+
+class RequestTemplate(BaseModel):
+ """
+ A template describing what a requester is asked when requesting access.
+ """ # noqa: E501
+ request_template_id: UUID = Field(description="The ID of the request template.")
+ name: StrictStr = Field(description="The name of the request template.")
+ custom_fields: Optional[List[RequestTemplateCustomField]] = Field(default=None, description="The fields on this template, in the order they are shown.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["request_template_id", "name", "custom_fields"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of RequestTemplate from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in custom_fields (list)
+ _items = []
+ if self.custom_fields:
+ for _item_custom_fields in self.custom_fields:
+ if _item_custom_fields:
+ _items.append(_item_custom_fields.to_dict())
+ _dict['custom_fields'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of RequestTemplate from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "request_template_id": obj.get("request_template_id"),
+ "name": obj.get("name"),
+ "custom_fields": [RequestTemplateCustomField.from_dict(_item) for _item in obj["custom_fields"]] if obj.get("custom_fields") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/request_template_custom_field.py b/opal_security/models/request_template_custom_field.py
new file mode 100644
index 0000000..bc5fe0c
--- /dev/null
+++ b/opal_security/models/request_template_custom_field.py
@@ -0,0 +1,114 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.request_template_custom_field_metadata import RequestTemplateCustomFieldMetadata
+from opal_security.models.request_template_custom_field_type_enum import RequestTemplateCustomFieldTypeEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class RequestTemplateCustomField(BaseModel):
+ """
+ A field on a request template.
+ """ # noqa: E501
+ name: StrictStr = Field(description="The label shown to the requester. `CALLOUT` fields are display-only, so their name is an internal identifier and is never displayed.")
+ description: Optional[StrictStr] = Field(default=None, description="Helper text shown beneath the field.")
+ type: RequestTemplateCustomFieldTypeEnum
+ required: Optional[StrictBool] = Field(default=None, description="Whether the requester must answer. Always false for `CALLOUT` fields, which collect no answer.")
+ metadata: Optional[RequestTemplateCustomFieldMetadata] = None
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["name", "description", "type", "required", "metadata"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomField from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of metadata
+ if self.metadata:
+ _dict['metadata'] = self.metadata.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomField from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "name": obj.get("name"),
+ "description": obj.get("description"),
+ "type": obj.get("type"),
+ "required": obj.get("required"),
+ "metadata": RequestTemplateCustomFieldMetadata.from_dict(obj["metadata"]) if obj.get("metadata") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/request_template_custom_field_callout_metadata.py b/opal_security/models/request_template_custom_field_callout_metadata.py
new file mode 100644
index 0000000..119c267
--- /dev/null
+++ b/opal_security/models/request_template_custom_field_callout_metadata.py
@@ -0,0 +1,110 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr, field_validator
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class RequestTemplateCustomFieldCalloutMetadata(BaseModel):
+ """
+ The message shown to a requester by a `CALLOUT` field, and how prominently to show it.
+ """ # noqa: E501
+ severity: StrictStr = Field(description="How prominently the message is shown.")
+ text: StrictStr = Field(description="The message shown to the requester.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["severity", "text"]
+
+ @field_validator('severity')
+ def severity_validate_enum(cls, value):
+ """Validates the enum"""
+ if value not in set(['INFO', 'WARNING', 'ERROR']):
+ raise ValueError("must be one of enum values ('INFO', 'WARNING', 'ERROR')")
+ return value
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomFieldCalloutMetadata from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomFieldCalloutMetadata from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "severity": obj.get("severity"),
+ "text": obj.get("text")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/request_template_custom_field_input.py b/opal_security/models/request_template_custom_field_input.py
new file mode 100644
index 0000000..b8fa7b6
--- /dev/null
+++ b/opal_security/models/request_template_custom_field_input.py
@@ -0,0 +1,114 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.request_template_custom_field_metadata import RequestTemplateCustomFieldMetadata
+from opal_security.models.request_template_custom_field_type_enum import RequestTemplateCustomFieldTypeEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class RequestTemplateCustomFieldInput(BaseModel):
+ """
+ A field to put on a request template. Separate from `RequestTemplateCustomField` because a callout's name may be omitted on write, while a field read back always has one.
+ """ # noqa: E501
+ name: Optional[StrictStr] = Field(default=None, description="The label shown to the requester. Required for every type except `CALLOUT`, which is display-only -- its name is an internal identifier, never displayed, and is generated if omitted.")
+ description: Optional[StrictStr] = Field(default=None, description="Helper text shown beneath the field.")
+ type: RequestTemplateCustomFieldTypeEnum
+ required: Optional[StrictBool] = Field(default=None, description="Whether the requester must answer. Ignored for `CALLOUT` fields, which collect no answer.")
+ metadata: Optional[RequestTemplateCustomFieldMetadata] = None
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["name", "description", "type", "required", "metadata"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomFieldInput from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of metadata
+ if self.metadata:
+ _dict['metadata'] = self.metadata.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomFieldInput from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "name": obj.get("name"),
+ "description": obj.get("description"),
+ "type": obj.get("type"),
+ "required": obj.get("required"),
+ "metadata": RequestTemplateCustomFieldMetadata.from_dict(obj["metadata"]) if obj.get("metadata") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/request_template_custom_field_metadata.py b/opal_security/models/request_template_custom_field_metadata.py
new file mode 100644
index 0000000..2644042
--- /dev/null
+++ b/opal_security/models/request_template_custom_field_metadata.py
@@ -0,0 +1,111 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.request_template_custom_field_callout_metadata import RequestTemplateCustomFieldCalloutMetadata
+from opal_security.models.request_template_custom_field_multi_choice_metadata import RequestTemplateCustomFieldMultiChoiceMetadata
+from typing import Optional, Set
+from typing_extensions import Self
+
+class RequestTemplateCustomFieldMetadata(BaseModel):
+ """
+ Extra configuration for field types that need it. Exactly one member is set, and which one is determined by the field's `type`.
+ """ # noqa: E501
+ callout_data: Optional[RequestTemplateCustomFieldCalloutMetadata] = None
+ multi_choice_data: Optional[RequestTemplateCustomFieldMultiChoiceMetadata] = None
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["callout_data", "multi_choice_data"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomFieldMetadata from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of callout_data
+ if self.callout_data:
+ _dict['callout_data'] = self.callout_data.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of multi_choice_data
+ if self.multi_choice_data:
+ _dict['multi_choice_data'] = self.multi_choice_data.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomFieldMetadata from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "callout_data": RequestTemplateCustomFieldCalloutMetadata.from_dict(obj["callout_data"]) if obj.get("callout_data") is not None else None,
+ "multi_choice_data": RequestTemplateCustomFieldMultiChoiceMetadata.from_dict(obj["multi_choice_data"]) if obj.get("multi_choice_data") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/request_template_custom_field_multi_choice_metadata.py b/opal_security/models/request_template_custom_field_multi_choice_metadata.py
new file mode 100644
index 0000000..83ccec7
--- /dev/null
+++ b/opal_security/models/request_template_custom_field_multi_choice_metadata.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class RequestTemplateCustomFieldMultiChoiceMetadata(BaseModel):
+ """
+ The options a requester can pick from in a `MULTI_CHOICE` or `MULTI_SELECT` field.
+ """ # noqa: E501
+ options: List[StrictStr]
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["options"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomFieldMultiChoiceMetadata from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of RequestTemplateCustomFieldMultiChoiceMetadata from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "options": obj.get("options")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/request_template_custom_field_type_enum.py b/opal_security/models/request_template_custom_field_type_enum.py
index e0a1fc6..df2a72d 100644
--- a/opal_security/models/request_template_custom_field_type_enum.py
+++ b/opal_security/models/request_template_custom_field_type_enum.py
@@ -21,7 +21,7 @@
class RequestTemplateCustomFieldTypeEnum(str, Enum):
"""
- The type of the custom request field.
+ The type of the custom request field. `CALLOUT` fields are display-only -- they show a message to the requester and collect no answer, so they never appear in a request's `custom_fields`.
"""
"""
@@ -31,6 +31,8 @@ class RequestTemplateCustomFieldTypeEnum(str, Enum):
LONG_TEXT = 'LONG_TEXT'
BOOLEAN = 'BOOLEAN'
MULTI_CHOICE = 'MULTI_CHOICE'
+ MULTI_SELECT = 'MULTI_SELECT'
+ CALLOUT = 'CALLOUT'
@classmethod
def from_json(cls, json_str: str) -> Self:
diff --git a/opal_security/models/resource.py b/opal_security/models/resource.py
index a717453..80db2fa 100644
--- a/opal_security/models/resource.py
+++ b/opal_security/models/resource.py
@@ -66,9 +66,11 @@ class Resource(BaseModel):
remote_info: Optional[ResourceRemoteInfo] = None
ancestor_resource_ids: Optional[List[UUID]] = Field(default=None, description="List of resource IDs that are ancestors of this resource.")
descendant_resource_ids: Optional[List[UUID]] = Field(default=None, description="List of resource IDs that are descendants of this resource.")
+ match_remote_name: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the resource's name is synced from the end system. When true, the name is overwritten with the remote name on each sync. Defaults to false.")
+ match_remote_description: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the resource's description is synced from the end system. When true, the description is overwritten with the remote description on each sync. Defaults to false.")
last_successful_sync: Optional[SyncTask] = Field(default=None, description="Information about the last successful sync of this resource.")
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["resource_id", "app_id", "name", "description", "admin_owner_id", "remote_resource_id", "remote_resource_name", "resource_type", "max_duration", "recommended_duration", "extensions_duration_in_minutes", "require_manager_approval", "require_support_ticket", "require_mfa_to_approve", "require_mfa_to_request", "require_mfa_to_connect", "auto_approval", "request_template_id", "is_requestable", "parent_resource_id", "configuration_template_id", "request_configurations", "request_configuration_list", "ticket_propagation", "custom_request_notification", "risk_sensitivity", "risk_sensitivity_override", "metadata", "remote_info", "ancestor_resource_ids", "descendant_resource_ids", "last_successful_sync"]
+ __properties: ClassVar[List[str]] = ["resource_id", "app_id", "name", "description", "admin_owner_id", "remote_resource_id", "remote_resource_name", "resource_type", "max_duration", "recommended_duration", "extensions_duration_in_minutes", "require_manager_approval", "require_support_ticket", "require_mfa_to_approve", "require_mfa_to_request", "require_mfa_to_connect", "auto_approval", "request_template_id", "is_requestable", "parent_resource_id", "configuration_template_id", "request_configurations", "request_configuration_list", "ticket_propagation", "custom_request_notification", "risk_sensitivity", "risk_sensitivity_override", "metadata", "remote_info", "ancestor_resource_ids", "descendant_resource_ids", "match_remote_name", "match_remote_description", "last_successful_sync"]
model_config = ConfigDict(
populate_by_name=True,
@@ -186,6 +188,8 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"remote_info": ResourceRemoteInfo.from_dict(obj["remote_info"]) if obj.get("remote_info") is not None else None,
"ancestor_resource_ids": obj.get("ancestor_resource_ids"),
"descendant_resource_ids": obj.get("descendant_resource_ids"),
+ "match_remote_name": obj.get("match_remote_name"),
+ "match_remote_description": obj.get("match_remote_description"),
"last_successful_sync": SyncTask.from_dict(obj["last_successful_sync"]) if obj.get("last_successful_sync") is not None else None
})
# store additional fields in additional_properties
diff --git a/opal_security/models/resource_access_level_list.py b/opal_security/models/resource_access_level_list.py
new file mode 100644
index 0000000..8dd8dc5
--- /dev/null
+++ b/opal_security/models/resource_access_level_list.py
@@ -0,0 +1,109 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.resource_access_level import ResourceAccessLevel
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceAccessLevelList(BaseModel):
+ """
+ A list of access levels defined for a resource.
+ """ # noqa: E501
+ results: Optional[List[ResourceAccessLevel]] = None
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["results"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceAccessLevelList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in results (list)
+ _items = []
+ if self.results:
+ for _item_results in self.results:
+ if _item_results:
+ _items.append(_item_results.to_dict())
+ _dict['results'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceAccessLevelList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "results": [ResourceAccessLevel.from_dict(_item) for _item in obj["results"]] if obj.get("results") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_custom_access_level_list.py b/opal_security/models/resource_custom_access_level_list.py
new file mode 100644
index 0000000..97147f6
--- /dev/null
+++ b/opal_security/models/resource_custom_access_level_list.py
@@ -0,0 +1,109 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict
+from typing import Any, ClassVar, Dict, List
+from opal_security.models.resource_custom_access_level_response import ResourceCustomAccessLevelResponse
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceCustomAccessLevelList(BaseModel):
+ """
+ A list of custom access levels.
+ """ # noqa: E501
+ custom_access_levels: List[ResourceCustomAccessLevelResponse]
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["custom_access_levels"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceCustomAccessLevelList from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in custom_access_levels (list)
+ _items = []
+ if self.custom_access_levels:
+ for _item_custom_access_levels in self.custom_access_levels:
+ if _item_custom_access_levels:
+ _items.append(_item_custom_access_levels.to_dict())
+ _dict['custom_access_levels'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceCustomAccessLevelList from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "custom_access_levels": [ResourceCustomAccessLevelResponse.from_dict(_item) for _item in obj["custom_access_levels"]] if obj.get("custom_access_levels") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_custom_access_level_response.py b/opal_security/models/resource_custom_access_level_response.py
new file mode 100644
index 0000000..180aec3
--- /dev/null
+++ b/opal_security/models/resource_custom_access_level_response.py
@@ -0,0 +1,123 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.resource_access_level import ResourceAccessLevel
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceCustomAccessLevelResponse(BaseModel):
+ """
+ A custom access level for a resource.
+ """ # noqa: E501
+ resource_custom_access_level_id: UUID = Field(description="The unique ID of the custom access level.")
+ resource_id: UUID = Field(description="The resource this access level belongs to.")
+ access_level: ResourceAccessLevel
+ policy: Optional[StrictStr] = Field(default=None, description="The policy document for this access level.")
+ requestable_by_default: StrictBool = Field(description="Whether this role is requestable.")
+ stackable_sensitivity_index: Optional[StrictInt] = Field(default=None, description="The sensitivity index in the access hierarchy. Null if unranked.")
+ member_resource_ids: Optional[List[UUID]] = Field(default=None, description="When addressed via a parent resource, lists the child resource IDs that back this aggregated entry.")
+ created_at: Optional[datetime] = None
+ updated_at: Optional[datetime] = None
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["resource_custom_access_level_id", "resource_id", "access_level", "policy", "requestable_by_default", "stackable_sensitivity_index", "member_resource_ids", "created_at", "updated_at"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceCustomAccessLevelResponse from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of access_level
+ if self.access_level:
+ _dict['access_level'] = self.access_level.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceCustomAccessLevelResponse from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "resource_custom_access_level_id": obj.get("resource_custom_access_level_id"),
+ "resource_id": obj.get("resource_id"),
+ "access_level": ResourceAccessLevel.from_dict(obj["access_level"]) if obj.get("access_level") is not None else None,
+ "policy": obj.get("policy"),
+ "requestable_by_default": obj.get("requestable_by_default"),
+ "stackable_sensitivity_index": obj.get("stackable_sensitivity_index"),
+ "member_resource_ids": obj.get("member_resource_ids"),
+ "created_at": obj.get("created_at"),
+ "updated_at": obj.get("updated_at")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_remote_info.py b/opal_security/models/resource_remote_info.py
index 02523eb..ea583a1 100644
--- a/opal_security/models/resource_remote_info.py
+++ b/opal_security/models/resource_remote_info.py
@@ -20,6 +20,8 @@
from pydantic import BaseModel, ConfigDict
from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.resource_remote_info_alicloud_ecs_instance import ResourceRemoteInfoAlicloudEcsInstance
+from opal_security.models.resource_remote_info_alicloud_ram_role import ResourceRemoteInfoAlicloudRamRole
from opal_security.models.resource_remote_info_anthropic_workspace import ResourceRemoteInfoAnthropicWorkspace
from opal_security.models.resource_remote_info_aws_account import ResourceRemoteInfoAwsAccount
from opal_security.models.resource_remote_info_aws_ec2_instance import ResourceRemoteInfoAwsEc2Instance
@@ -52,8 +54,10 @@
from opal_security.models.resource_remote_info_datastax_astra_role import ResourceRemoteInfoDatastaxAstraRole
from opal_security.models.resource_remote_info_devin_organization import ResourceRemoteInfoDevinOrganization
from opal_security.models.resource_remote_info_devin_role import ResourceRemoteInfoDevinRole
+from opal_security.models.resource_remote_info_docusign_permission_profile import ResourceRemoteInfoDocusignPermissionProfile
from opal_security.models.resource_remote_info_gcp_big_query_dataset import ResourceRemoteInfoGcpBigQueryDataset
from opal_security.models.resource_remote_info_gcp_big_query_table import ResourceRemoteInfoGcpBigQueryTable
+from opal_security.models.resource_remote_info_gcp_billing_account import ResourceRemoteInfoGcpBillingAccount
from opal_security.models.resource_remote_info_gcp_bucket import ResourceRemoteInfoGcpBucket
from opal_security.models.resource_remote_info_gcp_compute_instance import ResourceRemoteInfoGcpComputeInstance
from opal_security.models.resource_remote_info_gcp_folder import ResourceRemoteInfoGcpFolder
@@ -73,6 +77,8 @@
from opal_security.models.resource_remote_info_grafana_role import ResourceRemoteInfoGrafanaRole
from opal_security.models.resource_remote_info_hubspot_role import ResourceRemoteInfoHubspotRole
from opal_security.models.resource_remote_info_ilevel_advanced_role import ResourceRemoteInfoIlevelAdvancedRole
+from opal_security.models.resource_remote_info_linear_organization import ResourceRemoteInfoLinearOrganization
+from opal_security.models.resource_remote_info_linear_project import ResourceRemoteInfoLinearProject
from opal_security.models.resource_remote_info_netsuite_role import ResourceRemoteInfoNetsuiteRole
from opal_security.models.resource_remote_info_okta_app import ResourceRemoteInfoOktaApp
from opal_security.models.resource_remote_info_okta_custom_role import ResourceRemoteInfoOktaCustomRole
@@ -92,6 +98,8 @@
from opal_security.models.resource_remote_info_twingate_resource import ResourceRemoteInfoTwingateResource
from opal_security.models.resource_remote_info_workday_role import ResourceRemoteInfoWorkdayRole
from opal_security.models.resource_remote_info_zendesk_role import ResourceRemoteInfoZendeskRole
+from opal_security.models.resource_remote_info_zoom_license import ResourceRemoteInfoZoomLicense
+from opal_security.models.resource_remote_info_zoom_role import ResourceRemoteInfoZoomRole
from typing import Optional, Set
from typing_extensions import Self
@@ -131,6 +139,7 @@ class ResourceRemoteInfo(BaseModel):
gcp_gke_cluster: Optional[ResourceRemoteInfoGcpGkeCluster] = None
gcp_project: Optional[ResourceRemoteInfoGcpProject] = None
gcp_sql_instance: Optional[ResourceRemoteInfoGcpSqlInstance] = None
+ gcp_billing_account: Optional[ResourceRemoteInfoGcpBillingAccount] = None
gcp_service_account: Optional[ResourceRemoteInfoGcpServiceAccount] = None
google_workspace_role: Optional[ResourceRemoteInfoGoogleWorkspaceRole] = None
github_repo: Optional[ResourceRemoteInfoGithubRepo] = None
@@ -151,6 +160,7 @@ class ResourceRemoteInfo(BaseModel):
workday_role: Optional[ResourceRemoteInfoWorkdayRole] = None
salesforce_permission_set: Optional[ResourceRemoteInfoSalesforcePermissionSet] = None
salesforce_profile: Optional[ResourceRemoteInfoSalesforceProfile] = None
+ docusign_permission_profile: Optional[ResourceRemoteInfoDocusignPermissionProfile] = None
salesforce_role: Optional[ResourceRemoteInfoSalesforceRole] = None
teleport_role: Optional[ResourceRemoteInfoTeleportRole] = None
datastax_astra_role: Optional[ResourceRemoteInfoDatastaxAstraRole] = None
@@ -171,8 +181,14 @@ class ResourceRemoteInfo(BaseModel):
grafana_role: Optional[ResourceRemoteInfoGrafanaRole] = None
zendesk_role: Optional[ResourceRemoteInfoZendeskRole] = None
hubspot_role: Optional[ResourceRemoteInfoHubspotRole] = None
+ alicloud_ram_role: Optional[ResourceRemoteInfoAlicloudRamRole] = None
+ alicloud_ecs_instance: Optional[ResourceRemoteInfoAlicloudEcsInstance] = None
+ zoom_role: Optional[ResourceRemoteInfoZoomRole] = None
+ zoom_license: Optional[ResourceRemoteInfoZoomLicense] = None
+ linear_organization: Optional[ResourceRemoteInfoLinearOrganization] = None
+ linear_project: Optional[ResourceRemoteInfoLinearProject] = None
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["databricks_account_service_principal", "azure_subscription", "azure_resource_group", "azure_management_group", "azure_virtual_machine", "azure_storage_account", "azure_storage_container", "azure_sql_server", "azure_sql_database", "azure_sql_managed_instance", "azure_sql_managed_database", "azure_user_assigned_managed_identity", "azure_enterprise_app", "azure_entra_id_role", "aws_organizational_unit", "aws_account", "aws_permission_set", "aws_iam_role", "aws_ec2_instance", "aws_rds_cluster", "aws_rds_instance", "aws_eks_cluster", "custom_connector", "gcp_organization", "gcp_bucket", "gcp_compute_instance", "gcp_big_query_dataset", "gcp_big_query_table", "gcp_folder", "gcp_gke_cluster", "gcp_project", "gcp_sql_instance", "gcp_service_account", "google_workspace_role", "github_repo", "github_org_role", "github_org", "github_enterprise_role", "gitlab_project", "okta_app", "okta_standard_role", "okta_custom_role", "snowflake_database", "snowflake_schema", "snowflake_table", "ilevel_advanced_role", "tailscale_ssh", "twingate_resource", "pagerduty_role", "workday_role", "salesforce_permission_set", "salesforce_profile", "salesforce_role", "teleport_role", "datastax_astra_role", "coupa_role", "cursor_organization", "openai_platform_project", "openai_platform_service_account", "anthropic_workspace", "oracle_fusion_role", "devin_organization", "devin_role", "netsuite_role", "datadog_role", "clickhouse_database", "clickhouse_table", "grafana_folder", "grafana_dashboard", "grafana_role", "zendesk_role", "hubspot_role"]
+ __properties: ClassVar[List[str]] = ["databricks_account_service_principal", "azure_subscription", "azure_resource_group", "azure_management_group", "azure_virtual_machine", "azure_storage_account", "azure_storage_container", "azure_sql_server", "azure_sql_database", "azure_sql_managed_instance", "azure_sql_managed_database", "azure_user_assigned_managed_identity", "azure_enterprise_app", "azure_entra_id_role", "aws_organizational_unit", "aws_account", "aws_permission_set", "aws_iam_role", "aws_ec2_instance", "aws_rds_cluster", "aws_rds_instance", "aws_eks_cluster", "custom_connector", "gcp_organization", "gcp_bucket", "gcp_compute_instance", "gcp_big_query_dataset", "gcp_big_query_table", "gcp_folder", "gcp_gke_cluster", "gcp_project", "gcp_sql_instance", "gcp_billing_account", "gcp_service_account", "google_workspace_role", "github_repo", "github_org_role", "github_org", "github_enterprise_role", "gitlab_project", "okta_app", "okta_standard_role", "okta_custom_role", "snowflake_database", "snowflake_schema", "snowflake_table", "ilevel_advanced_role", "tailscale_ssh", "twingate_resource", "pagerduty_role", "workday_role", "salesforce_permission_set", "salesforce_profile", "docusign_permission_profile", "salesforce_role", "teleport_role", "datastax_astra_role", "coupa_role", "cursor_organization", "openai_platform_project", "openai_platform_service_account", "anthropic_workspace", "oracle_fusion_role", "devin_organization", "devin_role", "netsuite_role", "datadog_role", "clickhouse_database", "clickhouse_table", "grafana_folder", "grafana_dashboard", "grafana_role", "zendesk_role", "hubspot_role", "alicloud_ram_role", "alicloud_ecs_instance", "zoom_role", "zoom_license", "linear_organization", "linear_project"]
model_config = ConfigDict(
populate_by_name=True,
@@ -311,6 +327,9 @@ def to_dict(self) -> Dict[str, Any]:
# override the default output from pydantic by calling `to_dict()` of gcp_sql_instance
if self.gcp_sql_instance:
_dict['gcp_sql_instance'] = self.gcp_sql_instance.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of gcp_billing_account
+ if self.gcp_billing_account:
+ _dict['gcp_billing_account'] = self.gcp_billing_account.to_dict()
# override the default output from pydantic by calling `to_dict()` of gcp_service_account
if self.gcp_service_account:
_dict['gcp_service_account'] = self.gcp_service_account.to_dict()
@@ -371,6 +390,9 @@ def to_dict(self) -> Dict[str, Any]:
# override the default output from pydantic by calling `to_dict()` of salesforce_profile
if self.salesforce_profile:
_dict['salesforce_profile'] = self.salesforce_profile.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of docusign_permission_profile
+ if self.docusign_permission_profile:
+ _dict['docusign_permission_profile'] = self.docusign_permission_profile.to_dict()
# override the default output from pydantic by calling `to_dict()` of salesforce_role
if self.salesforce_role:
_dict['salesforce_role'] = self.salesforce_role.to_dict()
@@ -431,6 +453,24 @@ def to_dict(self) -> Dict[str, Any]:
# override the default output from pydantic by calling `to_dict()` of hubspot_role
if self.hubspot_role:
_dict['hubspot_role'] = self.hubspot_role.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of alicloud_ram_role
+ if self.alicloud_ram_role:
+ _dict['alicloud_ram_role'] = self.alicloud_ram_role.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of alicloud_ecs_instance
+ if self.alicloud_ecs_instance:
+ _dict['alicloud_ecs_instance'] = self.alicloud_ecs_instance.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of zoom_role
+ if self.zoom_role:
+ _dict['zoom_role'] = self.zoom_role.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of zoom_license
+ if self.zoom_license:
+ _dict['zoom_license'] = self.zoom_license.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of linear_organization
+ if self.linear_organization:
+ _dict['linear_organization'] = self.linear_organization.to_dict()
+ # override the default output from pydantic by calling `to_dict()` of linear_project
+ if self.linear_project:
+ _dict['linear_project'] = self.linear_project.to_dict()
# puts key-value pairs in additional_properties in the top level
if self.additional_properties is not None:
for _key, _value in self.additional_properties.items():
@@ -480,6 +520,7 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"gcp_gke_cluster": ResourceRemoteInfoGcpGkeCluster.from_dict(obj["gcp_gke_cluster"]) if obj.get("gcp_gke_cluster") is not None else None,
"gcp_project": ResourceRemoteInfoGcpProject.from_dict(obj["gcp_project"]) if obj.get("gcp_project") is not None else None,
"gcp_sql_instance": ResourceRemoteInfoGcpSqlInstance.from_dict(obj["gcp_sql_instance"]) if obj.get("gcp_sql_instance") is not None else None,
+ "gcp_billing_account": ResourceRemoteInfoGcpBillingAccount.from_dict(obj["gcp_billing_account"]) if obj.get("gcp_billing_account") is not None else None,
"gcp_service_account": ResourceRemoteInfoGcpServiceAccount.from_dict(obj["gcp_service_account"]) if obj.get("gcp_service_account") is not None else None,
"google_workspace_role": ResourceRemoteInfoGoogleWorkspaceRole.from_dict(obj["google_workspace_role"]) if obj.get("google_workspace_role") is not None else None,
"github_repo": ResourceRemoteInfoGithubRepo.from_dict(obj["github_repo"]) if obj.get("github_repo") is not None else None,
@@ -500,6 +541,7 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"workday_role": ResourceRemoteInfoWorkdayRole.from_dict(obj["workday_role"]) if obj.get("workday_role") is not None else None,
"salesforce_permission_set": ResourceRemoteInfoSalesforcePermissionSet.from_dict(obj["salesforce_permission_set"]) if obj.get("salesforce_permission_set") is not None else None,
"salesforce_profile": ResourceRemoteInfoSalesforceProfile.from_dict(obj["salesforce_profile"]) if obj.get("salesforce_profile") is not None else None,
+ "docusign_permission_profile": ResourceRemoteInfoDocusignPermissionProfile.from_dict(obj["docusign_permission_profile"]) if obj.get("docusign_permission_profile") is not None else None,
"salesforce_role": ResourceRemoteInfoSalesforceRole.from_dict(obj["salesforce_role"]) if obj.get("salesforce_role") is not None else None,
"teleport_role": ResourceRemoteInfoTeleportRole.from_dict(obj["teleport_role"]) if obj.get("teleport_role") is not None else None,
"datastax_astra_role": ResourceRemoteInfoDatastaxAstraRole.from_dict(obj["datastax_astra_role"]) if obj.get("datastax_astra_role") is not None else None,
@@ -519,7 +561,13 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"grafana_dashboard": ResourceRemoteInfoGrafanaDashboard.from_dict(obj["grafana_dashboard"]) if obj.get("grafana_dashboard") is not None else None,
"grafana_role": ResourceRemoteInfoGrafanaRole.from_dict(obj["grafana_role"]) if obj.get("grafana_role") is not None else None,
"zendesk_role": ResourceRemoteInfoZendeskRole.from_dict(obj["zendesk_role"]) if obj.get("zendesk_role") is not None else None,
- "hubspot_role": ResourceRemoteInfoHubspotRole.from_dict(obj["hubspot_role"]) if obj.get("hubspot_role") is not None else None
+ "hubspot_role": ResourceRemoteInfoHubspotRole.from_dict(obj["hubspot_role"]) if obj.get("hubspot_role") is not None else None,
+ "alicloud_ram_role": ResourceRemoteInfoAlicloudRamRole.from_dict(obj["alicloud_ram_role"]) if obj.get("alicloud_ram_role") is not None else None,
+ "alicloud_ecs_instance": ResourceRemoteInfoAlicloudEcsInstance.from_dict(obj["alicloud_ecs_instance"]) if obj.get("alicloud_ecs_instance") is not None else None,
+ "zoom_role": ResourceRemoteInfoZoomRole.from_dict(obj["zoom_role"]) if obj.get("zoom_role") is not None else None,
+ "zoom_license": ResourceRemoteInfoZoomLicense.from_dict(obj["zoom_license"]) if obj.get("zoom_license") is not None else None,
+ "linear_organization": ResourceRemoteInfoLinearOrganization.from_dict(obj["linear_organization"]) if obj.get("linear_organization") is not None else None,
+ "linear_project": ResourceRemoteInfoLinearProject.from_dict(obj["linear_project"]) if obj.get("linear_project") is not None else None
})
# store additional fields in additional_properties
for _key in obj.keys():
diff --git a/opal_security/models/resource_remote_info_alicloud_ecs_instance.py b/opal_security/models/resource_remote_info_alicloud_ecs_instance.py
new file mode 100644
index 0000000..9dfe5f2
--- /dev/null
+++ b/opal_security/models/resource_remote_info_alicloud_ecs_instance.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceRemoteInfoAlicloudEcsInstance(BaseModel):
+ """
+ Remote info for AliCloud ECS instance.
+ """ # noqa: E501
+ instance_id: StrictStr = Field(description="The ID of the ECS instance.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["instance_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoAlicloudEcsInstance from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoAlicloudEcsInstance from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "instance_id": obj.get("instance_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_remote_info_alicloud_ram_role.py b/opal_security/models/resource_remote_info_alicloud_ram_role.py
new file mode 100644
index 0000000..65b263d
--- /dev/null
+++ b/opal_security/models/resource_remote_info_alicloud_ram_role.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceRemoteInfoAlicloudRamRole(BaseModel):
+ """
+ Remote info for AliCloud RAM role.
+ """ # noqa: E501
+ role_arn: StrictStr = Field(description="The ARN of the AliCloud RAM role.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["role_arn"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoAlicloudRamRole from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoAlicloudRamRole from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "role_arn": obj.get("role_arn")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_remote_info_docusign_permission_profile.py b/opal_security/models/resource_remote_info_docusign_permission_profile.py
new file mode 100644
index 0000000..7c298a9
--- /dev/null
+++ b/opal_security/models/resource_remote_info_docusign_permission_profile.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceRemoteInfoDocusignPermissionProfile(BaseModel):
+ """
+ Remote info for Docusign permission profile.
+ """ # noqa: E501
+ permission_profile_id: StrictStr = Field(description="The ID of the Docusign permission profile.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["permission_profile_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoDocusignPermissionProfile from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoDocusignPermissionProfile from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "permission_profile_id": obj.get("permission_profile_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_remote_info_gcp_billing_account.py b/opal_security/models/resource_remote_info_gcp_billing_account.py
new file mode 100644
index 0000000..b5cb230
--- /dev/null
+++ b/opal_security/models/resource_remote_info_gcp_billing_account.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceRemoteInfoGcpBillingAccount(BaseModel):
+ """
+ Remote info for a GCP billing account.
+ """ # noqa: E501
+ billing_account_id: StrictStr = Field(description="The resource name of the billing account.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["billing_account_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoGcpBillingAccount from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoGcpBillingAccount from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "billing_account_id": obj.get("billing_account_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_remote_info_linear_organization.py b/opal_security/models/resource_remote_info_linear_organization.py
new file mode 100644
index 0000000..1271af5
--- /dev/null
+++ b/opal_security/models/resource_remote_info_linear_organization.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceRemoteInfoLinearOrganization(BaseModel):
+ """
+ Remote info for Linear organization.
+ """ # noqa: E501
+ org_id: StrictStr = Field(description="The ID of the Linear organization.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["org_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoLinearOrganization from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoLinearOrganization from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "org_id": obj.get("org_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_remote_info_linear_project.py b/opal_security/models/resource_remote_info_linear_project.py
new file mode 100644
index 0000000..95acd5e
--- /dev/null
+++ b/opal_security/models/resource_remote_info_linear_project.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceRemoteInfoLinearProject(BaseModel):
+ """
+ Remote info for Linear project.
+ """ # noqa: E501
+ project_id: StrictStr = Field(description="The ID of the Linear project.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["project_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoLinearProject from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoLinearProject from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "project_id": obj.get("project_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_remote_info_zoom_license.py b/opal_security/models/resource_remote_info_zoom_license.py
new file mode 100644
index 0000000..97e0c58
--- /dev/null
+++ b/opal_security/models/resource_remote_info_zoom_license.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceRemoteInfoZoomLicense(BaseModel):
+ """
+ Remote info for Zoom license (user type).
+ """ # noqa: E501
+ license_type: StrictStr = Field(description="The Zoom user type representing the license (e.g. \"2\" for Licensed).")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["license_type"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoZoomLicense from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoZoomLicense from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "license_type": obj.get("license_type")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_remote_info_zoom_role.py b/opal_security/models/resource_remote_info_zoom_role.py
new file mode 100644
index 0000000..161268b
--- /dev/null
+++ b/opal_security/models/resource_remote_info_zoom_role.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ResourceRemoteInfoZoomRole(BaseModel):
+ """
+ Remote info for Zoom role.
+ """ # noqa: E501
+ role_id: StrictStr = Field(description="The ID of the Zoom role.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["role_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoZoomRole from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ResourceRemoteInfoZoomRole from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "role_id": obj.get("role_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/resource_type_enum.py b/opal_security/models/resource_type_enum.py
index f95a03a..795a0ac 100644
--- a/opal_security/models/resource_type_enum.py
+++ b/opal_security/models/resource_type_enum.py
@@ -64,6 +64,7 @@ class ResourceTypeEnum(str, Enum):
GCP_BIG_QUERY_DATASET = 'GCP_BIG_QUERY_DATASET'
GCP_BIG_QUERY_TABLE = 'GCP_BIG_QUERY_TABLE'
GCP_SERVICE_ACCOUNT = 'GCP_SERVICE_ACCOUNT'
+ GCP_BILLING_ACCOUNT = 'GCP_BILLING_ACCOUNT'
GIT_HUB_REPO = 'GIT_HUB_REPO'
GIT_HUB_ORG_ROLE = 'GIT_HUB_ORG_ROLE'
GIT_LAB_PROJECT = 'GIT_LAB_PROJECT'
@@ -113,6 +114,13 @@ class ResourceTypeEnum(str, Enum):
TWINGATE_RESOURCE = 'TWINGATE_RESOURCE'
ZENDESK_ROLE = 'ZENDESK_ROLE'
HUBSPOT_ROLE = 'HUBSPOT_ROLE'
+ ALICLOUD_RAM_ROLE = 'ALICLOUD_RAM_ROLE'
+ ALICLOUD_ECS_INSTANCE = 'ALICLOUD_ECS_INSTANCE'
+ DOCUSIGN_PERMISSION_PROFILE = 'DOCUSIGN_PERMISSION_PROFILE'
+ ZOOM_ROLE = 'ZOOM_ROLE'
+ ZOOM_LICENSE = 'ZOOM_LICENSE'
+ LINEAR_ORGANIZATION = 'LINEAR_ORGANIZATION'
+ LINEAR_PROJECT = 'LINEAR_PROJECT'
@classmethod
def from_json(cls, json_str: str) -> Self:
diff --git a/opal_security/models/role_permission_target_type_enum.py b/opal_security/models/role_permission_target_type_enum.py
index c97f909..2b781e7 100644
--- a/opal_security/models/role_permission_target_type_enum.py
+++ b/opal_security/models/role_permission_target_type_enum.py
@@ -34,6 +34,7 @@ class RolePermissionTargetTypeEnum(str, Enum):
USER = 'USER'
ACCESS_REVIEW = 'ACCESS_REVIEW'
OWNER = 'OWNER'
+ EVENT = 'EVENT'
@classmethod
def from_json(cls, json_str: str) -> Self:
diff --git a/opal_security/models/run_opal_query_request.py b/opal_security/models/run_opal_query_request.py
new file mode 100644
index 0000000..e17a866
--- /dev/null
+++ b/opal_security/models/run_opal_query_request.py
@@ -0,0 +1,141 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+import pprint
+from pydantic import BaseModel, ConfigDict, Field, StrictStr, ValidationError, field_validator
+from typing import Any, List, Optional
+from opal_security.models.opal_access_path_query import OpalAccessPathQuery
+from opal_security.models.opal_node_query import OpalNodeQuery
+from pydantic import StrictStr, Field
+from typing import Union, List, Set, Optional, Dict
+from typing_extensions import Literal, Self
+
+RUNOPALQUERYREQUEST_ONE_OF_SCHEMAS = ["OpalAccessPathQuery", "OpalNodeQuery"]
+
+class RunOpalQueryRequest(BaseModel):
+ """
+ Request body for an ad-hoc OpalQuery. Set `type` to `NODE` to query entities, or `ACCESS_PATH` to query access edges. The fields available in `query` differ by type — refer to each tab for the full schema.
+ """
+ # data type: OpalNodeQuery
+ oneof_schema_1_validator: Optional[OpalNodeQuery] = None
+ # data type: OpalAccessPathQuery
+ oneof_schema_2_validator: Optional[OpalAccessPathQuery] = None
+ actual_instance: Optional[Union[OpalAccessPathQuery, OpalNodeQuery]] = None
+ one_of_schemas: Set[str] = { "OpalAccessPathQuery", "OpalNodeQuery" }
+
+ model_config = ConfigDict(
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ discriminator_value_class_map: Dict[str, str] = {
+ }
+
+ def __init__(self, *args, **kwargs) -> None:
+ if args:
+ if len(args) > 1:
+ raise ValueError("If a position argument is used, only 1 is allowed to set `actual_instance`")
+ if kwargs:
+ raise ValueError("If a position argument is used, keyword arguments cannot be used.")
+ super().__init__(actual_instance=args[0])
+ else:
+ super().__init__(**kwargs)
+
+ @field_validator('actual_instance')
+ def actual_instance_must_validate_oneof(cls, v):
+ instance = RunOpalQueryRequest.model_construct()
+ error_messages = []
+ match = 0
+ # validate data type: OpalNodeQuery
+ if not isinstance(v, OpalNodeQuery):
+ error_messages.append(f"Error! Input type `{type(v)}` is not `OpalNodeQuery`")
+ else:
+ match += 1
+ # validate data type: OpalAccessPathQuery
+ if not isinstance(v, OpalAccessPathQuery):
+ error_messages.append(f"Error! Input type `{type(v)}` is not `OpalAccessPathQuery`")
+ else:
+ match += 1
+ if match > 1:
+ # more than 1 match
+ raise ValueError("Multiple matches found when setting `actual_instance` in RunOpalQueryRequest with oneOf schemas: OpalAccessPathQuery, OpalNodeQuery. Details: " + ", ".join(error_messages))
+ elif match == 0:
+ # no match
+ raise ValueError("No match found when setting `actual_instance` in RunOpalQueryRequest with oneOf schemas: OpalAccessPathQuery, OpalNodeQuery. Details: " + ", ".join(error_messages))
+ else:
+ return v
+
+ @classmethod
+ def from_dict(cls, obj: Union[str, Dict[str, Any]]) -> Self:
+ return cls.from_json(json.dumps(obj))
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Returns the object represented by the json string"""
+ instance = cls.model_construct()
+ error_messages = []
+ match = 0
+
+ # deserialize data into OpalNodeQuery
+ try:
+ instance.actual_instance = OpalNodeQuery.from_json(json_str)
+ match += 1
+ except (ValidationError, ValueError) as e:
+ error_messages.append(str(e))
+ # deserialize data into OpalAccessPathQuery
+ try:
+ instance.actual_instance = OpalAccessPathQuery.from_json(json_str)
+ match += 1
+ except (ValidationError, ValueError) as e:
+ error_messages.append(str(e))
+
+ if match > 1:
+ # more than 1 match
+ raise ValueError("Multiple matches found when deserializing the JSON string into RunOpalQueryRequest with oneOf schemas: OpalAccessPathQuery, OpalNodeQuery. Details: " + ", ".join(error_messages))
+ elif match == 0:
+ # no match
+ raise ValueError("No match found when deserializing the JSON string into RunOpalQueryRequest with oneOf schemas: OpalAccessPathQuery, OpalNodeQuery. Details: " + ", ".join(error_messages))
+ else:
+ return instance
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the actual instance"""
+ if self.actual_instance is None:
+ return "null"
+
+ if hasattr(self.actual_instance, "to_json") and callable(self.actual_instance.to_json):
+ return self.actual_instance.to_json()
+ else:
+ return json.dumps(self.actual_instance)
+
+ def to_dict(self) -> Optional[Union[Dict[str, Any], OpalAccessPathQuery, OpalNodeQuery]]:
+ """Returns the dict representation of the actual instance"""
+ if self.actual_instance is None:
+ return None
+
+ if hasattr(self.actual_instance, "to_dict") and callable(self.actual_instance.to_dict):
+ return self.actual_instance.to_dict()
+ else:
+ # primitive type
+ return self.actual_instance
+
+ def to_str(self) -> str:
+ """Returns the string representation of the actual instance"""
+ return pprint.pformat(self.model_dump())
+
+
diff --git a/opal_security/models/sort_direction_enum.py b/opal_security/models/sort_direction_enum.py
new file mode 100644
index 0000000..65be240
--- /dev/null
+++ b/opal_security/models/sort_direction_enum.py
@@ -0,0 +1,38 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class SortDirectionEnum(str, Enum):
+ """
+ Sort direction for viewer campaign items.
+ """
+
+ """
+ allowed enum values
+ """
+ ASC = 'ASC'
+ DESC = 'DESC'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of SortDirectionEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/stop_campaign_request.py b/opal_security/models/stop_campaign_request.py
new file mode 100644
index 0000000..e1e97f0
--- /dev/null
+++ b/opal_security/models/stop_campaign_request.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool
+from typing import Any, ClassVar, Dict, List, Optional
+from typing import Optional, Set
+from typing_extensions import Self
+
+class StopCampaignRequest(BaseModel):
+ """
+ StopCampaignRequest
+ """ # noqa: E501
+ revoke_unreviewed: Optional[StrictBool] = Field(default=False, description="Revoke all unreviewed access grants. Access grants with no reviewer decision will be immediately revoked.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["revoke_unreviewed"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of StopCampaignRequest from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of StopCampaignRequest from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "revoke_unreviewed": obj.get("revoke_unreviewed") if obj.get("revoke_unreviewed") is not None else False
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/string_match_type.py b/opal_security/models/string_match_type.py
index 30af2a4..b90ea56 100644
--- a/opal_security/models/string_match_type.py
+++ b/opal_security/models/string_match_type.py
@@ -21,7 +21,7 @@
class StringMatchType(str, Enum):
"""
- How to match a string value against entity names.
+ How to match a string value against entity names. REGEX matches the value as a case-insensitive regular expression.
"""
"""
@@ -31,6 +31,7 @@ class StringMatchType(str, Enum):
EQUALS = 'EQUALS'
STARTS_WITH = 'STARTS_WITH'
ENDS_WITH = 'ENDS_WITH'
+ REGEX = 'REGEX'
@classmethod
def from_json(cls, json_str: str) -> Self:
diff --git a/opal_security/models/update_campaign_configuration_info.py b/opal_security/models/update_campaign_configuration_info.py
new file mode 100644
index 0000000..ff36870
--- /dev/null
+++ b/opal_security/models/update_campaign_configuration_info.py
@@ -0,0 +1,132 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.campaign_group_asset_visibility_policy_enum import CampaignGroupAssetVisibilityPolicyEnum
+from opal_security.models.campaign_revoke_on_enum import CampaignRevokeOnEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class UpdateCampaignConfigurationInfo(BaseModel):
+ """
+ Configuration fields to update on a campaign. All fields are optional; omitted fields are left unchanged. `query` and `reviewer_assignment_policy` are set at create time and cannot be updated here; including either field returns 400. `cron_expression` and `recurring_duration_days` may only be set when the campaign is a template; setting them on a one-off campaign returns 400. `is_template` is immutable and not accepted on update.
+ """ # noqa: E501
+ allow_self_review: Optional[StrictBool] = Field(default=None, description="Whether reviewers can review their own access.")
+ send_reviewer_assignment_notification: Optional[StrictBool] = Field(default=None, description="Whether to notify reviewers upon assignment.")
+ allow_reviewer_reassignment: Optional[StrictBool] = Field(default=None, description="Whether reviewers may reassign their reviews to another user.")
+ start_date: Optional[datetime] = Field(default=None, description="Scheduled start date of the campaign. May only be updated while the campaign has not started (started_at is null). When set, the date's calendar day in the campaign timezone must be at least tomorrow. ")
+ end_date: Optional[datetime] = Field(default=None, description="Scheduled end date of the campaign. When set, the date's calendar day in the campaign timezone must be at least tomorrow. ")
+ timezone: Optional[StrictStr] = Field(default=None, description="IANA timezone used to interpret campaign deadlines (e.g. America/Los_Angeles).")
+ revoke_on: Optional[CampaignRevokeOnEnum] = None
+ reminder_schedule: Optional[List[StrictInt]] = Field(default=None, description="Days before end date to send reminder notifications.")
+ reminder_include_manager: Optional[StrictBool] = Field(default=None, description="Whether to include the reviewer's manager in reminders.")
+ require_reason_on_denial: Optional[StrictBool] = Field(default=None, description="Whether reviewers must provide a reason when denying (revoking) access.")
+ hide_ai_suggestions: Optional[StrictBool] = Field(default=None, description="Whether AI suggestions are hidden from reviewers.")
+ custom_start_message: Optional[StrictStr] = Field(default=None, description="Optional custom message included when notifying reviewers that the campaign started.")
+ group_asset_visibility_policy: Optional[CampaignGroupAssetVisibilityPolicyEnum] = None
+ cron_expression: Optional[StrictStr] = Field(default=None, description="Cron expression driving the recurring schedule. Only valid on template campaigns. Pass an empty string to clear the active months (next_scheduled_run is cleared); the campaign remains a template.")
+ recurring_duration_days: Optional[StrictInt] = Field(default=None, description="Deadline window in days applied to each draft generated from this template. Only valid on template campaigns.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["allow_self_review", "send_reviewer_assignment_notification", "allow_reviewer_reassignment", "start_date", "end_date", "timezone", "revoke_on", "reminder_schedule", "reminder_include_manager", "require_reason_on_denial", "hide_ai_suggestions", "custom_start_message", "group_asset_visibility_policy", "cron_expression", "recurring_duration_days"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of UpdateCampaignConfigurationInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of UpdateCampaignConfigurationInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "allow_self_review": obj.get("allow_self_review"),
+ "send_reviewer_assignment_notification": obj.get("send_reviewer_assignment_notification"),
+ "allow_reviewer_reassignment": obj.get("allow_reviewer_reassignment"),
+ "start_date": obj.get("start_date"),
+ "end_date": obj.get("end_date"),
+ "timezone": obj.get("timezone"),
+ "revoke_on": obj.get("revoke_on"),
+ "reminder_schedule": obj.get("reminder_schedule"),
+ "reminder_include_manager": obj.get("reminder_include_manager"),
+ "require_reason_on_denial": obj.get("require_reason_on_denial"),
+ "hide_ai_suggestions": obj.get("hide_ai_suggestions"),
+ "custom_start_message": obj.get("custom_start_message"),
+ "group_asset_visibility_policy": obj.get("group_asset_visibility_policy"),
+ "cron_expression": obj.get("cron_expression"),
+ "recurring_duration_days": obj.get("recurring_duration_days")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/update_campaign_info.py b/opal_security/models/update_campaign_info.py
new file mode 100644
index 0000000..ceff325
--- /dev/null
+++ b/opal_security/models/update_campaign_info.py
@@ -0,0 +1,107 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.update_campaign_configuration_info import UpdateCampaignConfigurationInfo
+from typing import Optional, Set
+from typing_extensions import Self
+
+class UpdateCampaignInfo(BaseModel):
+ """
+ # UpdateCampaignInfo Object ### Description The `UpdateCampaignInfo` object is used to partially update a campaign. Omitted fields are left unchanged. ### Usage Example Use in the `PUT Campaign` endpoint.
+ """ # noqa: E501
+ name: Optional[StrictStr] = Field(default=None, description="The name of the campaign.")
+ configuration: Optional[UpdateCampaignConfigurationInfo] = Field(default=None, description="Configuration fields to create or update.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["name", "configuration"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of UpdateCampaignInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of configuration
+ if self.configuration:
+ _dict['configuration'] = self.configuration.to_dict()
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of UpdateCampaignInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "name": obj.get("name"),
+ "configuration": UpdateCampaignConfigurationInfo.from_dict(obj["configuration"]) if obj.get("configuration") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/update_group_info.py b/opal_security/models/update_group_info.py
index 3893c1f..53b926b 100644
--- a/opal_security/models/update_group_info.py
+++ b/opal_security/models/update_group_info.py
@@ -53,8 +53,10 @@ class UpdateGroupInfo(BaseModel):
request_configuration_list: Optional[CreateRequestConfigurationInfoList] = Field(default=None, description="The request configuration list of the configuration template. If not provided, the default request configuration will be used. Deprecated in favor of `request_configurations`.")
custom_request_notification: Optional[Annotated[str, Field(strict=True, max_length=800)]] = Field(default=None, description="Custom request notification sent to the requester when the request is approved.")
risk_sensitivity_override: Optional[RiskSensitivityEnum] = None
+ match_remote_name: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the group's name should be synced from the end system. When true, the name is overwritten with the remote name on each sync, so a `name` provided together with this field set to true will be replaced at the next sync. If not provided, the current value is left unchanged.")
+ match_remote_description: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the group's description should be synced from the end system. When true, the description is overwritten with the remote description on each sync, so a `description` provided together with this field set to true will be replaced at the next sync. If not provided, the current value is left unchanged.")
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["group_id", "name", "description", "admin_owner_id", "max_duration", "recommended_duration", "require_manager_approval", "require_support_ticket", "folder_id", "require_mfa_to_approve", "require_mfa_to_request", "auto_approval", "configuration_template_id", "request_template_id", "is_requestable", "group_leader_user_ids", "extensions_duration_in_minutes", "request_configurations", "request_configuration_list", "custom_request_notification", "risk_sensitivity_override"]
+ __properties: ClassVar[List[str]] = ["group_id", "name", "description", "admin_owner_id", "max_duration", "recommended_duration", "require_manager_approval", "require_support_ticket", "folder_id", "require_mfa_to_approve", "require_mfa_to_request", "auto_approval", "configuration_template_id", "request_template_id", "is_requestable", "group_leader_user_ids", "extensions_duration_in_minutes", "request_configurations", "request_configuration_list", "custom_request_notification", "risk_sensitivity_override", "match_remote_name", "match_remote_description"]
model_config = ConfigDict(
populate_by_name=True,
@@ -144,7 +146,9 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"request_configurations": [RequestConfiguration.from_dict(_item) for _item in obj["request_configurations"]] if obj.get("request_configurations") is not None else None,
"request_configuration_list": CreateRequestConfigurationInfoList.from_dict(obj["request_configuration_list"]) if obj.get("request_configuration_list") is not None else None,
"custom_request_notification": obj.get("custom_request_notification"),
- "risk_sensitivity_override": obj.get("risk_sensitivity_override")
+ "risk_sensitivity_override": obj.get("risk_sensitivity_override"),
+ "match_remote_name": obj.get("match_remote_name"),
+ "match_remote_description": obj.get("match_remote_description")
})
# store additional fields in additional_properties
for _key in obj.keys():
diff --git a/opal_security/models/update_group_user_request.py b/opal_security/models/update_group_user_request.py
index 0d13b8e..9ad14f1 100644
--- a/opal_security/models/update_group_user_request.py
+++ b/opal_security/models/update_group_user_request.py
@@ -28,7 +28,7 @@ class UpdateGroupUserRequest(BaseModel):
"""
UpdateGroupUserRequest
""" # noqa: E501
- duration_minutes: Annotated[int, Field(le=525960, strict=True)] = Field(description="The updated duration for which the group can be accessed (in minutes). Use 0 for indefinite, or a negative value to revoke access.")
+ duration_minutes: Annotated[int, Field(le=153722867, strict=True)] = Field(description="The updated duration for which the group can be accessed (in minutes). Use 0 for indefinite, or a negative value to revoke access.")
access_level_remote_id: Optional[StrictStr] = Field(default=None, description="The updated remote ID of the access level granted to this user.")
additional_properties: Dict[str, Any] = {}
__properties: ClassVar[List[str]] = ["duration_minutes", "access_level_remote_id"]
diff --git a/opal_security/models/update_paladin_info.py b/opal_security/models/update_paladin_info.py
new file mode 100644
index 0000000..1163947
--- /dev/null
+++ b/opal_security/models/update_paladin_info.py
@@ -0,0 +1,110 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from opal_security.models.paladin_connector import PaladinConnector
+from typing import Optional, Set
+from typing_extensions import Self
+
+class UpdatePaladinInfo(BaseModel):
+ """
+ Information for updating a Paladin.
+ """ # noqa: E501
+ name: StrictStr = Field(description="The name of the Paladin.")
+ monitor_mode: Optional[StrictBool] = Field(default=None, description="When true, the Paladin reasons about requests but takes no action. If omitted, the existing value is preserved.")
+ admin_view_only: Optional[StrictBool] = Field(default=None, description="When true, recommendations are visible only to admins. Only meaningful when monitor_mode is true. If omitted, the existing value is preserved.")
+ enabled_connectors: Optional[List[PaladinConnector]] = Field(default=None, description="The connectors the Paladin is allowed to use. If omitted, the existing connectors are preserved.")
+ instructions: Optional[StrictStr] = Field(default=None, description="The free-form instructions that guide the Paladin's decisions. If omitted, the existing instructions are preserved.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["name", "monitor_mode", "admin_view_only", "enabled_connectors", "instructions"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of UpdatePaladinInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of UpdatePaladinInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "name": obj.get("name"),
+ "monitor_mode": obj.get("monitor_mode"),
+ "admin_view_only": obj.get("admin_view_only"),
+ "enabled_connectors": obj.get("enabled_connectors"),
+ "instructions": obj.get("instructions")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/update_request_template_info.py b/opal_security/models/update_request_template_info.py
new file mode 100644
index 0000000..389ff38
--- /dev/null
+++ b/opal_security/models/update_request_template_info.py
@@ -0,0 +1,114 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.request_template_custom_field_input import RequestTemplateCustomFieldInput
+from typing import Optional, Set
+from typing_extensions import Self
+
+class UpdateRequestTemplateInfo(BaseModel):
+ """
+ Information for updating a request template. Omitted properties are left unchanged, but `custom_fields` replaces the template's fields wholesale when provided.
+ """ # noqa: E501
+ request_template_id: UUID = Field(description="The ID of the request template to update.")
+ name: Optional[StrictStr] = Field(default=None, description="The new name of the request template.")
+ custom_fields: Optional[List[RequestTemplateCustomFieldInput]] = Field(default=None, description="The complete set of fields for the template. Any field not included is removed.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["request_template_id", "name", "custom_fields"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of UpdateRequestTemplateInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # override the default output from pydantic by calling `to_dict()` of each item in custom_fields (list)
+ _items = []
+ if self.custom_fields:
+ for _item_custom_fields in self.custom_fields:
+ if _item_custom_fields:
+ _items.append(_item_custom_fields.to_dict())
+ _dict['custom_fields'] = _items
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of UpdateRequestTemplateInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "request_template_id": obj.get("request_template_id"),
+ "name": obj.get("name"),
+ "custom_fields": [RequestTemplateCustomFieldInput.from_dict(_item) for _item in obj["custom_fields"]] if obj.get("custom_fields") is not None else None
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/update_resource_custom_access_level_info.py b/opal_security/models/update_resource_custom_access_level_info.py
new file mode 100644
index 0000000..b828f59
--- /dev/null
+++ b/opal_security/models/update_resource_custom_access_level_info.py
@@ -0,0 +1,109 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictBool, StrictInt, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from typing import Optional, Set
+from typing_extensions import Self
+
+class UpdateResourceCustomAccessLevelInfo(BaseModel):
+ """
+ Info for updating a custom access level.
+ """ # noqa: E501
+ access_level_name: Optional[StrictStr] = Field(default=None, description="The new human-readable name.")
+ policy: Optional[StrictStr] = Field(default=None, description="The new policy document.")
+ requestable_by_default: Optional[StrictBool] = Field(default=None, description="Whether the role is requestable.")
+ stackable_sensitivity_index: Optional[StrictInt] = Field(default=None, description="The new sensitivity index.")
+ clear_stackable_sensitivity_index: Optional[StrictBool] = Field(default=None, description="Set to true to remove from the hierarchy.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["access_level_name", "policy", "requestable_by_default", "stackable_sensitivity_index", "clear_stackable_sensitivity_index"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of UpdateResourceCustomAccessLevelInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of UpdateResourceCustomAccessLevelInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "access_level_name": obj.get("access_level_name"),
+ "policy": obj.get("policy"),
+ "requestable_by_default": obj.get("requestable_by_default"),
+ "stackable_sensitivity_index": obj.get("stackable_sensitivity_index"),
+ "clear_stackable_sensitivity_index": obj.get("clear_stackable_sensitivity_index")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/update_resource_info.py b/opal_security/models/update_resource_info.py
index 6c46b86..f0a28a0 100644
--- a/opal_security/models/update_resource_info.py
+++ b/opal_security/models/update_resource_info.py
@@ -49,6 +49,8 @@ class UpdateResourceInfo(BaseModel):
ticket_propagation: Optional[TicketPropagationConfiguration] = None
custom_request_notification: Optional[Annotated[str, Field(strict=True, max_length=800)]] = Field(default=None, description="Custom request notification sent upon request approval.")
risk_sensitivity_override: Optional[RiskSensitivityEnum] = None
+ match_remote_name: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the resource's name should be synced from the end system. When true, the name is overwritten with the remote name on each sync, so a `name` provided together with this field set to true will be replaced at the next sync. If not provided, the current value is left unchanged.")
+ match_remote_description: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not the resource's description should be synced from the end system. When true, the description is overwritten with the remote description on each sync, so a `description` provided together with this field set to true will be replaced at the next sync. If not provided, the current value is left unchanged.")
configuration_template_id: Optional[UUID] = Field(default=None, description="The ID of the associated configuration template.")
request_template_id: Optional[UUID] = Field(default=None, description="The ID of the associated request template. Deprecated in favor of `request_configurations`.")
is_requestable: Optional[StrictBool] = Field(default=None, description="A bool representing whether or not to allow access requests to this resource. Deprecated in favor of `request_configurations`.")
@@ -57,7 +59,7 @@ class UpdateResourceInfo(BaseModel):
request_configurations: Optional[List[RequestConfiguration]] = Field(default=None, description="A list of configurations for requests to this resource. If not provided, the default request configuration will be used.")
request_configuration_list: Optional[CreateRequestConfigurationInfoList] = Field(default=None, description="A list of configurations for requests to this resource. If not provided, the default request configuration will be used. Deprecated in favor of `request_configurations`.")
additional_properties: Dict[str, Any] = {}
- __properties: ClassVar[List[str]] = ["resource_id", "name", "description", "admin_owner_id", "max_duration", "recommended_duration", "require_manager_approval", "require_support_ticket", "folder_id", "require_mfa_to_approve", "require_mfa_to_request", "require_mfa_to_connect", "auto_approval", "ticket_propagation", "custom_request_notification", "risk_sensitivity_override", "configuration_template_id", "request_template_id", "is_requestable", "extensions_duration_in_minutes", "parent_resource_id", "request_configurations", "request_configuration_list"]
+ __properties: ClassVar[List[str]] = ["resource_id", "name", "description", "admin_owner_id", "max_duration", "recommended_duration", "require_manager_approval", "require_support_ticket", "folder_id", "require_mfa_to_approve", "require_mfa_to_request", "require_mfa_to_connect", "auto_approval", "ticket_propagation", "custom_request_notification", "risk_sensitivity_override", "match_remote_name", "match_remote_description", "configuration_template_id", "request_template_id", "is_requestable", "extensions_duration_in_minutes", "parent_resource_id", "request_configurations", "request_configuration_list"]
model_config = ConfigDict(
populate_by_name=True,
@@ -146,6 +148,8 @@ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
"ticket_propagation": TicketPropagationConfiguration.from_dict(obj["ticket_propagation"]) if obj.get("ticket_propagation") is not None else None,
"custom_request_notification": obj.get("custom_request_notification"),
"risk_sensitivity_override": obj.get("risk_sensitivity_override"),
+ "match_remote_name": obj.get("match_remote_name"),
+ "match_remote_description": obj.get("match_remote_description"),
"configuration_template_id": obj.get("configuration_template_id"),
"request_template_id": obj.get("request_template_id"),
"is_requestable": obj.get("is_requestable"),
diff --git a/opal_security/models/update_resource_user_request.py b/opal_security/models/update_resource_user_request.py
index cef9218..587fbb7 100644
--- a/opal_security/models/update_resource_user_request.py
+++ b/opal_security/models/update_resource_user_request.py
@@ -28,7 +28,7 @@ class UpdateResourceUserRequest(BaseModel):
"""
UpdateResourceUserRequest
""" # noqa: E501
- duration_minutes: Annotated[int, Field(le=525960, strict=True)] = Field(description="The updated duration for which the resource can be accessed (in minutes). Use 0 for indefinite.")
+ duration_minutes: Annotated[int, Field(le=153722867, strict=True)] = Field(description="The updated duration for which the resource can be accessed (in minutes). Use 0 for indefinite.")
access_level_remote_id: Optional[StrictStr] = Field(default=None, description="The updated remote ID of the access level granted to this user.")
additional_properties: Dict[str, Any] = {}
__properties: ClassVar[List[str]] = ["duration_minutes", "access_level_remote_id"]
diff --git a/opal_security/models/update_user_info.py b/opal_security/models/update_user_info.py
new file mode 100644
index 0000000..3eec4b3
--- /dev/null
+++ b/opal_security/models/update_user_info.py
@@ -0,0 +1,104 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from typing import Optional, Set
+from typing_extensions import Self
+
+class UpdateUserInfo(BaseModel):
+ """
+ The user fields to update.
+ """ # noqa: E501
+ manager_id: Optional[UUID] = Field(default=None, description="The user's manager ID. Set to null to remove the manager.")
+ position: Optional[StrictStr] = Field(default=None, description="The user's position.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["manager_id", "position"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of UpdateUserInfo from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of UpdateUserInfo from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "manager_id": obj.get("manager_id"),
+ "position": obj.get("position")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/user_product_role_enum.py b/opal_security/models/user_product_role_enum.py
new file mode 100644
index 0000000..7e34173
--- /dev/null
+++ b/opal_security/models/user_product_role_enum.py
@@ -0,0 +1,38 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class UserProductRoleEnum(str, Enum):
+ """
+ The product role assigned to a user.
+ """
+
+ """
+ allowed enum values
+ """
+ MEMBER = 'MEMBER'
+ ADMIN = 'ADMIN'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of UserProductRoleEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/viewer_campaign_item.py b/opal_security/models/viewer_campaign_item.py
new file mode 100644
index 0000000..48ad773
--- /dev/null
+++ b/opal_security/models/viewer_campaign_item.py
@@ -0,0 +1,139 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import pprint
+import re # noqa: F401
+import json
+
+from datetime import datetime
+from pydantic import BaseModel, ConfigDict, Field, StrictStr
+from typing import Any, ClassVar, Dict, List, Optional
+from uuid import UUID
+from opal_security.models.entity_type_enum import EntityTypeEnum
+from opal_security.models.viewer_campaign_item_review_decision_enum import ViewerCampaignItemReviewDecisionEnum
+from typing import Optional, Set
+from typing_extensions import Self
+
+class ViewerCampaignItem(BaseModel):
+ """
+ A campaign review item assigned to the current viewer, matching GraphQL `ViewerCampaignItem`.
+ """ # noqa: E501
+ campaign_item_review_id: UUID = Field(description="The ID of the campaign item review.")
+ decision: Optional[ViewerCampaignItemReviewDecisionEnum] = Field(default=None, description="The reviewer's decision. Null when undecided.")
+ note: Optional[StrictStr] = Field(default=None, description="Optional note from the reviewer.")
+ decided_at: Optional[datetime] = Field(default=None, description="When the decision was finalized.")
+ pending_decision: Optional[ViewerCampaignItemReviewDecisionEnum] = Field(default=None, description="Pending decision staged by the viewer, if any.")
+ pending_note: Optional[StrictStr] = Field(default=None, description="Pending note attached to the reviewer's pending decision.")
+ updated_access_level_remote_id: Optional[StrictStr] = Field(default=None, description="Target access level remote ID when decision is CHANGE_ROLE.")
+ pending_updated_access_level_remote_id: Optional[StrictStr] = Field(default=None, description="Pending target access level remote ID when decision is CHANGE_ROLE.")
+ reassigned_to_reviewer_ids: Optional[List[UUID]] = Field(default=None, description="User IDs this review was reassigned to.")
+ principal_id: UUID = Field(description="Principal ID from the role assignment.")
+ principal_type: EntityTypeEnum
+ entity_id: UUID = Field(description="Entity ID from the role assignment.")
+ entity_type: EntityTypeEnum
+ access_level_name: Optional[StrictStr] = Field(default=None, description="Denormalized access level name.")
+ access_level_remote_id: Optional[StrictStr] = Field(default=None, description="Access level remote ID from the role assignment.")
+ granted_at: datetime = Field(description="When the access was originally granted.")
+ expires_at: Optional[datetime] = Field(default=None, description="When the access expires, if set.")
+ role_assignment_id: UUID = Field(description="ID of the underlying role assignment.")
+ additional_properties: Dict[str, Any] = {}
+ __properties: ClassVar[List[str]] = ["campaign_item_review_id", "decision", "note", "decided_at", "pending_decision", "pending_note", "updated_access_level_remote_id", "pending_updated_access_level_remote_id", "reassigned_to_reviewer_ids", "principal_id", "principal_type", "entity_id", "entity_type", "access_level_name", "access_level_remote_id", "granted_at", "expires_at", "role_assignment_id"]
+
+ model_config = ConfigDict(
+ populate_by_name=True,
+ validate_assignment=True,
+ protected_namespaces=(),
+ )
+
+
+ def to_str(self) -> str:
+ """Returns the string representation of the model using alias"""
+ return pprint.pformat(self.model_dump(by_alias=True))
+
+ def to_json(self) -> str:
+ """Returns the JSON representation of the model using alias"""
+ # TODO: pydantic v2: use .model_dump_json(by_alias=True, exclude_unset=True) instead
+ return json.dumps(self.to_dict())
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Optional[Self]:
+ """Create an instance of ViewerCampaignItem from a JSON string"""
+ return cls.from_dict(json.loads(json_str))
+
+ def to_dict(self) -> Dict[str, Any]:
+ """Return the dictionary representation of the model using alias.
+
+ This has the following differences from calling pydantic's
+ `self.model_dump(by_alias=True)`:
+
+ * `None` is only added to the output dict for nullable fields that
+ were set at model initialization. Other fields with value `None`
+ are ignored.
+ * Fields in `self.additional_properties` are added to the output dict.
+ """
+ excluded_fields: Set[str] = set([
+ "additional_properties",
+ ])
+
+ _dict = self.model_dump(
+ by_alias=True,
+ exclude=excluded_fields,
+ exclude_none=True,
+ )
+ # puts key-value pairs in additional_properties in the top level
+ if self.additional_properties is not None:
+ for _key, _value in self.additional_properties.items():
+ _dict[_key] = _value
+
+ return _dict
+
+ @classmethod
+ def from_dict(cls, obj: Optional[Dict[str, Any]]) -> Optional[Self]:
+ """Create an instance of ViewerCampaignItem from a dict"""
+ if obj is None:
+ return None
+
+ if not isinstance(obj, dict):
+ return cls.model_validate(obj)
+
+ _obj = cls.model_validate({
+ "campaign_item_review_id": obj.get("campaign_item_review_id"),
+ "decision": obj.get("decision"),
+ "note": obj.get("note"),
+ "decided_at": obj.get("decided_at"),
+ "pending_decision": obj.get("pending_decision"),
+ "pending_note": obj.get("pending_note"),
+ "updated_access_level_remote_id": obj.get("updated_access_level_remote_id"),
+ "pending_updated_access_level_remote_id": obj.get("pending_updated_access_level_remote_id"),
+ "reassigned_to_reviewer_ids": obj.get("reassigned_to_reviewer_ids"),
+ "principal_id": obj.get("principal_id"),
+ "principal_type": obj.get("principal_type"),
+ "entity_id": obj.get("entity_id"),
+ "entity_type": obj.get("entity_type"),
+ "access_level_name": obj.get("access_level_name"),
+ "access_level_remote_id": obj.get("access_level_remote_id"),
+ "granted_at": obj.get("granted_at"),
+ "expires_at": obj.get("expires_at"),
+ "role_assignment_id": obj.get("role_assignment_id")
+ })
+ # store additional fields in additional_properties
+ for _key in obj.keys():
+ if _key not in cls.__properties:
+ _obj.additional_properties[_key] = obj.get(_key)
+
+ return _obj
+
+
diff --git a/opal_security/models/viewer_campaign_item_review_decision_enum.py b/opal_security/models/viewer_campaign_item_review_decision_enum.py
new file mode 100644
index 0000000..e2ca27c
--- /dev/null
+++ b/opal_security/models/viewer_campaign_item_review_decision_enum.py
@@ -0,0 +1,42 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class ViewerCampaignItemReviewDecisionEnum(str, Enum):
+ """
+ Decision recorded on a campaign item review row.
+ """
+
+ """
+ allowed enum values
+ """
+ APPROVED = 'APPROVED'
+ REVOKED = 'REVOKED'
+ CHANGE_ROLE = 'CHANGE_ROLE'
+ ADMIN_REVOKED = 'ADMIN_REVOKED'
+ NO_ACTION = 'NO_ACTION'
+ REASSIGNED = 'REASSIGNED'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of ViewerCampaignItemReviewDecisionEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/viewer_campaign_item_sort_field_enum.py b/opal_security/models/viewer_campaign_item_sort_field_enum.py
new file mode 100644
index 0000000..350f005
--- /dev/null
+++ b/opal_security/models/viewer_campaign_item_sort_field_enum.py
@@ -0,0 +1,40 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class ViewerCampaignItemSortFieldEnum(str, Enum):
+ """
+ Sort field for viewer campaign items.
+ """
+
+ """
+ allowed enum values
+ """
+ PRINCIPAL_NAME = 'PRINCIPAL_NAME'
+ ENTITY_NAME = 'ENTITY_NAME'
+ EXPIRATION = 'EXPIRATION'
+ LAST_USED = 'LAST_USED'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of ViewerCampaignItemSortFieldEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/opal_security/models/viewer_campaign_item_status_enum.py b/opal_security/models/viewer_campaign_item_status_enum.py
new file mode 100644
index 0000000..bca318e
--- /dev/null
+++ b/opal_security/models/viewer_campaign_item_status_enum.py
@@ -0,0 +1,42 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+from __future__ import annotations
+import json
+from enum import Enum
+from typing_extensions import Self
+
+
+class ViewerCampaignItemStatusEnum(str, Enum):
+ """
+ Decision status for a viewer campaign item.
+ """
+
+ """
+ allowed enum values
+ """
+ APPROVED = 'APPROVED'
+ REVOKED = 'REVOKED'
+ CHANGE_ROLE = 'CHANGE_ROLE'
+ NO_ACTION = 'NO_ACTION'
+ PENDING = 'PENDING'
+ REASSIGNED = 'REASSIGNED'
+
+ @classmethod
+ def from_json(cls, json_str: str) -> Self:
+ """Create an instance of ViewerCampaignItemStatusEnum from a JSON string"""
+ return cls(json.loads(json_str))
+
+
diff --git a/test/test_campaign.py b/test/test_campaign.py
new file mode 100644
index 0000000..f262e1b
--- /dev/null
+++ b/test/test_campaign.py
@@ -0,0 +1,72 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign import Campaign
+
+class TestCampaign(unittest.TestCase):
+ """Campaign unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> Campaign:
+ """Test Campaign
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `Campaign`
+ """
+ model = Campaign()
+ if include_optional:
+ return Campaign(
+ campaign_id = 'f454d283-ca87-4a8a-bdbb-df212eca5353',
+ name = 'Q3 Access Review',
+ status = 'ONGOING',
+ is_template = False,
+ created_at = '2026-07-01T00:00:00.000+00:00',
+ updated_at = '2026-07-01T00:00:00.000+00:00',
+ created_by_user_id = '32acc112-21ff-4669-91c2-21e27683eaa1',
+ configuration = {configuration_id=39a4d283-ca87-4a8a-bdbb-df212eca5fdb, created_at=2026-07-01T00:00:00.000+00:00, updated_at=2026-07-01T00:00:00.000+00:00, reviewer_assignment_policy=MANUALLY, allow_self_review=false, send_reviewer_assignment_notification=true, allow_reviewer_reassignment=false, end_date=2026-09-30T00:00:00.000+00:00, timezone=America/Los_Angeles, revoke_on=END, reminder_schedule=[7, 3, 1], reminder_include_manager=true, require_reason_on_denial=false, hide_ai_suggestions=false, group_asset_visibility_policy=STRICT, is_template=false},
+ started_at = '2026-07-02T00:00:00.000+00:00',
+ started_by_user_id = '32acc112-21ff-4669-91c2-21e27683eaa1',
+ stopped_at = '2026-07-10T00:00:00.000+00:00',
+ stopped_by_user_id = '32acc112-21ff-4669-91c2-21e27683eaa1',
+ ended_at = '2026-07-14T00:00:00.000+00:00',
+ ended_by_user_id = '32acc112-21ff-4669-91c2-21e27683eaa1'
+ )
+ else:
+ return Campaign(
+ campaign_id = 'f454d283-ca87-4a8a-bdbb-df212eca5353',
+ name = 'Q3 Access Review',
+ status = 'ONGOING',
+ is_template = False,
+ created_at = '2026-07-01T00:00:00.000+00:00',
+ updated_at = '2026-07-01T00:00:00.000+00:00',
+ created_by_user_id = '32acc112-21ff-4669-91c2-21e27683eaa1',
+ )
+ """
+
+ def testCampaign(self):
+ """Test Campaign"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_configuration.py b/test/test_campaign_configuration.py
new file mode 100644
index 0000000..515511a
--- /dev/null
+++ b/test/test_campaign_configuration.py
@@ -0,0 +1,147 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_configuration import CampaignConfiguration
+
+class TestCampaignConfiguration(unittest.TestCase):
+ """CampaignConfiguration unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CampaignConfiguration:
+ """Test CampaignConfiguration
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CampaignConfiguration`
+ """
+ model = CampaignConfiguration()
+ if include_optional:
+ return CampaignConfiguration(
+ configuration_id = '39a4d283-ca87-4a8a-bdbb-df212eca5fdb',
+ created_at = '2026-07-01T00:00:00.000+00:00',
+ updated_at = '2026-07-01T00:00:00.000+00:00',
+ query = opal_security.models.opal_access_path_query_body.OpalAccessPathQueryBody(
+ principal_filter = opal_security.models.access_entity_filters.AccessEntityFilters(
+ entity_types = [
+ 'RESOURCE'
+ ],
+ entity_item_types = [
+ 'OPAL_ROLE'
+ ],
+ entity_name = opal_security.models.entity_name_filter.EntityNameFilter(
+ string_match_type = 'CONTAINS',
+ string = 'engineering', ),
+ entity_tag = opal_security.models.entity_tag_filter.EntityTagFilter(
+ key = 'team',
+ value = 'platform',
+ connection_id = '', ),
+ hr_idp_status = opal_security.models.idp_status_filter.IdpStatusFilter(
+ statuses = [
+ 'ACTIVE'
+ ],
+ not = True, ),
+ entity_admin_owner = opal_security.models.entity_admin_filter.EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ not = True, ),
+ entity_ids = [
+ ''
+ ],
+ imported_from_app = [
+ ''
+ ],
+ role_remote_ids = [
+ ''
+ ],
+ role_names = [
+ ''
+ ],
+ all_of = [
+ opal_security.models.access_entity_filters.AccessEntityFilters(
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), )
+ ],
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), ),
+ entitlement_filter = ,
+ principal_access_filters = null,
+ entitlement_access_filters = null,
+ access_level_remote_ids = [
+ ''
+ ],
+ access_level_names = [
+ ''
+ ],
+ edge_filter = opal_security.models.opal_access_path_edge_filter.OpalAccessPathEdgeFilter(
+ direct_only = True,
+ access_duration_type = 'EXPIRING_ONLY', ), ),
+ reviewer_assignment_policy = 'MANUALLY',
+ allow_self_review = False,
+ send_reviewer_assignment_notification = True,
+ allow_reviewer_reassignment = False,
+ start_date = '2026-07-02T00:00:00.000+00:00',
+ end_date = '2026-09-30T00:00:00.000+00:00',
+ timezone = 'America/Los_Angeles',
+ revoke_on = 'END',
+ reminder_schedule = [7, 3, 1],
+ reminder_include_manager = True,
+ require_reason_on_denial = False,
+ hide_ai_suggestions = False,
+ custom_start_message = 'Please complete your reviews by Friday.',
+ group_asset_visibility_policy = 'STRICT',
+ is_template = False,
+ cron_expression = '0 9 1 * *',
+ next_scheduled_run = '2026-08-01T16:00:00.000+00:00',
+ last_scheduled_run = '2026-07-01T16:00:00.000+00:00',
+ recurring_duration_days = 14
+ )
+ else:
+ return CampaignConfiguration(
+ configuration_id = '39a4d283-ca87-4a8a-bdbb-df212eca5fdb',
+ created_at = '2026-07-01T00:00:00.000+00:00',
+ updated_at = '2026-07-01T00:00:00.000+00:00',
+ reviewer_assignment_policy = 'MANUALLY',
+ allow_self_review = False,
+ send_reviewer_assignment_notification = True,
+ allow_reviewer_reassignment = False,
+ timezone = 'America/Los_Angeles',
+ revoke_on = 'END',
+ reminder_include_manager = True,
+ require_reason_on_denial = False,
+ hide_ai_suggestions = False,
+ group_asset_visibility_policy = 'STRICT',
+ is_template = False,
+ )
+ """
+
+ def testCampaignConfiguration(self):
+ """Test CampaignConfiguration"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_group_asset_visibility_policy_enum.py b/test/test_campaign_group_asset_visibility_policy_enum.py
new file mode 100644
index 0000000..e7fe747
--- /dev/null
+++ b/test/test_campaign_group_asset_visibility_policy_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_group_asset_visibility_policy_enum import CampaignGroupAssetVisibilityPolicyEnum
+
+class TestCampaignGroupAssetVisibilityPolicyEnum(unittest.TestCase):
+ """CampaignGroupAssetVisibilityPolicyEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testCampaignGroupAssetVisibilityPolicyEnum(self):
+ """Test CampaignGroupAssetVisibilityPolicyEnum"""
+ # inst = CampaignGroupAssetVisibilityPolicyEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_item.py b/test/test_campaign_item.py
new file mode 100644
index 0000000..dcd2d46
--- /dev/null
+++ b/test/test_campaign_item.py
@@ -0,0 +1,97 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_item import CampaignItem
+
+class TestCampaignItem(unittest.TestCase):
+ """CampaignItem unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CampaignItem:
+ """Test CampaignItem
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CampaignItem`
+ """
+ model = CampaignItem()
+ if include_optional:
+ return CampaignItem(
+ campaign_item_id = '',
+ campaign_id = '',
+ target_type = 'ROLE_ASSIGNMENT',
+ role_assignment_id = '',
+ status = 'PENDING',
+ created_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ is_target_deleted = True,
+ principal_id = '',
+ principal_type = 'GROUP',
+ entity_id = '',
+ entity_type = 'GROUP',
+ access_level = {access_level_name=AdminRole, access_level_remote_id=arn:aws:iam::590304332660:role/AdministratorAccess},
+ access_level_name = '',
+ reviews = [
+ opal_security.models.campaign_item_review.CampaignItemReview(
+ campaign_item_review_id = '',
+ campaign_item_id = '',
+ reviewer_user_id = '',
+ assignment_source = 'MANUAL',
+ decision = null,
+ note = '',
+ updated_access_level_remote_id = '',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'), )
+ ],
+ admin_override = opal_security.models.campaign_item_admin_override.CampaignItemAdminOverride(
+ actor_user_id = '',
+ decision = 'APPROVED',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'), )
+ )
+ else:
+ return CampaignItem(
+ campaign_item_id = '',
+ campaign_id = '',
+ target_type = 'ROLE_ASSIGNMENT',
+ role_assignment_id = '',
+ status = 'PENDING',
+ created_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ is_target_deleted = True,
+ reviews = [
+ opal_security.models.campaign_item_review.CampaignItemReview(
+ campaign_item_review_id = '',
+ campaign_item_id = '',
+ reviewer_user_id = '',
+ assignment_source = 'MANUAL',
+ decision = null,
+ note = '',
+ updated_access_level_remote_id = '',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'), )
+ ],
+ )
+ """
+
+ def testCampaignItem(self):
+ """Test CampaignItem"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_item_admin_override.py b/test/test_campaign_item_admin_override.py
new file mode 100644
index 0000000..dd5b36a
--- /dev/null
+++ b/test/test_campaign_item_admin_override.py
@@ -0,0 +1,57 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_item_admin_override import CampaignItemAdminOverride
+
+class TestCampaignItemAdminOverride(unittest.TestCase):
+ """CampaignItemAdminOverride unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CampaignItemAdminOverride:
+ """Test CampaignItemAdminOverride
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CampaignItemAdminOverride`
+ """
+ model = CampaignItemAdminOverride()
+ if include_optional:
+ return CampaignItemAdminOverride(
+ actor_user_id = '',
+ decision = 'APPROVED',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f')
+ )
+ else:
+ return CampaignItemAdminOverride(
+ actor_user_id = '',
+ decision = 'APPROVED',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ )
+ """
+
+ def testCampaignItemAdminOverride(self):
+ """Test CampaignItemAdminOverride"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_item_review.py b/test/test_campaign_item_review.py
new file mode 100644
index 0000000..060b6e1
--- /dev/null
+++ b/test/test_campaign_item_review.py
@@ -0,0 +1,63 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_item_review import CampaignItemReview
+
+class TestCampaignItemReview(unittest.TestCase):
+ """CampaignItemReview unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CampaignItemReview:
+ """Test CampaignItemReview
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CampaignItemReview`
+ """
+ model = CampaignItemReview()
+ if include_optional:
+ return CampaignItemReview(
+ campaign_item_review_id = '',
+ campaign_item_id = '',
+ reviewer_user_id = '',
+ assignment_source = 'MANUAL',
+ decision = 'APPROVED',
+ note = '',
+ updated_access_level_remote_id = '',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f')
+ )
+ else:
+ return CampaignItemReview(
+ campaign_item_review_id = '',
+ campaign_item_id = '',
+ reviewer_user_id = '',
+ assignment_source = 'MANUAL',
+ )
+ """
+
+ def testCampaignItemReview(self):
+ """Test CampaignItemReview"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_item_review_decision_enum.py b/test/test_campaign_item_review_decision_enum.py
new file mode 100644
index 0000000..513a9c5
--- /dev/null
+++ b/test/test_campaign_item_review_decision_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_item_review_decision_enum import CampaignItemReviewDecisionEnum
+
+class TestCampaignItemReviewDecisionEnum(unittest.TestCase):
+ """CampaignItemReviewDecisionEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testCampaignItemReviewDecisionEnum(self):
+ """Test CampaignItemReviewDecisionEnum"""
+ # inst = CampaignItemReviewDecisionEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_item_reviewer_assignment_source_enum.py b/test/test_campaign_item_reviewer_assignment_source_enum.py
new file mode 100644
index 0000000..3d73ba3
--- /dev/null
+++ b/test/test_campaign_item_reviewer_assignment_source_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_item_reviewer_assignment_source_enum import CampaignItemReviewerAssignmentSourceEnum
+
+class TestCampaignItemReviewerAssignmentSourceEnum(unittest.TestCase):
+ """CampaignItemReviewerAssignmentSourceEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testCampaignItemReviewerAssignmentSourceEnum(self):
+ """Test CampaignItemReviewerAssignmentSourceEnum"""
+ # inst = CampaignItemReviewerAssignmentSourceEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_item_status_enum.py b/test/test_campaign_item_status_enum.py
new file mode 100644
index 0000000..ba750c4
--- /dev/null
+++ b/test/test_campaign_item_status_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_item_status_enum import CampaignItemStatusEnum
+
+class TestCampaignItemStatusEnum(unittest.TestCase):
+ """CampaignItemStatusEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testCampaignItemStatusEnum(self):
+ """Test CampaignItemStatusEnum"""
+ # inst = CampaignItemStatusEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_item_target_type_enum.py b/test/test_campaign_item_target_type_enum.py
new file mode 100644
index 0000000..8bc15a8
--- /dev/null
+++ b/test/test_campaign_item_target_type_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_item_target_type_enum import CampaignItemTargetTypeEnum
+
+class TestCampaignItemTargetTypeEnum(unittest.TestCase):
+ """CampaignItemTargetTypeEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testCampaignItemTargetTypeEnum(self):
+ """Test CampaignItemTargetTypeEnum"""
+ # inst = CampaignItemTargetTypeEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_revoke_on_enum.py b/test/test_campaign_revoke_on_enum.py
new file mode 100644
index 0000000..cdde5a0
--- /dev/null
+++ b/test/test_campaign_revoke_on_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_revoke_on_enum import CampaignRevokeOnEnum
+
+class TestCampaignRevokeOnEnum(unittest.TestCase):
+ """CampaignRevokeOnEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testCampaignRevokeOnEnum(self):
+ """Test CampaignRevokeOnEnum"""
+ # inst = CampaignRevokeOnEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaign_status_enum.py b/test/test_campaign_status_enum.py
new file mode 100644
index 0000000..d2b1c42
--- /dev/null
+++ b/test/test_campaign_status_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.campaign_status_enum import CampaignStatusEnum
+
+class TestCampaignStatusEnum(unittest.TestCase):
+ """CampaignStatusEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testCampaignStatusEnum(self):
+ """Test CampaignStatusEnum"""
+ # inst = CampaignStatusEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_campaigns_api.py b/test/test_campaigns_api.py
new file mode 100644
index 0000000..5e70d0c
--- /dev/null
+++ b/test/test_campaigns_api.py
@@ -0,0 +1,93 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.api.campaigns_api import CampaignsApi
+
+
+class TestCampaignsApi(unittest.TestCase):
+ """CampaignsApi unit test stubs"""
+
+ def setUp(self) -> None:
+ self.api = CampaignsApi()
+
+ def tearDown(self) -> None:
+ pass
+
+ def test_create_campaign(self) -> None:
+ """Test case for create_campaign
+
+ """
+ pass
+
+ def test_end_campaign(self) -> None:
+ """Test case for end_campaign
+
+ End campaign
+ """
+ pass
+
+ def test_get_campaign(self) -> None:
+ """Test case for get_campaign
+
+ Get campaign by ID
+ """
+ pass
+
+ def test_get_campaign_items(self) -> None:
+ """Test case for get_campaign_items
+
+ List campaign items
+ """
+ pass
+
+ def test_get_campaign_viewer_items(self) -> None:
+ """Test case for get_campaign_viewer_items
+
+ List viewer campaign items
+ """
+ pass
+
+ def test_get_campaigns(self) -> None:
+ """Test case for get_campaigns
+
+ """
+ pass
+
+ def test_start_campaign(self) -> None:
+ """Test case for start_campaign
+
+ Start campaign
+ """
+ pass
+
+ def test_stop_campaign(self) -> None:
+ """Test case for stop_campaign
+
+ Stop campaign
+ """
+ pass
+
+ def test_update_campaign(self) -> None:
+ """Test case for update_campaign
+
+ Update campaign
+ """
+ pass
+
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_create_campaign_configuration_info.py b/test/test_create_campaign_configuration_info.py
new file mode 100644
index 0000000..8bb4c92
--- /dev/null
+++ b/test/test_create_campaign_configuration_info.py
@@ -0,0 +1,191 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.create_campaign_configuration_info import CreateCampaignConfigurationInfo
+
+class TestCreateCampaignConfigurationInfo(unittest.TestCase):
+ """CreateCampaignConfigurationInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CreateCampaignConfigurationInfo:
+ """Test CreateCampaignConfigurationInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CreateCampaignConfigurationInfo`
+ """
+ model = CreateCampaignConfigurationInfo()
+ if include_optional:
+ return CreateCampaignConfigurationInfo(
+ query = opal_security.models.opal_access_path_query_body.OpalAccessPathQueryBody(
+ principal_filter = opal_security.models.access_entity_filters.AccessEntityFilters(
+ entity_types = [
+ 'RESOURCE'
+ ],
+ entity_item_types = [
+ 'OPAL_ROLE'
+ ],
+ entity_name = opal_security.models.entity_name_filter.EntityNameFilter(
+ string_match_type = 'CONTAINS',
+ string = 'engineering', ),
+ entity_tag = opal_security.models.entity_tag_filter.EntityTagFilter(
+ key = 'team',
+ value = 'platform',
+ connection_id = '', ),
+ hr_idp_status = opal_security.models.idp_status_filter.IdpStatusFilter(
+ statuses = [
+ 'ACTIVE'
+ ],
+ not = True, ),
+ entity_admin_owner = opal_security.models.entity_admin_filter.EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ not = True, ),
+ entity_ids = [
+ ''
+ ],
+ imported_from_app = [
+ ''
+ ],
+ role_remote_ids = [
+ ''
+ ],
+ role_names = [
+ ''
+ ],
+ all_of = [
+ opal_security.models.access_entity_filters.AccessEntityFilters(
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), )
+ ],
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), ),
+ entitlement_filter = ,
+ principal_access_filters = null,
+ entitlement_access_filters = null,
+ access_level_remote_ids = [
+ ''
+ ],
+ access_level_names = [
+ ''
+ ],
+ edge_filter = opal_security.models.opal_access_path_edge_filter.OpalAccessPathEdgeFilter(
+ direct_only = True,
+ access_duration_type = 'EXPIRING_ONLY', ), ),
+ reviewer_assignment_policy = 'MANUALLY',
+ allow_self_review = False,
+ send_reviewer_assignment_notification = True,
+ allow_reviewer_reassignment = False,
+ start_date = '2026-07-02T00:00:00.000+00:00',
+ end_date = '2026-09-30T00:00:00.000+00:00',
+ timezone = 'America/Los_Angeles',
+ revoke_on = 'END',
+ reminder_schedule = [7, 3, 1],
+ reminder_include_manager = True,
+ require_reason_on_denial = False,
+ hide_ai_suggestions = False,
+ custom_start_message = 'Please complete your reviews by Friday.',
+ group_asset_visibility_policy = 'STRICT',
+ is_template = False,
+ cron_expression = '0 9 1 * *',
+ recurring_duration_days = 14,
+ excluded_role_assignment_ids = [
+ ''
+ ]
+ )
+ else:
+ return CreateCampaignConfigurationInfo(
+ query = opal_security.models.opal_access_path_query_body.OpalAccessPathQueryBody(
+ principal_filter = opal_security.models.access_entity_filters.AccessEntityFilters(
+ entity_types = [
+ 'RESOURCE'
+ ],
+ entity_item_types = [
+ 'OPAL_ROLE'
+ ],
+ entity_name = opal_security.models.entity_name_filter.EntityNameFilter(
+ string_match_type = 'CONTAINS',
+ string = 'engineering', ),
+ entity_tag = opal_security.models.entity_tag_filter.EntityTagFilter(
+ key = 'team',
+ value = 'platform',
+ connection_id = '', ),
+ hr_idp_status = opal_security.models.idp_status_filter.IdpStatusFilter(
+ statuses = [
+ 'ACTIVE'
+ ],
+ not = True, ),
+ entity_admin_owner = opal_security.models.entity_admin_filter.EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ not = True, ),
+ entity_ids = [
+ ''
+ ],
+ imported_from_app = [
+ ''
+ ],
+ role_remote_ids = [
+ ''
+ ],
+ role_names = [
+ ''
+ ],
+ all_of = [
+ opal_security.models.access_entity_filters.AccessEntityFilters(
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), )
+ ],
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), ),
+ entitlement_filter = ,
+ principal_access_filters = null,
+ entitlement_access_filters = null,
+ access_level_remote_ids = [
+ ''
+ ],
+ access_level_names = [
+ ''
+ ],
+ edge_filter = opal_security.models.opal_access_path_edge_filter.OpalAccessPathEdgeFilter(
+ direct_only = True,
+ access_duration_type = 'EXPIRING_ONLY', ), ),
+ )
+ """
+
+ def testCreateCampaignConfigurationInfo(self):
+ """Test CreateCampaignConfigurationInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_create_campaign_info.py b/test/test_create_campaign_info.py
new file mode 100644
index 0000000..661b7ca
--- /dev/null
+++ b/test/test_create_campaign_info.py
@@ -0,0 +1,55 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.create_campaign_info import CreateCampaignInfo
+
+class TestCreateCampaignInfo(unittest.TestCase):
+ """CreateCampaignInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CreateCampaignInfo:
+ """Test CreateCampaignInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CreateCampaignInfo`
+ """
+ model = CreateCampaignInfo()
+ if include_optional:
+ return CreateCampaignInfo(
+ name = 'Q3 Access Review',
+ configuration = {query={principalFilter={entityTypes=[USER]}}, end_date=2026-09-30T00:00:00.000+00:00, timezone=America/Los_Angeles, allow_self_review=false}
+ )
+ else:
+ return CreateCampaignInfo(
+ name = 'Q3 Access Review',
+ configuration = {query={principalFilter={entityTypes=[USER]}}, end_date=2026-09-30T00:00:00.000+00:00, timezone=America/Los_Angeles, allow_self_review=false},
+ )
+ """
+
+ def testCreateCampaignInfo(self):
+ """Test CreateCampaignInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_create_paladin_context_source_info.py b/test/test_create_paladin_context_source_info.py
new file mode 100644
index 0000000..56a81bf
--- /dev/null
+++ b/test/test_create_paladin_context_source_info.py
@@ -0,0 +1,59 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.create_paladin_context_source_info import CreatePaladinContextSourceInfo
+
+class TestCreatePaladinContextSourceInfo(unittest.TestCase):
+ """CreatePaladinContextSourceInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CreatePaladinContextSourceInfo:
+ """Test CreatePaladinContextSourceInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CreatePaladinContextSourceInfo`
+ """
+ model = CreatePaladinContextSourceInfo()
+ if include_optional:
+ return CreatePaladinContextSourceInfo(
+ source_kind = 'SLACK_CHANNEL',
+ third_party_provider = 'SLACK',
+ remote_id = '',
+ name = '',
+ url = ''
+ )
+ else:
+ return CreatePaladinContextSourceInfo(
+ source_kind = 'SLACK_CHANNEL',
+ third_party_provider = 'SLACK',
+ remote_id = '',
+ )
+ """
+
+ def testCreatePaladinContextSourceInfo(self):
+ """Test CreatePaladinContextSourceInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_create_paladin_info.py b/test/test_create_paladin_info.py
new file mode 100644
index 0000000..44bcb8a
--- /dev/null
+++ b/test/test_create_paladin_info.py
@@ -0,0 +1,61 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.create_paladin_info import CreatePaladinInfo
+
+class TestCreatePaladinInfo(unittest.TestCase):
+ """CreatePaladinInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CreatePaladinInfo:
+ """Test CreatePaladinInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CreatePaladinInfo`
+ """
+ model = CreatePaladinInfo()
+ if include_optional:
+ return CreatePaladinInfo(
+ name = 'paladin-agent-1',
+ owner_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ monitor_mode = True,
+ admin_view_only = True,
+ enabled_connectors = [
+ 'NOTION'
+ ],
+ instructions = ''
+ )
+ else:
+ return CreatePaladinInfo(
+ name = 'paladin-agent-1',
+ owner_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ )
+ """
+
+ def testCreatePaladinInfo(self):
+ """Test CreatePaladinInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_create_request_template_info.py b/test/test_create_request_template_info.py
new file mode 100644
index 0000000..b5eeec3
--- /dev/null
+++ b/test/test_create_request_template_info.py
@@ -0,0 +1,66 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.create_request_template_info import CreateRequestTemplateInfo
+
+class TestCreateRequestTemplateInfo(unittest.TestCase):
+ """CreateRequestTemplateInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CreateRequestTemplateInfo:
+ """Test CreateRequestTemplateInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CreateRequestTemplateInfo`
+ """
+ model = CreateRequestTemplateInfo()
+ if include_optional:
+ return CreateRequestTemplateInfo(
+ name = 'Production access questions',
+ custom_fields = [
+ opal_security.models.request_template_custom_field_input.RequestTemplateCustomFieldInput(
+ name = 'Why do you need this access?',
+ description = '',
+ type = 'SHORT_TEXT',
+ required = True,
+ metadata = opal_security.models.request_template_custom_field_metadata.RequestTemplateCustomFieldMetadata(
+ callout_data = opal_security.models.request_template_custom_field_callout_metadata.RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.', ),
+ multi_choice_data = opal_security.models.request_template_custom_field_multi_choice_metadata.RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance], ), ), )
+ ]
+ )
+ else:
+ return CreateRequestTemplateInfo(
+ name = 'Production access questions',
+ )
+ """
+
+ def testCreateRequestTemplateInfo(self):
+ """Test CreateRequestTemplateInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_create_resource_custom_access_level_info.py b/test/test_create_resource_custom_access_level_info.py
new file mode 100644
index 0000000..c02831d
--- /dev/null
+++ b/test/test_create_resource_custom_access_level_info.py
@@ -0,0 +1,56 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.create_resource_custom_access_level_info import CreateResourceCustomAccessLevelInfo
+
+class TestCreateResourceCustomAccessLevelInfo(unittest.TestCase):
+ """CreateResourceCustomAccessLevelInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> CreateResourceCustomAccessLevelInfo:
+ """Test CreateResourceCustomAccessLevelInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `CreateResourceCustomAccessLevelInfo`
+ """
+ model = CreateResourceCustomAccessLevelInfo()
+ if include_optional:
+ return CreateResourceCustomAccessLevelInfo(
+ access_level = {access_level_name=AdminRole, access_level_remote_id=arn:aws:iam::590304332660:role/AdministratorAccess},
+ policy = '',
+ requestable_by_default = True,
+ stackable_sensitivity_index = 56
+ )
+ else:
+ return CreateResourceCustomAccessLevelInfo(
+ access_level = {access_level_name=AdminRole, access_level_remote_id=arn:aws:iam::590304332660:role/AdministratorAccess},
+ )
+ """
+
+ def testCreateResourceCustomAccessLevelInfo(self):
+ """Test CreateResourceCustomAccessLevelInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_entity_admin_filter.py b/test/test_entity_admin_filter.py
new file mode 100644
index 0000000..cb116f0
--- /dev/null
+++ b/test/test_entity_admin_filter.py
@@ -0,0 +1,58 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.entity_admin_filter import EntityAdminFilter
+
+class TestEntityAdminFilter(unittest.TestCase):
+ """EntityAdminFilter unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> EntityAdminFilter:
+ """Test EntityAdminFilter
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `EntityAdminFilter`
+ """
+ model = EntityAdminFilter()
+ if include_optional:
+ return EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ var_not = True
+ )
+ else:
+ return EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ )
+ """
+
+ def testEntityAdminFilter(self):
+ """Test EntityAdminFilter"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_group_access_level_list.py b/test/test_group_access_level_list.py
new file mode 100644
index 0000000..a48a840
--- /dev/null
+++ b/test/test_group_access_level_list.py
@@ -0,0 +1,54 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.group_access_level_list import GroupAccessLevelList
+
+class TestGroupAccessLevelList(unittest.TestCase):
+ """GroupAccessLevelList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> GroupAccessLevelList:
+ """Test GroupAccessLevelList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `GroupAccessLevelList`
+ """
+ model = GroupAccessLevelList()
+ if include_optional:
+ return GroupAccessLevelList(
+ results = [
+ {access_level_name=Developer, access_level_remote_id=20}
+ ]
+ )
+ else:
+ return GroupAccessLevelList(
+ )
+ """
+
+ def testGroupAccessLevelList(self):
+ """Test GroupAccessLevelList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_group_remote_info_confluence_group.py b/test/test_group_remote_info_confluence_group.py
new file mode 100644
index 0000000..854c469
--- /dev/null
+++ b/test/test_group_remote_info_confluence_group.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.group_remote_info_confluence_group import GroupRemoteInfoConfluenceGroup
+
+class TestGroupRemoteInfoConfluenceGroup(unittest.TestCase):
+ """GroupRemoteInfoConfluenceGroup unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> GroupRemoteInfoConfluenceGroup:
+ """Test GroupRemoteInfoConfluenceGroup
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `GroupRemoteInfoConfluenceGroup`
+ """
+ model = GroupRemoteInfoConfluenceGroup()
+ if include_optional:
+ return GroupRemoteInfoConfluenceGroup(
+ group_id = 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'
+ )
+ else:
+ return GroupRemoteInfoConfluenceGroup(
+ group_id = 'a1b2c3d4-e5f6-7890-abcd-ef1234567890',
+ )
+ """
+
+ def testGroupRemoteInfoConfluenceGroup(self):
+ """Test GroupRemoteInfoConfluenceGroup"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_group_remote_info_docusign_group.py b/test/test_group_remote_info_docusign_group.py
new file mode 100644
index 0000000..c577373
--- /dev/null
+++ b/test/test_group_remote_info_docusign_group.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.group_remote_info_docusign_group import GroupRemoteInfoDocusignGroup
+
+class TestGroupRemoteInfoDocusignGroup(unittest.TestCase):
+ """GroupRemoteInfoDocusignGroup unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> GroupRemoteInfoDocusignGroup:
+ """Test GroupRemoteInfoDocusignGroup
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `GroupRemoteInfoDocusignGroup`
+ """
+ model = GroupRemoteInfoDocusignGroup()
+ if include_optional:
+ return GroupRemoteInfoDocusignGroup(
+ group_id = '12345'
+ )
+ else:
+ return GroupRemoteInfoDocusignGroup(
+ group_id = '12345',
+ )
+ """
+
+ def testGroupRemoteInfoDocusignGroup(self):
+ """Test GroupRemoteInfoDocusignGroup"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_group_remote_info_docusign_signing_group.py b/test/test_group_remote_info_docusign_signing_group.py
new file mode 100644
index 0000000..f3112b1
--- /dev/null
+++ b/test/test_group_remote_info_docusign_signing_group.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.group_remote_info_docusign_signing_group import GroupRemoteInfoDocusignSigningGroup
+
+class TestGroupRemoteInfoDocusignSigningGroup(unittest.TestCase):
+ """GroupRemoteInfoDocusignSigningGroup unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> GroupRemoteInfoDocusignSigningGroup:
+ """Test GroupRemoteInfoDocusignSigningGroup
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `GroupRemoteInfoDocusignSigningGroup`
+ """
+ model = GroupRemoteInfoDocusignSigningGroup()
+ if include_optional:
+ return GroupRemoteInfoDocusignSigningGroup(
+ signing_group_id = '12345'
+ )
+ else:
+ return GroupRemoteInfoDocusignSigningGroup(
+ signing_group_id = '12345',
+ )
+ """
+
+ def testGroupRemoteInfoDocusignSigningGroup(self):
+ """Test GroupRemoteInfoDocusignSigningGroup"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_group_remote_info_jira_group.py b/test/test_group_remote_info_jira_group.py
new file mode 100644
index 0000000..281b878
--- /dev/null
+++ b/test/test_group_remote_info_jira_group.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.group_remote_info_jira_group import GroupRemoteInfoJiraGroup
+
+class TestGroupRemoteInfoJiraGroup(unittest.TestCase):
+ """GroupRemoteInfoJiraGroup unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> GroupRemoteInfoJiraGroup:
+ """Test GroupRemoteInfoJiraGroup
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `GroupRemoteInfoJiraGroup`
+ """
+ model = GroupRemoteInfoJiraGroup()
+ if include_optional:
+ return GroupRemoteInfoJiraGroup(
+ group_id = 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'
+ )
+ else:
+ return GroupRemoteInfoJiraGroup(
+ group_id = 'a1b2c3d4-e5f6-7890-abcd-ef1234567890',
+ )
+ """
+
+ def testGroupRemoteInfoJiraGroup(self):
+ """Test GroupRemoteInfoJiraGroup"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_group_remote_info_linear_team.py b/test/test_group_remote_info_linear_team.py
new file mode 100644
index 0000000..a05baff
--- /dev/null
+++ b/test/test_group_remote_info_linear_team.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.group_remote_info_linear_team import GroupRemoteInfoLinearTeam
+
+class TestGroupRemoteInfoLinearTeam(unittest.TestCase):
+ """GroupRemoteInfoLinearTeam unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> GroupRemoteInfoLinearTeam:
+ """Test GroupRemoteInfoLinearTeam
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `GroupRemoteInfoLinearTeam`
+ """
+ model = GroupRemoteInfoLinearTeam()
+ if include_optional:
+ return GroupRemoteInfoLinearTeam(
+ team_id = '8caed98e-1234-5678-9abc-def012345678'
+ )
+ else:
+ return GroupRemoteInfoLinearTeam(
+ team_id = '8caed98e-1234-5678-9abc-def012345678',
+ )
+ """
+
+ def testGroupRemoteInfoLinearTeam(self):
+ """Test GroupRemoteInfoLinearTeam"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_group_remote_info_tableau_group.py b/test/test_group_remote_info_tableau_group.py
new file mode 100644
index 0000000..0e8a204
--- /dev/null
+++ b/test/test_group_remote_info_tableau_group.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.group_remote_info_tableau_group import GroupRemoteInfoTableauGroup
+
+class TestGroupRemoteInfoTableauGroup(unittest.TestCase):
+ """GroupRemoteInfoTableauGroup unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> GroupRemoteInfoTableauGroup:
+ """Test GroupRemoteInfoTableauGroup
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `GroupRemoteInfoTableauGroup`
+ """
+ model = GroupRemoteInfoTableauGroup()
+ if include_optional:
+ return GroupRemoteInfoTableauGroup(
+ group_id = 'a1b2c3d4-e5f6-7890-abcd-ef1234567890'
+ )
+ else:
+ return GroupRemoteInfoTableauGroup(
+ group_id = 'a1b2c3d4-e5f6-7890-abcd-ef1234567890',
+ )
+ """
+
+ def testGroupRemoteInfoTableauGroup(self):
+ """Test GroupRemoteInfoTableauGroup"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_group_remote_info_zoom_group.py b/test/test_group_remote_info_zoom_group.py
new file mode 100644
index 0000000..7277031
--- /dev/null
+++ b/test/test_group_remote_info_zoom_group.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.group_remote_info_zoom_group import GroupRemoteInfoZoomGroup
+
+class TestGroupRemoteInfoZoomGroup(unittest.TestCase):
+ """GroupRemoteInfoZoomGroup unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> GroupRemoteInfoZoomGroup:
+ """Test GroupRemoteInfoZoomGroup
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `GroupRemoteInfoZoomGroup`
+ """
+ model = GroupRemoteInfoZoomGroup()
+ if include_optional:
+ return GroupRemoteInfoZoomGroup(
+ group_id = 'SoBVexyrQjqCkcxjpBWi6w'
+ )
+ else:
+ return GroupRemoteInfoZoomGroup(
+ group_id = 'SoBVexyrQjqCkcxjpBWi6w',
+ )
+ """
+
+ def testGroupRemoteInfoZoomGroup(self):
+ """Test GroupRemoteInfoZoomGroup"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_idp_status_filter.py b/test/test_idp_status_filter.py
new file mode 100644
index 0000000..5ee962a
--- /dev/null
+++ b/test/test_idp_status_filter.py
@@ -0,0 +1,55 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.idp_status_filter import IdpStatusFilter
+
+class TestIdpStatusFilter(unittest.TestCase):
+ """IdpStatusFilter unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> IdpStatusFilter:
+ """Test IdpStatusFilter
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `IdpStatusFilter`
+ """
+ model = IdpStatusFilter()
+ if include_optional:
+ return IdpStatusFilter(
+ statuses = [
+ 'ACTIVE'
+ ],
+ var_not = True
+ )
+ else:
+ return IdpStatusFilter(
+ )
+ """
+
+ def testIdpStatusFilter(self):
+ """Test IdpStatusFilter"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_invite_user_info.py b/test/test_invite_user_info.py
new file mode 100644
index 0000000..6306555
--- /dev/null
+++ b/test/test_invite_user_info.py
@@ -0,0 +1,59 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.invite_user_info import InviteUserInfo
+
+class TestInviteUserInfo(unittest.TestCase):
+ """InviteUserInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> InviteUserInfo:
+ """Test InviteUserInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `InviteUserInfo`
+ """
+ model = InviteUserInfo()
+ if include_optional:
+ return InviteUserInfo(
+ email = '',
+ first_name = '',
+ last_name = '',
+ role = 'MEMBER'
+ )
+ else:
+ return InviteUserInfo(
+ email = '',
+ first_name = '',
+ last_name = '',
+ role = 'MEMBER',
+ )
+ """
+
+ def testInviteUserInfo(self):
+ """Test InviteUserInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_opal_access_path_edge_filter.py b/test/test_opal_access_path_edge_filter.py
new file mode 100644
index 0000000..0a4b6cb
--- /dev/null
+++ b/test/test_opal_access_path_edge_filter.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.opal_access_path_edge_filter import OpalAccessPathEdgeFilter
+
+class TestOpalAccessPathEdgeFilter(unittest.TestCase):
+ """OpalAccessPathEdgeFilter unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> OpalAccessPathEdgeFilter:
+ """Test OpalAccessPathEdgeFilter
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `OpalAccessPathEdgeFilter`
+ """
+ model = OpalAccessPathEdgeFilter()
+ if include_optional:
+ return OpalAccessPathEdgeFilter(
+ direct_only = True,
+ access_duration_type = 'EXPIRING_ONLY'
+ )
+ else:
+ return OpalAccessPathEdgeFilter(
+ )
+ """
+
+ def testOpalAccessPathEdgeFilter(self):
+ """Test OpalAccessPathEdgeFilter"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_opal_access_path_query.py b/test/test_opal_access_path_query.py
new file mode 100644
index 0000000..0772c51
--- /dev/null
+++ b/test/test_opal_access_path_query.py
@@ -0,0 +1,116 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.opal_access_path_query import OpalAccessPathQuery
+
+class TestOpalAccessPathQuery(unittest.TestCase):
+ """OpalAccessPathQuery unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> OpalAccessPathQuery:
+ """Test OpalAccessPathQuery
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `OpalAccessPathQuery`
+ """
+ model = OpalAccessPathQuery()
+ if include_optional:
+ return OpalAccessPathQuery(
+ type = 'ACCESS_PATH',
+ query = opal_security.models.opal_access_path_query_body.OpalAccessPathQueryBody(
+ principal_filter = opal_security.models.access_entity_filters.AccessEntityFilters(
+ entity_types = [
+ 'RESOURCE'
+ ],
+ entity_item_types = [
+ 'OPAL_ROLE'
+ ],
+ entity_name = opal_security.models.entity_name_filter.EntityNameFilter(
+ string_match_type = 'CONTAINS',
+ string = 'engineering', ),
+ entity_tag = opal_security.models.entity_tag_filter.EntityTagFilter(
+ key = 'team',
+ value = 'platform',
+ connection_id = '', ),
+ hr_idp_status = opal_security.models.idp_status_filter.IdpStatusFilter(
+ statuses = [
+ 'ACTIVE'
+ ],
+ not = True, ),
+ entity_admin_owner = opal_security.models.entity_admin_filter.EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ not = True, ),
+ entity_ids = [
+ ''
+ ],
+ imported_from_app = [
+ ''
+ ],
+ role_remote_ids = [
+ ''
+ ],
+ role_names = [
+ ''
+ ],
+ all_of = [
+ opal_security.models.access_entity_filters.AccessEntityFilters(
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), )
+ ],
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), ),
+ entitlement_filter = ,
+ principal_access_filters = null,
+ entitlement_access_filters = null,
+ access_level_remote_ids = [
+ ''
+ ],
+ access_level_names = [
+ ''
+ ],
+ edge_filter = opal_security.models.opal_access_path_edge_filter.OpalAccessPathEdgeFilter(
+ direct_only = True,
+ access_duration_type = 'EXPIRING_ONLY', ), ),
+ first = 200,
+ after = '',
+ include_count = False
+ )
+ else:
+ return OpalAccessPathQuery(
+ type = 'ACCESS_PATH',
+ )
+ """
+
+ def testOpalAccessPathQuery(self):
+ """Test OpalAccessPathQuery"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_opal_access_path_query_body.py b/test/test_opal_access_path_query_body.py
new file mode 100644
index 0000000..0ee8639
--- /dev/null
+++ b/test/test_opal_access_path_query_body.py
@@ -0,0 +1,160 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.opal_access_path_query_body import OpalAccessPathQueryBody
+
+class TestOpalAccessPathQueryBody(unittest.TestCase):
+ """OpalAccessPathQueryBody unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> OpalAccessPathQueryBody:
+ """Test OpalAccessPathQueryBody
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `OpalAccessPathQueryBody`
+ """
+ model = OpalAccessPathQueryBody()
+ if include_optional:
+ return OpalAccessPathQueryBody(
+ principal_filter = opal_security.models.access_entity_filters.AccessEntityFilters(
+ entity_types = [
+ 'RESOURCE'
+ ],
+ entity_item_types = [
+ 'OPAL_ROLE'
+ ],
+ entity_name = opal_security.models.entity_name_filter.EntityNameFilter(
+ string_match_type = 'CONTAINS',
+ string = 'engineering', ),
+ entity_tag = opal_security.models.entity_tag_filter.EntityTagFilter(
+ key = 'team',
+ value = 'platform',
+ connection_id = '', ),
+ hr_idp_status = opal_security.models.idp_status_filter.IdpStatusFilter(
+ statuses = [
+ 'ACTIVE'
+ ],
+ not = True, ),
+ entity_admin_owner = opal_security.models.entity_admin_filter.EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ not = True, ),
+ entity_ids = [
+ ''
+ ],
+ imported_from_app = [
+ ''
+ ],
+ role_remote_ids = [
+ ''
+ ],
+ role_names = [
+ ''
+ ],
+ all_of = [
+ opal_security.models.access_entity_filters.AccessEntityFilters(
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), )
+ ],
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), ),
+ entitlement_filter = opal_security.models.access_entity_filters.AccessEntityFilters(
+ entity_types = [
+ 'RESOURCE'
+ ],
+ entity_item_types = [
+ 'OPAL_ROLE'
+ ],
+ entity_name = opal_security.models.entity_name_filter.EntityNameFilter(
+ string_match_type = 'CONTAINS',
+ string = 'engineering', ),
+ entity_tag = opal_security.models.entity_tag_filter.EntityTagFilter(
+ key = 'team',
+ value = 'platform',
+ connection_id = '', ),
+ hr_idp_status = opal_security.models.idp_status_filter.IdpStatusFilter(
+ statuses = [
+ 'ACTIVE'
+ ],
+ not = True, ),
+ entity_admin_owner = opal_security.models.entity_admin_filter.EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ not = True, ),
+ entity_ids = [
+ ''
+ ],
+ imported_from_app = [
+ ''
+ ],
+ role_remote_ids = [
+ ''
+ ],
+ role_names = [
+ ''
+ ],
+ all_of = [
+ opal_security.models.access_entity_filters.AccessEntityFilters(
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), )
+ ],
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), ),
+ principal_access_filters = opal_security.models.access_relationship_filters.AccessRelationshipFilters(
+ is_accessible_by = null,
+ has_access_to = null, ),
+ entitlement_access_filters = opal_security.models.access_relationship_filters.AccessRelationshipFilters(
+ is_accessible_by = null,
+ has_access_to = null, ),
+ access_level_remote_ids = [
+ ''
+ ],
+ access_level_names = [
+ ''
+ ],
+ edge_filter = opal_security.models.opal_access_path_edge_filter.OpalAccessPathEdgeFilter(
+ direct_only = True,
+ access_duration_type = 'EXPIRING_ONLY', )
+ )
+ else:
+ return OpalAccessPathQueryBody(
+ )
+ """
+
+ def testOpalAccessPathQueryBody(self):
+ """Test OpalAccessPathQueryBody"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_opal_access_path_query_results.py b/test/test_opal_access_path_query_results.py
new file mode 100644
index 0000000..116bb4a
--- /dev/null
+++ b/test/test_opal_access_path_query_results.py
@@ -0,0 +1,92 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.opal_access_path_query_results import OpalAccessPathQueryResults
+
+class TestOpalAccessPathQueryResults(unittest.TestCase):
+ """OpalAccessPathQueryResults unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> OpalAccessPathQueryResults:
+ """Test OpalAccessPathQueryResults
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `OpalAccessPathQueryResults`
+ """
+ model = OpalAccessPathQueryResults()
+ if include_optional:
+ return OpalAccessPathQueryResults(
+ type = 'ACCESS_PATH',
+ edges = [
+ opal_security.models.opal_access_path_result_edge.OpalAccessPathResultEdge(
+ node = opal_security.models.opal_access_path_result_node.OpalAccessPathResultNode(
+ principal_id = '',
+ entitlement_id = '',
+ access_level_remote_id = '',
+ access_level_name = '',
+ expiration = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ depth = 56,
+ path = [
+ ''
+ ], ),
+ cursor = '', )
+ ],
+ page_info = opal_security.models.page_info.PageInfo(
+ has_next_page = True,
+ end_cursor = '',
+ has_previous_page = True,
+ start_cursor = '', ),
+ total_count = 56
+ )
+ else:
+ return OpalAccessPathQueryResults(
+ type = 'ACCESS_PATH',
+ edges = [
+ opal_security.models.opal_access_path_result_edge.OpalAccessPathResultEdge(
+ node = opal_security.models.opal_access_path_result_node.OpalAccessPathResultNode(
+ principal_id = '',
+ entitlement_id = '',
+ access_level_remote_id = '',
+ access_level_name = '',
+ expiration = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ depth = 56,
+ path = [
+ ''
+ ], ),
+ cursor = '', )
+ ],
+ page_info = opal_security.models.page_info.PageInfo(
+ has_next_page = True,
+ end_cursor = '',
+ has_previous_page = True,
+ start_cursor = '', ),
+ )
+ """
+
+ def testOpalAccessPathQueryResults(self):
+ """Test OpalAccessPathQueryResults"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_opal_access_path_result_edge.py b/test/test_opal_access_path_result_edge.py
new file mode 100644
index 0000000..5c4dd90
--- /dev/null
+++ b/test/test_opal_access_path_result_edge.py
@@ -0,0 +1,73 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.opal_access_path_result_edge import OpalAccessPathResultEdge
+
+class TestOpalAccessPathResultEdge(unittest.TestCase):
+ """OpalAccessPathResultEdge unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> OpalAccessPathResultEdge:
+ """Test OpalAccessPathResultEdge
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `OpalAccessPathResultEdge`
+ """
+ model = OpalAccessPathResultEdge()
+ if include_optional:
+ return OpalAccessPathResultEdge(
+ node = opal_security.models.opal_access_path_result_node.OpalAccessPathResultNode(
+ principal_id = '',
+ entitlement_id = '',
+ access_level_remote_id = '',
+ access_level_name = '',
+ expiration = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ depth = 56,
+ path = [
+ ''
+ ], ),
+ cursor = ''
+ )
+ else:
+ return OpalAccessPathResultEdge(
+ node = opal_security.models.opal_access_path_result_node.OpalAccessPathResultNode(
+ principal_id = '',
+ entitlement_id = '',
+ access_level_remote_id = '',
+ access_level_name = '',
+ expiration = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ depth = 56,
+ path = [
+ ''
+ ], ),
+ cursor = '',
+ )
+ """
+
+ def testOpalAccessPathResultEdge(self):
+ """Test OpalAccessPathResultEdge"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_opal_access_path_result_node.py b/test/test_opal_access_path_result_node.py
new file mode 100644
index 0000000..5f81d45
--- /dev/null
+++ b/test/test_opal_access_path_result_node.py
@@ -0,0 +1,66 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.opal_access_path_result_node import OpalAccessPathResultNode
+
+class TestOpalAccessPathResultNode(unittest.TestCase):
+ """OpalAccessPathResultNode unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> OpalAccessPathResultNode:
+ """Test OpalAccessPathResultNode
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `OpalAccessPathResultNode`
+ """
+ model = OpalAccessPathResultNode()
+ if include_optional:
+ return OpalAccessPathResultNode(
+ principal_id = '',
+ entitlement_id = '',
+ access_level_remote_id = '',
+ access_level_name = '',
+ expiration = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ depth = 56,
+ path = [
+ ''
+ ]
+ )
+ else:
+ return OpalAccessPathResultNode(
+ principal_id = '',
+ entitlement_id = '',
+ depth = 56,
+ path = [
+ ''
+ ],
+ )
+ """
+
+ def testOpalAccessPathResultNode(self):
+ """Test OpalAccessPathResultNode"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_opal_query_results.py b/test/test_opal_query_results.py
new file mode 100644
index 0000000..650b4e4
--- /dev/null
+++ b/test/test_opal_query_results.py
@@ -0,0 +1,92 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.opal_query_results import OpalQueryResults
+
+class TestOpalQueryResults(unittest.TestCase):
+ """OpalQueryResults unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> OpalQueryResults:
+ """Test OpalQueryResults
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `OpalQueryResults`
+ """
+ model = OpalQueryResults()
+ if include_optional:
+ return OpalQueryResults(
+ type = 'NODE',
+ edges = [
+ opal_security.models.opal_access_path_result_edge.OpalAccessPathResultEdge(
+ node = opal_security.models.opal_access_path_result_node.OpalAccessPathResultNode(
+ principal_id = '',
+ entitlement_id = '',
+ access_level_remote_id = '',
+ access_level_name = '',
+ expiration = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ depth = 56,
+ path = [
+ ''
+ ], ),
+ cursor = '', )
+ ],
+ page_info = opal_security.models.page_info.PageInfo(
+ has_next_page = True,
+ end_cursor = '',
+ has_previous_page = True,
+ start_cursor = '', ),
+ total_count = 56
+ )
+ else:
+ return OpalQueryResults(
+ type = 'NODE',
+ edges = [
+ opal_security.models.opal_access_path_result_edge.OpalAccessPathResultEdge(
+ node = opal_security.models.opal_access_path_result_node.OpalAccessPathResultNode(
+ principal_id = '',
+ entitlement_id = '',
+ access_level_remote_id = '',
+ access_level_name = '',
+ expiration = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ depth = 56,
+ path = [
+ ''
+ ], ),
+ cursor = '', )
+ ],
+ page_info = opal_security.models.page_info.PageInfo(
+ has_next_page = True,
+ end_cursor = '',
+ has_previous_page = True,
+ start_cursor = '', ),
+ )
+ """
+
+ def testOpalQueryResults(self):
+ """Test OpalQueryResults"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paginated_campaign_items_list.py b/test/test_paginated_campaign_items_list.py
new file mode 100644
index 0000000..5db6dfb
--- /dev/null
+++ b/test/test_paginated_campaign_items_list.py
@@ -0,0 +1,111 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paginated_campaign_items_list import PaginatedCampaignItemsList
+
+class TestPaginatedCampaignItemsList(unittest.TestCase):
+ """PaginatedCampaignItemsList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> PaginatedCampaignItemsList:
+ """Test PaginatedCampaignItemsList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `PaginatedCampaignItemsList`
+ """
+ model = PaginatedCampaignItemsList()
+ if include_optional:
+ return PaginatedCampaignItemsList(
+ next = '',
+ previous = '',
+ results = [
+ opal_security.models.campaign_item.CampaignItem(
+ campaign_item_id = '',
+ campaign_id = '',
+ target_type = 'ROLE_ASSIGNMENT',
+ role_assignment_id = '',
+ status = 'PENDING',
+ created_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ is_target_deleted = True,
+ principal_id = '',
+ principal_type = null,
+ entity_id = '',
+ entity_type = null,
+ access_level = null,
+ access_level_name = '',
+ reviews = [
+ opal_security.models.campaign_item_review.CampaignItemReview(
+ campaign_item_review_id = '',
+ campaign_item_id = '',
+ reviewer_user_id = '',
+ assignment_source = 'MANUAL',
+ decision = null,
+ note = '',
+ updated_access_level_remote_id = '',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'), )
+ ],
+ admin_override = null, )
+ ],
+ total_count = 56
+ )
+ else:
+ return PaginatedCampaignItemsList(
+ results = [
+ opal_security.models.campaign_item.CampaignItem(
+ campaign_item_id = '',
+ campaign_id = '',
+ target_type = 'ROLE_ASSIGNMENT',
+ role_assignment_id = '',
+ status = 'PENDING',
+ created_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ is_target_deleted = True,
+ principal_id = '',
+ principal_type = null,
+ entity_id = '',
+ entity_type = null,
+ access_level = null,
+ access_level_name = '',
+ reviews = [
+ opal_security.models.campaign_item_review.CampaignItemReview(
+ campaign_item_review_id = '',
+ campaign_item_id = '',
+ reviewer_user_id = '',
+ assignment_source = 'MANUAL',
+ decision = null,
+ note = '',
+ updated_access_level_remote_id = '',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'), )
+ ],
+ admin_override = null, )
+ ],
+ total_count = 56,
+ )
+ """
+
+ def testPaginatedCampaignItemsList(self):
+ """Test PaginatedCampaignItemsList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paginated_campaigns_list.py b/test/test_paginated_campaigns_list.py
new file mode 100644
index 0000000..8ef400e
--- /dev/null
+++ b/test/test_paginated_campaigns_list.py
@@ -0,0 +1,59 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paginated_campaigns_list import PaginatedCampaignsList
+
+class TestPaginatedCampaignsList(unittest.TestCase):
+ """PaginatedCampaignsList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> PaginatedCampaignsList:
+ """Test PaginatedCampaignsList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `PaginatedCampaignsList`
+ """
+ model = PaginatedCampaignsList()
+ if include_optional:
+ return PaginatedCampaignsList(
+ next = 'cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzQzMjYlMkIwMCUzQTAw',
+ previous = 'cj1sZXdwd2VycWVtY29zZnNkc2NzUWxNMEUxTXk0ME16UXpNallsTWtJ',
+ results = [
+ {campaign_id=f454d283-ca87-4a8a-bdbb-df212eca5353, name=Q3 Access Review, status=DRAFT, is_template=false, created_at=2026-07-01T00:00:00.000+00:00, updated_at=2026-07-01T00:00:00.000+00:00, created_by_user_id=32acc112-21ff-4669-91c2-21e27683eaa1}
+ ]
+ )
+ else:
+ return PaginatedCampaignsList(
+ results = [
+ {campaign_id=f454d283-ca87-4a8a-bdbb-df212eca5353, name=Q3 Access Review, status=DRAFT, is_template=false, created_at=2026-07-01T00:00:00.000+00:00, updated_at=2026-07-01T00:00:00.000+00:00, created_by_user_id=32acc112-21ff-4669-91c2-21e27683eaa1}
+ ],
+ )
+ """
+
+ def testPaginatedCampaignsList(self):
+ """Test PaginatedCampaignsList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paginated_request_template_list.py b/test/test_paginated_request_template_list.py
new file mode 100644
index 0000000..d6e2546
--- /dev/null
+++ b/test/test_paginated_request_template_list.py
@@ -0,0 +1,71 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paginated_request_template_list import PaginatedRequestTemplateList
+
+class TestPaginatedRequestTemplateList(unittest.TestCase):
+ """PaginatedRequestTemplateList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> PaginatedRequestTemplateList:
+ """Test PaginatedRequestTemplateList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `PaginatedRequestTemplateList`
+ """
+ model = PaginatedRequestTemplateList()
+ if include_optional:
+ return PaginatedRequestTemplateList(
+ next = 'cD0yMDIxLTAxLTA2KzAzJTNBMjQlM0E1My40MzAyMTMlMkIwMCUzQTAw',
+ previous = 'cj0xJnA9MjAyMS0wMS0wNSswMyUzQTI0JTNBNTMuNDMwMjEz',
+ results = [
+ opal_security.models.request_template.RequestTemplate(
+ request_template_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ name = 'Production access questions',
+ custom_fields = [
+ opal_security.models.request_template_custom_field.RequestTemplateCustomField(
+ name = 'Why do you need this access?',
+ description = '',
+ type = 'SHORT_TEXT',
+ required = True,
+ metadata = opal_security.models.request_template_custom_field_metadata.RequestTemplateCustomFieldMetadata(
+ callout_data = opal_security.models.request_template_custom_field_callout_metadata.RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.', ),
+ multi_choice_data = opal_security.models.request_template_custom_field_multi_choice_metadata.RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance], ), ), )
+ ], )
+ ]
+ )
+ else:
+ return PaginatedRequestTemplateList(
+ )
+ """
+
+ def testPaginatedRequestTemplateList(self):
+ """Test PaginatedRequestTemplateList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paginated_viewer_campaign_items_list.py b/test/test_paginated_viewer_campaign_items_list.py
new file mode 100644
index 0000000..1ca22c7
--- /dev/null
+++ b/test/test_paginated_viewer_campaign_items_list.py
@@ -0,0 +1,101 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paginated_viewer_campaign_items_list import PaginatedViewerCampaignItemsList
+
+class TestPaginatedViewerCampaignItemsList(unittest.TestCase):
+ """PaginatedViewerCampaignItemsList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> PaginatedViewerCampaignItemsList:
+ """Test PaginatedViewerCampaignItemsList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `PaginatedViewerCampaignItemsList`
+ """
+ model = PaginatedViewerCampaignItemsList()
+ if include_optional:
+ return PaginatedViewerCampaignItemsList(
+ next = '',
+ previous = '',
+ results = [
+ opal_security.models.viewer_campaign_item.ViewerCampaignItem(
+ campaign_item_review_id = '',
+ decision = null,
+ note = '',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ pending_decision = null,
+ pending_note = '',
+ updated_access_level_remote_id = '',
+ pending_updated_access_level_remote_id = '',
+ reassigned_to_reviewer_ids = [
+ ''
+ ],
+ principal_id = '',
+ principal_type = 'GROUP',
+ entity_id = '',
+ entity_type = 'GROUP',
+ access_level_name = '',
+ access_level_remote_id = '',
+ granted_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ expires_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ role_assignment_id = '', )
+ ],
+ total_count = 56
+ )
+ else:
+ return PaginatedViewerCampaignItemsList(
+ results = [
+ opal_security.models.viewer_campaign_item.ViewerCampaignItem(
+ campaign_item_review_id = '',
+ decision = null,
+ note = '',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ pending_decision = null,
+ pending_note = '',
+ updated_access_level_remote_id = '',
+ pending_updated_access_level_remote_id = '',
+ reassigned_to_reviewer_ids = [
+ ''
+ ],
+ principal_id = '',
+ principal_type = 'GROUP',
+ entity_id = '',
+ entity_type = 'GROUP',
+ access_level_name = '',
+ access_level_remote_id = '',
+ granted_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ expires_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ role_assignment_id = '', )
+ ],
+ total_count = 56,
+ )
+ """
+
+ def testPaginatedViewerCampaignItemsList(self):
+ """Test PaginatedViewerCampaignItemsList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paladin.py b/test/test_paladin.py
new file mode 100644
index 0000000..b67d437
--- /dev/null
+++ b/test/test_paladin.py
@@ -0,0 +1,69 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paladin import Paladin
+
+class TestPaladin(unittest.TestCase):
+ """Paladin unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> Paladin:
+ """Test Paladin
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `Paladin`
+ """
+ model = Paladin()
+ if include_optional:
+ return Paladin(
+ paladin_id = '32acc112-21ff-4669-91c2-21e27683eaa1',
+ name = 'paladin-agent-1',
+ owner_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ monitor_mode = True,
+ admin_view_only = True,
+ enabled_connectors = [
+ 'NOTION'
+ ],
+ instructions = 'Approve read-only access; escalate anything that grants write access.'
+ )
+ else:
+ return Paladin(
+ paladin_id = '32acc112-21ff-4669-91c2-21e27683eaa1',
+ name = 'paladin-agent-1',
+ owner_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ monitor_mode = True,
+ admin_view_only = True,
+ enabled_connectors = [
+ 'NOTION'
+ ],
+ instructions = 'Approve read-only access; escalate anything that grants write access.',
+ )
+ """
+
+ def testPaladin(self):
+ """Test Paladin"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paladin_api.py b/test/test_paladin_api.py
new file mode 100644
index 0000000..4f81371
--- /dev/null
+++ b/test/test_paladin_api.py
@@ -0,0 +1,88 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.api.paladin_api import PaladinApi
+
+
+class TestPaladinApi(unittest.TestCase):
+ """PaladinApi unit test stubs"""
+
+ def setUp(self) -> None:
+ self.api = PaladinApi()
+
+ def tearDown(self) -> None:
+ pass
+
+ def test_create_paladin(self) -> None:
+ """Test case for create_paladin
+
+ Create Paladin
+ """
+ pass
+
+ def test_create_paladin_context_source(self) -> None:
+ """Test case for create_paladin_context_source
+
+ Add a Paladin context source
+ """
+ pass
+
+ def test_delete_paladin(self) -> None:
+ """Test case for delete_paladin
+
+ Delete Paladin
+ """
+ pass
+
+ def test_delete_paladin_context_source(self) -> None:
+ """Test case for delete_paladin_context_source
+
+ Remove a Paladin context source
+ """
+ pass
+
+ def test_get_paladin(self) -> None:
+ """Test case for get_paladin
+
+ Get Paladin by ID
+ """
+ pass
+
+ def test_get_paladin_from_name(self) -> None:
+ """Test case for get_paladin_from_name
+
+ Get Paladins by name
+ """
+ pass
+
+ def test_list_paladin_context_sources(self) -> None:
+ """Test case for list_paladin_context_sources
+
+ List Paladin context sources
+ """
+ pass
+
+ def test_update_paladin(self) -> None:
+ """Test case for update_paladin
+
+ Update Paladin
+ """
+ pass
+
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paladin_connector.py b/test/test_paladin_connector.py
new file mode 100644
index 0000000..2f2a44d
--- /dev/null
+++ b/test/test_paladin_connector.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paladin_connector import PaladinConnector
+
+class TestPaladinConnector(unittest.TestCase):
+ """PaladinConnector unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testPaladinConnector(self):
+ """Test PaladinConnector"""
+ # inst = PaladinConnector()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paladin_context_source.py b/test/test_paladin_context_source.py
new file mode 100644
index 0000000..c09d856
--- /dev/null
+++ b/test/test_paladin_context_source.py
@@ -0,0 +1,65 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paladin_context_source import PaladinContextSource
+
+class TestPaladinContextSource(unittest.TestCase):
+ """PaladinContextSource unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> PaladinContextSource:
+ """Test PaladinContextSource
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `PaladinContextSource`
+ """
+ model = PaladinContextSource()
+ if include_optional:
+ return PaladinContextSource(
+ id = '',
+ paladin_id = '',
+ source_kind = 'SLACK_CHANNEL',
+ third_party_provider = 'SLACK',
+ remote_id = '',
+ name = '',
+ url = ''
+ )
+ else:
+ return PaladinContextSource(
+ id = '',
+ paladin_id = '',
+ source_kind = 'SLACK_CHANNEL',
+ third_party_provider = 'SLACK',
+ remote_id = '',
+ name = '',
+ url = '',
+ )
+ """
+
+ def testPaladinContextSource(self):
+ """Test PaladinContextSource"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paladin_context_source_kind.py b/test/test_paladin_context_source_kind.py
new file mode 100644
index 0000000..4bb1fbe
--- /dev/null
+++ b/test/test_paladin_context_source_kind.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paladin_context_source_kind import PaladinContextSourceKind
+
+class TestPaladinContextSourceKind(unittest.TestCase):
+ """PaladinContextSourceKind unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testPaladinContextSourceKind(self):
+ """Test PaladinContextSourceKind"""
+ # inst = PaladinContextSourceKind()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paladin_context_source_list.py b/test/test_paladin_context_source_list.py
new file mode 100644
index 0000000..b57b87b
--- /dev/null
+++ b/test/test_paladin_context_source_list.py
@@ -0,0 +1,57 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paladin_context_source_list import PaladinContextSourceList
+
+class TestPaladinContextSourceList(unittest.TestCase):
+ """PaladinContextSourceList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> PaladinContextSourceList:
+ """Test PaladinContextSourceList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `PaladinContextSourceList`
+ """
+ model = PaladinContextSourceList()
+ if include_optional:
+ return PaladinContextSourceList(
+ results = [
+ {id=8a1f2c3d-4b5e-6f70-8192-a3b4c5d6e7f8, paladin_id=32acc112-21ff-4669-91c2-21e27683eaa1, source_kind=SLACK_CHANNEL, third_party_provider=SLACK, remote_id=C0123456789, name=#access-requests, url=https://example.slack.com/archives/C0123456789}
+ ]
+ )
+ else:
+ return PaladinContextSourceList(
+ results = [
+ {id=8a1f2c3d-4b5e-6f70-8192-a3b4c5d6e7f8, paladin_id=32acc112-21ff-4669-91c2-21e27683eaa1, source_kind=SLACK_CHANNEL, third_party_provider=SLACK, remote_id=C0123456789, name=#access-requests, url=https://example.slack.com/archives/C0123456789}
+ ],
+ )
+ """
+
+ def testPaladinContextSourceList(self):
+ """Test PaladinContextSourceList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paladin_context_source_provider.py b/test/test_paladin_context_source_provider.py
new file mode 100644
index 0000000..6769f2f
--- /dev/null
+++ b/test/test_paladin_context_source_provider.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paladin_context_source_provider import PaladinContextSourceProvider
+
+class TestPaladinContextSourceProvider(unittest.TestCase):
+ """PaladinContextSourceProvider unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testPaladinContextSourceProvider(self):
+ """Test PaladinContextSourceProvider"""
+ # inst = PaladinContextSourceProvider()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_paladin_list.py b/test/test_paladin_list.py
new file mode 100644
index 0000000..9752fd6
--- /dev/null
+++ b/test/test_paladin_list.py
@@ -0,0 +1,57 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.paladin_list import PaladinList
+
+class TestPaladinList(unittest.TestCase):
+ """PaladinList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> PaladinList:
+ """Test PaladinList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `PaladinList`
+ """
+ model = PaladinList()
+ if include_optional:
+ return PaladinList(
+ results = [
+ {paladin_id=32acc112-21ff-4669-91c2-21e27683eaa1, name=paladin-agent-1, owner_id=7c86c85d-0651-43e2-a748-d69d658418e8, monitor_mode=true, admin_view_only=false, enabled_connectors=[SLACK]}
+ ]
+ )
+ else:
+ return PaladinList(
+ results = [
+ {paladin_id=32acc112-21ff-4669-91c2-21e27683eaa1, name=paladin-agent-1, owner_id=7c86c85d-0651-43e2-a748-d69d658418e8, monitor_mode=true, admin_view_only=false, enabled_connectors=[SLACK]}
+ ],
+ )
+ """
+
+ def testPaladinList(self):
+ """Test PaladinList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_remind_request200_response.py b/test/test_remind_request200_response.py
new file mode 100644
index 0000000..3f2c92c
--- /dev/null
+++ b/test/test_remind_request200_response.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.remind_request200_response import RemindRequest200Response
+
+class TestRemindRequest200Response(unittest.TestCase):
+ """RemindRequest200Response unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> RemindRequest200Response:
+ """Test RemindRequest200Response
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `RemindRequest200Response`
+ """
+ model = RemindRequest200Response()
+ if include_optional:
+ return RemindRequest200Response(
+ success = True
+ )
+ else:
+ return RemindRequest200Response(
+ success = True,
+ )
+ """
+
+ def testRemindRequest200Response(self):
+ """Test RemindRequest200Response"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_request_template.py b/test/test_request_template.py
new file mode 100644
index 0000000..40d4958
--- /dev/null
+++ b/test/test_request_template.py
@@ -0,0 +1,68 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.request_template import RequestTemplate
+
+class TestRequestTemplate(unittest.TestCase):
+ """RequestTemplate unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> RequestTemplate:
+ """Test RequestTemplate
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `RequestTemplate`
+ """
+ model = RequestTemplate()
+ if include_optional:
+ return RequestTemplate(
+ request_template_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ name = 'Production access questions',
+ custom_fields = [
+ opal_security.models.request_template_custom_field.RequestTemplateCustomField(
+ name = 'Why do you need this access?',
+ description = '',
+ type = 'SHORT_TEXT',
+ required = True,
+ metadata = opal_security.models.request_template_custom_field_metadata.RequestTemplateCustomFieldMetadata(
+ callout_data = opal_security.models.request_template_custom_field_callout_metadata.RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.', ),
+ multi_choice_data = opal_security.models.request_template_custom_field_multi_choice_metadata.RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance], ), ), )
+ ]
+ )
+ else:
+ return RequestTemplate(
+ request_template_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ name = 'Production access questions',
+ )
+ """
+
+ def testRequestTemplate(self):
+ """Test RequestTemplate"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_request_template_custom_field.py b/test/test_request_template_custom_field.py
new file mode 100644
index 0000000..8c308f6
--- /dev/null
+++ b/test/test_request_template_custom_field.py
@@ -0,0 +1,63 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.request_template_custom_field import RequestTemplateCustomField
+
+class TestRequestTemplateCustomField(unittest.TestCase):
+ """RequestTemplateCustomField unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> RequestTemplateCustomField:
+ """Test RequestTemplateCustomField
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `RequestTemplateCustomField`
+ """
+ model = RequestTemplateCustomField()
+ if include_optional:
+ return RequestTemplateCustomField(
+ name = 'Why do you need this access?',
+ description = '',
+ type = 'SHORT_TEXT',
+ required = True,
+ metadata = opal_security.models.request_template_custom_field_metadata.RequestTemplateCustomFieldMetadata(
+ callout_data = opal_security.models.request_template_custom_field_callout_metadata.RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.', ),
+ multi_choice_data = opal_security.models.request_template_custom_field_multi_choice_metadata.RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance], ), )
+ )
+ else:
+ return RequestTemplateCustomField(
+ name = 'Why do you need this access?',
+ type = 'SHORT_TEXT',
+ )
+ """
+
+ def testRequestTemplateCustomField(self):
+ """Test RequestTemplateCustomField"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_request_template_custom_field_callout_metadata.py b/test/test_request_template_custom_field_callout_metadata.py
new file mode 100644
index 0000000..4ac70ed
--- /dev/null
+++ b/test/test_request_template_custom_field_callout_metadata.py
@@ -0,0 +1,55 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.request_template_custom_field_callout_metadata import RequestTemplateCustomFieldCalloutMetadata
+
+class TestRequestTemplateCustomFieldCalloutMetadata(unittest.TestCase):
+ """RequestTemplateCustomFieldCalloutMetadata unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> RequestTemplateCustomFieldCalloutMetadata:
+ """Test RequestTemplateCustomFieldCalloutMetadata
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `RequestTemplateCustomFieldCalloutMetadata`
+ """
+ model = RequestTemplateCustomFieldCalloutMetadata()
+ if include_optional:
+ return RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.'
+ )
+ else:
+ return RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.',
+ )
+ """
+
+ def testRequestTemplateCustomFieldCalloutMetadata(self):
+ """Test RequestTemplateCustomFieldCalloutMetadata"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_request_template_custom_field_input.py b/test/test_request_template_custom_field_input.py
new file mode 100644
index 0000000..90d1ea0
--- /dev/null
+++ b/test/test_request_template_custom_field_input.py
@@ -0,0 +1,62 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.request_template_custom_field_input import RequestTemplateCustomFieldInput
+
+class TestRequestTemplateCustomFieldInput(unittest.TestCase):
+ """RequestTemplateCustomFieldInput unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> RequestTemplateCustomFieldInput:
+ """Test RequestTemplateCustomFieldInput
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `RequestTemplateCustomFieldInput`
+ """
+ model = RequestTemplateCustomFieldInput()
+ if include_optional:
+ return RequestTemplateCustomFieldInput(
+ name = 'Why do you need this access?',
+ description = '',
+ type = 'SHORT_TEXT',
+ required = True,
+ metadata = opal_security.models.request_template_custom_field_metadata.RequestTemplateCustomFieldMetadata(
+ callout_data = opal_security.models.request_template_custom_field_callout_metadata.RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.', ),
+ multi_choice_data = opal_security.models.request_template_custom_field_multi_choice_metadata.RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance], ), )
+ )
+ else:
+ return RequestTemplateCustomFieldInput(
+ type = 'SHORT_TEXT',
+ )
+ """
+
+ def testRequestTemplateCustomFieldInput(self):
+ """Test RequestTemplateCustomFieldInput"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_request_template_custom_field_metadata.py b/test/test_request_template_custom_field_metadata.py
new file mode 100644
index 0000000..d4886b7
--- /dev/null
+++ b/test/test_request_template_custom_field_metadata.py
@@ -0,0 +1,56 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.request_template_custom_field_metadata import RequestTemplateCustomFieldMetadata
+
+class TestRequestTemplateCustomFieldMetadata(unittest.TestCase):
+ """RequestTemplateCustomFieldMetadata unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> RequestTemplateCustomFieldMetadata:
+ """Test RequestTemplateCustomFieldMetadata
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `RequestTemplateCustomFieldMetadata`
+ """
+ model = RequestTemplateCustomFieldMetadata()
+ if include_optional:
+ return RequestTemplateCustomFieldMetadata(
+ callout_data = opal_security.models.request_template_custom_field_callout_metadata.RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.', ),
+ multi_choice_data = opal_security.models.request_template_custom_field_multi_choice_metadata.RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance], )
+ )
+ else:
+ return RequestTemplateCustomFieldMetadata(
+ )
+ """
+
+ def testRequestTemplateCustomFieldMetadata(self):
+ """Test RequestTemplateCustomFieldMetadata"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_request_template_custom_field_multi_choice_metadata.py b/test/test_request_template_custom_field_multi_choice_metadata.py
new file mode 100644
index 0000000..2b05096
--- /dev/null
+++ b/test/test_request_template_custom_field_multi_choice_metadata.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.request_template_custom_field_multi_choice_metadata import RequestTemplateCustomFieldMultiChoiceMetadata
+
+class TestRequestTemplateCustomFieldMultiChoiceMetadata(unittest.TestCase):
+ """RequestTemplateCustomFieldMultiChoiceMetadata unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> RequestTemplateCustomFieldMultiChoiceMetadata:
+ """Test RequestTemplateCustomFieldMultiChoiceMetadata
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `RequestTemplateCustomFieldMultiChoiceMetadata`
+ """
+ model = RequestTemplateCustomFieldMultiChoiceMetadata()
+ if include_optional:
+ return RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance]
+ )
+ else:
+ return RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance],
+ )
+ """
+
+ def testRequestTemplateCustomFieldMultiChoiceMetadata(self):
+ """Test RequestTemplateCustomFieldMultiChoiceMetadata"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_request_templates_api.py b/test/test_request_templates_api.py
new file mode 100644
index 0000000..22c3037
--- /dev/null
+++ b/test/test_request_templates_api.py
@@ -0,0 +1,62 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.api.request_templates_api import RequestTemplatesApi
+
+
+class TestRequestTemplatesApi(unittest.TestCase):
+ """RequestTemplatesApi unit test stubs"""
+
+ def setUp(self) -> None:
+ self.api = RequestTemplatesApi()
+
+ def tearDown(self) -> None:
+ pass
+
+ def test_create_request_template(self) -> None:
+ """Test case for create_request_template
+
+ """
+ pass
+
+ def test_delete_request_template(self) -> None:
+ """Test case for delete_request_template
+
+ """
+ pass
+
+ def test_get_request_template(self) -> None:
+ """Test case for get_request_template
+
+ """
+ pass
+
+ def test_get_request_templates(self) -> None:
+ """Test case for get_request_templates
+
+ """
+ pass
+
+ def test_update_request_template(self) -> None:
+ """Test case for update_request_template
+
+ """
+ pass
+
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_access_level_list.py b/test/test_resource_access_level_list.py
new file mode 100644
index 0000000..da55e90
--- /dev/null
+++ b/test/test_resource_access_level_list.py
@@ -0,0 +1,54 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_access_level_list import ResourceAccessLevelList
+
+class TestResourceAccessLevelList(unittest.TestCase):
+ """ResourceAccessLevelList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceAccessLevelList:
+ """Test ResourceAccessLevelList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceAccessLevelList`
+ """
+ model = ResourceAccessLevelList()
+ if include_optional:
+ return ResourceAccessLevelList(
+ results = [
+ {access_level_name=AdminRole, access_level_remote_id=arn:aws:iam::590304332660:role/AdministratorAccess}
+ ]
+ )
+ else:
+ return ResourceAccessLevelList(
+ )
+ """
+
+ def testResourceAccessLevelList(self):
+ """Test ResourceAccessLevelList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_custom_access_level_list.py b/test/test_resource_custom_access_level_list.py
new file mode 100644
index 0000000..8eb2cef
--- /dev/null
+++ b/test/test_resource_custom_access_level_list.py
@@ -0,0 +1,79 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_custom_access_level_list import ResourceCustomAccessLevelList
+
+class TestResourceCustomAccessLevelList(unittest.TestCase):
+ """ResourceCustomAccessLevelList unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceCustomAccessLevelList:
+ """Test ResourceCustomAccessLevelList
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceCustomAccessLevelList`
+ """
+ model = ResourceCustomAccessLevelList()
+ if include_optional:
+ return ResourceCustomAccessLevelList(
+ custom_access_levels = [
+ opal_security.models.resource_custom_access_level_response.ResourceCustomAccessLevelResponse(
+ resource_custom_access_level_id = '',
+ resource_id = '',
+ access_level = {access_level_name=AdminRole, access_level_remote_id=arn:aws:iam::590304332660:role/AdministratorAccess},
+ policy = '',
+ requestable_by_default = True,
+ stackable_sensitivity_index = 56,
+ member_resource_ids = [
+ ''
+ ],
+ created_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ updated_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'), )
+ ]
+ )
+ else:
+ return ResourceCustomAccessLevelList(
+ custom_access_levels = [
+ opal_security.models.resource_custom_access_level_response.ResourceCustomAccessLevelResponse(
+ resource_custom_access_level_id = '',
+ resource_id = '',
+ access_level = {access_level_name=AdminRole, access_level_remote_id=arn:aws:iam::590304332660:role/AdministratorAccess},
+ policy = '',
+ requestable_by_default = True,
+ stackable_sensitivity_index = 56,
+ member_resource_ids = [
+ ''
+ ],
+ created_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ updated_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'), )
+ ],
+ )
+ """
+
+ def testResourceCustomAccessLevelList(self):
+ """Test ResourceCustomAccessLevelList"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_custom_access_level_response.py b/test/test_resource_custom_access_level_response.py
new file mode 100644
index 0000000..619f137
--- /dev/null
+++ b/test/test_resource_custom_access_level_response.py
@@ -0,0 +1,66 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_custom_access_level_response import ResourceCustomAccessLevelResponse
+
+class TestResourceCustomAccessLevelResponse(unittest.TestCase):
+ """ResourceCustomAccessLevelResponse unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceCustomAccessLevelResponse:
+ """Test ResourceCustomAccessLevelResponse
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceCustomAccessLevelResponse`
+ """
+ model = ResourceCustomAccessLevelResponse()
+ if include_optional:
+ return ResourceCustomAccessLevelResponse(
+ resource_custom_access_level_id = '',
+ resource_id = '',
+ access_level = {access_level_name=AdminRole, access_level_remote_id=arn:aws:iam::590304332660:role/AdministratorAccess},
+ policy = '',
+ requestable_by_default = True,
+ stackable_sensitivity_index = 56,
+ member_resource_ids = [
+ ''
+ ],
+ created_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ updated_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f')
+ )
+ else:
+ return ResourceCustomAccessLevelResponse(
+ resource_custom_access_level_id = '',
+ resource_id = '',
+ access_level = {access_level_name=AdminRole, access_level_remote_id=arn:aws:iam::590304332660:role/AdministratorAccess},
+ requestable_by_default = True,
+ )
+ """
+
+ def testResourceCustomAccessLevelResponse(self):
+ """Test ResourceCustomAccessLevelResponse"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_remote_info_alicloud_ecs_instance.py b/test/test_resource_remote_info_alicloud_ecs_instance.py
new file mode 100644
index 0000000..3164f84
--- /dev/null
+++ b/test/test_resource_remote_info_alicloud_ecs_instance.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_remote_info_alicloud_ecs_instance import ResourceRemoteInfoAlicloudEcsInstance
+
+class TestResourceRemoteInfoAlicloudEcsInstance(unittest.TestCase):
+ """ResourceRemoteInfoAlicloudEcsInstance unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceRemoteInfoAlicloudEcsInstance:
+ """Test ResourceRemoteInfoAlicloudEcsInstance
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceRemoteInfoAlicloudEcsInstance`
+ """
+ model = ResourceRemoteInfoAlicloudEcsInstance()
+ if include_optional:
+ return ResourceRemoteInfoAlicloudEcsInstance(
+ instance_id = 'i-bp1a1234567890abcd'
+ )
+ else:
+ return ResourceRemoteInfoAlicloudEcsInstance(
+ instance_id = 'i-bp1a1234567890abcd',
+ )
+ """
+
+ def testResourceRemoteInfoAlicloudEcsInstance(self):
+ """Test ResourceRemoteInfoAlicloudEcsInstance"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_remote_info_alicloud_ram_role.py b/test/test_resource_remote_info_alicloud_ram_role.py
new file mode 100644
index 0000000..c4fe767
--- /dev/null
+++ b/test/test_resource_remote_info_alicloud_ram_role.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_remote_info_alicloud_ram_role import ResourceRemoteInfoAlicloudRamRole
+
+class TestResourceRemoteInfoAlicloudRamRole(unittest.TestCase):
+ """ResourceRemoteInfoAlicloudRamRole unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceRemoteInfoAlicloudRamRole:
+ """Test ResourceRemoteInfoAlicloudRamRole
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceRemoteInfoAlicloudRamRole`
+ """
+ model = ResourceRemoteInfoAlicloudRamRole()
+ if include_optional:
+ return ResourceRemoteInfoAlicloudRamRole(
+ role_arn = 'acs:ram::1234567890:role/MyRole'
+ )
+ else:
+ return ResourceRemoteInfoAlicloudRamRole(
+ role_arn = 'acs:ram::1234567890:role/MyRole',
+ )
+ """
+
+ def testResourceRemoteInfoAlicloudRamRole(self):
+ """Test ResourceRemoteInfoAlicloudRamRole"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_remote_info_docusign_permission_profile.py b/test/test_resource_remote_info_docusign_permission_profile.py
new file mode 100644
index 0000000..ced4c0d
--- /dev/null
+++ b/test/test_resource_remote_info_docusign_permission_profile.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_remote_info_docusign_permission_profile import ResourceRemoteInfoDocusignPermissionProfile
+
+class TestResourceRemoteInfoDocusignPermissionProfile(unittest.TestCase):
+ """ResourceRemoteInfoDocusignPermissionProfile unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceRemoteInfoDocusignPermissionProfile:
+ """Test ResourceRemoteInfoDocusignPermissionProfile
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceRemoteInfoDocusignPermissionProfile`
+ """
+ model = ResourceRemoteInfoDocusignPermissionProfile()
+ if include_optional:
+ return ResourceRemoteInfoDocusignPermissionProfile(
+ permission_profile_id = '12345'
+ )
+ else:
+ return ResourceRemoteInfoDocusignPermissionProfile(
+ permission_profile_id = '12345',
+ )
+ """
+
+ def testResourceRemoteInfoDocusignPermissionProfile(self):
+ """Test ResourceRemoteInfoDocusignPermissionProfile"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_remote_info_gcp_billing_account.py b/test/test_resource_remote_info_gcp_billing_account.py
new file mode 100644
index 0000000..7cc38b9
--- /dev/null
+++ b/test/test_resource_remote_info_gcp_billing_account.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_remote_info_gcp_billing_account import ResourceRemoteInfoGcpBillingAccount
+
+class TestResourceRemoteInfoGcpBillingAccount(unittest.TestCase):
+ """ResourceRemoteInfoGcpBillingAccount unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceRemoteInfoGcpBillingAccount:
+ """Test ResourceRemoteInfoGcpBillingAccount
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceRemoteInfoGcpBillingAccount`
+ """
+ model = ResourceRemoteInfoGcpBillingAccount()
+ if include_optional:
+ return ResourceRemoteInfoGcpBillingAccount(
+ billing_account_id = 'billingAccounts/012345-567890-ABCDEF'
+ )
+ else:
+ return ResourceRemoteInfoGcpBillingAccount(
+ billing_account_id = 'billingAccounts/012345-567890-ABCDEF',
+ )
+ """
+
+ def testResourceRemoteInfoGcpBillingAccount(self):
+ """Test ResourceRemoteInfoGcpBillingAccount"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_remote_info_linear_organization.py b/test/test_resource_remote_info_linear_organization.py
new file mode 100644
index 0000000..e26a908
--- /dev/null
+++ b/test/test_resource_remote_info_linear_organization.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_remote_info_linear_organization import ResourceRemoteInfoLinearOrganization
+
+class TestResourceRemoteInfoLinearOrganization(unittest.TestCase):
+ """ResourceRemoteInfoLinearOrganization unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceRemoteInfoLinearOrganization:
+ """Test ResourceRemoteInfoLinearOrganization
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceRemoteInfoLinearOrganization`
+ """
+ model = ResourceRemoteInfoLinearOrganization()
+ if include_optional:
+ return ResourceRemoteInfoLinearOrganization(
+ org_id = 'df85baa9-0af5-4f28-a5b5-64e4b2ddeedc'
+ )
+ else:
+ return ResourceRemoteInfoLinearOrganization(
+ org_id = 'df85baa9-0af5-4f28-a5b5-64e4b2ddeedc',
+ )
+ """
+
+ def testResourceRemoteInfoLinearOrganization(self):
+ """Test ResourceRemoteInfoLinearOrganization"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_remote_info_linear_project.py b/test/test_resource_remote_info_linear_project.py
new file mode 100644
index 0000000..e22c7e7
--- /dev/null
+++ b/test/test_resource_remote_info_linear_project.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_remote_info_linear_project import ResourceRemoteInfoLinearProject
+
+class TestResourceRemoteInfoLinearProject(unittest.TestCase):
+ """ResourceRemoteInfoLinearProject unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceRemoteInfoLinearProject:
+ """Test ResourceRemoteInfoLinearProject
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceRemoteInfoLinearProject`
+ """
+ model = ResourceRemoteInfoLinearProject()
+ if include_optional:
+ return ResourceRemoteInfoLinearProject(
+ project_id = '58ed91a7-1234-5678-9abc-def012345678'
+ )
+ else:
+ return ResourceRemoteInfoLinearProject(
+ project_id = '58ed91a7-1234-5678-9abc-def012345678',
+ )
+ """
+
+ def testResourceRemoteInfoLinearProject(self):
+ """Test ResourceRemoteInfoLinearProject"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_remote_info_zoom_license.py b/test/test_resource_remote_info_zoom_license.py
new file mode 100644
index 0000000..41ce9fd
--- /dev/null
+++ b/test/test_resource_remote_info_zoom_license.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_remote_info_zoom_license import ResourceRemoteInfoZoomLicense
+
+class TestResourceRemoteInfoZoomLicense(unittest.TestCase):
+ """ResourceRemoteInfoZoomLicense unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceRemoteInfoZoomLicense:
+ """Test ResourceRemoteInfoZoomLicense
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceRemoteInfoZoomLicense`
+ """
+ model = ResourceRemoteInfoZoomLicense()
+ if include_optional:
+ return ResourceRemoteInfoZoomLicense(
+ license_type = '2'
+ )
+ else:
+ return ResourceRemoteInfoZoomLicense(
+ license_type = '2',
+ )
+ """
+
+ def testResourceRemoteInfoZoomLicense(self):
+ """Test ResourceRemoteInfoZoomLicense"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_resource_remote_info_zoom_role.py b/test/test_resource_remote_info_zoom_role.py
new file mode 100644
index 0000000..33f5258
--- /dev/null
+++ b/test/test_resource_remote_info_zoom_role.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.resource_remote_info_zoom_role import ResourceRemoteInfoZoomRole
+
+class TestResourceRemoteInfoZoomRole(unittest.TestCase):
+ """ResourceRemoteInfoZoomRole unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ResourceRemoteInfoZoomRole:
+ """Test ResourceRemoteInfoZoomRole
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ResourceRemoteInfoZoomRole`
+ """
+ model = ResourceRemoteInfoZoomRole()
+ if include_optional:
+ return ResourceRemoteInfoZoomRole(
+ role_id = '0'
+ )
+ else:
+ return ResourceRemoteInfoZoomRole(
+ role_id = '0',
+ )
+ """
+
+ def testResourceRemoteInfoZoomRole(self):
+ """Test ResourceRemoteInfoZoomRole"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_run_opal_query_request.py b/test/test_run_opal_query_request.py
new file mode 100644
index 0000000..00a9fa4
--- /dev/null
+++ b/test/test_run_opal_query_request.py
@@ -0,0 +1,116 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.run_opal_query_request import RunOpalQueryRequest
+
+class TestRunOpalQueryRequest(unittest.TestCase):
+ """RunOpalQueryRequest unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> RunOpalQueryRequest:
+ """Test RunOpalQueryRequest
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `RunOpalQueryRequest`
+ """
+ model = RunOpalQueryRequest()
+ if include_optional:
+ return RunOpalQueryRequest(
+ type = 'NODE',
+ query = opal_security.models.opal_access_path_query_body.OpalAccessPathQueryBody(
+ principal_filter = opal_security.models.access_entity_filters.AccessEntityFilters(
+ entity_types = [
+ 'RESOURCE'
+ ],
+ entity_item_types = [
+ 'OPAL_ROLE'
+ ],
+ entity_name = opal_security.models.entity_name_filter.EntityNameFilter(
+ string_match_type = 'CONTAINS',
+ string = 'engineering', ),
+ entity_tag = opal_security.models.entity_tag_filter.EntityTagFilter(
+ key = 'team',
+ value = 'platform',
+ connection_id = '', ),
+ hr_idp_status = opal_security.models.idp_status_filter.IdpStatusFilter(
+ statuses = [
+ 'ACTIVE'
+ ],
+ not = True, ),
+ entity_admin_owner = opal_security.models.entity_admin_filter.EntityAdminFilter(
+ owner_ids = [
+ ''
+ ],
+ not = True, ),
+ entity_ids = [
+ ''
+ ],
+ imported_from_app = [
+ ''
+ ],
+ role_remote_ids = [
+ ''
+ ],
+ role_names = [
+ ''
+ ],
+ all_of = [
+ opal_security.models.access_entity_filters.AccessEntityFilters(
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), )
+ ],
+ any_of = [
+
+ ],
+ not = opal_security.models.not.not(), ),
+ entitlement_filter = ,
+ principal_access_filters = null,
+ entitlement_access_filters = null,
+ access_level_remote_ids = [
+ ''
+ ],
+ access_level_names = [
+ ''
+ ],
+ edge_filter = opal_security.models.opal_access_path_edge_filter.OpalAccessPathEdgeFilter(
+ direct_only = True,
+ access_duration_type = 'EXPIRING_ONLY', ), ),
+ first = 200,
+ after = '',
+ include_count = False
+ )
+ else:
+ return RunOpalQueryRequest(
+ type = 'NODE',
+ )
+ """
+
+ def testRunOpalQueryRequest(self):
+ """Test RunOpalQueryRequest"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_sort_direction_enum.py b/test/test_sort_direction_enum.py
new file mode 100644
index 0000000..5edcbed
--- /dev/null
+++ b/test/test_sort_direction_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.sort_direction_enum import SortDirectionEnum
+
+class TestSortDirectionEnum(unittest.TestCase):
+ """SortDirectionEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testSortDirectionEnum(self):
+ """Test SortDirectionEnum"""
+ # inst = SortDirectionEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_stop_campaign_request.py b/test/test_stop_campaign_request.py
new file mode 100644
index 0000000..90d430f
--- /dev/null
+++ b/test/test_stop_campaign_request.py
@@ -0,0 +1,52 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.stop_campaign_request import StopCampaignRequest
+
+class TestStopCampaignRequest(unittest.TestCase):
+ """StopCampaignRequest unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> StopCampaignRequest:
+ """Test StopCampaignRequest
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `StopCampaignRequest`
+ """
+ model = StopCampaignRequest()
+ if include_optional:
+ return StopCampaignRequest(
+ revoke_unreviewed = True
+ )
+ else:
+ return StopCampaignRequest(
+ )
+ """
+
+ def testStopCampaignRequest(self):
+ """Test StopCampaignRequest"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_update_campaign_configuration_info.py b/test/test_update_campaign_configuration_info.py
new file mode 100644
index 0000000..5976f91
--- /dev/null
+++ b/test/test_update_campaign_configuration_info.py
@@ -0,0 +1,66 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.update_campaign_configuration_info import UpdateCampaignConfigurationInfo
+
+class TestUpdateCampaignConfigurationInfo(unittest.TestCase):
+ """UpdateCampaignConfigurationInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> UpdateCampaignConfigurationInfo:
+ """Test UpdateCampaignConfigurationInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `UpdateCampaignConfigurationInfo`
+ """
+ model = UpdateCampaignConfigurationInfo()
+ if include_optional:
+ return UpdateCampaignConfigurationInfo(
+ allow_self_review = False,
+ send_reviewer_assignment_notification = True,
+ allow_reviewer_reassignment = False,
+ start_date = '2026-07-02T00:00:00.000+00:00',
+ end_date = '2026-09-30T00:00:00.000+00:00',
+ timezone = 'America/Los_Angeles',
+ revoke_on = 'END',
+ reminder_schedule = [7, 3, 1],
+ reminder_include_manager = True,
+ require_reason_on_denial = False,
+ hide_ai_suggestions = False,
+ custom_start_message = 'Please complete your reviews by Friday.',
+ group_asset_visibility_policy = 'STRICT',
+ cron_expression = '0 9 1 * *',
+ recurring_duration_days = 14
+ )
+ else:
+ return UpdateCampaignConfigurationInfo(
+ )
+ """
+
+ def testUpdateCampaignConfigurationInfo(self):
+ """Test UpdateCampaignConfigurationInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_update_campaign_info.py b/test/test_update_campaign_info.py
new file mode 100644
index 0000000..c103d6a
--- /dev/null
+++ b/test/test_update_campaign_info.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.update_campaign_info import UpdateCampaignInfo
+
+class TestUpdateCampaignInfo(unittest.TestCase):
+ """UpdateCampaignInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> UpdateCampaignInfo:
+ """Test UpdateCampaignInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `UpdateCampaignInfo`
+ """
+ model = UpdateCampaignInfo()
+ if include_optional:
+ return UpdateCampaignInfo(
+ name = 'Q3 Access Review (Updated)',
+ configuration = {end_date=2026-09-30T00:00:00.000+00:00, timezone=America/Los_Angeles, allow_self_review=false}
+ )
+ else:
+ return UpdateCampaignInfo(
+ )
+ """
+
+ def testUpdateCampaignInfo(self):
+ """Test UpdateCampaignInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_update_paladin_info.py b/test/test_update_paladin_info.py
new file mode 100644
index 0000000..4c7f39c
--- /dev/null
+++ b/test/test_update_paladin_info.py
@@ -0,0 +1,59 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.update_paladin_info import UpdatePaladinInfo
+
+class TestUpdatePaladinInfo(unittest.TestCase):
+ """UpdatePaladinInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> UpdatePaladinInfo:
+ """Test UpdatePaladinInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `UpdatePaladinInfo`
+ """
+ model = UpdatePaladinInfo()
+ if include_optional:
+ return UpdatePaladinInfo(
+ name = 'paladin-agent-1',
+ monitor_mode = True,
+ admin_view_only = True,
+ enabled_connectors = [
+ 'NOTION'
+ ],
+ instructions = ''
+ )
+ else:
+ return UpdatePaladinInfo(
+ name = 'paladin-agent-1',
+ )
+ """
+
+ def testUpdatePaladinInfo(self):
+ """Test UpdatePaladinInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_update_request_template_info.py b/test/test_update_request_template_info.py
new file mode 100644
index 0000000..855db97
--- /dev/null
+++ b/test/test_update_request_template_info.py
@@ -0,0 +1,67 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.update_request_template_info import UpdateRequestTemplateInfo
+
+class TestUpdateRequestTemplateInfo(unittest.TestCase):
+ """UpdateRequestTemplateInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> UpdateRequestTemplateInfo:
+ """Test UpdateRequestTemplateInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `UpdateRequestTemplateInfo`
+ """
+ model = UpdateRequestTemplateInfo()
+ if include_optional:
+ return UpdateRequestTemplateInfo(
+ request_template_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ name = '',
+ custom_fields = [
+ opal_security.models.request_template_custom_field_input.RequestTemplateCustomFieldInput(
+ name = 'Why do you need this access?',
+ description = '',
+ type = 'SHORT_TEXT',
+ required = True,
+ metadata = opal_security.models.request_template_custom_field_metadata.RequestTemplateCustomFieldMetadata(
+ callout_data = opal_security.models.request_template_custom_field_callout_metadata.RequestTemplateCustomFieldCalloutMetadata(
+ severity = 'WARNING',
+ text = 'This role grants access to production customer data.', ),
+ multi_choice_data = opal_security.models.request_template_custom_field_multi_choice_metadata.RequestTemplateCustomFieldMultiChoiceMetadata(
+ options = [Incident response, Scheduled maintenance], ), ), )
+ ]
+ )
+ else:
+ return UpdateRequestTemplateInfo(
+ request_template_id = '7c86c85d-0651-43e2-a748-d69d658418e8',
+ )
+ """
+
+ def testUpdateRequestTemplateInfo(self):
+ """Test UpdateRequestTemplateInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_update_resource_custom_access_level_info.py b/test/test_update_resource_custom_access_level_info.py
new file mode 100644
index 0000000..7bad3ae
--- /dev/null
+++ b/test/test_update_resource_custom_access_level_info.py
@@ -0,0 +1,56 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.update_resource_custom_access_level_info import UpdateResourceCustomAccessLevelInfo
+
+class TestUpdateResourceCustomAccessLevelInfo(unittest.TestCase):
+ """UpdateResourceCustomAccessLevelInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> UpdateResourceCustomAccessLevelInfo:
+ """Test UpdateResourceCustomAccessLevelInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `UpdateResourceCustomAccessLevelInfo`
+ """
+ model = UpdateResourceCustomAccessLevelInfo()
+ if include_optional:
+ return UpdateResourceCustomAccessLevelInfo(
+ access_level_name = '',
+ policy = '',
+ requestable_by_default = True,
+ stackable_sensitivity_index = 56,
+ clear_stackable_sensitivity_index = True
+ )
+ else:
+ return UpdateResourceCustomAccessLevelInfo(
+ )
+ """
+
+ def testUpdateResourceCustomAccessLevelInfo(self):
+ """Test UpdateResourceCustomAccessLevelInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_update_user_info.py b/test/test_update_user_info.py
new file mode 100644
index 0000000..d0518b7
--- /dev/null
+++ b/test/test_update_user_info.py
@@ -0,0 +1,53 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.update_user_info import UpdateUserInfo
+
+class TestUpdateUserInfo(unittest.TestCase):
+ """UpdateUserInfo unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> UpdateUserInfo:
+ """Test UpdateUserInfo
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `UpdateUserInfo`
+ """
+ model = UpdateUserInfo()
+ if include_optional:
+ return UpdateUserInfo(
+ manager_id = '',
+ position = ''
+ )
+ else:
+ return UpdateUserInfo(
+ )
+ """
+
+ def testUpdateUserInfo(self):
+ """Test UpdateUserInfo"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_user_product_role_enum.py b/test/test_user_product_role_enum.py
new file mode 100644
index 0000000..31f2524
--- /dev/null
+++ b/test/test_user_product_role_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.user_product_role_enum import UserProductRoleEnum
+
+class TestUserProductRoleEnum(unittest.TestCase):
+ """UserProductRoleEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testUserProductRoleEnum(self):
+ """Test UserProductRoleEnum"""
+ # inst = UserProductRoleEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_viewer_campaign_item.py b/test/test_viewer_campaign_item.py
new file mode 100644
index 0000000..e379cd7
--- /dev/null
+++ b/test/test_viewer_campaign_item.py
@@ -0,0 +1,78 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.viewer_campaign_item import ViewerCampaignItem
+
+class TestViewerCampaignItem(unittest.TestCase):
+ """ViewerCampaignItem unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def make_instance(self, include_optional) -> ViewerCampaignItem:
+ """Test ViewerCampaignItem
+ include_optional is a boolean, when False only required
+ params are included, when True both required and
+ optional params are included """
+ # uncomment below to create an instance of `ViewerCampaignItem`
+ """
+ model = ViewerCampaignItem()
+ if include_optional:
+ return ViewerCampaignItem(
+ campaign_item_review_id = '',
+ decision = 'APPROVED',
+ note = '',
+ decided_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ pending_decision = 'APPROVED',
+ pending_note = '',
+ updated_access_level_remote_id = '',
+ pending_updated_access_level_remote_id = '',
+ reassigned_to_reviewer_ids = [
+ ''
+ ],
+ principal_id = '',
+ principal_type = 'GROUP',
+ entity_id = '',
+ entity_type = 'GROUP',
+ access_level_name = '',
+ access_level_remote_id = '',
+ granted_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ expires_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ role_assignment_id = ''
+ )
+ else:
+ return ViewerCampaignItem(
+ campaign_item_review_id = '',
+ principal_id = '',
+ principal_type = 'GROUP',
+ entity_id = '',
+ entity_type = 'GROUP',
+ granted_at = datetime.datetime.strptime('2013-10-20 19:20:30.00', '%Y-%m-%d %H:%M:%S.%f'),
+ role_assignment_id = '',
+ )
+ """
+
+ def testViewerCampaignItem(self):
+ """Test ViewerCampaignItem"""
+ # inst_req_only = self.make_instance(include_optional=False)
+ # inst_req_and_optional = self.make_instance(include_optional=True)
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_viewer_campaign_item_review_decision_enum.py b/test/test_viewer_campaign_item_review_decision_enum.py
new file mode 100644
index 0000000..d655e5b
--- /dev/null
+++ b/test/test_viewer_campaign_item_review_decision_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.viewer_campaign_item_review_decision_enum import ViewerCampaignItemReviewDecisionEnum
+
+class TestViewerCampaignItemReviewDecisionEnum(unittest.TestCase):
+ """ViewerCampaignItemReviewDecisionEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testViewerCampaignItemReviewDecisionEnum(self):
+ """Test ViewerCampaignItemReviewDecisionEnum"""
+ # inst = ViewerCampaignItemReviewDecisionEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_viewer_campaign_item_sort_field_enum.py b/test/test_viewer_campaign_item_sort_field_enum.py
new file mode 100644
index 0000000..84b29f3
--- /dev/null
+++ b/test/test_viewer_campaign_item_sort_field_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.viewer_campaign_item_sort_field_enum import ViewerCampaignItemSortFieldEnum
+
+class TestViewerCampaignItemSortFieldEnum(unittest.TestCase):
+ """ViewerCampaignItemSortFieldEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testViewerCampaignItemSortFieldEnum(self):
+ """Test ViewerCampaignItemSortFieldEnum"""
+ # inst = ViewerCampaignItemSortFieldEnum()
+
+if __name__ == '__main__':
+ unittest.main()
diff --git a/test/test_viewer_campaign_item_status_enum.py b/test/test_viewer_campaign_item_status_enum.py
new file mode 100644
index 0000000..d823daf
--- /dev/null
+++ b/test/test_viewer_campaign_item_status_enum.py
@@ -0,0 +1,34 @@
+# coding: utf-8
+
+"""
+ Opal API
+
+ The Opal API is a RESTful API that allows you to interact with the Opal Security platform programmatically.
+
+ The version of the OpenAPI document: 1.0
+ Contact: hello@opal.dev
+ Generated by OpenAPI Generator (https://openapi-generator.tech)
+
+ Do not edit the class manually.
+""" # noqa: E501
+
+
+import unittest
+
+from opal_security.models.viewer_campaign_item_status_enum import ViewerCampaignItemStatusEnum
+
+class TestViewerCampaignItemStatusEnum(unittest.TestCase):
+ """ViewerCampaignItemStatusEnum unit test stubs"""
+
+ def setUp(self):
+ pass
+
+ def tearDown(self):
+ pass
+
+ def testViewerCampaignItemStatusEnum(self):
+ """Test ViewerCampaignItemStatusEnum"""
+ # inst = ViewerCampaignItemStatusEnum()
+
+if __name__ == '__main__':
+ unittest.main()