CapabilityGrant class

A capability held by an entry, optionally qualified by a resource, optionally marked additive. A qualified grant confers nothing without a live entry for the same subject, and is bounded as delegated authority is.

Constructors

CapabilityGrant({required Capability capability, ResourceQualifier? resource, bool? additive})
const
CapabilityGrant.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

additive → bool?
true declares an ADDITIVE grant: a capability no role implies, granted to this entry beside its role rather than through it, and therefore not intersected with the role's ceiling. Granting one requires unrestricted act authority (act: {scope: all}) of the granter, and an entry never acquires one by virtue of its role. Absent or false → an ordinary grant, intersected with the role's ceiling, and refused when written if it lies outside it. A consumer MUST refuse additive: true on a capability the role's ceiling already includes, so that the flag cannot be used to make an ordinary capability survive a later role change.
final
capability → String
final
hashCode → int
The hash code for this object.
no setterinherited
resource → ResourceQualifier?
Optional qualifier. Absent covers every resource of the capability's kind.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited