AclEntryStepUp class
Per-entry authentication step-up configuration, consumed by the ACL maintainer when it gates an operation behind a step-up (see auth/step-up/policy). ADDITIVE-ONLY: a per-entry setting MAY raise the assurance required of this subject above the maintainer's system-wide floor, but MUST NOT lower it. The maintainer resolves the effective requirement as the strictest of (system floor, this entry). Carried forward from 0.1 unchanged.
Constructors
- AclEntryStepUp({String? approver, AclEntryStepUpRequire? require})
-
const
-
AclEntryStepUp.fromJson(Map<
String, dynamic> json) -
Read this payload from a decoded JSON object.
factory
Properties
- approver → ResourceQualifier?
-
VID authorized to ratify step-up for this subject — the
recipientthe maintainer addresses an auth/step-up/approve-request to (e.g. the holder's mobile authenticator or browser companion). Absent → the subject is its own approver (modeself) when it holds a usable authenticator; if neither anapprovernor a self authenticator exists, no step-up method is available for this subject and the maintainer's fail-closed rule applies.final - hashCode → int
-
The hash code for this object.
no setterinherited
- require → AclEntryStepUpRequire?
-
Minimum step-up mode this subject MUST satisfy for gated operations, raising the
system floor.
self= the subject re-authenticates its own session;delegated= a separateapproverMUST ratify. Omitted → the system floor applies unchanged. A value weaker than the resolved floor is ignored (additive-only).final - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, dynamic> - Serialize to a JSON-encodable map, omitting absent members.
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited