Payload class
Amend the non-role attributes of an existing AclEntry 0.2: its act scope (widening
only), approve scope, capability scope, approvable-capability scope, key scope,
label, expiry or step-up requirement. Every member REPLACES the stored value; an
omitted member leaves it unchanged. Role changes are NOT expressible here — they go
through acl/change-role, which requires the current role as a compare-and-swap.
delegatedBy and the provenance timestamps are maintainer-populated and not
settable.
Constructors
- Payload({required String subject, AuthorityScope? act, AuthorityScope? approve, CapabilityScope? capabilities, ApproveCapabilityScope? approveCapabilities, KeyScope? keys, String? label, String? expiresAt, PayloadStepUp? stepUp, String? reason, Ext? ext})
-
const
-
Payload.fromJson(Map<
String, dynamic> json) -
Read this payload from a decoded JSON object.
factory
Properties
- act → Object?
-
Replacement act scope, in the same explicit form as the entry's (
all,none, or a non-empty context list). A replacement that WIDENS or equals the stored scope is accepted, subject to the granter bound. NARROWING THE ACT SCOPE IS A REVOCATION and a consumer MUST refuse it here withnarrowingNotPermitted, directing the caller to acl/revoke, so that every removal of where a subject may act passes through the task that is audited and reasoned as a revocation.final - approve → Object?
-
Replacement approve scope. To withdraw approve authority entirely, send
{"scope": "none"}— there is no null form, because the explicit value is the only spelling that cannot be misread. Widening is an escalation vector (a subject able to approve can ratify operations it could not authorize) and is bounded by the granter's own approve authority. Narrowing is accepted here and is a privilege reduction (see the specification).final - approveCapabilities → Object?
-
Replacement approvable-capability scope, applied wholesale. Omitted leaves it
unchanged.
{"scope": "ceiling"}lets the subject approve its role's full approve ceiling within its approve scope (a privilege increase);{"scope": "none"}withdraws it;listedstates the exact set. There is no null form. Bounded by the granter's own approve authority.final - capabilities → Object?
-
Replacement capability scope, applied wholesale, in the same explicit form as the
entry's. Omitted leaves it unchanged.
{"scope": "ceiling"}returns the entry to its role's full ceiling — a privilege INCREASE, bounded and gated like any widening;{"scope": "none"}removes every capability;listedstates the exact set. There is no null form. Every listed capability is checked as on a grant (registry, ceiling, additive, granter bound). A replacement that removes a capability the entry held is a privilege reduction.final - expiresAt → ResourceQualifier?
-
Replacement expiry. Explicit
nullmakes the entry permanent — a privilege increase, which a consumer SHOULD gate at least as strictly as the original grant, and which is refused where the granter's own entry expires.final - ext → Ext?
-
Ecosystem-defined extension members per SPEC.md §4.5.1.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- keys → Object?
-
Replacement key scope, applied wholesale. Omitted leaves it unchanged.
{"scope": "all"}lets the subject reach every key within its act scope again — a privilege increase a consumer SHOULD gate like clearingexpiresAt;{"scope": "none"}removes every key;listedstates the exact set. There is no null form. A replacement that narrows the stored key scope IS a privilege reduction: it is accepted here, because acl/revoke/0.2 narrows only the act scope, but the consumer MUST audit it as a reduction and apply it at the subject's next authorization decision.final - label → ResourceQualifier?
-
Replacement human-readable label. Explicit
nullclears it. Omitted leaves it unchanged.final - reason → ResourceQualifier?
-
Optional human-readable rationale, recorded with the change.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- stepUp → PayloadStepUp?
-
Replacement per-entry step-up configuration. Same additive-only rule as on the
entry itself: it MAY raise the assurance required of this subject above the system
floor but MUST NOT lower it.
final
- subject → String
-
VID of the entry to amend. The entry MUST already exist; this task does not create
one (use acl/grant).
final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, dynamic> - Serialize to a JSON-encodable map, omitting absent members.
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited