adminScope property

PayloadAdminScope? adminScope
final

How wide the ACL entry the maintainer writes for the minted admin is. context (the default, and what every integration-class consumer wants) binds the admin to context alone. unrestricted binds it to no context at all — the shape an ACL reads as a super-admin, able to act in every context the maintainer holds today and in every one created later — and is what an operator console asks for. context is resolved and authoritative in BOTH cases: it is where the admin DID is minted and the home a consumer stores its own configuration under, so unrestricted widens the grant without making the target context optional. A maintainer MUST refuse unrestricted with provision/integration:forbidden unless the relayer is itself a super-admin, because no admin may confer authority it does not hold. A maintainer that does not implement this member ignores it and writes a context-scoped entry; that is why the outcome is echoed as summary.adminScope rather than assumed from the ask.

Implementation

final PayloadAdminScope? adminScope;