diff --git a/.generator/schemas/v2/openapi.yaml b/.generator/schemas/v2/openapi.yaml
index 8307610ee5f..419caee7342 100644
--- a/.generator/schemas/v2/openapi.yaml
+++ b/.generator/schemas/v2/openapi.yaml
@@ -95624,6 +95624,12 @@ components:
format: date-time
readOnly: true
type: string
+ default_permissions_opt_out:
+ description: |-
+ Whether to exclude restricted default permissions from this role.
+ Restricted default permissions are automatically assigned to every role by default. Set this field to `true` to exclude them.
+ Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization.
+ type: boolean
modified_at:
description: Time of last role modification.
format: date-time
@@ -95755,6 +95761,12 @@ components:
format: date-time
readOnly: true
type: string
+ default_permissions_opt_out:
+ description: |-
+ Whether to exclude restricted default permissions from this role.
+ Restricted default permissions are automatically assigned to every role by default. Set this field to `true` to exclude them.
+ Some of these permissions can only be excluded after Minimal Access Roles is enabled for the organization.
+ type: boolean
modified_at:
description: Time of last role modification.
format: date-time
diff --git a/src/main/java/com/datadog/api/client/v2/model/RoleCreateAttributes.java b/src/main/java/com/datadog/api/client/v2/model/RoleCreateAttributes.java
index 2a839f59922..a0088761584 100644
--- a/src/main/java/com/datadog/api/client/v2/model/RoleCreateAttributes.java
+++ b/src/main/java/com/datadog/api/client/v2/model/RoleCreateAttributes.java
@@ -23,6 +23,7 @@
/** Attributes of the created role. */
@JsonPropertyOrder({
RoleCreateAttributes.JSON_PROPERTY_CREATED_AT,
+ RoleCreateAttributes.JSON_PROPERTY_DEFAULT_PERMISSIONS_OPT_OUT,
RoleCreateAttributes.JSON_PROPERTY_MODIFIED_AT,
RoleCreateAttributes.JSON_PROPERTY_NAME,
RoleCreateAttributes.JSON_PROPERTY_RECEIVES_PERMISSIONS_FROM
@@ -34,6 +35,10 @@ public class RoleCreateAttributes {
public static final String JSON_PROPERTY_CREATED_AT = "created_at";
private OffsetDateTime createdAt;
+ public static final String JSON_PROPERTY_DEFAULT_PERMISSIONS_OPT_OUT =
+ "default_permissions_opt_out";
+ private Boolean defaultPermissionsOptOut;
+
public static final String JSON_PROPERTY_MODIFIED_AT = "modified_at";
private OffsetDateTime modifiedAt;
@@ -63,6 +68,30 @@ public OffsetDateTime getCreatedAt() {
return createdAt;
}
+ public RoleCreateAttributes defaultPermissionsOptOut(Boolean defaultPermissionsOptOut) {
+ this.defaultPermissionsOptOut = defaultPermissionsOptOut;
+ return this;
+ }
+
+ /**
+ * Whether to exclude restricted default permissions from this role. Restricted default
+ * permissions are automatically assigned to every role by default. Set this field to true
+ * to exclude them. Some of these permissions can only be excluded after Minimal Access
+ * Roles is enabled for the organization.
+ *
+ * @return defaultPermissionsOptOut
+ */
+ @jakarta.annotation.Nullable
+ @JsonProperty(JSON_PROPERTY_DEFAULT_PERMISSIONS_OPT_OUT)
+ @JsonInclude(value = JsonInclude.Include.USE_DEFAULTS)
+ public Boolean getDefaultPermissionsOptOut() {
+ return defaultPermissionsOptOut;
+ }
+
+ public void setDefaultPermissionsOptOut(Boolean defaultPermissionsOptOut) {
+ this.defaultPermissionsOptOut = defaultPermissionsOptOut;
+ }
+
/**
* Time of last role modification.
*
@@ -184,6 +213,8 @@ public boolean equals(Object o) {
}
RoleCreateAttributes roleCreateAttributes = (RoleCreateAttributes) o;
return Objects.equals(this.createdAt, roleCreateAttributes.createdAt)
+ && Objects.equals(
+ this.defaultPermissionsOptOut, roleCreateAttributes.defaultPermissionsOptOut)
&& Objects.equals(this.modifiedAt, roleCreateAttributes.modifiedAt)
&& Objects.equals(this.name, roleCreateAttributes.name)
&& Objects.equals(
@@ -193,7 +224,13 @@ public boolean equals(Object o) {
@Override
public int hashCode() {
- return Objects.hash(createdAt, modifiedAt, name, receivesPermissionsFrom, additionalProperties);
+ return Objects.hash(
+ createdAt,
+ defaultPermissionsOptOut,
+ modifiedAt,
+ name,
+ receivesPermissionsFrom,
+ additionalProperties);
}
@Override
@@ -201,6 +238,9 @@ public String toString() {
StringBuilder sb = new StringBuilder();
sb.append("class RoleCreateAttributes {\n");
sb.append(" createdAt: ").append(toIndentedString(createdAt)).append("\n");
+ sb.append(" defaultPermissionsOptOut: ")
+ .append(toIndentedString(defaultPermissionsOptOut))
+ .append("\n");
sb.append(" modifiedAt: ").append(toIndentedString(modifiedAt)).append("\n");
sb.append(" name: ").append(toIndentedString(name)).append("\n");
sb.append(" receivesPermissionsFrom: ")
diff --git a/src/main/java/com/datadog/api/client/v2/model/RoleUpdateAttributes.java b/src/main/java/com/datadog/api/client/v2/model/RoleUpdateAttributes.java
index 93cc3398b04..ba42aa3d532 100644
--- a/src/main/java/com/datadog/api/client/v2/model/RoleUpdateAttributes.java
+++ b/src/main/java/com/datadog/api/client/v2/model/RoleUpdateAttributes.java
@@ -22,6 +22,7 @@
/** Attributes of the role. */
@JsonPropertyOrder({
RoleUpdateAttributes.JSON_PROPERTY_CREATED_AT,
+ RoleUpdateAttributes.JSON_PROPERTY_DEFAULT_PERMISSIONS_OPT_OUT,
RoleUpdateAttributes.JSON_PROPERTY_MODIFIED_AT,
RoleUpdateAttributes.JSON_PROPERTY_NAME,
RoleUpdateAttributes.JSON_PROPERTY_RECEIVES_PERMISSIONS_FROM,
@@ -34,6 +35,10 @@ public class RoleUpdateAttributes {
public static final String JSON_PROPERTY_CREATED_AT = "created_at";
private OffsetDateTime createdAt;
+ public static final String JSON_PROPERTY_DEFAULT_PERMISSIONS_OPT_OUT =
+ "default_permissions_opt_out";
+ private Boolean defaultPermissionsOptOut;
+
public static final String JSON_PROPERTY_MODIFIED_AT = "modified_at";
private OffsetDateTime modifiedAt;
@@ -58,6 +63,30 @@ public OffsetDateTime getCreatedAt() {
return createdAt;
}
+ public RoleUpdateAttributes defaultPermissionsOptOut(Boolean defaultPermissionsOptOut) {
+ this.defaultPermissionsOptOut = defaultPermissionsOptOut;
+ return this;
+ }
+
+ /**
+ * Whether to exclude restricted default permissions from this role. Restricted default
+ * permissions are automatically assigned to every role by default. Set this field to true
+ * to exclude them. Some of these permissions can only be excluded after Minimal Access
+ * Roles is enabled for the organization.
+ *
+ * @return defaultPermissionsOptOut
+ */
+ @jakarta.annotation.Nullable
+ @JsonProperty(JSON_PROPERTY_DEFAULT_PERMISSIONS_OPT_OUT)
+ @JsonInclude(value = JsonInclude.Include.USE_DEFAULTS)
+ public Boolean getDefaultPermissionsOptOut() {
+ return defaultPermissionsOptOut;
+ }
+
+ public void setDefaultPermissionsOptOut(Boolean defaultPermissionsOptOut) {
+ this.defaultPermissionsOptOut = defaultPermissionsOptOut;
+ }
+
/**
* Time of last role modification.
*
@@ -201,6 +230,8 @@ public boolean equals(Object o) {
}
RoleUpdateAttributes roleUpdateAttributes = (RoleUpdateAttributes) o;
return Objects.equals(this.createdAt, roleUpdateAttributes.createdAt)
+ && Objects.equals(
+ this.defaultPermissionsOptOut, roleUpdateAttributes.defaultPermissionsOptOut)
&& Objects.equals(this.modifiedAt, roleUpdateAttributes.modifiedAt)
&& Objects.equals(this.name, roleUpdateAttributes.name)
&& Objects.equals(
@@ -212,7 +243,13 @@ public boolean equals(Object o) {
@Override
public int hashCode() {
return Objects.hash(
- createdAt, modifiedAt, name, receivesPermissionsFrom, userCount, additionalProperties);
+ createdAt,
+ defaultPermissionsOptOut,
+ modifiedAt,
+ name,
+ receivesPermissionsFrom,
+ userCount,
+ additionalProperties);
}
@Override
@@ -220,6 +257,9 @@ public String toString() {
StringBuilder sb = new StringBuilder();
sb.append("class RoleUpdateAttributes {\n");
sb.append(" createdAt: ").append(toIndentedString(createdAt)).append("\n");
+ sb.append(" defaultPermissionsOptOut: ")
+ .append(toIndentedString(defaultPermissionsOptOut))
+ .append("\n");
sb.append(" modifiedAt: ").append(toIndentedString(modifiedAt)).append("\n");
sb.append(" name: ").append(toIndentedString(name)).append("\n");
sb.append(" receivesPermissionsFrom: ")
diff --git a/src/test/resources/com/datadog/api/client/v2/api/roles.feature b/src/test/resources/com/datadog/api/client/v2/api/roles.feature
index b926c82f443..60dc17e9644 100644
--- a/src/test/resources/com/datadog/api/client/v2/api/roles.feature
+++ b/src/test/resources/com/datadog/api/client/v2/api/roles.feature
@@ -15,7 +15,7 @@ Feature: Roles
And a valid "appKeyAuth" key in the system
And an instance of "Roles" API
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Add a user to a role returns "Bad Request" response
Given new "AddUserToRole" request
And request contains "role_id" parameter from "REPLACE.ME"
@@ -23,7 +23,7 @@ Feature: Roles
When the request is sent
Then the response status is 400 Bad Request
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Add a user to a role returns "Not found" response
Given new "AddUserToRole" request
And request contains "role_id" parameter from "REPLACE.ME"
@@ -31,7 +31,7 @@ Feature: Roles
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Add a user to a role returns "OK" response
Given there is a valid "role" in the system
And there is a valid "user" in the system
@@ -44,7 +44,7 @@ Feature: Roles
And the response "data[0].type" is equal to "{{ user.data.type }}"
And the response "data[0].relationships.roles.data" has item with field "id" with value "{{ role.data.id }}"
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Create a new role by cloning an existing role returns "Bad Request" response
Given there is a valid "role" in the system
And new "CloneRole" request
@@ -53,7 +53,7 @@ Feature: Roles
When the request is sent
Then the response status is 400 Bad Request
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Create a new role by cloning an existing role returns "Conflict" response
Given there is a valid "role" in the system
And new "CloneRole" request
@@ -62,7 +62,7 @@ Feature: Roles
When the request is sent
Then the response status is 409 Conflict
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Create a new role by cloning an existing role returns "Not found" response
Given new "CloneRole" request
And request contains "role_id" parameter from "REPLACE.ME"
@@ -70,7 +70,7 @@ Feature: Roles
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Create a new role by cloning an existing role returns "OK" response
Given there is a valid "role" in the system
And new "CloneRole" request
@@ -80,21 +80,21 @@ Feature: Roles
Then the response status is 200 OK
And the response "data.attributes.name" is equal to "{{ unique }} clone"
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Create role returns "Bad Request" response
Given new "CreateRole" request
And body with value {"data": {"attributes": {"name": "developers", "receives_permissions_from": []}, "relationships": {"permissions": {"data": [{"type": "permissions"}]}}, "type": "roles"}}
When the request is sent
Then the response status is 400 Bad Request
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Create role returns "OK" response
Given new "CreateRole" request
And body with value {"data": {"attributes": {"name": "developers", "receives_permissions_from": []}, "relationships": {"permissions": {"data": [{"type": "permissions"}]}}, "type": "roles"}}
When the request is sent
Then the response status is 200 OK
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Create role with a permission returns "OK" response
Given new "CreateRole" request
And there is a valid "permission" in the system
@@ -105,14 +105,14 @@ Feature: Roles
And the response "data.type" is equal to "roles"
And the response "data.relationships.permissions.data" has item with field "id" with value "{{ permission.id }}"
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Delete role returns "Not found" response
Given new "DeleteRole" request
And request contains "role_id" parameter from "REPLACE.ME"
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Delete role returns "OK" response
Given there is a valid "role" in the system
And new "DeleteRole" request
@@ -120,14 +120,14 @@ Feature: Roles
When the request is sent
Then the response status is 204 OK
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Get a role returns "Not found" response
Given new "GetRole" request
And request contains "role_id" parameter from "REPLACE.ME"
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Get a role returns "OK" response
Given there is a valid "role" in the system
And new "GetRole" request
@@ -137,14 +137,14 @@ Feature: Roles
And the response "data.attributes.name" has the same value as "role.data.attributes.name"
And the response "data.id" has the same value as "role.data.id"
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Get all users of a role returns "Not found" response
Given new "ListRoleUsers" request
And request contains "role_id" parameter from "REPLACE.ME"
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Get all users of a role returns "OK" response
Given there is a valid "role" in the system
And there is a valid "user" in the system
@@ -156,7 +156,7 @@ Feature: Roles
And the response "meta.page.total_count" is equal to 1
And the response "data" has item with field "id" with value "{{ user.data.id }}"
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Grant permission to a role returns "Bad Request" response
Given new "AddPermissionToRole" request
And request contains "role_id" parameter from "REPLACE.ME"
@@ -164,7 +164,7 @@ Feature: Roles
When the request is sent
Then the response status is 400 Bad Request
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Grant permission to a role returns "Not found" response
Given new "AddPermissionToRole" request
And request contains "role_id" parameter from "REPLACE.ME"
@@ -172,7 +172,7 @@ Feature: Roles
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Grant permission to a role returns "OK" response
Given there is a valid "role" in the system
And there is a valid "permission" in the system
@@ -184,14 +184,14 @@ Feature: Roles
And the response "data[0].type" is equal to "{{ permission.type }}"
And the response "data" has item with field "id" with value "{{ permission.id }}"
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: List permissions for a role returns "Not found" response
Given new "ListRolePermissions" request
And request contains "role_id" parameter from "REPLACE.ME"
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: List permissions for a role returns "OK" response
Given there is a valid "role" in the system
And there is a valid "permission" in the system
@@ -227,14 +227,14 @@ Feature: Roles
And the response "data" has item with field "attributes.name" with value "admin"
And the response "data" has item with field "attributes.name_aliases" with value []
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: List role templates returns "OK" response
Given operation "ListRoleTemplates" enabled
And new "ListRoleTemplates" request
When the request is sent
Then the response status is 200 OK
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: List roles returns "OK" response
Given there is a valid "role" in the system
And new "ListRoles" request
@@ -245,7 +245,7 @@ Feature: Roles
And the response "data[0].id" has the same value as "role.data.id"
And the response "data[0].attributes.name" has the same value as "role.data.attributes.name"
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Remove a user from a role returns "Bad Request" response
Given new "RemoveUserFromRole" request
And request contains "role_id" parameter from "REPLACE.ME"
@@ -253,7 +253,7 @@ Feature: Roles
When the request is sent
Then the response status is 400 Bad Request
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Remove a user from a role returns "Not found" response
Given new "RemoveUserFromRole" request
And request contains "role_id" parameter from "REPLACE.ME"
@@ -261,7 +261,7 @@ Feature: Roles
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Remove a user from a role returns "OK" response
Given there is a valid "role" in the system
And there is a valid "user" in the system
@@ -272,7 +272,7 @@ Feature: Roles
When the request is sent
Then the response status is 200 OK
- @skip-validation @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @skip-validation @team:DataDog/access-policies-lifecycle
Scenario: Revoke permission returns "Bad Request" response
Given there is a valid "role" in the system
And new "RemovePermissionFromRole" request
@@ -281,7 +281,7 @@ Feature: Roles
When the request is sent
Then the response status is 400 Bad Request
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Revoke permission returns "Not found" response
Given there is a valid "permission" in the system
And new "RemovePermissionFromRole" request
@@ -290,7 +290,7 @@ Feature: Roles
When the request is sent
Then the response status is 404 Not found
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Revoke permission returns "OK" response
Given there is a valid "role" in the system
And there is a valid "permission" in the system
@@ -302,7 +302,7 @@ Feature: Roles
Then the response status is 200 OK
And the response "data[0].type" is equal to "permissions"
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Update a role returns "Bad Request" response
Given there is a valid "role" in the system
And there is a valid "permission" in the system
@@ -312,7 +312,7 @@ Feature: Roles
When the request is sent
Then the response status is 400 Bad Request
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Update a role returns "Bad Role ID" response
Given there is a valid "role" in the system
And there is a valid "permission" in the system
@@ -322,7 +322,7 @@ Feature: Roles
When the request is sent
Then the response status is 422 Bad Role ID in Request
- @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @team:DataDog/access-policies-lifecycle
Scenario: Update a role returns "Not found" response
Given there is a valid "permission" in the system
And new "UpdateRole" request
@@ -331,7 +331,7 @@ Feature: Roles
When the request is sent
Then the response status is 404 Not found
- @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @skip @team:DataDog/access-policies-lifecycle
Scenario: Update a role returns "OK" response
Given there is a valid "role" in the system
And there is a valid "permission" in the system
@@ -342,7 +342,7 @@ Feature: Roles
Then the response status is 200 OK
And the response "data.attributes.name" is equal to "{{ role.data.attributes.name }}-updated"
- @generated @skip @team:DataDog/aaa-core-access @team:DataDog/access-policies-lifecycle
+ @generated @skip @team:DataDog/access-policies-lifecycle
Scenario: Update a role returns "Unprocessable Entity" response
Given new "UpdateRole" request
And request contains "role_id" parameter from "REPLACE.ME"