4dcb819c06
CIAM-5056
37 lines
1.5 KiB
Text
37 lines
1.5 KiB
Text
[[_permission_create_scope]]
|
|
= Creating scope-based permissions
|
|
|
|
A scope-based permission defines a set of one or more scopes to protect using a set of one or more authorization policies. Unlike resource-based permissions, you can use this permission type to create permissions not only for a resource, but also for the scopes associated with it, providing more granularity when defining the permissions that govern your resources and the actions that can be performed on them.
|
|
|
|
To create a new scope-based permission, select *Create scope-based permission* from the *Create permission* dropdown.
|
|
|
|
.Add Scope Permission
|
|
image:images/permission/create-scope.png[alt="Add Scope Permission"]
|
|
|
|
== Configuration
|
|
|
|
* *Name*
|
|
+
|
|
A human-readable and unique string describing the permission. A best practice is to use names that are closely related to your business and security requirements, so you
|
|
can identify them more easily.
|
|
+
|
|
* *Description*
|
|
+
|
|
A string containing details about this permission.
|
|
+
|
|
* *Resource*
|
|
+
|
|
Restricts the scopes to those associated with the selected resource. If none is selected, all scopes are available.
|
|
+
|
|
* *Scopes*
|
|
+
|
|
Defines a set of one or more scopes to protect.
|
|
|
|
* *Policy*
|
|
+
|
|
Defines a set of one or more policies to associate with a permission. To associate a policy you can either select an existing policy
|
|
or create a new one by selecting the type of the policy you want to create.
|
|
|
|
* *Decision Strategy*
|
|
+
|
|
The <<_permission_decision_strategies, Decision Strategy>> for this permission.
|