Skip to main content

TwinPrincipalPermissionsGet

One principal's permission entry on a twin, as listed by GET /twins/{twinId}/permissions and returned by the mutation endpoints.

This is where the provenance split lives: permissions is what an administrator can edit here, inheritedPermissions is what confers ability on the twin from elsewhere, and effectivePermissions is what this principal can actually do. All three describe this row's principal — a twin's own representation is the one that describes the caller, and it carries the verdict alone.

Index

Properties

effectivePermissions

effectivePermissions: TwinBoundCapabilityName[]

The union of permissions and every inheritedPermissions entry — what this principal can actually do on the twin. Calculated by the service on every read and never accepted on a write. Mixes both capability vocabularies, so it is typed the widened way.

optionaletag

etag?: string

Optimistic concurrency token for this entry, to send back on the next mutation of this principal. Two entries in one listing may carry different values — edit each with the one its own row reported. Absent when the service had none to report.

inheritedPermissions

inheritedPermissions: InheritedPermissions[]

One entry per place outside this twin that confers ability on it. A twin has one possible source: the domain, source: 'twin', carrying whichever of ViewAssets, EditAssets and DeleteAssets this principal holds customer-wide, because twins/{twinId}/assets gates on them. The asset catalog capability and ManageAssetPermissions never appear — they are domain-wide and confer nothing on one twin. Empty when the principal holds none of them.

name

name: string

The principal's display title.

permissions

What this principal holds from grants made on the twin itself, and the only part this surface writes: setTwinPermissions replaces exactly this set.

principalId

principalId: string

Global id of the principal (a group; users are not grantable per ADR-0008 §6).

readOnly

readOnly: boolean

True exactly when a PUT or DELETE naming this principal would be refused with SystemPrincipalImmutable: the twin's own default groups and the seeded Twinfinity system principals. Render the control as disabled rather than discovering the constraint by attempting a write.