UiPath Documentation
uipath-cli
latest
false
UiPath CLI 用户指南
重要 :
请注意,此内容已使用机器翻译进行了本地化。 新发布内容的本地化可能需要 1-2 周的时间才能完成。

uip 管理员授权

“uip adminauthorization”的语法和选项,用于管理授权服务角色、角色分配、权限目录和有效访问权限查找。

uip admin authorization 管理 UiPath 授权服务基元:策略管理点 (PAP) 上的自定义角色定义、权限定义的只读目录以及针对策略决策点的有效访问查找(PDP)。它作为@uipath/authz-commands包提供,这是组合到单个uip admin工具中的七个子包之一 — 有关管理子资源的完整目录,请参阅uip admin 。

备注:

内置产品区域的角色/权限策略 CRUD基于不同的命令 — uip gov access-policy — 该命令针对相同的 authz-sdk Swagger,但归监管工具所有。此页面介绍自定义角色、分配对象以及计算有效访问权限。

该资源跨越一个页面​

下面的每个动词都作为 uip admin authorization <verb> 进行调用 — 此子资源没有单独的同级页面。

概念​

  • 角色形状— 角色的--scope加上可选的--service一起决定了角色的应用位置: Organization (组织范围内)、 TenantGlobal (应用于每个租户的模板)、 Tenant (一个租户)或Project (范围限定于注册项目级权限的服务,例如Document Understanding、Reinfer)。单独的 --service 会从服务注册表中推断作用域 — 组织级别的服务(例如apps)推断 Organization;租户级别服务(例如documentunderstanding)推断 Tenant。结合使用 --scope 和 --service 以覆盖推理。
  • 拥有自己的角色目录的服务( orchestrator 、 dataservice 、 insights 、 taskmining 、 testmanager 、 automationops 、 casemanagement 、 processmining )和平台级别的服务会阻止创作— authz 、 oms 、 platform 、 identity 、 licensingroles create / update / delete和roles assignments create均拒绝此列表中的--service值;列出这些服务的角色/权限/分配仍然有效。
  • 角色创作是 PUT 样式的更新插入— roles create始终新建角色(ID 由服务器生成); roles update <id>使用相同的 ID 重新发送完整的角色正文。不带 update 的 --description 会通过先获取角色来保留当前描述,而不会清除当前描述。
  • 分配作用域组合— roles assignments list / create使用与角色创作相同的推理矩阵从--scope / --service / --scope-id / --tenant-id构建scope路径,并带有一个退出窗口: --scope-path <path>按原义发送确切路径,覆盖每隔两个作用域标志。TenantGlobal不是有效的分配作用域(仅是角色创作作用域),但可以作为Tenant创建时别名。
  • 批处理模式— roles assignments create --file <path>和roles assignments delete --file <path> / <id>接受 JSON 数组进行批量操作,但与内联单个项目标志/参数互斥。底层的批量更新端点是尽最大努力,对未知/已删除的分配 ID 执行静默无操作— delete不会验证 ID 事先是否存在。
  • --login-validity <minutes>适用于此处的每个动词(覆盖该一次调用的交互式登录令牌生存期 — 很少需要)。

大纲​

uip admin authorization roles list [--limit <n>] [--offset <n>] [--filter <fragment>] [--service <service>] [--scope <type>] [--role-type BuiltIn|Custom] [--tenant-id <guid>]
uip admin authorization roles get <id>
uip admin authorization roles create --name <name> --file <path> [--description <text>] [--service <service>] [--scope <type>] [--tenant-id <guid>]
uip admin authorization roles update <id> --name <name> --file <path> [--description <text>] [--service <service>] [--scope <type>] [--tenant-id <guid>]
uip admin authorization roles delete <id>

uip admin authorization roles assignments list [--limit <n>] [--offset <n>] [--service <service>] [--identity-id <id>] [--scope <type>] [--scope-id <id>] [--scope-path <path>] [--tenant-id <guid>] [--include-inherited]
uip admin authorization roles assignments create (--role-id <guid> --identity-id <guid> --identity-type <type> [--service <service>] [--scope <type>] [--scope-id <id>] [--scope-path <path>] [--tenant-id <guid>]) | --file <path>
uip admin authorization roles assignments delete [<id>] | --file <path>

uip admin authorization permissions list [--service <service>] [--scope <type>]

uip admin authorization check-access [<identity>] [--scope Tenant|Folder] [--tenant-id <guid>] [--folder-id <guid>] [--service <service>] | --file <path>
uip admin authorization roles list [--limit <n>] [--offset <n>] [--filter <fragment>] [--service <service>] [--scope <type>] [--role-type BuiltIn|Custom] [--tenant-id <guid>]
uip admin authorization roles get <id>
uip admin authorization roles create --name <name> --file <path> [--description <text>] [--service <service>] [--scope <type>] [--tenant-id <guid>]
uip admin authorization roles update <id> --name <name> --file <path> [--description <text>] [--service <service>] [--scope <type>] [--tenant-id <guid>]
uip admin authorization roles delete <id>

uip admin authorization roles assignments list [--limit <n>] [--offset <n>] [--service <service>] [--identity-id <id>] [--scope <type>] [--scope-id <id>] [--scope-path <path>] [--tenant-id <guid>] [--include-inherited]
uip admin authorization roles assignments create (--role-id <guid> --identity-id <guid> --identity-type <type> [--service <service>] [--scope <type>] [--scope-id <id>] [--scope-path <path>] [--tenant-id <guid>]) | --file <path>
uip admin authorization roles assignments delete [<id>] | --file <path>

uip admin authorization permissions list [--service <service>] [--scope <type>]

uip admin authorization check-access [<identity>] [--scope Tenant|Folder] [--tenant-id <guid>] [--folder-id <guid>] [--service <service>] | --file <path>

uip 管理员授权角色​

管理 PAP 上的自定义角色定义。

uip 管理员授权角色列表​

列出调用者所在组织的角色 — 默认情况下为内置角色和自定义角色。

选项​
长值默认描述
--limit <n>整数20页面大小。
--offset <n>整数0要跳过的记录(从零开始)。
--filter <fragment>字符串—角色名称的子字符串匹配项。
--service <service>字符串—拥有的服务(例如apps、documentunderstanding)。与 --scope 结合使用,或单独从服务注册表中推断作用域。
--scope <type>Organization|TenantGlobal|Tenant|Project|Folder—按角色形状筛选。给定 --service 时为可选。
--role-type <type>BuiltIn|Custom—按角色类型筛选。
--tenant-id <guid>UUID—限制特定租户范围内的角色。查找包含 uip admin tenants list --filter <name> 的 UUID。

列表适用于所有服务,包括无法通过此 CLI 编写角色目录的服务(请参阅概念),仅阻止创作。

示例​
uip admin authorization roles list
uip admin authorization roles list --scope Organization
uip admin authorization roles list --service apps --filter Admin
uip admin authorization roles list
uip admin authorization roles list --scope Organization
uip admin authorization roles list --service apps --filter Admin
数据形状(--输出 json)​
{
  "Code": "AuthzRolesList",
  "Data": {
    "totalCount": 1,
    "results": [
      {
        "id": "11111111-2222-3333-4444-555555555555",
        "name": "Folder Admin",
        "description": "Folder admin role",
        "type": "BuiltIn",
        "scopeType": "Folder",
        "ownerServiceName": "orchestrator",
        "ownerServiceId": "<service-guid>",
        "tenantId": "<tenant-guid>",
        "createdBy": "<user-guid>",
        "createdOn": "<iso-date>",
        "actionDetails": []
      }
    ]
  }
}
{
  "Code": "AuthzRolesList",
  "Data": {
    "totalCount": 1,
    "results": [
      {
        "id": "11111111-2222-3333-4444-555555555555",
        "name": "Folder Admin",
        "description": "Folder admin role",
        "type": "BuiltIn",
        "scopeType": "Folder",
        "ownerServiceName": "orchestrator",
        "ownerServiceId": "<service-guid>",
        "tenantId": "<tenant-guid>",
        "createdBy": "<user-guid>",
        "createdOn": "<iso-date>",
        "actionDetails": []
      }
    ]
  }
}

uip 管理员授权角色获取​

按 ID 获取单个角色。

参数​
名称必填用途
<id>是角色 UUID。从roles list获取。
示例​
uip admin authorization roles get 11111111-2222-3333-4444-555555555555
uip admin authorization roles get 11111111-2222-3333-4444-555555555555
数据形状(--输出 json)​
{
  "Code": "AuthzRoleGet",
  "Data": {
    "id": "11111111-2222-3333-4444-555555555555",
    "name": "Folder Admin",
    "description": "Folder admin role",
    "type": "BuiltIn",
    "scopeType": "Folder",
    "ownerServiceName": "orchestrator",
    "actionDetails": [
      { "id": "<action-guid>", "name": "OR.FOLDERS.READ", "namespace": "ORCHESTRATOR", "resourceAction": "Read" }
    ]
  }
}
{
  "Code": "AuthzRoleGet",
  "Data": {
    "id": "11111111-2222-3333-4444-555555555555",
    "name": "Folder Admin",
    "description": "Folder admin role",
    "type": "BuiltIn",
    "scopeType": "Folder",
    "ownerServiceName": "orchestrator",
    "actionDetails": [
      { "id": "<action-guid>", "name": "OR.FOLDERS.READ", "namespace": "ORCHESTRATOR", "resourceAction": "Read" }
    ]
  }
}

uip 管理员授权角色创建​

创建自定义角色。始终创建 — 角色 ID 由服务器生成;使用 roles update <id> 修改现有角色。

选项​
长值必填描述
--name <name>字符串是角色显示名称。
--file <path>路径是JSON 文件,其中包含字符串数组形式的角色授予操作,例如["STUDIO.X.Y", "STUDIO.A.B"]。
--description <text>字符串否角色描述。
--service <service>字符串否所属服务 — 推断作用域,或与 --scope 结合使用。拒绝创作阻止服务列表。
--scope <type>Organization|TenantGlobal|Tenant|Project否*角色形状。其中至少需要 --scope/--service 之一。
--tenant-id <guid>UUID否Tenant/Project 作用域的租户。不允许与 Organization/TenantGlobal 配合使用。默认为登录租户。
示例​
uip admin authorization roles create --scope Organization --name "Org Reader" \
  --description "Read-only org admin" --file ./actions.json

uip admin authorization roles create --service documentunderstanding --name "DU Tenant Editor" --file ./actions.json

uip admin authorization roles create --scope Project --service documentunderstanding \
  --name "DU Project Editor" --file ./actions.json
uip admin authorization roles create --scope Organization --name "Org Reader" \
  --description "Read-only org admin" --file ./actions.json

uip admin authorization roles create --service documentunderstanding --name "DU Tenant Editor" --file ./actions.json

uip admin authorization roles create --scope Project --service documentunderstanding \
  --name "DU Project Editor" --file ./actions.json
数据形状(--输出 json)​
{ "Code": "AuthzRoleCreated", "Data": { "createdRoleId": "<new-role-guid>" } }
{ "Code": "AuthzRoleCreated", "Data": { "createdRoleId": "<new-role-guid>" } }

uip 管理员授权角色更新​

按 ID 更新现有自定义角色 — 与 create 相同的 PUT 样式更新插入,在正文中发送 ID。

参数​
名称必填用途
<id>是角色 UUID。
选项​

与 create 相同(需要 --name,需要 --file,--description、--service、--scope、--tenant-id)。省略 --description 将保留角色的当前值(首先获取),而不是清除该值。与 create 相同的创作阻止服务列表。

示例​
uip admin authorization roles update 11111111-2222-3333-4444-555555555555 \
  --scope Tenant --name "Tenant Reader" --file ./actions.json
uip admin authorization roles update 11111111-2222-3333-4444-555555555555 \
  --scope Tenant --name "Tenant Reader" --file ./actions.json
数据形状(--输出 json)​
{ "Code": "AuthzRoleUpdated", "Data": { "createdRoleId": "11111111-2222-3333-4444-555555555555" } }
{ "Code": "AuthzRoleUpdated", "Data": { "createdRoleId": "11111111-2222-3333-4444-555555555555" } }

uip 管理员授权角色删除​

按 ID 删除自定义角色。无法删除内置角色、主机组织角色以及阻止创作的服务拥有的角色(请参阅概念)。CLI 会预取角色并拒绝。

参数​
名称必填用途
<id>是角色 UUID。
示例​
uip admin authorization roles delete 11111111-2222-3333-4444-555555555555
uip admin authorization roles delete 11111111-2222-3333-4444-555555555555
数据形状(--输出 json)​
{ "Code": "AuthzRoleDeleted", "Data": {} }
{ "Code": "AuthzRoleDeleted", "Data": {} }

uip 管理员授权角色分配​

管理人员拥有角色(嵌套在 roles 下)。

uip 管理员授权角色分配列表​

列出角色分配,按身份分组。未提供作用域标志时,默认为登录租户,并且仅默认为直接(非继承)分配。

选项​
长值默认描述
--limit <n>整数10页面大小(服务器上限为 10 个分配组)。
--offset <n>整数0要跳过的记录。
--service <service>字符串—拥有服务。与 --scope 结合使用,或单独设置服务注册表中的作用域。
--identity-id <id>UUID—限制为一个身份(用户/组/外部应用程序)。
--scope <type>Organization|Tenant|Project|Folder|App登录租户TenantGlobal 在此处无效。Project/Folder/App 需要 --service 和 --scope-id。
--scope-id <id>字符串—项目 ID/文件夹名称或 ID/应用程序 ID,与 --service 配对,用于 Project/Folder/App 作用域。
--scope-path <path>字符串—高级:逐字发送的确切作用域路径,覆盖 --scope/--service/--scope-id/--tenant-id。
--tenant-id <guid>UUID登录租户Tenant/Project/Folder/App 作用域的租户。
--include-inherited标记关闭包括从父作用域继承的分配,而不仅仅是直接分配。

列表适用于所有服务,包括无法通过此 CLI 创作分配的服务 — 仅阻止创作。

示例​
uip admin authorization roles assignments list
uip admin authorization roles assignments list --scope Folder --service orchestrator --scope-id Insights
uip admin authorization roles assignments list --scope-path /tenant/11111111-2222-3333-4444-555555555555/reinfer
uip admin authorization roles assignments list
uip admin authorization roles assignments list --scope Folder --service orchestrator --scope-id Insights
uip admin authorization roles assignments list --scope-path /tenant/11111111-2222-3333-4444-555555555555/reinfer
数据形状(--输出 json)​
{
  "Code": "AuthzAssignmentsList",
  "Data": {
    "totalCount": 1,
    "results": [
      {
        "securityPrincipalId": "<user-guid>",
        "displayName": "Jane Doe",
        "email": "jane.doe@acme.example",
        "type": "User",
        "roleAssignmentDtos": [
          {
            "id": "<assignment-guid>",
            "type": "Direct",
            "scope": "/tenant/<tenant-guid>",
            "roleId": "<role-guid>",
            "roleName": "Tenant Administrator",
            "inherited": false,
            "mutable": true
          }
        ]
      }
    ]
  }
}
{
  "Code": "AuthzAssignmentsList",
  "Data": {
    "totalCount": 1,
    "results": [
      {
        "securityPrincipalId": "<user-guid>",
        "displayName": "Jane Doe",
        "email": "jane.doe@acme.example",
        "type": "User",
        "roleAssignmentDtos": [
          {
            "id": "<assignment-guid>",
            "type": "Direct",
            "scope": "/tenant/<tenant-guid>",
            "roleId": "<role-guid>",
            "roleName": "Tenant Administrator",
            "inherited": false,
            "mutable": true
          }
        ]
      }
    ]
  }
}

uip 管理员授权角色分配创建​

创建一个角色分配(内联)或多个角色分配(通过 --file 进行批量)——这两种模式是互斥的。

选项 — 内联模式​
长值必填描述
--role-id <guid>UUID是(内联)要分配的角色。
--identity-id <guid>UUID是(内联)要向其分配角色的安全主体。
--identity-type <type>User|Group|Robot|ExternalApplication是(内联)主体类型。
--service <service>字符串否与 assignments list 相同的作用域组合语义。拒绝创作阻止服务列表。
--scope <type>Organization|TenantGlobal|Tenant|Project|Folder|App否TenantGlobal 此处接受作为 Tenant 的别名。
--scope-id <id>字符串否与 --service 配对,适用于 Project/Folder/App。
--scope-path <path>字符串否高级:原义路径,覆盖其他作用域标志。
--tenant-id <guid>UUID否默认为登录租户。
选项 — 批处理模式​
长值必填描述
--file <path>路径是(批处理)AddRoleAssignmentRequest 对象的 JSON 数组,每个对象都有自己的 scope:{roleId, securityPrincipalId, securityPrincipalType, scope?, tenantId?}。以自动化方式发送。

将 --file 与任何内联标志一起传递均为错误;两者均未通过也不是错误。

示例​
uip admin authorization roles assignments create \
  --role-id 98dc776b-835c-407f-9d58-6676318ac968 \
  --identity-id b44fc962-d544-4c99-b520-71121070ec17 --identity-type User

uip admin authorization roles assignments create --file ./assignments.json
uip admin authorization roles assignments create \
  --role-id 98dc776b-835c-407f-9d58-6676318ac968 \
  --identity-id b44fc962-d544-4c99-b520-71121070ec17 --identity-type User

uip admin authorization roles assignments create --file ./assignments.json
数据形状(--输出 json)​
{ "Code": "AuthzAssignmentCreated", "Data": {} }
{ "Code": "AuthzAssignmentCreated", "Data": {} }

uip 管理员授权角色分配删除​

删除一个分配(位置 ID)或多个(通过 --file 批量删除)— 互斥。

参数​
名称必填用途
[id]有条件地单个分配 UUID。与 --file 互斥。
选项​
长值描述
--file <path>路径分配 ID 字符串的 JSON 数组,例如["0fae98e1-...", "1aab33cf-..."]。以自动化方式发送。
备注:

批量更新端点以静默方式对未知或已删除的 ID 空任何操作,仍报告“成功”— 此命令不会验证 ID 事先是否存在。如果需要确认是否发生删除,请列出之前/之后。

示例​
uip admin authorization roles assignments delete 0fae98e1-0f2e-4f8d-bdab-7ce1cf475676
uip admin authorization roles assignments delete --file ./assignment-ids.json
uip admin authorization roles assignments delete 0fae98e1-0f2e-4f8d-bdab-7ce1cf475676
uip admin authorization roles assignments delete --file ./assignment-ids.json
数据形状(--输出 json)​
{ "Code": "AuthzAssignmentDeleted", "Data": {} }
{ "Code": "AuthzAssignmentDeleted", "Data": {} }

uip 管理员授权权限​

跨服务权限定义的只读目录。

uip 管理员授权权限列表​

选项​
长值描述
--service <service>字符串拥有服务。与 --scope 结合使用,或单独从服务注册表中推断作用域。
--scope <type>Organization|TenantGlobal|Tenant|Project筛选可用于此形状角色的权限。镜像 roles create --scope。
示例​
uip admin authorization permissions list
uip admin authorization permissions list --scope Project --service documentunderstanding
uip admin authorization permissions list
uip admin authorization permissions list --scope Project --service documentunderstanding
数据形状(--输出 json)​
{
  "Code": "AuthzPermissionsList",
  "Data": [
    {
      "id": "<action-guid>",
      "name": "OR.FOLDERS.READ",
      "namespace": "ORCHESTRATOR",
      "serviceDisplayName": "Orchestrator",
      "resourceType": "Folders",
      "resourceAction": "Read",
      "resourceGroup": "Folder",
      "description": "View folders",
      "scopeType": "Folder"
    }
  ]
}
{
  "Code": "AuthzPermissionsList",
  "Data": [
    {
      "id": "<action-guid>",
      "name": "OR.FOLDERS.READ",
      "namespace": "ORCHESTRATOR",
      "serviceDisplayName": "Orchestrator",
      "resourceType": "Folders",
      "resourceAction": "Read",
      "resourceGroup": "Folder",
      "description": "View folders",
      "scopeType": "Folder"
    }
  ]
}

uip admin 授权检查-访问​

通过策略决策点计算安全主体在租户或文件夹作用域内的有效权限。

参数​

名称必填用途
[identity]有条件地用户 UUID 或通过身份搜索解析的名称/电子邮件的子字符串。除非使用 --file,否则为必填项。

选项​

长值默认描述
--scope <type>Tenant|FolderTenant评估作用域。
--tenant-id <guid>UUID登录租户对于 Tenant 作用域,同时用作作用域 ID 和父 ID;对于 Folder 作用域,为父文件夹 ID。
--folder-id <guid>UUID—需要适用于--scope Folder 。用作作用域 ID。
--service <service>字符串—将结果限制为一项服务。
--file <path>路径—完整的请求正文(高级 — 例如 RoleNameStartsWith 筛选器)。与“位置”标志和“每个作用域”标志互斥。

通过用户搜索子字符串匹配来解析非 GUID <identity>:0 次匹配失败,并显示发现提示,使用 1 次匹配,在失败并显示候选列表之前,超过 1 次尝试精确的电子邮件/用户名匹配。

示例​

uip admin authorization check-access alice@example.com
uip admin authorization check-access <user-guid> --scope Folder --folder-id <folder-guid>
uip admin authorization check-access --file ./check-access.json
uip admin authorization check-access alice@example.com
uip admin authorization check-access <user-guid> --scope Folder --folder-id <folder-guid>
uip admin authorization check-access --file ./check-access.json

数据形状(--输出 json)​

{
  "Code": "AuthzCheckAccess",
  "Data": {
    "roleAssignments": { "totalCount": 0, "results": [] },
    "grantedServicesMetadata": [],
    "grantedRolesMetadata": []
  }
}
{
  "Code": "AuthzCheckAccess",
  "Data": {
    "roleAssignments": { "totalCount": 0, "results": [] },
    "grantedServicesMetadata": [],
    "grantedRolesMetadata": []
  }
}
  • uip admin — 完整的uip admin子资源目录。
  • uip gov access-policy — 适用于内置产品区域的策略 CRUD,与 authz-sdk Swagger 相同。

另请参阅​

此页面有帮助吗?

连接

需要帮助? 支持

想要了解详细内容? UiPath Academy

有问题? UiPath 论坛

保持更新