UIP 或角色
“uip 或角色”的语法和选项,用于管理 Orchestrator RBAC 角色、权限和文件夹级别分配。
uip or roles 管理 Orchestrator 角色和权限 (RBAC)。角色捆绑权限并在租户(全局)或文件夹(作用域)级别分配给用户、组、机器人、计算机或外部应用程序。此页面上的动词涵盖角色及其权限、角色-用户成员身份、主体级别角色/权限检查以及文件夹级别分配。有关每个用户的租户级别角色分配,请参阅users assign-roles中的uip or users 。
大纲
uip or roles permissions list [options]
uip or roles list [options]
uip or roles get <role-key>
uip or roles create --name <name> --type <Tenant|Folder>
uip or roles update <role-key> [--add-permissions <names>] [--remove-permissions <names>]
uip or roles delete <role-key> -y
uip or roles users list <role-key> [options]
uip or roles users set <role-key> [--add-user-keys <keys>] [--remove-user-keys <keys>]
uip or roles user-roles list <principal-name> [--type <type>] [options]
uip or roles user-permissions list <username> [--folder-path <path> | --folder-key <key>]
uip or roles assign --user-key <key> --role-keys <keys> [--folder-path <path> | --folder-key <key>]
uip or roles permissions list [options]
uip or roles list [options]
uip or roles get <role-key>
uip or roles create --name <name> --type <Tenant|Folder>
uip or roles update <role-key> [--add-permissions <names>] [--remove-permissions <names>]
uip or roles delete <role-key> -y
uip or roles users list <role-key> [options]
uip or roles users set <role-key> [--add-user-keys <keys>] [--remove-user-keys <keys>]
uip or roles user-roles list <principal-name> [--type <type>] [options]
uip or roles user-permissions list <username> [--folder-path <path> | --folder-key <key>]
uip or roles assign --user-key <key> --role-keys <keys> [--folder-path <path> | --folder-key <key>]
动词
| 动词 | 用途 |
|---|---|
permissions list | 列出可授予的权限名称。 |
list | 列出租户中的角色。 |
get | 获取一个角色及其授予的权限。 |
create | 在Tenant或Folder作用域中创建没有权限的角色。 |
update (别名 edit) | 添加或删除角色的权限。 |
delete | 删除用户创建的角色。 |
users list | 列出分配到角色的用户。 |
users set | 添加或删除角色中的用户(批量)。 |
user-roles list | 列出主体(用户、组、机器人、计算机或外部应用程序)在租户和每个文件夹中的完整角色分配。 |
user-permissions list | 列出用户的有效权限(租户范围内或仅限于一个文件夹)。 |
assign | 将文件夹级别角色分配给特定文件夹中的用户。 |
UIP 或角色权限列表
列出每个可授予的权限名称。将这些名称与roles update --add-permissions一起使用。
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
-l | --limit | 数字 | 50 | 页面大小。 |
| — | --offset | 数字 | 0 | 跳过计数。 |
| — | --sort-by | 字段 | Name asc | OData 排序。 |
示例
uip or roles permissions list --limit 200
uip or roles permissions list --output-filter 'Data[].Name'
uip or roles permissions list --output table
uip or roles permissions list --limit 200
uip or roles permissions list --output-filter 'Data[].Name'
uip or roles permissions list --output table
数据形状(--输出 json)
{
"Code": "PermissionList",
"Data": [{ "Name": "Assets.Create" }, { "Name": "Assets.Delete" }]
}
{
"Code": "PermissionList",
"Data": [{ "Name": "Assets.Create" }, { "Name": "Assets.Delete" }]
}
UIP 或角色列表
列出角色。返回密钥 (GUID)、ID、名称、显示名称、类型以及角色是否可编辑。使用带有 roles get、roles update 或 roles users set 的角色密钥。
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
-l | --limit | 数字 | 50 | 页面大小。 |
| — | --offset | 数字 | 0 | 跳过计数。 |
| — | --sort-by | 字段 | Id desc | OData 排序。 |
示例
uip or roles list --limit 50
uip or roles list --output-filter "Data[?Type=='Tenant'].Name"
uip or roles list --output table
uip or roles list --limit 50
uip or roles list --output-filter "Data[?Type=='Tenant'].Name"
uip or roles list --output table
数据形状(--输出 json)
{
"Code": "RoleList",
"Data": [
{
"Key": "a1b2c3d4-0000-0000-0000-000000000001",
"ID": 1,
"Name": "Administrator",
"DisplayName": "Administrator",
"Type": "Tenant",
"IsEditable": false
}
]
}
{
"Code": "RoleList",
"Data": [
{
"Key": "a1b2c3d4-0000-0000-0000-000000000001",
"ID": 1,
"Name": "Administrator",
"DisplayName": "Administrator",
"Type": "Tenant",
"IsEditable": false
}
]
}
UIP 或角色 Get
获取及其授予权限的角色。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<role-key> | 是 | 角色密钥 (GUID)。使用 roles list 进行查找。 |
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|
示例
uip or roles get a1b2c3d4-0000-0000-0000-000000000001
uip or roles get a1b2c3d4-0000-0000-0000-000000000001 \
--output-filter 'Data.Permissions'
uip or roles get a1b2c3d4-0000-0000-0000-000000000001 --output table
uip or roles get a1b2c3d4-0000-0000-0000-000000000001
uip or roles get a1b2c3d4-0000-0000-0000-000000000001 \
--output-filter 'Data.Permissions'
uip or roles get a1b2c3d4-0000-0000-0000-000000000001 --output table
数据形状(--输出 json)
{
"Code": "Role",
"Data": {
"Key": "a1b2c3d4-0000-0000-0000-000000000001",
"ID": 1,
"Name": "Administrator",
"DisplayName": "Administrator",
"Type": "Tenant",
"IsStatic": true,
"IsEditable": false,
"Permissions": "Assets.View, Assets.Create, Jobs.View"
}
}
{
"Code": "Role",
"Data": {
"Key": "a1b2c3d4-0000-0000-0000-000000000001",
"ID": 1,
"Name": "Administrator",
"DisplayName": "Administrator",
"Type": "Tenant",
"IsStatic": true,
"IsEditable": false,
"Permissions": "Assets.View, Assets.Create, Jobs.View"
}
}
UIP 或角色创建
创建没有权限的角色。创建后,使用roles update --add-permissions授予权限。
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
| — | --name | text | 必填 | 角色名称。 |
| — | --type | Tenant | Folder | 必填 | Tenant 适用于整个租户; Folder 适用于文件夹。 |
示例
uip or roles create --name "Read Only" --type Tenant
uip or roles create --name "Folder Viewer" --type Folder
uip or roles create --name "Read Only" --type Tenant \
--output-filter 'Data.Key'
uip or roles create --name "Read Only" --type Tenant
uip or roles create --name "Folder Viewer" --type Folder
uip or roles create --name "Read Only" --type Tenant \
--output-filter 'Data.Key'
数据形状(--输出 json)
{
"Code": "RoleCreated",
"Data": {
"Key": "a1b2c3d4-0000-0000-0000-000000000010",
"ID": 10,
"Name": "Read Only",
"Type": "Tenant",
"Status": "Created successfully"
}
}
{
"Code": "RoleCreated",
"Data": {
"Key": "a1b2c3d4-0000-0000-0000-000000000010",
"ID": 10,
"Name": "Read Only",
"Type": "Tenant",
"Status": "Created successfully"
}
}
UIP 或角色更新
添加或删除角色的权限。读取当前权限,在--add-permissions --remove-permissions名称的isGranted ,然后保存。在租户的完整权限目录中查找并添加新名称(尚未在角色上)。
edit 是此动词的已注册别名,uip or roles edit 的作用与 uip or roles update 相同。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<role-key> | 是 | 角色密钥 (GUID)。 |
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
| — | --add-permissions | CSV 名称 | — | 要授予的权限。 |
| — | --remove-permissions | CSV 名称 | — | 要撤销的权限。 |
至少需要--add-permissions或--remove-permissions 。
示例
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--add-permissions Assets.View,Jobs.View
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--remove-permissions Jobs.Edit
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--add-permissions Assets.View --output-filter 'Data.Status'
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--add-permissions Assets.View,Jobs.View
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--remove-permissions Jobs.Edit
uip or roles update a1b2c3d4-0000-0000-0000-000000000010 \
--add-permissions Assets.View --output-filter 'Data.Status'
数据形状(--输出 json)
{
"Code": "RoleUpdated",
"Data": { "Key": "a1b2c3d4-0000-0000-0000-000000000010", "Status": "Updated successfully" }
}
{
"Code": "RoleUpdated",
"Data": { "Key": "a1b2c3d4-0000-0000-0000-000000000010", "Status": "Updated successfully" }
}
UIP 或角色删除
删除用户创建的角色。无法删除内置角色 (其中IsStatic=true )。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<role-key> | 是 | 角色密钥 (GUID)。 |
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
-y | --yes | 标记 | — | 必需。确认此不可撤销的操作 — CLI 从不提示。 |
示例
uip or roles delete a1b2c3d4-0000-0000-0000-000000000010 --yes
uip or roles delete a1b2c3d4-0000-0000-0000-000000000010 --yes \
--output-filter 'Data.Status'
uip or roles delete a1b2c3d4-0000-0000-0000-000000000010 --yes
uip or roles delete a1b2c3d4-0000-0000-0000-000000000010 --yes \
--output-filter 'Data.Status'
数据形状(--输出 json)
{
"Code": "RoleDeleted",
"Data": { "Key": "a1b2c3d4-0000-0000-0000-000000000010", "Status": "Deleted successfully" }
}
{
"Code": "RoleDeleted",
"Data": { "Key": "a1b2c3d4-0000-0000-0000-000000000010", "Status": "Deleted successfully" }
}
UIP 或角色用户列表
列出分配到角色的用户。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<role-key> | 是 | 角色密钥 (GUID)。 |
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
-l | --limit | 数字 | 50 | 页面大小。 |
| — | --offset | 数字 | 0 | 跳过计数。 |
示例
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001 --limit 200
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001 \
--output-filter 'Data[].UserName'
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001 --limit 200
uip or roles users list a1b2c3d4-0000-0000-0000-000000000001 \
--output-filter 'Data[].UserName'
数据形状(--输出 json)
{
"Code": "RoleUserList",
"Data": [
{
"Key": "d4e5f6a7-0000-0000-0000-000000000001",
"ID": 101,
"UserName": "admin@example.com",
"FullName": "Admin User",
"Type": "User"
}
]
}
{
"Code": "RoleUserList",
"Data": [
{
"Key": "d4e5f6a7-0000-0000-0000-000000000001",
"ID": 101,
"UserName": "admin@example.com",
"FullName": "Admin User",
"Type": "User"
}
]
}
UIP 或用户设置的角色
添加或删除角色中的用户(批量)。提供 --add-user-keys和/或 --remove-user-keys。请至少提供一个。仅加法/减法 — 未在任一标志中命名的现有成员身份保持不变(与 users assign-roles 不同, 会替换完整列表)。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<role-key> | 是 | 角色密钥 (GUID)。 |
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
| — | --add-user-keys | CSV 格式的 GUID | — | 要添加的用户。 |
| — | --remove-user-keys | CSV 格式的 GUID | — | 要删除的用户。 |
示例
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-0000-0000-0000-000000000001
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-…-001,d4e5f6a7-…-002 \
--remove-user-keys d4e5f6a7-…-099
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-…-001 --output-filter 'Data.Added'
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-0000-0000-0000-000000000001
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-…-001,d4e5f6a7-…-002 \
--remove-user-keys d4e5f6a7-…-099
uip or roles users set a1b2c3d4-0000-0000-0000-000000000010 \
--add-user-keys d4e5f6a7-…-001 --output-filter 'Data.Added'
数据形状(--输出 json)
{
"Code": "RoleUsersUpdated",
"Data": {
"RoleKey": "a1b2c3d4-0000-0000-0000-000000000010",
"Added": 1,
"Removed": 0,
"Status": "Updated successfully"
}
}
{
"Code": "RoleUsersUpdated",
"Data": {
"RoleKey": "a1b2c3d4-0000-0000-0000-000000000010",
"Added": 1,
"Removed": 0,
"Status": "Updated successfully"
}
}
UIP 或角色用户角色列表
列出主体(用户、目录组、目录机器人、计算机或外部应用程序)在租户和每个文件夹中的所有角色分配。用于审核主体的完整访问配置文件。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<principal-name> | 是 | 要查找的用户名、组名称、机器人名称、计算机名称或外部应用程序名称。 |
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
| — | --type | User | Group | Robot | Machine | ExternalApplication | User | 主体类型。DirectoryUser/DirectoryGroup/DirectoryRobot/DirectoryExternalApplication 拼写也接受为别名。 |
-l | --limit | 数字 | 50 | 页面大小。 |
| — | --offset | 数字 | 0 | 跳过计数。 |
示例
uip or roles user-roles list admin@example.com
uip or roles user-roles list "MRS Developers" --type Group
uip or roles user-roles list admin@example.com \
--output-filter "Data[?Scope=='Folder']"
uip or roles user-roles list admin@example.com
uip or roles user-roles list "MRS Developers" --type Group
uip or roles user-roles list admin@example.com \
--output-filter "Data[?Scope=='Folder']"
数据形状(--输出 json)
{
"Code": "UserRoleList",
"Data": [
{ "Scope": "Tenant", "FolderPath": "", "Role": "Administrator" },
{ "Scope": "Folder", "FolderPath": "Shared", "Role": "Folder Administrator" }
]
}
{
"Code": "UserRoleList",
"Data": [
{ "Scope": "Tenant", "FolderPath": "", "Role": "Administrator" },
{ "Scope": "Folder", "FolderPath": "Shared", "Role": "Folder Administrator" }
]
}
UIP 或角色用户权限列表
列出用户的有效权限。没有文件夹选项时,显示租户级别的角色和权限;为 --folder-path/--folder-key,改为显示在该特定文件夹中授予的角色和权限。返回所有匹配角色授予的权限的重复数据删除并集。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<username> | 是 | 要查找的用户名。 |
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
| — | --folder-path | 路径 | — | 显示此文件夹的文件夹级权限,而非租户级权限。 |
| — | --folder-key | GUID | — | --folder-path 的文件夹替代选项。 |
示例
uip or roles user-permissions list admin@example.com
uip or roles user-permissions list admin@example.com --folder-path "Shared"
uip or roles user-permissions list admin@example.com
uip or roles user-permissions list admin@example.com --folder-path "Shared"
数据形状(--输出 json)
租户级别:
{
"Code": "UserPermissionList",
"Data": {
"Roles": ["Administrator"],
"Permissions": ["Jobs.View", "Assets.Create"]
}
}
{
"Code": "UserPermissionList",
"Data": {
"Roles": ["Administrator"],
"Permissions": ["Jobs.View", "Assets.Create"]
}
}
文件夹范围:
{
"Code": "UserPermissionList",
"Data": {
"FolderPath": "Shared",
"Roles": ["Folder User"],
"Permissions": ["Jobs.View", "Assets.View"]
}
}
{
"Code": "UserPermissionList",
"Data": {
"FolderPath": "Shared",
"Roles": ["Folder User"],
"Permissions": ["Jobs.View", "Assets.View"]
}
}
UIP 或角色分配
将文件夹级别角色分配给用户。仅使用文件夹类型的角色。需要--folder-path或--folder-key 。
注意 — 对角色具有破坏性。服务器使用通过--role-keys传递的密钥替换目标文件夹的用户的整个文件夹级别角色列表。不在有效负载中的角色将被静默删除。要保留现有文件夹角色,请先使用 roles user-roles list <principal-name> --type <type> 读取这些角色,并将所需的完整并集传递给 --role-keys。对于角色的附加租户级别角色成员身份,请改用 roles users set。
选项
| 短 | 长 | 值 | 默认 | 描述 |
|---|---|---|---|---|
| — | --user-key | GUID | 必填 | 用户密钥。 |
| — | --role-keys | CSV 格式的 GUID | 必填 | 要在文件夹中分配的角色 GUID。 |
| — | --folder-path | 路径 | — | 目标文件夹。提供此项或--folder-key 。 |
| — | --folder-key | GUID | — | 目标文件夹。 |
示例
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-0000-0000-0000-000000000002 \
--folder-path "Shared"
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-…-002,a1b2c3d4-…-003 \
--folder-key b1c2d3e4-0000-0000-0000-000000000001
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-0000-0000-0000-000000000002 \
--folder-path "Shared" --output-filter 'Data.Status'
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-0000-0000-0000-000000000002 \
--folder-path "Shared"
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-…-002,a1b2c3d4-…-003 \
--folder-key b1c2d3e4-0000-0000-0000-000000000001
uip or roles assign --user-key d4e5f6a7-0000-0000-0000-000000000001 \
--role-keys a1b2c3d4-0000-0000-0000-000000000002 \
--folder-path "Shared" --output-filter 'Data.Status'
数据形状(--输出 json)
{
"Code": "PermissionsAssigned",
"Data": {
"UserKey": "d4e5f6a7-0000-0000-0000-000000000001",
"FolderPath": "Shared",
"Status": "Assigned successfully"
}
}
{
"Code": "PermissionsAssigned",
"Data": {
"UserKey": "d4e5f6a7-0000-0000-0000-000000000001",
"FolderPath": "Shared",
"Status": "Assigned successfully"
}
}
退出代码
请参阅退出代码。没有动词特定的覆盖。
相关命令
uip or users— 查找用户密钥;用于租户级别角色分配的users assign-roles。uip or folders— 查找roles assign文件夹密钥
另请参阅
- 大纲
- 动词
- UIP 或角色权限列表
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色列表
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色 Get
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色创建
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色更新
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色删除
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色用户列表
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或用户设置的角色
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色用户角色列表
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色用户权限列表
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 或角色分配
- 选项
- 示例
- 数据形状(--输出 json)
- 退出代码
- 相关命令
- 另请参阅