objectio.k8s.api.authorization.v1.SubjectAccessReviewSpec
SubjectAccessReviewSpec is a description of the access request. Exactly one of resourceAttributes and nonResourceAttributes must be set
- Source
specs/apis__authorization.k8s.io__v1_openapi.json- Revision
9a79c3bd90f7- Active snapshot
2a9112600697
extra corresponds to the user.Info.GetExtra() method from the authenticator. Since that is input to the authorizer it needs a reflection here.
groups is the groups you're testing for.
nonResourceAttributes describes information for a non-resource access request
resourceAttributes describes information for a resource access request
uid information about the requesting user.
user is the user you're testing for. If you specify "User" but not "Groups", then is it interpreted as "What if User were not a member of any groups