CodamAIDocs
Topicdone

How role names are built

The API path /audit/question becomes audit-question, and that becomes audit-question-read. The rule shown with examples.

Variants
base roleaction rolefield rolemodel without a foldernested folders, spaces, CamelCasecustom name from the model file

What this is about

You do not assign role names by hand. The generator builds them during the build from the model’s API path. You know the path from the URL: model question in folder audit lives under /api/rest/audit/question/….

The transformation

  1. 1
    Hub
    model Question in folder audit
  2. 2
    Generator
    builds the API path: folder and model name in lower case → /audit/question
  3. 3
    Generator
    removes the slashes at the start and end, replaces the others with - → audit-question
    This is the base role. It applies to every operation that is not marked in the hub.
  4. 4
    Generator
    READ is marked in the hub → appends -read: audit-question-read
  5. 5
    Generator
    writes all roles into the model's metadata and into the role catalog
    Result: After the build the names are fixed. At runtime CDMS does not compute anything anymore.

The rules

RuleExample
Folder and model name are lower-casedAudit/Question → audit-question
Every folder becomes a part of the name, from outer to inneraudit/checklisten/question → audit-checklisten-question
Spaces in folder names become -folder Meine Daten → meine-daten-…
CamelCase is not splitSponsorInvoice → sponsorinvoice
Model without a folder: only the model nameMachine → machine
The level (system, tenant, user) does not mattera user model note in folder crm → crm-note
Action role: append the operation in lower case-create, -read, -update, -delete

A subtype of an abstract model gets its roles from its own folder and name. It does not inherit roles from the abstract model.

Examples

Which roles the generator builds
FolderModelmarked in the hubRoles
auditQuestionREADread and search: audit-question-read, everything else: audit-question
–MachineCREATE, READ, UPDATE, DELETEmachine-create, machine-read, machine-update, machine-delete; download, history, rollback: machine
–Gaugenothinggauge for every operation
tenant/accountingSponsorInvoicenothingtenant-accounting-sponsorinvoice

Field roles

A field role belongs to a field, not to a model: to a relation or to a simple field. Its name has three parts:

  1. 1
    Hub
    model Company (without a folder) with the relation employees, field role marked for READ
  2. 2
    Generator
    takes the base role of the model that has the field → company
  3. 3
    Generator
    appends the field name in lower case → company-employees
  4. 4
    Generator
    appends the operation → company-employees-read
    Result: A field role always ends with an operation. There is no "base field role" without an operation.

If a model inherits the field from an abstract model, the field role carries the name of the abstract model, because that is where the field is defined. What a field role allows is described in Permissions on relations (field roles) and Protected values.

Custom names

In a model file (YAML), an endpoint can carry its own role name with roleRequired: <name>. This name applies unchanged and takes precedence over every rule above. The hub does not have this setting. See Model roles.

Pitfalls

Where to go next

Sources in the code and the knowledge base
  • CDMS/cdms-generator – CdmsModelContext (deriveRole, roleFor), CdmsYamlLoader (modelFullPath, normalizeFolderSegment, deriveApiPath, roleActionOf, roleBaseOf, field roles)
  • CDMS/cdms-generator – ModelRoleRestrictionTest
  • CDMS/cdms-generator – RoleRegistryProcessor (role catalog)
  • CDMS/cdms-integrationtest/structure/models.yaml
Search