Interface PolicyProps
- All Superinterfaces:
software.amazon.jsii.JsiiSerializable
- All Known Implementing Classes:
PolicyProps.Jsii$Proxy
Example:
PolicyEngine policyEngine;
Policy advancedPolicy = Policy.Builder.create(this, "AdvancedPolicy")
.policyEngine(policyEngine)
.statement(PolicyStatement.fromCedar("permit(principal, action, resource) when { context.custom > 10 };"))
.description("Advanced policy with custom Cedar logic")
.build();
policyEngine.addPolicy("CustomPolicy", AddPolicyOptions.builder()
.statement(PolicyStatement.fromCedar("forbid(principal, action, resource) when { resource.confidential == true };"))
.description("Custom policy from Cedar string")
.build());
-
Nested Class Summary
Nested ClassesModifier and TypeInterfaceDescriptionstatic final classA builder forPolicyPropsstatic final classAn implementation forPolicyProps -
Method Summary
Modifier and TypeMethodDescriptionstatic PolicyProps.Builderbuilder()default StringOptional description for the policy.The policy engine this policy belongs to.default StringThe name of the policy.The Cedar policy statement for this policy.default PolicyValidationModeValidation mode for the policy.Methods inherited from interface software.amazon.jsii.JsiiSerializable
$jsii$toJson
-
Method Details
-
getPolicyEngine
The policy engine this policy belongs to.[disable-awslint:prefer-ref-interface]
-
getStatement
The Cedar policy statement for this policy.Build a type-safe statement with the
PolicyStatementfactories, which validate at synthesis time and reject values that cannot be represented safely in Cedar.For raw Cedar (features this API does not model, or migrating an existing policy), use
PolicyStatement.fromCedar('...'). That string is used exactly as given: the module does not escape, quote, or validate it, so it is treated as trusted input and you own its correctness and safety. Do not assemble it from values that come from outside your application, such as a request body or a database record. -
getDescription
Optional description for the policy.Maximum length of 4096.
Default: - No description
-
getPolicyName
The name of the policy.Valid characters: a-z, A-Z, 0-9, _ (underscore) Must start with a letter, 1-48 characters Pattern: ^[A-Za-z][A-Za-z0-9_]*$
Default: - Auto-generated unique name
-
getValidationMode
Validation mode for the policy.Controls how Cedar analyzer validation findings are handled.
Default: PolicyValidationMode.FAIL_ON_ANY_FINDINGS
-
builder
- Returns:
- a
PolicyProps.BuilderofPolicyProps
-