preauthenticated_requests
Creates, updates, deletes, gets or lists a preauthenticated_requests resource.
Overview​
| Name | preauthenticated_requests |
| Type | Resource |
| Id | oci.object_storage.preauthenticated_requests |
Fields​
The following fields are returned by SELECT queries:
- get
- list
Fetches the metadata for the specified pre-authenticated request.
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier to use when directly addressing the pre-authenticated request. |
name | string | The user-provided name of the pre-authenticated request. |
accessType | string | The operation that can be performed on this resource. (ObjectRead, ObjectWrite, ObjectReadWrite, AnyObjectWrite, AnyObjectRead, AnyObjectReadWrite) |
bucketListingAction | string | Specifies whether a list operation is allowed on a PAR with accessType "AnyObjectRead" or "AnyObjectReadWrite". Deny: Prevents the user from performing a list operation. ListObjects: Authorizes the user to perform a list operation. (x-obmcs-enumref: #/definitions/PreauthenticatedRequest/bucketListingAction) |
objectName | string | The name of object that is being granted access to by the pre-authenticated request. This can be null and if it is, the pre-authenticated request grants access to the entire bucket. |
timeCreated | string (date-time) | The date when the pre-authenticated request was created as per [RFC 3339](https:​//tools.ietf.org/html/rfc3339). |
timeExpires | string (date-time) | The expiration date for the pre-authenticated request as per [RFC 3339](https:​//tools.ietf.org/html/rfc3339). After this date the pre-authenticated request will no longer be valid. |
Get summary information about pre-authenticated requests.<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier to use when directly addressing the pre-authenticated request. |
name | string | The user-provided name of the pre-authenticated request. |
accessType | string | The operation that can be performed on this resource. (ObjectRead, ObjectWrite, ObjectReadWrite, AnyObjectWrite, AnyObjectRead, AnyObjectReadWrite) |
bucketListingAction | string | Specifies whether a list operation is allowed on a PAR with accessType "AnyObjectRead" or "AnyObjectReadWrite". Deny: Prevents the user from performing a list operation. ListObjects: Authorizes the user to perform a list operation. (x-obmcs-enumref: #/definitions/PreauthenticatedRequest/bucketListingAction) |
objectName | string | The name of object that is being granted access to by the pre-authenticated request. This can be null and if it is, the pre-authenticated request grants access to the entire bucket. |
timeCreated | string (date-time) | The date when the pre-authenticated request was created as per [RFC 3339](https:​//tools.ietf.org/html/rfc3339). |
timeExpires | string (date-time) | The expiration date for the pre-authenticated request as per [RFC 3339](https:​//tools.ietf.org/html/rfc3339). After this date the pre-authenticated request will no longer be valid. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | namespaceName, bucketName, parId, region | opc-client-request-id | Gets the pre-authenticated request for the bucket. |
list | select | namespaceName, bucketName, region | objectNamePrefix, limit, page, opc-client-request-id | Lists pre-authenticated requests for the bucket.<br /> |
create | insert | namespaceName, bucketName, region, name, accessType, timeExpires | opc-client-request-id | Creates a pre-authenticated request specific to the bucket.<br /> |
delete | delete | namespaceName, bucketName, parId, region | opc-client-request-id | Deletes the pre-authenticated request for the bucket. |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
bucketName | string | The name of the bucket. Avoid entering confidential information. Example: my-new-bucket1 |
namespaceName | string | The Object Storage namespace used for the request. |
parId | string | The unique identifier for the pre-authenticated request. This can be used to manage operations against the pre-authenticated request, such as GET or DELETE. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
limit | integer | For list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
objectNamePrefix | string | User-specified object name prefixes can be used to query and return a list of pre-authenticated requests. |
opc-client-request-id | string | The client request ID for tracing. |
page | string | For list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
SELECT examples​
- get
- list
Gets the pre-authenticated request for the bucket.
SELECT
id,
name,
accessType,
bucketListingAction,
objectName,
timeCreated,
timeExpires
FROM oci.object_storage.preauthenticated_requests
WHERE namespaceName = '{{ namespaceName }}' -- required
AND bucketName = '{{ bucketName }}' -- required
AND parId = '{{ parId }}' -- required
AND region = '{{ region }}' -- required
AND opc-client-request-id = '{{ opc-client-request-id }}'
;
Lists pre-authenticated requests for the bucket.<br />
SELECT
id,
name,
accessType,
bucketListingAction,
objectName,
timeCreated,
timeExpires
FROM oci.object_storage.preauthenticated_requests
WHERE namespaceName = '{{ namespaceName }}' -- required
AND bucketName = '{{ bucketName }}' -- required
AND region = '{{ region }}' -- required
AND objectNamePrefix = '{{ objectNamePrefix }}'
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND opc-client-request-id = '{{ opc-client-request-id }}'
;
INSERT examples​
- create
- Manifest
Creates a pre-authenticated request specific to the bucket.<br />
INSERT INTO oci.object_storage.preauthenticated_requests (
accessType,
bucketListingAction,
name,
objectName,
timeExpires,
namespaceName,
bucketName,
region,
opc-client-request-id
)
SELECT
'{{ accessType }}' /* required */,
'{{ bucketListingAction }}',
'{{ name }}' /* required */,
'{{ objectName }}',
'{{ timeExpires }}' /* required */,
'{{ namespaceName }}',
'{{ bucketName }}',
'{{ region }}',
'{{ opc-client-request-id }}'
RETURNING
id,
name,
accessType,
accessUri,
bucketListingAction,
objectName,
timeCreated,
timeExpires
;
# Description fields are for documentation purposes
- name: preauthenticated_requests
props:
- name: namespaceName
value: "{{ namespaceName }}"
description: Required parameter for the preauthenticated_requests resource.
- name: bucketName
value: "{{ bucketName }}"
description: Required parameter for the preauthenticated_requests resource.
- name: region
value: "{{ region }}"
description: Required parameter for the preauthenticated_requests resource.
- name: accessType
value: "{{ accessType }}"
description: |
The operation that can be performed on this resource.
valid_values: ['ObjectRead', 'ObjectWrite', 'ObjectReadWrite', 'AnyObjectWrite', 'AnyObjectRead', 'AnyObjectReadWrite']
- name: bucketListingAction
value: "{{ bucketListingAction }}"
description: |
Specifies whether a list operation is allowed on a PAR with accessType "AnyObjectRead" or "AnyObjectReadWrite".
Deny: Prevents the user from performing a list operation.
ListObjects: Authorizes the user to perform a list operation.
default: Deny
- name: name
value: "{{ name }}"
description: |
A user-specified name for the pre-authenticated request. Names can be helpful in managing pre-authenticated requests.
Avoid entering confidential information.
- name: objectName
value: "{{ objectName }}"
description: |
The name of the object that is being granted access to by the pre-authenticated request. Avoid entering confidential
information. The object name can be null and if so, the pre-authenticated request grants access to the entire bucket
if the access type allows that. The object name can be a prefix as well, in that case pre-authenticated request
grants access to all the objects within the bucket starting with that prefix provided that we have the correct access type.
- name: timeExpires
value: "{{ timeExpires }}"
description: |
The expiration date for the pre-authenticated request as per [RFC 3339](https://tools.ietf.org/html/rfc3339).
After this date the pre-authenticated request will no longer be valid.
- name: opc-client-request-id
value: "{{ opc-client-request-id }}"
description: The client request ID for tracing.
description: The client request ID for tracing.
DELETE examples​
- delete
Deletes the pre-authenticated request for the bucket.
DELETE FROM oci.object_storage.preauthenticated_requests
WHERE namespaceName = '{{ namespaceName }}' --required
AND bucketName = '{{ bucketName }}' --required
AND parId = '{{ parId }}' --required
AND region = '{{ region }}' --required
AND opc-client-request-id = '{{ opc-client-request-id }}'
;