blob: 83c7fdf05d648f9451cc8b60a387824ee38a7714 [file] [log] [blame]
Instrumental71037c32018-03-26 13:51:48 -07001USE authz;
2
3// Create 'org' root NS
4INSERT INTO ns (name,description,parent,scope,type)
5 VALUES('org','Root Namespace','.',1,1);
6
7INSERT INTO role(ns, name, perms, description)
8 VALUES('org','admin',{'org.access|*|*'},'Org Admins');
9
10INSERT INTO role(ns, name, perms, description)
11 VALUES('org','owner',{'org.access|*|read,approve'},'Org Owners');
12
13INSERT INTO perm(ns, type, instance, action, roles, description)
14 VALUES ('org','access','*','read,approve',{'org.owner'},'Org Read Access');
15
16INSERT INTO perm(ns, type, instance, action, roles, description)
17 VALUES ('org','access','*','*',{'org.admin'},'Org Write Access');
18
19// Create Root pass
20INSERT INTO cred (id,ns,type,cred,expires)
21 VALUES ('initial@osaaf.org','org.osaaf',1,0x008c5926ca861023c1d2a36653fd88e2,'2099-12-31') using TTL 14400;
22
23INSERT INTO user_role(user,role,expires,ns,rname)
24 VALUES ('initial@osaaf.org','org.admin','2099-12-31','org','admin') using TTL 14400;
25
26
27// Create org.osaaf
28INSERT INTO ns (name,description,parent,scope,type)
29 VALUES('org.osaaf','OSAAF Namespace','org',2,2);
30
31INSERT INTO role(ns, name, perms,description)
32 VALUES('org.osaaf','admin',{'org.osaaf.access|*|*'},'OSAAF Admins');
33
34INSERT INTO perm(ns, type, instance, action, roles,description)
35 VALUES ('org.osaaf','access','*','*',{'org.osaaf.admin'},'OSAAF Write Access');
36
37INSERT INTO role(ns, name, perms,description)
38 VALUES('org.osaaf','owner',{'org.osaaf.access|*|read,approve'},'OSAAF Owners');
39
40INSERT INTO perm(ns, type, instance, action, roles,description)
41 VALUES ('org.osaaf','access','*','read,appove',{'org.osaaf.owner'},'OSAAF Read Access');
42
43// Create org.osaaf.aaf
44INSERT INTO ns (name,description,parent,scope,type)
45 VALUES('org.osaaf.aaf','Application Authorization Framework','org.osaaf',3,3);
46
47INSERT INTO role(ns, name, perms, description)
48 VALUES('org.osaaf.aaf','admin',{'org.osaaf.aaf.access|*|*'},'AAF Admins');
49
50INSERT INTO perm(ns, type, instance, action, roles, description)
51 VALUES ('org.osaaf.aaf','access','*','*',{'org.osaaf.aaf.admin'},'AAF Write Access');
52
53INSERT INTO perm(ns, type, instance, action, roles, description)
54 VALUES ('org.osaaf.aaf','access','*','read,approve',{'org.osaaf.aaf.owner'},'AAF Read Access');
55
56INSERT INTO role(ns, name, perms, description)
57 VALUES('org.osaaf.aaf','owner',{'org.osaaf.aaf.access|*|read,approve'},'AAF Owners');
58
59INSERT INTO user_role(user,role,expires,ns,rname)
60 VALUES ('initial@osaaf.org','org.osaaf.aaf.admin','2099-12-31','org.osaaf.aaf','admin') using TTL 14400;
61