Availability: OneSpan Authentication Server 3.29 and later
Scenario: Administration
Support: full-sdk
The adminRoleExecute command executes administrative operations to manage administrator roles. To assign an administrator role to or remove it from an user account, use the userExecute command.
| Command | Description |
|---|---|
| ADMINROLECMD_CREATE | Creates a new administrator role (see ADMINROLECMD_CREATE). |
| ADMINROLECMD_DELETE | Deletes an existing administrator role (see ADMINROLECMD_DELETE). |
| ADMINROLECMD_UPDATE | Updates an existing administrator role (see ADMINROLECMD_UPDATE). |
| ADMINROLECMD_VIEW | Retrieves the settings of an existing administrator role (see ADMINROLECMD_VIEW). |
Parameters
| Parameter name | Data type | Description |
|---|---|---|
sessionID | String | Required. The session identifier of the current administrative session. The logon command returns this identifier after a successful logon (see logon (Command)). |
cmd | AdminRoleCmdIDEnum | Required. The operation to be executed. See Table: adminRoleExecute commands (SOAP administration). |
attributeSet | AdminRoleAttributeSet | Required. A set containing zero or more attribute fields. |
| Parameter name | Data type | Description |
|---|---|---|
results | AdminRoleResults | Required. Result structure containing return and status codes and a list of zero or more result attribute fields. |
The following field attributes are available for the operations of this command:
| Attribute name | Data type | Description |
|---|---|---|
| ADMINROLEFLD_CREATE_TIME | DateTime | The date and time the data record was created. |
| ADMINROLEFLD_DESCRIPTION | String | A custom description for the administrator role. Up to 1024 characters. |
| ADMINROLEFLD_LOGICAL_ADMIN_PRIVILEGES_TEMPLATE | String | A human-readable, comma-separated list of the administrative privileges assigned to the administrator role. Each administrative privilege is specified as follows: admin_priv_name [true|false] For a list of possible privileges, see SOAP authentication. Up to 1024 characters. |
| ADMINROLEFLD_MODIFY_TIME | DateTime | The date and time the data record was last modified. |
| ADMINROLEFLD_NAME | String | The name of the administrator role. Up to 255 characters. |
| ADMINROLEFLD_TEMPLATEID | String | A unique identifier of the administrator role that is automatically generated when the administrator roles is created. Up to 60 characters. |
ADMINROLECMD_CREATE
ADMINROLE_CREATE defines a new administrator role.
Parameters
The following attributes can be specified in the attributeSet input parameter of this command:
| Attribute name | Optionality |
|---|---|
| ADMINROLEFLD_DESCRIPTION | Optional |
| ADMINROLEFLD_LOGICAL_ADMIN_PRIVILEGES_TEMPLATE | Optional |
| ADMINROLEFLD_NAME | Mandatory |
The following attributes will be specified in the results output parameter of this command:
| Attribute name | Returned |
|---|---|
| ADMINROLEFLD_CREATE_TIME | Always |
| ADMINROLEFLD_DESCRIPTION | If defined |
| ADMINROLEFLD_LOGICAL_ADMIN_PRIVILEGES_TEMPLATE | If defined |
| ADMINROLEFLD_MODIFY_TIME | Always |
| ADMINROLEFLD_NAME | Always |
| ADMINROLEFLD_TEMPLATEID | Always |
Requirements
Required administrative privileges:
- Create Role
ADMINROLECMD_DELETE
ADMINROLECMD_DELETE deletes the specified administrator role.
Parameters
The following attributes can be specified in the attributeSet input parameter of this command:
| Attribute name | Optionality |
|---|---|
| ADMINROLEFLD_TEMPLATEID | Mandatory |
This command returns no result attributes.
Requirements
Required administrative privileges:
- Delete Role
ADMINROLECMD_UPDATE
ADMINROLECMD_UPDATE updates the specified administrator role record.
Parameters
The following attributes can be specified in the attributeSet input parameter of this command:
| Attribute name | Optionality |
|---|---|
| ADMINROLEFLD_DESCRIPTION | Optional |
| ADMINROLEFLD_LOGICAL_ADMIN_PRIVILEGES_TEMPLATE | Optional |
| ADMINROLEFLD_NAME | Optional |
| ADMINROLEFLD_TEMPLATEID | Mandatory |
The following attributes will be specified in the results output parameter of this command:
| Attribute name | Returned |
|---|---|
| ADMINROLEFLD_CREATE_TIME | Always |
| ADMINROLEFLD_DESCRIPTION | If defined |
| ADMINROLEFLD_LOGICAL_ADMIN_PRIVILEGES_TEMPLATE | If defined |
| ADMINROLEFLD_MODIFY_TIME | Always |
| ADMINROLEFLD_NAME | Always |
| ADMINROLEFLD_TEMPLATEID | Always |
Requirements
Required administrative privileges:
- Update Role
ADMINROLECMD_VIEW
COMPONENTCMD_VIEW retrieves the settings of the specified client component.
Parameters
The following attributes can be specified in the attributeSet input parameter of this command:
| Attribute name | Optionality |
|---|---|
| ADMINROLEFLD_TEMPLATEID | Mandatory |
The following attributes will be specified in the results output parameter of this command:
| Attribute name | Returned |
|---|---|
| ADMINROLEFLD_CREATE_TIME | Always |
| ADMINROLEFLD_DESCRIPTION | If defined |
| ADMINROLEFLD_LOGICAL_ADMIN_PRIVILEGES_TEMPLATE | If defined |
| ADMINROLEFLD_MODIFY_TIME | Always |
| ADMINROLEFLD_NAME | Always |
| ADMINROLEFLD_TEMPLATEID | Always |
Requirements
Required administrative privileges:
- View Role