Class PermissionDiagnostics

java.lang.Object
io.jenkins.plugins.namespacecloud.client.PermissionDiagnostics

public final class PermissionDiagnostics extends Object
Turns a PERMISSION_DENIED from the Namespace API into the concrete list of grants the token is missing.

Namespace attaches a Authz.PermissionDeniedError to the gRPC status details, which names each resource_type/action pair that was refused. That is far more actionable than the status message alone, and it is the only reliable way to check a scoped token: TenantService.DescribePolicies requires an admin-scoped token, so calling it from a least-privilege Jenkins token would itself be denied.

  • Method Details

    • missingAccess

      public static List<Authz.Access> missingAccess(Throwable t)
      Extracts the refused permissions from a failed RPC.
      Returns:
      the missing accesses, or an empty list if the throwable is not a permission error or carries no structured details.
    • format

      public static String format(List<Authz.Access> missing)
      "instance: create, ingress: access" — for display in a form validation message.