Class Evaluation
- All Implemented Interfaces:
Serializable,SdkPojo,ToCopyableBuilder<Evaluation.Builder,Evaluation>
Represents an individual evaluation for a single action and resource pair. This includes the context, the resulting effect, and any policies that matched.
- See Also:
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionfinal Stringaction()The action evaluated for this request (for example,iam:PassRole).static Evaluation.Builderbuilder()context()The context keys and values specific to this evaluation.final booleanfinal booleanequalsBySdkFields(Object obj) Indicates whether some other object is "equal to" this one by SDK fields.final EvaluatedEffectThe result of the evaluation.final StringThe result of the evaluation.final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz) final booleanFor responses, this returns true if the service returned a value for the Context property.final inthashCode()final booleanFor responses, this returns true if the service returned a value for the MatchedPolicies property.final List<MatchedPolicy> The policies that matched during evaluation of this action and resource.final Stringresource()The resource that the action targeted.static Class<? extends Evaluation.Builder> Take this object and create a builder that contains all of the current property values of this object.final StringtoString()Returns a string representation of this object.Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
Method Details
-
action
The action evaluated for this request (for example,
iam:PassRole).- Returns:
- The action evaluated for this request (for example,
iam:PassRole).
-
resource
The resource that the action targeted. This is typically a resource ARN, but can be a wildcard ARN that matches multiple resources, or empty for actions that are not resource-specific.
- Returns:
- The resource that the action targeted. This is typically a resource ARN, but can be a wildcard ARN that matches multiple resources, or empty for actions that are not resource-specific.
-
hasContext
public final boolean hasContext()For responses, this returns true if the service returned a value for the Context property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
context
The context keys and values specific to this evaluation. These are applied on top of the request context.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasContext()method.- Returns:
- The context keys and values specific to this evaluation. These are applied on top of the request context.
-
evaluatedEffect
The result of the evaluation. Valid values:
-
ALLOW- The action was allowed. -
EXPLICIT_DENY- The action was explicitly denied by a policy. -
IMPLICIT_DENY- The action was denied because no policy allowed it.
If the service returns an enum value that is not available in the current SDK version,
evaluatedEffectwill returnEvaluatedEffect.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available fromevaluatedEffectAsString().- Returns:
- The result of the evaluation. Valid values:
-
ALLOW- The action was allowed. -
EXPLICIT_DENY- The action was explicitly denied by a policy. -
IMPLICIT_DENY- The action was denied because no policy allowed it.
-
- See Also:
-
-
evaluatedEffectAsString
The result of the evaluation. Valid values:
-
ALLOW- The action was allowed. -
EXPLICIT_DENY- The action was explicitly denied by a policy. -
IMPLICIT_DENY- The action was denied because no policy allowed it.
If the service returns an enum value that is not available in the current SDK version,
evaluatedEffectwill returnEvaluatedEffect.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available fromevaluatedEffectAsString().- Returns:
- The result of the evaluation. Valid values:
-
ALLOW- The action was allowed. -
EXPLICIT_DENY- The action was explicitly denied by a policy. -
IMPLICIT_DENY- The action was denied because no policy allowed it.
-
- See Also:
-
-
hasMatchedPolicies
public final boolean hasMatchedPolicies()For responses, this returns true if the service returned a value for the MatchedPolicies property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified. -
matchedPolicies
The policies that matched during evaluation of this action and resource. An implicit denial produces no matched policies.
Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasMatchedPolicies()method.- Returns:
- The policies that matched during evaluation of this action and resource. An implicit denial produces no matched policies.
-
toBuilder
Description copied from interface:ToCopyableBuilderTake this object and create a builder that contains all of the current property values of this object.- Specified by:
toBuilderin interfaceToCopyableBuilder<Evaluation.Builder,Evaluation> - Returns:
- a builder for type T
-
builder
-
serializableBuilderClass
-
hashCode
-
equals
-
equalsBySdkFields
Description copied from interface:SdkPojoIndicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in anSdkPojoclass, and is generated based on a service model.If an
SdkPojoclass does not have any inherited fields,equalsBySdkFieldsandequalsare essentially the same.- Specified by:
equalsBySdkFieldsin interfaceSdkPojo- Parameters:
obj- the object to be compared with- Returns:
- true if the other object equals to this object by sdk fields, false otherwise.
-
toString
-
getValueForField
-
sdkFields
-
sdkFieldNameToField
- Specified by:
sdkFieldNameToFieldin interfaceSdkPojo- Returns:
- The mapping between the field name and its corresponding field.
-