Edit view access
Grant or revoke access to a View.
Adding and removing are authorized separately, following edit_collection_access: a
request doing both must satisfy both, and one doing neither is a no-op that needs
neither.
Unlike edit_collection_access, the gate also depends on which relation is being
changed. associated_group is not an ordinary grant — the org’s all-members group
carries can_view_views, so adding or removing it is what makes a View org-visible or
private, and that is reserved to the author. Every other editable relation stays on
can_add_access / can_remove_access, which is what lets an editor hand out access,
edit rights included, without also controlling who can see the View.
Gating the whole call on can_change_accessibility would not work: one request may mix
an ordinary grant with a sharing change, and an editor has to keep being able to make the
former. So the two are checked independently and a request needs whichever apply to it.
Authorizing here rather than in the service means a request that fails any of these checks
writes nothing. generic_edit_access applies its adds before it validates the removes,
so a partially-authorized request must not reach it.
Access control
- Restricted tokens need the API scope
api.everything_else
/v1/views/id/{view_id}/accessAuthorizationBearer token · headerrequiredview_idstringrequiredX-Roboto-Org-IdstringX-Roboto-User-Idstringapplication/jsonaddAuthZTupleRecord[]Show propertiesHide properties
AuthZTupleRecorduserstringrequiredrelationstringrequiredobjstringrequiredremoveAuthZTupleRecord[]Show propertiesHide properties
AuthZTupleRecorduserstringrequiredrelationstringrequiredobjstringrequiredOK
dataobjectrequiredResponse payload for a request to describe fine-grained access to a Roboto resource
Show propertiesHide properties
relationsAuthZTupleRecord[]requiredShow propertiesHide properties
AuthZTupleRecorduserstringrequiredrelationstringrequiredobjstringrequiredgroup_permissionsobjectThrown when the conversation context (messages, system prompt, tool results) exceeds the model's context window limit.
The token estimate and the model's context limit are not carried on the exception, so a caller cannot read usage numbers off it.
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown when authentication fails
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown if an operation would exceed a user or org level limit.
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown if a user is attempting to perform an action unrecognized by the Roboto platform.
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown if there is a conflict between a resource you're creating and another existing resource
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown if a resource is missing or expired.
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullAn error the platform reported that this SDK release cannot resolve to a specific exception class.
Reported for an element of a :py:class:~roboto.http.BatchResponse whose error names a code this release
defines no class for, or that arrived without a code, without a message, or as text that is not an
error envelope at all. It carries whatever code and message the platform sent, so a caller handling the
failure still learns what went wrong; when no message could be read, the message is the error's raw text.
The error envelope carries no status code, so http_status_code reports the 500 inherited from
:py:class:RobotoDomainException rather than the status the failure actually had.
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown by shimmed out APIs which have not yet been implemented
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown when a service is unavailable, such as when it's under heavy load and can't accept new requests. This is expected to be transient and ought to be retried.
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown when the service times out while processing a request. This is exepcted to be transient and ought to be retried.
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | nullThrown when the server cannot complete the request because the response payload exceeds a storage or transport capacity limit (e.g., Lambda response size). This is NOT expected to be transient and should NOT be retried.
errorobjectShow propertiesHide properties
error_codenumbermessagestringstack_tracestring | null