From f69ada2feb6b0d0ecbf633b3aa82dbffda72373e Mon Sep 17 00:00:00 2001 From: authzedbot <86801627+authzedbot@users.noreply.github.com> Date: Thu, 24 Sep 2026 20:01:12 +0000 Subject: [PATCH] chore: update api version --- buf.gen.yaml | 2 +- .../v0/roaringlookupresources.grpc-client.ts | 120 ++++++++++ .../materialize/v0/roaringlookupresources.ts | 207 ++++++++++++++++++ .../api/v1/permission_service.grpc-client.ts | 18 ++ .../authzed/api/v1/permission_service.ts | 42 +++- 5 files changed, 386 insertions(+), 3 deletions(-) create mode 100644 src/authzedapi/authzed/api/materialize/v0/roaringlookupresources.grpc-client.ts create mode 100644 src/authzedapi/authzed/api/materialize/v0/roaringlookupresources.ts diff --git a/buf.gen.yaml b/buf.gen.yaml index 3ab6df6..d09c646 100644 --- a/buf.gen.yaml +++ b/buf.gen.yaml @@ -9,4 +9,4 @@ plugins: - client_grpc1 inputs: # This SHA refers to the v1.41.0 commit with deprecated APIs removed - - module: "buf.build/authzed/api:v1.53.0" + - module: "buf.build/authzed/api:v1.57.0" diff --git a/src/authzedapi/authzed/api/materialize/v0/roaringlookupresources.grpc-client.ts b/src/authzedapi/authzed/api/materialize/v0/roaringlookupresources.grpc-client.ts new file mode 100644 index 0000000..a726bd2 --- /dev/null +++ b/src/authzedapi/authzed/api/materialize/v0/roaringlookupresources.grpc-client.ts @@ -0,0 +1,120 @@ +// @generated by protobuf-ts 2.9.1 with parameter generate_dependencies,long_type_string,client_grpc1 +// @generated from protobuf file "authzed/api/materialize/v0/roaringlookupresources.proto" (package "authzed.api.materialize.v0", syntax proto3) +// tslint:disable +import { RoaringLookupResourcesService } from "./roaringlookupresources.js"; +import type { BinaryWriteOptions } from "@protobuf-ts/runtime"; +import type { BinaryReadOptions } from "@protobuf-ts/runtime"; +import type { ExperimentalRoaringLookupResourcesResponse } from "./roaringlookupresources.js"; +import type { ExperimentalRoaringLookupResourcesRequest } from "./roaringlookupresources.js"; +import * as grpc from "@grpc/grpc-js"; +/** + * @generated from protobuf service authzed.api.materialize.v0.RoaringLookupResourcesService + */ +export interface IRoaringLookupResourcesServiceClient { + /** + * EXPERIMENTAL: RoaringLookupResources returns a roaring64 bitmap of the IDs + * of the resources of the given type on which the given subject has the + * given permission. This API is experimental and subject to change or + * removal. + * + * The bitmap is serialized in the RoaringFormatSpec 64-bit portable format + * (https://github.com/RoaringBitmap/RoaringFormatSpec#extention-for-64-bit-implementations), + * which OpenSearch consumes directly via a `"value_type": "bitmap"` terms + * query against a `long` field, once Base64-encoded. + * + * The IDs in the bitmap are the resource object IDs exactly as they appear + * in the relationships: no surrogate or internal ID is introduced, so the + * caller can use the bitmap directly against its own data (for example, a + * search index keyed by the same IDs). + * + * For this API to be usable, every resource object ID of the requested type + * must be a canonical decimal integer that fits in 44 bits -- at most + * 17592186044415 (2^44 - 1). Canonical means the string round-trips through + * uint64 formatting unchanged: `document:007` and `document:7` are distinct + * objects that would collide as the integer 7, so non-canonical IDs are + * rejected. If any resource object ID violates either rule, the call fails + * with FAILED_PRECONDITION rather than returning a partial bitmap, since a + * bitmap that is quietly too small is a wrong authorization answer. When the + * permission relates a type to itself (for example `group#member` looked up + * for a `group#member` subject), the subject is one of its own resources, so + * the subject's object ID is held to the same rules and can itself be the ID + * named in that error. + * + * Response size: the whole bitmap is returned in a single unary message, and + * most gRPC clients default to refusing messages larger than 4 MiB. Roaring + * is compact -- a million sequential IDs encode in a few hundred bytes -- but + * sparse IDs cost close to 10 bytes each, so a result of more than roughly + * 400,000 widely-spread IDs can exceed that default and fail on the CLIENT + * side with RESOURCE_EXHAUSTED ("received message larger than max"). This is + * a limit of the caller's own gRPC configuration, not of the service: raise + * it to match the largest result you expect (in Go, + * grpc.WithDefaultCallOptions(grpc.MaxCallRecvMsgSize(n)); other languages + * have an equivalent channel option). The `cardinality` field is returned so + * callers can see how large a result is once received; no server-side result + * limit is applied. + * + * @generated from protobuf rpc: ExperimentalRoaringLookupResources(authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesRequest) returns (authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesResponse); + */ + experimentalRoaringLookupResources(input: ExperimentalRoaringLookupResourcesRequest, metadata: grpc.Metadata, options: grpc.CallOptions, callback: (err: grpc.ServiceError | null, value?: ExperimentalRoaringLookupResourcesResponse) => void): grpc.ClientUnaryCall; + experimentalRoaringLookupResources(input: ExperimentalRoaringLookupResourcesRequest, metadata: grpc.Metadata, callback: (err: grpc.ServiceError | null, value?: ExperimentalRoaringLookupResourcesResponse) => void): grpc.ClientUnaryCall; + experimentalRoaringLookupResources(input: ExperimentalRoaringLookupResourcesRequest, options: grpc.CallOptions, callback: (err: grpc.ServiceError | null, value?: ExperimentalRoaringLookupResourcesResponse) => void): grpc.ClientUnaryCall; + experimentalRoaringLookupResources(input: ExperimentalRoaringLookupResourcesRequest, callback: (err: grpc.ServiceError | null, value?: ExperimentalRoaringLookupResourcesResponse) => void): grpc.ClientUnaryCall; +} +/** + * @generated from protobuf service authzed.api.materialize.v0.RoaringLookupResourcesService + */ +export class RoaringLookupResourcesServiceClient extends grpc.Client implements IRoaringLookupResourcesServiceClient { + private readonly _binaryOptions: Partial; + constructor(address: string, credentials: grpc.ChannelCredentials, options: grpc.ClientOptions = {}, binaryOptions: Partial = {}) { + super(address, credentials, options); + this._binaryOptions = binaryOptions; + } + /** + * EXPERIMENTAL: RoaringLookupResources returns a roaring64 bitmap of the IDs + * of the resources of the given type on which the given subject has the + * given permission. This API is experimental and subject to change or + * removal. + * + * The bitmap is serialized in the RoaringFormatSpec 64-bit portable format + * (https://github.com/RoaringBitmap/RoaringFormatSpec#extention-for-64-bit-implementations), + * which OpenSearch consumes directly via a `"value_type": "bitmap"` terms + * query against a `long` field, once Base64-encoded. + * + * The IDs in the bitmap are the resource object IDs exactly as they appear + * in the relationships: no surrogate or internal ID is introduced, so the + * caller can use the bitmap directly against its own data (for example, a + * search index keyed by the same IDs). + * + * For this API to be usable, every resource object ID of the requested type + * must be a canonical decimal integer that fits in 44 bits -- at most + * 17592186044415 (2^44 - 1). Canonical means the string round-trips through + * uint64 formatting unchanged: `document:007` and `document:7` are distinct + * objects that would collide as the integer 7, so non-canonical IDs are + * rejected. If any resource object ID violates either rule, the call fails + * with FAILED_PRECONDITION rather than returning a partial bitmap, since a + * bitmap that is quietly too small is a wrong authorization answer. When the + * permission relates a type to itself (for example `group#member` looked up + * for a `group#member` subject), the subject is one of its own resources, so + * the subject's object ID is held to the same rules and can itself be the ID + * named in that error. + * + * Response size: the whole bitmap is returned in a single unary message, and + * most gRPC clients default to refusing messages larger than 4 MiB. Roaring + * is compact -- a million sequential IDs encode in a few hundred bytes -- but + * sparse IDs cost close to 10 bytes each, so a result of more than roughly + * 400,000 widely-spread IDs can exceed that default and fail on the CLIENT + * side with RESOURCE_EXHAUSTED ("received message larger than max"). This is + * a limit of the caller's own gRPC configuration, not of the service: raise + * it to match the largest result you expect (in Go, + * grpc.WithDefaultCallOptions(grpc.MaxCallRecvMsgSize(n)); other languages + * have an equivalent channel option). The `cardinality` field is returned so + * callers can see how large a result is once received; no server-side result + * limit is applied. + * + * @generated from protobuf rpc: ExperimentalRoaringLookupResources(authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesRequest) returns (authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesResponse); + */ + experimentalRoaringLookupResources(input: ExperimentalRoaringLookupResourcesRequest, metadata: grpc.Metadata | grpc.CallOptions | ((err: grpc.ServiceError | null, value?: ExperimentalRoaringLookupResourcesResponse) => void), options?: grpc.CallOptions | ((err: grpc.ServiceError | null, value?: ExperimentalRoaringLookupResourcesResponse) => void), callback?: ((err: grpc.ServiceError | null, value?: ExperimentalRoaringLookupResourcesResponse) => void)): grpc.ClientUnaryCall { + const method = RoaringLookupResourcesService.methods[0]; + return this.makeUnaryRequest(`/${RoaringLookupResourcesService.typeName}/${method.name}`, (value: ExperimentalRoaringLookupResourcesRequest): Buffer => Buffer.from(method.I.toBinary(value, this._binaryOptions)), (value: Buffer): ExperimentalRoaringLookupResourcesResponse => method.O.fromBinary(value, this._binaryOptions), input, (metadata as any), (options as any), (callback as any)); + } +} diff --git a/src/authzedapi/authzed/api/materialize/v0/roaringlookupresources.ts b/src/authzedapi/authzed/api/materialize/v0/roaringlookupresources.ts new file mode 100644 index 0000000..d6a010f --- /dev/null +++ b/src/authzedapi/authzed/api/materialize/v0/roaringlookupresources.ts @@ -0,0 +1,207 @@ +// @generated by protobuf-ts 2.9.1 with parameter generate_dependencies,long_type_string,client_grpc1 +// @generated from protobuf file "authzed/api/materialize/v0/roaringlookupresources.proto" (package "authzed.api.materialize.v0", syntax proto3) +// tslint:disable +import { ServiceType } from "@protobuf-ts/runtime-rpc"; +import type { BinaryWriteOptions } from "@protobuf-ts/runtime"; +import type { IBinaryWriter } from "@protobuf-ts/runtime"; +import { WireType } from "@protobuf-ts/runtime"; +import type { BinaryReadOptions } from "@protobuf-ts/runtime"; +import type { IBinaryReader } from "@protobuf-ts/runtime"; +import { UnknownFieldHandler } from "@protobuf-ts/runtime"; +import type { PartialMessage } from "@protobuf-ts/runtime"; +import { reflectionMergePartial } from "@protobuf-ts/runtime"; +import { MESSAGE_TYPE } from "@protobuf-ts/runtime"; +import { MessageType } from "@protobuf-ts/runtime"; +import { ZedToken } from "../../v1/core.js"; +import { SubjectReference } from "../../v1/core.js"; +import { Consistency } from "../../v1/permission_service.js"; +/** + * @generated from protobuf message authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesRequest + */ +export interface ExperimentalRoaringLookupResourcesRequest { + /** + * consistency selects the snapshot at which the lookup is performed. If + * unspecified, minimize_latency is used. + * + * @generated from protobuf field: authzed.api.v1.Consistency consistency = 1; + */ + consistency?: Consistency; + /** + * resource_object_type is the type of resource over which to look up access. + * + * @generated from protobuf field: string resource_object_type = 2; + */ + resourceObjectType: string; + /** + * permission is the name of the permission or relation to look up. + * + * @generated from protobuf field: string permission = 3; + */ + permission: string; + /** + * subject is the subject for which access is being looked up. + * + * @generated from protobuf field: authzed.api.v1.SubjectReference subject = 4; + */ + subject?: SubjectReference; +} +/** + * @generated from protobuf message authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesResponse + */ +export interface ExperimentalRoaringLookupResourcesResponse { + /** + * bitmap is the roaring64 bitmap, in RoaringFormatSpec 64-bit portable + * format, of the resource object IDs accessible to the subject. The IDs are + * the object IDs from the relationships themselves, as 44-bit integers. + * + * @generated from protobuf field: bytes bitmap = 1; + */ + bitmap: Uint8Array; + /** + * cardinality is the number of resource IDs in the bitmap. + * + * @generated from protobuf field: uint64 cardinality = 2; + */ + cardinality: string; + /** + * at_revision is the ZedToken at which the lookup was performed. + * + * @generated from protobuf field: authzed.api.v1.ZedToken at_revision = 3; + */ + atRevision?: ZedToken; +} +// @generated message type with reflection information, may provide speed optimized methods +class ExperimentalRoaringLookupResourcesRequest$Type extends MessageType { + constructor() { + super("authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesRequest", [ + { no: 1, name: "consistency", kind: "message", T: () => Consistency }, + { no: 2, name: "resource_object_type", kind: "scalar", T: 9 /*ScalarType.STRING*/, options: { "buf.validate.field": { string: { maxBytes: "128", pattern: "^([a-z][a-z0-9_]{1,61}[a-z0-9]/)*[a-z][a-z0-9_]{1,62}[a-z0-9]$" } }, "validate.rules": { string: { maxBytes: "128", pattern: "^([a-z][a-z0-9_]{1,61}[a-z0-9]/)*[a-z][a-z0-9_]{1,62}[a-z0-9]$" } } } }, + { no: 3, name: "permission", kind: "scalar", T: 9 /*ScalarType.STRING*/, options: { "buf.validate.field": { string: { maxBytes: "64", pattern: "^[a-z][a-z0-9_]{1,62}[a-z0-9]$" } }, "validate.rules": { string: { maxBytes: "64", pattern: "^[a-z][a-z0-9_]{1,62}[a-z0-9]$" } } } }, + { no: 4, name: "subject", kind: "message", T: () => SubjectReference, options: { "buf.validate.field": { required: true }, "validate.rules": { message: { required: true } } } } + ]); + } + create(value?: PartialMessage): ExperimentalRoaringLookupResourcesRequest { + const message = { resourceObjectType: "", permission: "" }; + globalThis.Object.defineProperty(message, MESSAGE_TYPE, { enumerable: false, value: this }); + if (value !== undefined) + reflectionMergePartial(this, message, value); + return message; + } + internalBinaryRead(reader: IBinaryReader, length: number, options: BinaryReadOptions, target?: ExperimentalRoaringLookupResourcesRequest): ExperimentalRoaringLookupResourcesRequest { + let message = target ?? this.create(), end = reader.pos + length; + while (reader.pos < end) { + let [fieldNo, wireType] = reader.tag(); + switch (fieldNo) { + case /* authzed.api.v1.Consistency consistency */ 1: + message.consistency = Consistency.internalBinaryRead(reader, reader.uint32(), options, message.consistency); + break; + case /* string resource_object_type */ 2: + message.resourceObjectType = reader.string(); + break; + case /* string permission */ 3: + message.permission = reader.string(); + break; + case /* authzed.api.v1.SubjectReference subject */ 4: + message.subject = SubjectReference.internalBinaryRead(reader, reader.uint32(), options, message.subject); + break; + default: + let u = options.readUnknownField; + if (u === "throw") + throw new globalThis.Error(`Unknown field ${fieldNo} (wire type ${wireType}) for ${this.typeName}`); + let d = reader.skip(wireType); + if (u !== false) + (u === true ? UnknownFieldHandler.onRead : u)(this.typeName, message, fieldNo, wireType, d); + } + } + return message; + } + internalBinaryWrite(message: ExperimentalRoaringLookupResourcesRequest, writer: IBinaryWriter, options: BinaryWriteOptions): IBinaryWriter { + /* authzed.api.v1.Consistency consistency = 1; */ + if (message.consistency) + Consistency.internalBinaryWrite(message.consistency, writer.tag(1, WireType.LengthDelimited).fork(), options).join(); + /* string resource_object_type = 2; */ + if (message.resourceObjectType !== "") + writer.tag(2, WireType.LengthDelimited).string(message.resourceObjectType); + /* string permission = 3; */ + if (message.permission !== "") + writer.tag(3, WireType.LengthDelimited).string(message.permission); + /* authzed.api.v1.SubjectReference subject = 4; */ + if (message.subject) + SubjectReference.internalBinaryWrite(message.subject, writer.tag(4, WireType.LengthDelimited).fork(), options).join(); + let u = options.writeUnknownFields; + if (u !== false) + (u == true ? UnknownFieldHandler.onWrite : u)(this.typeName, message, writer); + return writer; + } +} +/** + * @generated MessageType for protobuf message authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesRequest + */ +export const ExperimentalRoaringLookupResourcesRequest = new ExperimentalRoaringLookupResourcesRequest$Type(); +// @generated message type with reflection information, may provide speed optimized methods +class ExperimentalRoaringLookupResourcesResponse$Type extends MessageType { + constructor() { + super("authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesResponse", [ + { no: 1, name: "bitmap", kind: "scalar", T: 12 /*ScalarType.BYTES*/ }, + { no: 2, name: "cardinality", kind: "scalar", T: 4 /*ScalarType.UINT64*/ }, + { no: 3, name: "at_revision", kind: "message", T: () => ZedToken, options: { "buf.validate.field": { required: true }, "validate.rules": { message: { required: true } } } } + ]); + } + create(value?: PartialMessage): ExperimentalRoaringLookupResourcesResponse { + const message = { bitmap: new Uint8Array(0), cardinality: "0" }; + globalThis.Object.defineProperty(message, MESSAGE_TYPE, { enumerable: false, value: this }); + if (value !== undefined) + reflectionMergePartial(this, message, value); + return message; + } + internalBinaryRead(reader: IBinaryReader, length: number, options: BinaryReadOptions, target?: ExperimentalRoaringLookupResourcesResponse): ExperimentalRoaringLookupResourcesResponse { + let message = target ?? this.create(), end = reader.pos + length; + while (reader.pos < end) { + let [fieldNo, wireType] = reader.tag(); + switch (fieldNo) { + case /* bytes bitmap */ 1: + message.bitmap = reader.bytes(); + break; + case /* uint64 cardinality */ 2: + message.cardinality = reader.uint64().toString(); + break; + case /* authzed.api.v1.ZedToken at_revision */ 3: + message.atRevision = ZedToken.internalBinaryRead(reader, reader.uint32(), options, message.atRevision); + break; + default: + let u = options.readUnknownField; + if (u === "throw") + throw new globalThis.Error(`Unknown field ${fieldNo} (wire type ${wireType}) for ${this.typeName}`); + let d = reader.skip(wireType); + if (u !== false) + (u === true ? UnknownFieldHandler.onRead : u)(this.typeName, message, fieldNo, wireType, d); + } + } + return message; + } + internalBinaryWrite(message: ExperimentalRoaringLookupResourcesResponse, writer: IBinaryWriter, options: BinaryWriteOptions): IBinaryWriter { + /* bytes bitmap = 1; */ + if (message.bitmap.length) + writer.tag(1, WireType.LengthDelimited).bytes(message.bitmap); + /* uint64 cardinality = 2; */ + if (message.cardinality !== "0") + writer.tag(2, WireType.Varint).uint64(message.cardinality); + /* authzed.api.v1.ZedToken at_revision = 3; */ + if (message.atRevision) + ZedToken.internalBinaryWrite(message.atRevision, writer.tag(3, WireType.LengthDelimited).fork(), options).join(); + let u = options.writeUnknownFields; + if (u !== false) + (u == true ? UnknownFieldHandler.onWrite : u)(this.typeName, message, writer); + return writer; + } +} +/** + * @generated MessageType for protobuf message authzed.api.materialize.v0.ExperimentalRoaringLookupResourcesResponse + */ +export const ExperimentalRoaringLookupResourcesResponse = new ExperimentalRoaringLookupResourcesResponse$Type(); +/** + * @generated ServiceType for protobuf service authzed.api.materialize.v0.RoaringLookupResourcesService + */ +export const RoaringLookupResourcesService = new ServiceType("authzed.api.materialize.v0.RoaringLookupResourcesService", [ + { name: "ExperimentalRoaringLookupResources", options: {}, I: ExperimentalRoaringLookupResourcesRequest, O: ExperimentalRoaringLookupResourcesResponse } +]); diff --git a/src/authzedapi/authzed/api/v1/permission_service.grpc-client.ts b/src/authzedapi/authzed/api/v1/permission_service.grpc-client.ts index ef5fa08..c70527b 100644 --- a/src/authzedapi/authzed/api/v1/permission_service.grpc-client.ts +++ b/src/authzedapi/authzed/api/v1/permission_service.grpc-client.ts @@ -98,6 +98,11 @@ export interface IPermissionsServiceClient { * LookupResources returns all the resources of a given type that a subject * can access whether via a computed permission or relation membership. * + * Results are streamed and **not guaranteed to be unique**: the same resource + * may be returned more than once (for example via caveated/conditional + * results, or when a limit is set), possibly with differing permissionship. + * Callers that require uniqueness should deduplicate results. + * * @generated from protobuf rpc: LookupResources(authzed.api.v1.LookupResourcesRequest) returns (stream authzed.api.v1.LookupResourcesResponse); */ lookupResources(input: LookupResourcesRequest, metadata?: grpc.Metadata, options?: grpc.CallOptions): grpc.ClientReadableStream; @@ -106,6 +111,10 @@ export interface IPermissionsServiceClient { * LookupSubjects returns all the subjects of a given type that * have access whether via a computed permission or relation membership. * + * Results are streamed and **not guaranteed to be unique**: the same subject + * may be returned more than once, possibly with differing permissionship. + * Callers that require uniqueness should deduplicate results. + * * @generated from protobuf rpc: LookupSubjects(authzed.api.v1.LookupSubjectsRequest) returns (stream authzed.api.v1.LookupSubjectsResponse); */ lookupSubjects(input: LookupSubjectsRequest, metadata?: grpc.Metadata, options?: grpc.CallOptions): grpc.ClientReadableStream; @@ -215,6 +224,11 @@ export class PermissionsServiceClient extends grpc.Client implements IPermission * LookupResources returns all the resources of a given type that a subject * can access whether via a computed permission or relation membership. * + * Results are streamed and **not guaranteed to be unique**: the same resource + * may be returned more than once (for example via caveated/conditional + * results, or when a limit is set), possibly with differing permissionship. + * Callers that require uniqueness should deduplicate results. + * * @generated from protobuf rpc: LookupResources(authzed.api.v1.LookupResourcesRequest) returns (stream authzed.api.v1.LookupResourcesResponse); */ lookupResources(input: LookupResourcesRequest, metadata?: grpc.Metadata | grpc.CallOptions, options?: grpc.CallOptions): grpc.ClientReadableStream { @@ -225,6 +239,10 @@ export class PermissionsServiceClient extends grpc.Client implements IPermission * LookupSubjects returns all the subjects of a given type that * have access whether via a computed permission or relation membership. * + * Results are streamed and **not guaranteed to be unique**: the same subject + * may be returned more than once, possibly with differing permissionship. + * Callers that require uniqueness should deduplicate results. + * * @generated from protobuf rpc: LookupSubjects(authzed.api.v1.LookupSubjectsRequest) returns (stream authzed.api.v1.LookupSubjectsResponse); */ lookupSubjects(input: LookupSubjectsRequest, metadata?: grpc.Metadata | grpc.CallOptions, options?: grpc.CallOptions): grpc.ClientReadableStream { diff --git a/src/authzedapi/authzed/api/v1/permission_service.ts b/src/authzedapi/authzed/api/v1/permission_service.ts index 61c9f4d..3b501f8 100644 --- a/src/authzedapi/authzed/api/v1/permission_service.ts +++ b/src/authzedapi/authzed/api/v1/permission_service.ts @@ -343,6 +343,20 @@ export interface DeleteRelationshipsRequest { * @generated from protobuf field: google.protobuf.Struct optional_transaction_metadata = 5; */ optionalTransactionMetadata?: Struct; + /** + * optional_cursor, if specified, indicates the cursor after which deletion should resume. It is used to + * continue a batched, partial deletion where a previous call left off, by passing back the + * after_result_cursor returned on the previous DeleteRelationshipsResponse. + * + * A cursor allows a large deletion to be performed as a series of calls without re-examining the + * relationships already deleted by earlier calls. It therefore requires optional_limit and + * optional_allow_partial_deletions to be set, and is only supported by datastores whose deletion can be + * ordered and resumed; datastores that do not support cursored deletion will return an error if a cursor + * is provided. + * + * @generated from protobuf field: authzed.api.v1.Cursor optional_cursor = 6; + */ + optionalCursor?: Cursor; } /** * @generated from protobuf message authzed.api.v1.DeleteRelationshipsResponse @@ -366,6 +380,16 @@ export interface DeleteRelationshipsResponse { * @generated from protobuf field: uint64 relationships_deleted_count = 3; */ relationshipsDeletedCount: string; + /** + * after_result_cursor holds a cursor that can be used to resume the deletion after the relationships + * deleted by this call, by supplying it as the optional_cursor on a subsequent DeleteRelationshipsRequest. + * + * It is populated only when deletion_progress is DELETION_PROGRESS_PARTIAL and the datastore supports + * cursored deletion; it is unset once DELETION_PROGRESS_COMPLETE is returned. + * + * @generated from protobuf field: authzed.api.v1.Cursor after_result_cursor = 4; + */ + afterResultCursor?: Cursor; } /** * @generated from protobuf enum authzed.api.v1.DeleteRelationshipsResponse.DeletionProgress @@ -1625,7 +1649,8 @@ class DeleteRelationshipsRequest$Type extends MessageType Precondition, options: { "validate.rules": { repeated: { items: { message: { required: true } } } } } }, { no: 3, name: "optional_limit", kind: "scalar", T: 13 /*ScalarType.UINT32*/, options: { "buf.validate.field": { uint32: { gte: 0 } }, "validate.rules": { uint32: { gte: 0 } } } }, { no: 4, name: "optional_allow_partial_deletions", kind: "scalar", T: 8 /*ScalarType.BOOL*/ }, - { no: 5, name: "optional_transaction_metadata", kind: "message", T: () => Struct, options: { "buf.validate.field": { required: false }, "validate.rules": { message: { required: false } } } } + { no: 5, name: "optional_transaction_metadata", kind: "message", T: () => Struct, options: { "buf.validate.field": { required: false }, "validate.rules": { message: { required: false } } } }, + { no: 6, name: "optional_cursor", kind: "message", T: () => Cursor } ]); } create(value?: PartialMessage): DeleteRelationshipsRequest { @@ -1655,6 +1680,9 @@ class DeleteRelationshipsRequest$Type extends MessageType ZedToken }, { no: 2, name: "deletion_progress", kind: "enum", T: () => ["authzed.api.v1.DeleteRelationshipsResponse.DeletionProgress", DeleteRelationshipsResponse_DeletionProgress, "DELETION_PROGRESS_"] }, - { no: 3, name: "relationships_deleted_count", kind: "scalar", T: 4 /*ScalarType.UINT64*/ } + { no: 3, name: "relationships_deleted_count", kind: "scalar", T: 4 /*ScalarType.UINT64*/ }, + { no: 4, name: "after_result_cursor", kind: "message", T: () => Cursor } ]); } create(value?: PartialMessage): DeleteRelationshipsResponse { @@ -1722,6 +1754,9 @@ class DeleteRelationshipsResponse$Type extends MessageType