Skip to content

role_create

role_create is implemented by handleRoleCreate in src/api/handlers/roles/role_create.osl.

Handles the role create protocol operation through the resource-specific helper and storage layers.

Gate Requirement
Authentication Required by the central API gate.
Central permission manage_roles
Broadcast Not marked global directly by this adapter. A helper may emit focused or server-wide updates.

Every request includes cmd: "role_create" and may include an opaque listener correlation value.

Field Validation / meaning
name schema.string().minLen(1).maxLen(64)
description schema.string().optional()
color schema.string().optional()
gradient schema.array(schema.any()).optional()
permissions schema.array(schema.string()).optional()
hoisted schema.boolean().optional()
self_assignable schema.boolean().optional()
category schema.string().optional()

The handler and shared validation path use these OSL schema definitions before normalization:

*schema.Schema schemaRoleCreate = schema.object({
name: schema.string().minLen(1).maxLen(64),
description: schema.string().optional(),
color: schema.string().optional(),
gradient: schema.array(schema.any()).optional(),
permissions: schema.array(schema.string()).optional(),
hoisted: schema.boolean().optional(),
self_assignable: schema.boolean().optional(),
category: schema.string().optional()
})
  1. handleCmd enforces authentication and the manage_roles permission.
  2. dispatchCmd routes role_create to handleRoleCreate.
  3. The adapter validates and normalizes input, then calls its domain collaborators.
  4. Durable mutations complete before the response or event is returned.
  5. onMessage adds the request listener to direct responses and performs any marked broadcast.

Direct collaborators visible in the handler: roleFromName, requestedPerms, userHasPermission, roleCreate, auditRecord, broadcastAuthed

Response/event command names visible in this adapter: role_create.

Validation and domain failures use:

{
"cmd": "error",
"val": "<message>",
"src": "role_create",
"listener": "<copied from request>"
}