user_roles_set
user_roles_set is implemented by handleUserRolesSet in src/api/handlers/roles/user_roles_set.osl.
Persists the target role set, then returns and broadcasts the canonical user_roles_get shape and refreshes the target’s channels.
Access
Section titled “Access”| Gate | Requirement |
|---|---|
| Authentication | Required by the central API gate. |
| Central permission | manage_roles |
| Broadcast | Not marked global directly by this adapter. A helper may emit focused or server-wide updates. |
Request
Section titled “Request”Every request includes cmd: "user_roles_set" and may include an opaque listener correlation value.
| Field | Validation / meaning |
|---|---|
user |
schema.string().trim().minLen(1) |
roles |
schema.array(schema.string()).minLen(1) |
Validator source
Section titled “Validator source”The handler and shared validation path use these OSL schema definitions before normalization:
*schema.Schema schemaUserRolesSet = schema.object({ user: schema.string().trim().minLen(1), roles: schema.array(schema.string()).minLen(1)})Processing path
Section titled “Processing path”handleCmdenforces authentication and themanage_rolespermission.dispatchCmdroutesuser_roles_settohandleUserRolesSet.- The adapter validates and normalizes input, then calls its domain collaborators.
- Durable mutations complete before the response or event is returned.
onMessageadds the request listener to direct responses and performs any marked broadcast.
Direct collaborators visible in the handler: roleFromName, userFromUsername, nextRoles, roleManageError, previousRoles, userRolesSet, calcUserColor, calcUserGradient, auditRecord, broadcastAuthed
Responses and events
Section titled “Responses and events”Response/event command names visible in this adapter: user_roles_get, channels_get.
Validation and domain failures use:
{ "cmd": "error", "val": "<message>", "src": "user_roles_set", "listener": "<copied from request>"}