memberships
Creates, updates, deletes, gets or lists a memberships resource.
Overview
| Name | memberships |
| Type | Resource |
| Id | google.cloudidentity.memberships |
Fields
The following fields are returned by SELECT queries:
- get
- list
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The resource name of the Membership. Shall be of the form groups/{group}/memberships/{membership}. |
createTime | string (google-datetime) | Output only. The time when the Membership was created. |
deliverySetting | string | Output only. Delivery setting associated with the membership. (DELIVERY_SETTING_UNSPECIFIED, ALL_MAIL, DIGEST, DAILY, NONE, DISABLED) |
preferredMemberKey | object | Required. Immutable. The EntityKey of the member. (id: EntityKey) |
roles | array | The MembershipRoles that apply to the Membership. If unspecified, defaults to a single MembershipRole with name MEMBER. Must not contain duplicate MembershipRoles with the same name. |
type | string | Output only. The type of the membership. (TYPE_UNSPECIFIED, USER, SERVICE_ACCOUNT, GROUP, SHARED_DRIVE, CBCM_BROWSER, CHROME_OS_DEVICE, OTHER) |
updateTime | string (google-datetime) | Output only. The time when the Membership was last updated. |
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The resource name of the Membership. Shall be of the form groups/{group}/memberships/{membership}. |
createTime | string (google-datetime) | Output only. The time when the Membership was created. |
deliverySetting | string | Output only. Delivery setting associated with the membership. (DELIVERY_SETTING_UNSPECIFIED, ALL_MAIL, DIGEST, DAILY, NONE, DISABLED) |
preferredMemberKey | object | Required. Immutable. The EntityKey of the member. (id: EntityKey) |
roles | array | The MembershipRoles that apply to the Membership. If unspecified, defaults to a single MembershipRole with name MEMBER. Must not contain duplicate MembershipRoles with the same name. |
type | string | Output only. The type of the membership. (TYPE_UNSPECIFIED, USER, SERVICE_ACCOUNT, GROUP, SHARED_DRIVE, CBCM_BROWSER, CHROME_OS_DEVICE, OTHER) |
updateTime | string (google-datetime) | Output only. The time when the Membership was last updated. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | groupsId, membershipsId | Retrieves a Membership. | |
list | select | groupsId | view, pageToken, pageSize | Lists the Memberships within a Group. |
create | insert | groupsId | Creates a Membership. | |
delete | delete | groupsId, membershipsId | Deletes a Membership. | |
check_transitive_membership | exec | groupsId | query | Check a potential member for membership in a group. Note: This feature is only available to Google Workspace Enterprise Standard, Enterprise Plus, and Enterprise for Education; and Cloud Identity Premium accounts. If the account of the member is not one of these, a 403 (PERMISSION_DENIED) HTTP status code will be returned. A member has membership to a group as long as there is a single viewable transitive membership between the group and the member. The actor must have view permissions to at least one transitive membership between the member and group. |
search_direct_groups | exec | groupsId | pageToken, pageSize, orderBy, query | Searches direct groups of a member. Groups for which the actor does not have the permission to view memberships are silently filtered out. |
search_transitive_memberships | exec | groupsId | pageToken, pageSize | Search transitive memberships of a group. Note: This feature is only available to Google Workspace Enterprise Standard, Enterprise Plus, and Enterprise for Education; and Cloud Identity Premium accounts. If the account of the group is not one of these, a 403 (PERMISSION_DENIED) HTTP status code will be returned. A transitive membership is any direct or indirect membership of a group. Actor must have view permissions to all transitive memberships. |
search_transitive_groups | exec | groupsId | query, pageToken, pageSize | Search transitive groups of a member. Note: This feature is only available to Google Workspace Enterprise Standard, Enterprise Plus, and Enterprise for Education; and Cloud Identity Premium accounts. If the account of the member is not one of these, a 403 (PERMISSION_DENIED) HTTP status code will be returned. A transitive group is any group that has a direct or indirect membership to the member. Actor must have view permissions all transitive groups. |
lookup | exec | groupsId | memberKey.id, memberKey.namespace | Looks up the resource name of a Membership by its EntityKey. |
modify_membership_roles | exec | groupsId, membershipsId | Modifies the MembershipRoles of a Membership. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
groupsId | string | |
membershipsId | string | |
memberKey.id | string | |
memberKey.namespace | string | |
orderBy | string | |
pageSize | integer (int32) | |
pageToken | string | |
query | string | |
view | string |
SELECT examples
- get
- list
Retrieves a Membership.
SELECT
name,
createTime,
deliverySetting,
preferredMemberKey,
roles,
type,
updateTime
FROM google.cloudidentity.memberships
WHERE groupsId = '{{ groupsId }}' -- required
AND membershipsId = '{{ membershipsId }}' -- required
;
Lists the Memberships within a Group.
SELECT
name,
createTime,
deliverySetting,
preferredMemberKey,
roles,
type,
updateTime
FROM google.cloudidentity.memberships
WHERE groupsId = '{{ groupsId }}' -- required
AND view = '{{ view }}'
AND pageToken = '{{ pageToken }}'
AND pageSize = '{{ pageSize }}'
;
INSERT examples
- create
- Manifest
Creates a Membership.
INSERT INTO google.cloudidentity.memberships (
data__preferredMemberKey,
data__roles,
groupsId
)
SELECT
'{{ preferredMemberKey }}',
'{{ roles }}',
'{{ groupsId }}'
RETURNING
name,
done,
error,
metadata,
response
;
# Description fields are for documentation purposes
- name: memberships
props:
- name: groupsId
value: "{{ groupsId }}"
description: Required parameter for the memberships resource.
- name: preferredMemberKey
description: |
Required. Immutable. The `EntityKey` of the member.
value:
namespace: "{{ namespace }}"
id: "{{ id }}"
- name: roles
description: |
The `MembershipRole`s that apply to the `Membership`. If unspecified, defaults to a single `MembershipRole` with `name` `MEMBER`. Must not contain duplicate `MembershipRole`s with the same `name`.
value:
- restrictionEvaluations:
memberRestrictionEvaluation:
state: "{{ state }}"
name: "{{ name }}"
expiryDetail:
expireTime: "{{ expireTime }}"
DELETE examples
- delete
Deletes a Membership.
DELETE FROM google.cloudidentity.memberships
WHERE groupsId = '{{ groupsId }}' --required
AND membershipsId = '{{ membershipsId }}' --required
;
Lifecycle Methods
- check_transitive_membership
- search_direct_groups
- search_transitive_memberships
- search_transitive_groups
- lookup
- modify_membership_roles
Check a potential member for membership in a group. Note: This feature is only available to Google Workspace Enterprise Standard, Enterprise Plus, and Enterprise for Education; and Cloud Identity Premium accounts. If the account of the member is not one of these, a 403 (PERMISSION_DENIED) HTTP status code will be returned. A member has membership to a group as long as there is a single viewable transitive membership between the group and the member. The actor must have view permissions to at least one transitive membership between the member and group.
EXEC google.cloudidentity.memberships.check_transitive_membership
@groupsId='{{ groupsId }}' --required,
@query='{{ query }}'
;
Searches direct groups of a member. Groups for which the actor does not have the permission to view memberships are silently filtered out.
EXEC google.cloudidentity.memberships.search_direct_groups
@groupsId='{{ groupsId }}' --required,
@pageToken='{{ pageToken }}',
@pageSize='{{ pageSize }}',
@orderBy='{{ orderBy }}',
@query='{{ query }}'
;
Search transitive memberships of a group. Note: This feature is only available to Google Workspace Enterprise Standard, Enterprise Plus, and Enterprise for Education; and Cloud Identity Premium accounts. If the account of the group is not one of these, a 403 (PERMISSION_DENIED) HTTP status code will be returned. A transitive membership is any direct or indirect membership of a group. Actor must have view permissions to all transitive memberships.
EXEC google.cloudidentity.memberships.search_transitive_memberships
@groupsId='{{ groupsId }}' --required,
@pageToken='{{ pageToken }}',
@pageSize='{{ pageSize }}'
;
Search transitive groups of a member. Note: This feature is only available to Google Workspace Enterprise Standard, Enterprise Plus, and Enterprise for Education; and Cloud Identity Premium accounts. If the account of the member is not one of these, a 403 (PERMISSION_DENIED) HTTP status code will be returned. A transitive group is any group that has a direct or indirect membership to the member. Actor must have view permissions all transitive groups.
EXEC google.cloudidentity.memberships.search_transitive_groups
@groupsId='{{ groupsId }}' --required,
@query='{{ query }}',
@pageToken='{{ pageToken }}',
@pageSize='{{ pageSize }}'
;
Looks up the resource name of a Membership by its EntityKey.
EXEC google.cloudidentity.memberships.lookup
@groupsId='{{ groupsId }}' --required,
@memberKey.id='{{ memberKey.id }}',
@memberKey.namespace='{{ memberKey.namespace }}'
;
Modifies the MembershipRoles of a Membership.
EXEC google.cloudidentity.memberships.modify_membership_roles
@groupsId='{{ groupsId }}' --required,
@membershipsId='{{ membershipsId }}' --required
@@json=
'{
"addRoles": "{{ addRoles }}",
"removeRoles": "{{ removeRoles }}",
"updateRolesParams": "{{ updateRolesParams }}"
}'
;