Queries the list of policy attachments by calling ListPolicyAttachments.
Operation description
You can query the following information:
All authorization records under an Alibaba Cloud account or a resource group.
All access policies granted to a Resource Access Management (RAM) user, RAM user group, or RAM role.
RAM users, RAM user groups, and RAM roles that have a specific permission under an Alibaba Cloud account or a resource group.
Try it now
Test
RAM authorization
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| ResourceGroupId |
string |
No |
The ID of the resource group or the Alibaba Cloud account ID to which the resource group belongs. If this parameter is left empty, all authorization records under the current account are listed. |
rg-001 |
| PolicyType |
string |
No |
The type of the access policy. If this parameter is left empty, all types of access policies are listed.
|
System |
| PolicyName |
string |
No |
Policy Name of the access policy. Policy Name must be 1 to 128 characters in length and can contain letters, digits, and hyphens (-). |
AdministratorAccess |
| PrincipalType |
string |
No |
The authorization object type. If this parameter is left empty, all types of authorization objects are listed.
|
IMSUser |
| PrincipalName |
string |
No |
The name of the principal. |
alice@demo.onaliyun.com |
| PageNumber |
integer |
No |
The page number. Minimum value: 1. Default value: 1. |
1 |
| PageSize |
integer |
No |
The number of entries per page. Valid values: 1 to 100. Default value: 10. |
10 |
| Language |
string |
No |
The language type. The description of the system access policy is returned in the specified language.
|
zh-CN |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| PageNumber |
integer |
The page number. |
1 |
| PageSize |
integer |
The number of entries per page. |
10 |
| PolicyAttachments |
object |
||
| PolicyAttachment |
array<object> |
The access policy information. |
|
|
object |
The access policy information. |
||
| AttachDate |
string |
The time when the policy was attached. The time is in RFC 3339 UTC format, indicated by Z. |
2015-01-23T12:33:18Z |
| Description |
string |
The description of the access policy. |
Administrator permissions |
| PolicyName |
string |
The name of the access policy. |
AdministratorAccess |
| PolicyType |
string |
The type of the access policy.
|
System |
| PrincipalName |
string |
The name of the principal. |
alice@demo.onaliyun.com |
| PrincipalType |
string |
The authorization object type.
|
IMSUser |
| ResourceGroupId |
string |
The ID of the resource group or the Alibaba Cloud account ID to which the resource group belongs. |
rg-9gLOoK**** |
| RequestId |
string |
The request ID. |
7B8A4E7D-6CFF-471D-84DF-195A7A241ECB |
| TotalCount |
integer |
The total number of entries returned. |
2 |
Examples
Success response
JSON format
{
"PageNumber": 1,
"PageSize": 10,
"PolicyAttachments": {
"PolicyAttachment": [
{
"AttachDate": "2015-01-23T12:33:18Z",
"Description": "管理员权限",
"PolicyName": "AdministratorAccess",
"PolicyType": "System",
"PrincipalName": "alice@demo.onaliyun.com",
"PrincipalType": "IMSUser",
"ResourceGroupId": "rg-9gLOoK****"
}
]
},
"RequestId": "7B8A4E7D-6CFF-471D-84DF-195A7A241ECB",
"TotalCount": 2
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | InvalidParameter.PolicyType | The specified policy type is invalid. | The specified policy type is invalid. |
| 404 | EntityNotExists.ResourceGroup | The specified resource group does not exist. You must first create a resource group. | The specified resource group does not exist. |
| 404 | EntityNotExist.Policy | The policy does not exist. | The policy does not exist. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.