Copyright | (c) 2013-2021 Brendan Hay |
---|---|
License | Mozilla Public License, v. 2.0. |
Maintainer | Brendan Hay <brendan.g.hay+amazonka@gmail.com> |
Stability | auto-generated |
Portability | non-portable (GHC extensions) |
Safe Haskell | None |
Creates an Amazon QuickSight user, whose identity is associated with the AWS Identity and Access Management (IAM) identity or role specified in the request.
Synopsis
- data RegisterUser = RegisterUser' {
- userName :: Maybe Text
- customPermissionsName :: Maybe Text
- customFederationProviderUrl :: Maybe Text
- externalLoginFederationProviderType :: Maybe Text
- iamArn :: Maybe Text
- externalLoginId :: Maybe Text
- sessionName :: Maybe Text
- identityType :: IdentityType
- email :: Text
- userRole :: UserRole
- awsAccountId :: Text
- namespace :: Text
- newRegisterUser :: IdentityType -> Text -> UserRole -> Text -> Text -> RegisterUser
- registerUser_userName :: Lens' RegisterUser (Maybe Text)
- registerUser_customPermissionsName :: Lens' RegisterUser (Maybe Text)
- registerUser_customFederationProviderUrl :: Lens' RegisterUser (Maybe Text)
- registerUser_externalLoginFederationProviderType :: Lens' RegisterUser (Maybe Text)
- registerUser_iamArn :: Lens' RegisterUser (Maybe Text)
- registerUser_externalLoginId :: Lens' RegisterUser (Maybe Text)
- registerUser_sessionName :: Lens' RegisterUser (Maybe Text)
- registerUser_identityType :: Lens' RegisterUser IdentityType
- registerUser_email :: Lens' RegisterUser Text
- registerUser_userRole :: Lens' RegisterUser UserRole
- registerUser_awsAccountId :: Lens' RegisterUser Text
- registerUser_namespace :: Lens' RegisterUser Text
- data RegisterUserResponse = RegisterUserResponse' {}
- newRegisterUserResponse :: Int -> RegisterUserResponse
- registerUserResponse_requestId :: Lens' RegisterUserResponse (Maybe Text)
- registerUserResponse_userInvitationUrl :: Lens' RegisterUserResponse (Maybe Text)
- registerUserResponse_user :: Lens' RegisterUserResponse (Maybe User)
- registerUserResponse_status :: Lens' RegisterUserResponse Int
Creating a Request
data RegisterUser Source #
See: newRegisterUser
smart constructor.
RegisterUser' | |
|
Instances
:: IdentityType | |
-> Text | |
-> UserRole | |
-> Text | |
-> Text | |
-> RegisterUser |
Create a value of RegisterUser
with all optional fields omitted.
Use generic-lens or optics to modify other optional fields.
The following record fields are available, with the corresponding lenses provided for backwards compatibility:
$sel:userName:RegisterUser'
, registerUser_userName
- The Amazon QuickSight user name that you want to create for the user you
are registering.
$sel:customPermissionsName:RegisterUser'
, registerUser_customPermissionsName
- (Enterprise edition only) The name of the custom permissions profile
that you want to assign to this user. Customized permissions allows you
to control a user's access by restricting access the following
operations:
- Create and update data sources
- Create and update datasets
- Create and update email reports
- Subscribe to email reports
To add custom permissions to an existing user, use UpdateUser
instead.
A set of custom permissions includes any combination of these
restrictions. Currently, you need to create the profile names for custom
permission sets by using the Amazon QuickSight console. Then, you use
the RegisterUser
API operation to assign the named set of permissions
to a Amazon QuickSight user.
Amazon QuickSight custom permissions are applied through IAMpolicies. Therefore, they override the permissions typically granted by assigning Amazon QuickSight users to one of the default security cohorts in Amazon QuickSight (admin, author, reader).
This feature is available only to Amazon QuickSight Enterprise edition subscriptions.
$sel:customFederationProviderUrl:RegisterUser'
, registerUser_customFederationProviderUrl
- The URL of the custom OpenID Connect (OIDC) provider that provides
identity to let a user federate into Amazon QuickSight with an
associated Identity and Access Management(IAM) role. This parameter
should only be used when ExternalLoginFederationProviderType
parameter
is set to CUSTOM_OIDC
.
$sel:externalLoginFederationProviderType:RegisterUser'
, registerUser_externalLoginFederationProviderType
- The type of supported external login provider that provides identity to
let a user federate into Amazon QuickSight with an associated Identity
and Access Management(IAM) role. The type of supported external login
provider can be one of the following.
COGNITO
: Amazon Cognito. The provider URL is cognito-identity.amazonaws.com. When choosing theCOGNITO
provider type, don’t use the "CustomFederationProviderUrl" parameter which is only needed when the external provider is custom.CUSTOM_OIDC
: Custom OpenID Connect (OIDC) provider. When choosingCUSTOM_OIDC
type, use theCustomFederationProviderUrl
parameter to provide the custom OIDC provider URL.
$sel:iamArn:RegisterUser'
, registerUser_iamArn
- The ARN of the IAMuser or role that you are registering with Amazon
QuickSight.
$sel:externalLoginId:RegisterUser'
, registerUser_externalLoginId
- The identity ID for a user in the external login provider.
$sel:sessionName:RegisterUser'
, registerUser_sessionName
- You need to use this parameter only when you register one or more users
using an assumed IAMrole. You don't need to provide the session name
for other scenarios, for example when you are registering an IAMuser or
an Amazon QuickSight user. You can register multiple users using the
same IAMrole if each user has a different session name. For more
information on assuming IAMroles, see
assume-role
in the AWS CLI Reference.
$sel:identityType:RegisterUser'
, registerUser_identityType
- Amazon QuickSight supports several ways of managing the identity of
users. This parameter accepts two values:
IAM
: A user whose identity maps to an existing IAMuser or role.QUICKSIGHT
: A user whose identity is owned and managed internally by Amazon QuickSight.
$sel:email:RegisterUser'
, registerUser_email
- The email address of the user that you want to register.
$sel:userRole:RegisterUser'
, registerUser_userRole
- The Amazon QuickSight role for the user. The user role can be one of the
following:
READER
: A user who has read-only access to dashboards.AUTHOR
: A user who can create data sources, datasets, analyses, and dashboards.ADMIN
: A user who is an author, who can also manage Amazon QuickSight settings.RESTRICTED_READER
: This role isn't currently available for use.RESTRICTED_AUTHOR
: This role isn't currently available for use.
$sel:awsAccountId:RegisterUser'
, registerUser_awsAccountId
- The ID for the Amazon Web Services account that the user is in.
Currently, you use the ID for the Amazon Web Services account that
contains your Amazon QuickSight account.
$sel:namespace:RegisterUser'
, registerUser_namespace
- The namespace. Currently, you should set this to default
.
Request Lenses
registerUser_userName :: Lens' RegisterUser (Maybe Text) Source #
The Amazon QuickSight user name that you want to create for the user you are registering.
registerUser_customPermissionsName :: Lens' RegisterUser (Maybe Text) Source #
(Enterprise edition only) The name of the custom permissions profile that you want to assign to this user. Customized permissions allows you to control a user's access by restricting access the following operations:
- Create and update data sources
- Create and update datasets
- Create and update email reports
- Subscribe to email reports
To add custom permissions to an existing user, use UpdateUser
instead.
A set of custom permissions includes any combination of these
restrictions. Currently, you need to create the profile names for custom
permission sets by using the Amazon QuickSight console. Then, you use
the RegisterUser
API operation to assign the named set of permissions
to a Amazon QuickSight user.
Amazon QuickSight custom permissions are applied through IAMpolicies. Therefore, they override the permissions typically granted by assigning Amazon QuickSight users to one of the default security cohorts in Amazon QuickSight (admin, author, reader).
This feature is available only to Amazon QuickSight Enterprise edition subscriptions.
registerUser_customFederationProviderUrl :: Lens' RegisterUser (Maybe Text) Source #
The URL of the custom OpenID Connect (OIDC) provider that provides
identity to let a user federate into Amazon QuickSight with an
associated Identity and Access Management(IAM) role. This parameter
should only be used when ExternalLoginFederationProviderType
parameter
is set to CUSTOM_OIDC
.
registerUser_externalLoginFederationProviderType :: Lens' RegisterUser (Maybe Text) Source #
The type of supported external login provider that provides identity to let a user federate into Amazon QuickSight with an associated Identity and Access Management(IAM) role. The type of supported external login provider can be one of the following.
COGNITO
: Amazon Cognito. The provider URL is cognito-identity.amazonaws.com. When choosing theCOGNITO
provider type, don’t use the "CustomFederationProviderUrl" parameter which is only needed when the external provider is custom.CUSTOM_OIDC
: Custom OpenID Connect (OIDC) provider. When choosingCUSTOM_OIDC
type, use theCustomFederationProviderUrl
parameter to provide the custom OIDC provider URL.
registerUser_iamArn :: Lens' RegisterUser (Maybe Text) Source #
The ARN of the IAMuser or role that you are registering with Amazon QuickSight.
registerUser_externalLoginId :: Lens' RegisterUser (Maybe Text) Source #
The identity ID for a user in the external login provider.
registerUser_sessionName :: Lens' RegisterUser (Maybe Text) Source #
You need to use this parameter only when you register one or more users using an assumed IAMrole. You don't need to provide the session name for other scenarios, for example when you are registering an IAMuser or an Amazon QuickSight user. You can register multiple users using the same IAMrole if each user has a different session name. For more information on assuming IAMroles, see assume-role in the AWS CLI Reference.
registerUser_identityType :: Lens' RegisterUser IdentityType Source #
Amazon QuickSight supports several ways of managing the identity of users. This parameter accepts two values:
IAM
: A user whose identity maps to an existing IAMuser or role.QUICKSIGHT
: A user whose identity is owned and managed internally by Amazon QuickSight.
registerUser_email :: Lens' RegisterUser Text Source #
The email address of the user that you want to register.
registerUser_userRole :: Lens' RegisterUser UserRole Source #
The Amazon QuickSight role for the user. The user role can be one of the following:
READER
: A user who has read-only access to dashboards.AUTHOR
: A user who can create data sources, datasets, analyses, and dashboards.ADMIN
: A user who is an author, who can also manage Amazon QuickSight settings.RESTRICTED_READER
: This role isn't currently available for use.RESTRICTED_AUTHOR
: This role isn't currently available for use.
registerUser_awsAccountId :: Lens' RegisterUser Text Source #
The ID for the Amazon Web Services account that the user is in. Currently, you use the ID for the Amazon Web Services account that contains your Amazon QuickSight account.
registerUser_namespace :: Lens' RegisterUser Text Source #
The namespace. Currently, you should set this to default
.
Destructuring the Response
data RegisterUserResponse Source #
See: newRegisterUserResponse
smart constructor.
RegisterUserResponse' | |
|
Instances
newRegisterUserResponse Source #
Create a value of RegisterUserResponse
with all optional fields omitted.
Use generic-lens or optics to modify other optional fields.
The following record fields are available, with the corresponding lenses provided for backwards compatibility:
$sel:requestId:RegisterUserResponse'
, registerUserResponse_requestId
- The Amazon Web Services request ID for this operation.
$sel:userInvitationUrl:RegisterUserResponse'
, registerUserResponse_userInvitationUrl
- The URL the user visits to complete registration and provide a password.
This is returned only for users with an identity type of QUICKSIGHT
.
$sel:user:RegisterUserResponse'
, registerUserResponse_user
- The user's user name.
$sel:status:RegisterUserResponse'
, registerUserResponse_status
- The HTTP status of the request.
Response Lenses
registerUserResponse_requestId :: Lens' RegisterUserResponse (Maybe Text) Source #
The Amazon Web Services request ID for this operation.
registerUserResponse_userInvitationUrl :: Lens' RegisterUserResponse (Maybe Text) Source #
The URL the user visits to complete registration and provide a password.
This is returned only for users with an identity type of QUICKSIGHT
.
registerUserResponse_user :: Lens' RegisterUserResponse (Maybe User) Source #
The user's user name.
registerUserResponse_status :: Lens' RegisterUserResponse Int Source #
The HTTP status of the request.