Legal holds, step 1: the hold itself
inbuxa:LegalHold get/set places a hold on accounts, groups, domains, tenants or the whole server, with an optional date range. A hold's range and scope can only widen, a released hold is read-only, and none is ever deleted. Placing, changing and releasing each need a reason and are audited (LH-1, LH-3, LH-10, AU-12). Permissions 669-672 (see, place, widen or release, export held data) go to server administrators only; the tenant ceiling always strips them, as it does Impersonate (LH-13). Schema: Compliance > Legal Holds. What a hold keeps comes next, through the undelete hooks. Also moves the lock expiry helpers below the lock module's imports.
This commit is contained in:
@@ -7080,6 +7080,10 @@ impl EnumImpl for Permission {
|
||||
b"sysAccountLockCreate" => Permission::SysAccountLockCreate,
|
||||
b"sysAccountLockUpdate" => Permission::SysAccountLockUpdate,
|
||||
b"sysAccountLockDestroy" => Permission::SysAccountLockDestroy,
|
||||
b"sysLegalHoldGet" => Permission::SysLegalHoldGet,
|
||||
b"sysLegalHoldCreate" => Permission::SysLegalHoldCreate,
|
||||
b"sysLegalHoldUpdate" => Permission::SysLegalHoldUpdate,
|
||||
b"sysLegalHoldExport" => Permission::SysLegalHoldExport,
|
||||
b"sysAccountGet" => Permission::SysAccountGet,
|
||||
b"sysAccountCreate" => Permission::SysAccountCreate,
|
||||
b"sysAccountUpdate" => Permission::SysAccountUpdate,
|
||||
@@ -7765,6 +7769,10 @@ impl EnumImpl for Permission {
|
||||
Permission::SysAccountLockCreate => "sysAccountLockCreate",
|
||||
Permission::SysAccountLockUpdate => "sysAccountLockUpdate",
|
||||
Permission::SysAccountLockDestroy => "sysAccountLockDestroy",
|
||||
Permission::SysLegalHoldGet => "sysLegalHoldGet",
|
||||
Permission::SysLegalHoldCreate => "sysLegalHoldCreate",
|
||||
Permission::SysLegalHoldUpdate => "sysLegalHoldUpdate",
|
||||
Permission::SysLegalHoldExport => "sysLegalHoldExport",
|
||||
Permission::SysAccountGet => "sysAccountGet",
|
||||
Permission::SysAccountCreate => "sysAccountCreate",
|
||||
Permission::SysAccountUpdate => "sysAccountUpdate",
|
||||
@@ -8443,6 +8451,10 @@ impl EnumImpl for Permission {
|
||||
666 => Some(Permission::SysAccountLockCreate),
|
||||
667 => Some(Permission::SysAccountLockUpdate),
|
||||
668 => Some(Permission::SysAccountLockDestroy),
|
||||
669 => Some(Permission::SysLegalHoldGet),
|
||||
670 => Some(Permission::SysLegalHoldCreate),
|
||||
671 => Some(Permission::SysLegalHoldUpdate),
|
||||
672 => Some(Permission::SysLegalHoldExport),
|
||||
219 => Some(Permission::SysAccountGet),
|
||||
220 => Some(Permission::SysAccountCreate),
|
||||
221 => Some(Permission::SysAccountUpdate),
|
||||
@@ -8887,7 +8899,7 @@ impl EnumImpl for Permission {
|
||||
}
|
||||
}
|
||||
|
||||
const COUNT: usize = 669;
|
||||
const COUNT: usize = 673;
|
||||
}
|
||||
|
||||
impl serde::Serialize for Permission {
|
||||
|
||||
Reference in New Issue
Block a user