| Product |
Abbreviation in CAM |
Console |
Authorization by Tag |
Authorization Granularity |
IP Restriction |
| Intelligent Guidance |
ig |
Supported |
not supported |
Operation level |
Supported |
Note:
The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.
- Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
- Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
- Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.
API authorization granularity
Two authorization granularity levels of API are supported: resource level, and operation level.
- Resource level: It supports the authorization of a specific resource.
- Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.
Write operations
| API |
API Description |
Authorization Granularity |
Six-segment Resource Description |
IP Restriction |
| AddTokensPackage |
Add Tokens Package |
Operation level |
* |
Supported |
| BindOpenPlatform |
Bind Open Platform |
Operation level |
* |
Supported |
| CloseService |
Close Service |
Operation level |
* |
Supported |
| DestroyPostPackage |
Destroy Post Package |
Operation level |
* |
Supported |
| GetOpenPlatformInfo |
Get Open Platform Info |
Operation level |
* |
Supported |
| ModifyGlobalServiceStatus |
Modify Global Service Status |
Operation level |
* |
Supported |
| ModifyHospitalName |
Modify Hospital Name |
Operation level |
* |
Supported |
| ModifyHospitalStatus |
Modify Hospital Status |
Operation level |
* |
Supported |
| OpenService |
Open Service |
Operation level |
* |
Supported |
| UnbindGuideOpenPlatform |
Unbind Guide Open Platform |
Operation level |
* |
Supported |
List Operations
| API |
API Description |
Authorization Granularity |
Six-segment Resource Description |
IP Restriction |
| DescribeGlobalOrderList |
Describe Global Order List |
Operation level |
* |
Supported |
| DescribeIgOrderList |
Describe Ig Order List |
Operation level |
* |
Supported |
| DescribeTokensPackageList |
Describe Tokens Package List |
Operation level |
* |
Supported |
Read operations
| API |
API Description |
Authorization Granularity |
Six-segment Resource Description |
IP Restriction |
| DescribeHospitalToken |
Describe Hospital Token |
Operation level |
* |
Supported |
| DescribeServiceOverView |
Describe Service OverView |
Operation level |
* |
Supported |
| DescribeServiceStatus |
Describe Service Status |
Operation level |
* |
Supported |
| GetLLMDiagnosisDrug |
LLM Diagnosis Drug |
Operation level |
* |
Supported |
| GetLLMDiagnosisDrugChat |
LLM Diagnosis Drug Chat |
Operation level |
* |
Supported |
| GetLLMDiagnosisHealth |
LLM Diagnosis Health |
Operation level |
* |
Supported |
| GetLLMReportInterpretation |
LLM Report Interpretation |
Operation level |
* |
Supported |
| GetWhiteList |
Get White List |
Operation level |
* |
Supported |
| IsBindGuideOpenPlatform |
Is Bind Guide Open Platform |
Operation level |
* |
Supported |
| QueryDrugInstructions |
Query DrugInstructions |
Operation level |
* |
Supported |