This topic describes the authorization system of the Low-Code Development Platform and the RAM authorization flow.
Authorization system for Mobi Platform members
The Low-Code Development Platform uses the Alibaba Cloud account system to manage user permissions. The authentication process includes two types of permissions: platform-level and workspace-level. Before a RAM user can access the Low-Code Development Platform, they must request the required RAM permissions from the root account. After RAM authorization is complete, you must add the member and their role in the workspace settings to grant workspace-level permissions. This is required to access resources in a specific workspace.
How to grant RAM authorization
RAM authorization is the process of granting specific permissions to an account in the RAM console.
The Low-Code Development Platform provides two permissions in the RAM console. You must complete the RAM authorization before a RAM user can access the Low-Code Development Platform. Otherwise, a permission error may occur.
After adding RAM account management capabilities to the ADMIN role, an administrator can manage the platform permissions for other RAM users. They can also manage ADMIN and DEV members within their workspace.
Permission name |
Note |
Managing permissions for the Low-Code Development Platform (MOBILCDPDEV) |
|
Grants read-only access to Low-Code Development Platform (MOBILCDPDEV). |
|
AliyunRAMFullAccess |
Grants permissions to manage Resource Access Management (RAM). This includes managing users and their authorizations. |
Only an account with permissions to operate RAM can grant RAM authorizations.
No permission page
If a RAM user tries to access the Low-Code Development Platform without RAM authorization, they are redirected to a no permission page.
Configuration steps
1. Configure RAM permissions
Configuration page: RAM Configuration
2. Configure workspace permissions
Configuration page: Low-Code Development Platform console