
# 身份策略授权参考
云服务在IAM预置了常用的权限，称为系统身份策略。如果IAM系统身份策略无法满足授权要求，管理员可以根据各服务支持的授权项，创建IAM自定义身份策略来进行精细的访问控制，IAM自定义身份策略是对系统身份策略的扩展和补充。
除IAM服务外，[Organizations](https://support.huaweicloud.com/productdesc-organizations/org_01_0011.html)服务中的[服务控制策略](https://support.huaweicloud.com/usermanual-organizations/org_03_0065.html)（Service Control Policy，以下简称SCP）也可以使用这些授权项元素设置访问控制策略。
SCP不直接进行授权，只划定权限边界。将SCP绑定到组织单元或者成员账号时，并没有直接对组织单元或成员账号授予操作权限，而是规定了成员账号或组织单元包含的成员账号的授权范围。IAM身份策略授予权限的有效性受SCP限制，只有在SCP允许范围内的权限才能生效。
IAM服务与Organizations服务在使用这些元素进行访问控制时，存在着一些区别，详情请参见：[IAM服务与Organizations服务权限访问控制的区别](https://support.huaweicloud.com/organizations_faq/org_06_0004.html)。
本章节介绍IAM服务身份策略授权场景中自定义身份策略和组织服务中SCP使用的元素，这些元素包含了操作（Action）、资源（Resource）和条件（Condition）。
- 如何使用这些元素编辑IAM自定义身份策略，请参考[创建自定义身份策略](https://support.huaweicloud.com/usermanual-iam5/iam_01_0917.html)。
- 如何使用这些元素编辑SCP自定义策略，请参考[创建SCP](https://support.huaweicloud.com/usermanual-organizations/org_03_0035.html)。
#### 操作（Action）
操作（Action）即为身份策略中支持的授权项。
- "访问级别"列描述如何对操作进行分类（List、Read和Write等）。此分类可帮助您了解在身份策略中相应操作对应的访问级别。
- "资源类型"列指每个操作是否支持资源级权限。
  - 资源类型支持通配符号\*表示所有。如果此列没有值（-），则必须在身份策略语句的Resource元素中指定所有资源类型（"\*"）。
  
  - 如果该列包含资源类型，则必须在具有该操作的语句中指定该资源的URN。
  
  - 资源类型列中必需资源在表中用星号（\*）标识，表示使用此操作必须指定该资源类型。
  
  
  关于CodeArts Req定义的资源类型的详细信息请参见[资源类型（Resource）]。
  
- "条件键"列包括了可以在身份策略语句的Condition元素中支持指定的键值。
  - 如果该授权项资源类型列存在值，则表示条件键仅对列举的资源类型生效。
  
  - 如果该授权项资源类型列没有值（-），则表示条件键对整个授权项生效。
  
  - 如果此列条件键没有值（-），表示此操作不支持指定条件键。
  
  
  关于CodeArts Req定义的条件键的详细信息请参见[条件（Condition）]。
  
- "别名"列包括了可以在身份策略中配置的策略授权项。通过这些授权项，可以控制支持策略授权的API访问。详细信息请参见[身份策略兼容性说明](https://support.huaweicloud.com/iam5_faq/iam_01_1103.html)。
您可以在身份策略语句的Action元素中指定以下CodeArts Req的相关操作。
表1CodeArts Req支持的授权项 
| 授权项                                            | 描述                      | 访问级别  | 资源类型（\*为必须） | 条件键                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | 别名                                      |
|:---|:---|:---|:---|:---|:---|
| codeartsreq::createTenantConfiguration         | 授予权限以创建租户配置。            | Write | -           | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | -                                       |
| codeartsreq::listOffering                      | 授予权限以获取已经安装的服务。         | Read  | -           | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | -                                       |
| codeartsreq::updateTenantConfiguration         | 授予权限以更新租户配置。            | Write | -           | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | projectmanConfig:template:update        |
| codeartsreq::setImportedWorkitemCreator        | 授予权限以设置导入工作项创建者。        | Write | -           | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | projectmanConfig:systemSettingField:set |
| codeartsreq::deleteTenantConfiguration         | 授予权限以删除租户配置。            | Write | -           | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | projectmanConfig:template:delete        |
| codeartsreq:workitem:get                       | 授予权限以查看工作项资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workitem:list                      | 授予权限以查询工作项资源。           | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workitem:create                    | 授予权限以创建工作项资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workitem:update                    | 授予权限以更新工作项资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workitem:collaborate               | 授予权限以更新工作项资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workitem:delete                    | 授予权限以删除工作项资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workitem:import                    | 授予权限以导入工作项资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workitem:export                    | 授予权限以导出工作项资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:iteration:get                      | 授予权限以查看迭代资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:iteration:list                     | 授予权限以查询迭代资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:iteration:create                   | 授予权限以创建迭代资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:iteration:update                   | 授予权限以更新迭代资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:iteration:delete                   | 授予权限以删除迭代资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:iteration:import                   | 授予权限以导入迭代资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:iteration:export                   | 授予权限以导出迭代资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:plan:get                           | 授予权限以查看规划资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:plan:list                          | 授予权限以查询规划资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:plan:create                        | 授予权限以创建规划资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:plan:update                        | 授予权限以更新规划资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:plan:delete                        | 授予权限以删除规划资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:plan:import                        | 授予权限以导入规划资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:plan:export                        | 授予权限以导出规划资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:plan:baseline                      | 授予权限以基线规划资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:report:get                         | 授予权限以查看报表资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:report:list                        | 授予权限以查询报表资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:report:create                      | 授予权限以创建报表资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:report:update                      | 授予权限以更新报表资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:report:delete                      | 授予权限以删除报表资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:dashboard:get                      | 授予权限以查看仪表盘资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:dashboard:list                     | 授予权限以查询仪表盘资源。           | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:dashboard:create                   | 授予权限以创建仪表盘资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:dashboard:update                   | 授予权限以更新仪表盘资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:dashboard:delete                   | 授予权限以删除仪表盘资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:recycleBin:get                     | 授予权限以查看回收站资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:recycleBin:list                    | 授予权限以查询回收站资源。           | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:recycleBin:update                  | 授予权限以更新回收站资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:recycleBin:delete                  | 授予权限以删除回收站资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:defect:get                         | 授予权限以查看缺陷资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:defect:list                        | 授予权限以查询缺陷资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:defect:create                      | 授予权限以创建缺陷资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:defect:update                      | 授予权限以更新缺陷资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:defect:delete                      | 授予权限以删除缺陷资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:defect:import                      | 授予权限以导入缺陷资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:defect:export                      | 授予权限以导出缺陷资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:defect:collaborate                 | 授予权限以协同缺陷资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:configuration:get                  | 授予权限以查看工作配置资源。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:configuration:list                 | 授予权限以查询工作配置资源。          | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:configuration:share                | 授予权限以共享工作配置资源。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:configuration:create               | 授予权限以创建工作配置资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:configuration:update               | 授予权限以更新工作配置资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:configuration:delete               | 授予权限以删除工作配置资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:feature:get                        | 授予权限以查看特性资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:feature:list                       | 授予权限以查询特性资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:feature:create                     | 授予权限以创建特性资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:feature:update                     | 授予权限以更新特性资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:feature:delete                     | 授予权限以删除特性资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:feature:import                     | 授予权限以导入特性资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:feature:export                     | 授予权限以导出特性资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:get                     | 授予权限以查看特性集资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:list                    | 授予权限以查询特性集资源。           | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:create                  | 授予权限以创建特性集资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:baseline                | 授予权限以基线特性集资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:update                  | 授予权限以更新特性集资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:delete                  | 授予权限以删除特性集资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:import                  | 授予权限以导入特性集资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:export                  | 授予权限以导出特性集资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:developmentRequirement:get         | 授予权限以查看研发需求资源。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:developmentRequirement:list        | 授予权限以查询研发需求资源。          | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:developmentRequirement:create      | 授予权限以创建研发需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:developmentRequirement:update      | 授予权限以更新研发需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:developmentRequirement:collaborate | 授予权限以协同研发需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:developmentRequirement:delete      | 授予权限以删除研发需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:developmentRequirement:import      | 授予权限以导入研发需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:developmentRequirement:export      | 授予权限以导出研发需求资源。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:review:get                         | 授予权限以查看评审资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:review:list                        | 授予权限以查询评审资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:review:create                      | 授予权限以创建评审资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:review:update                      | 授予权限以更新评审资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:review:delete                      | 授予权限以删除评审资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:rawRequirement:get                 | 授予权限以查看原始需求资源。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:rawRequirement:list                | 授予权限以查询原始需求资源。          | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:rawRequirement:create              | 授予权限以创建原始需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:rawRequirement:update              | 授予权限以更新原始需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:rawRequirement:collaborate         | 授予权限以协同原始需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:rawRequirement:delete              | 授予权限以删除原始需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:rawRequirement:import              | 授予权限以导入原始需求资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:rawRequirement:export              | 授予权限以导出原始需求资源。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:task:get                           | 授予权限以查看任务资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:task:list                          | 授予权限以查询任务资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:task:create                        | 授予权限以创建任务资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:task:update                        | 授予权限以更新任务资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:task:delete                        | 授予权限以删除任务资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:project:get                        | 授予权限以查看项目资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:project:list                       | 授予权限以查询项目资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:project:create                     | 授予权限以创建项目资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:project:update                     | 授予权限以更新项目资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:project:delete                     | 授予权限以删除项目资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:member:get                         | 授予权限以查看成员资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:member:list                        | 授予权限以查询成员资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:member:create                      | 授予权限以创建成员资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:member:update                      | 授予权限以更新成员资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:member:delete                      | 授予权限以删除成员资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:custom:get                         | 授予权限以查看自定义资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:custom:list                        | 授予权限以查询自定义资源。           | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:custom:create                      | 授予权限以创建自定义资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:custom:update                      | 授予权限以更新自定义资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:custom:delete                      | 授予权限以删除自定义资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:tag:get                            | 授予权限以查看标签资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:tag:list                           | 授予权限以查询标签资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:tag:create                         | 授予权限以创建标签资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:tag:update                         | 授予权限以更新标签资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:tag:delete                         | 授予权限以删除标签资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workhour:get                       | 授予权限以查看工时资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workhour:list                      | 授予权限以查询工时资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workhour:create                    | 授予权限以创建工时资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workhour:update                    | 授予权限以更新工时资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workhour:delete                    | 授予权限以删除工时资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:attachment:get                     | 授予权限以获取附件详情。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:attachment:download                | 授予权限以下载附件资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:attachment:list                    | 授予权限以查询附件资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:attachment:upload                  | 授予权限以创建附件资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:attachment:delete                  | 授予权限以删除附件资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:release:get                        | 授予权限以查看发布计划资源。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:release:list                       | 授予权限以查询发布计划资源。          | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:release:create                     | 授予权限以创建发布计划资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:release:update                     | 授予权限以更新发布计划资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:release:delete                     | 授予权限以删除发布计划资源。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:risk:get                           | 授予权限以查看风险资源。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:risk:list                          | 授予权限以查询风险资源。            | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:risk:create                        | 授予权限以创建风险资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:risk:update                        | 授予权限以更新风险资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:risk:delete                        | 授予权限以删除风险资源。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workflow:get                       | 授予权限以查看工作流资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workflow:list                      | 授予权限以查询工作流资源。           | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workflow:create                    | 授予权限以创建工作流资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workflow:update                    | 授予权限以更新工作流资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workflow:delete                    | 授予权限以删除工作流资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workflow:execute                   | 授予权限以运行工作流资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:automation:get                     | 授予权限以查看自动化资源。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:automation:list                    | 授予权限以查询自动化资源。           | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:automation:create                  | 授予权限以创建自动化资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:automation:update                  | 授予权限以更新自动化资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:automation:delete                  | 授予权限以删除自动化资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:automation:execute                 | 授予权限以执行自动化资源。           | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:report:export                      | 授予权限以下载报表。              | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::showGuide                         | 授予权限以显示用户指导。            | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::listValidModels                   | 授予权限以查询可用的模型。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:attachment:update                  | 授予权限以更新附件。              | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:createBaseline          | 授予权限以创建基线快照。            | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:listBaseline            | 授予权限以获取基线快照列表。          | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:featureSet:getBaseline             | 授予权限以获取基线快照详情。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::downloadImportAndExportRecord     | 授予权限以下载导入导出记录。          | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::queryRecordList                   | 授予权限以查询导入导出记录列表。        | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::getUnReachableActivity            | 授予权限以校验不可达事件。           | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::showWorkItemFlowRightObjectInfo   | 授予权限以查询工作流实体信息。         | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::saveBehavior                      | 授予权限以保存看板用户行为。          | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::updateIssueAccessorySize          | 授予权限以更新scrum工作项的附件大小。   | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::updateJobCache                    | 授予权限以更新scrum用户操作历史缓存。   | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::listScrumJobCache                 | 授予权限以查询scrum用户操作历史缓存列表。 | List  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq::createJobCache                    | 授予权限以创建scrum用户操作缓存。     | Write | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
| codeartsreq:workhour:export                    | 授予权限以下载工时。              | Read  | -           | - [codeartsreq:Model]  - [codeartsreq:ProjectId]   | -                                       |
   
CodeArts Req的API通常对应着一个或多个授权项。[表2]展示了API与授权项的关系，以及该API需要依赖的授权项。
 表2API与授权项的关系 
| API                                                                                                                                                                          | 对应的授权项                                    | 依赖的授权项 |
|:---|:---|:---|
| -                                                                                                                                                                            | codeartsreq:rawRequirement:update         | -      |
| [POST /v4/projects/{project_id}/issues/{issue_id}/work-hours](https://support.huaweicloud.com/api-projectman/AddIssueWorkHours.html)                                         | codeartsreq:workhour:create               | -      |
| -                                                                                                                                                                            | codeartsreq:iteration:create              | -      |
| -                                                                                                                                                                            | codeartsreq:member:create                 | -      |
| -                                                                                                                                                                            | codeartsreq:project:create                | -      |
| -                                                                                                                                                                            | codeartsreq:developmentRequirement:create | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:create               | -      |
| -                                                                                                                                                                            | codeartsreq:rawRequirement:create         | -      |
| -                                                                                                                                                                            | codeartsreq:developmentRequirement:create | -      |
| -                                                                                                                                                                            | codeartsreq:developmentRequirement:delete | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:delete               | -      |
| [DELETE /v4/projects/{project_id}/issues](https://support.huaweicloud.com/api-projectman/BatchDeleteIssuesV4.html)                                                           | codeartsreq:workitem:delete               | -      |
| [DELETE /v4/projects/{project_id}/iterations](https://support.huaweicloud.com/api-projectman/BatchDeleteIterationsV4.html)                                                   | codeartsreq:iteration:delete              | -      |
| [DELETE /v1/planservice/projects/{project_id}/plans/batch-delete](https://support.huaweicloud.com/api-projectman/BatchDeletePlans.html)                                      | codeartsreq:plan:delete                   | -      |
| -                                                                                                                                                                            | codeartsreq:project:delete                | -      |
| -                                                                                                                                                                            | codeartsreq:iteration:delete              | -      |
| -                                                                                                                                                                            | codeartsreq:rawRequirement:delete         | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| [PUT /v1/planservice/projects/{project_id}/plans/batch-baseline](https://support.huaweicloud.com/api-projectman/BatchUpdateBaseline.html)                                    | codeartsreq:plan:baseline                 | -      |
| [PUT /v4/domain/child-users](https://support.huaweicloud.com/api-projectman/BatchUpdateChildNickNames.html)                                                                  | codeartsreq:member:update                 | -      |
| -                                                                                                                                                                            | codeartsreq:developmentRequirement:update | -      |
| [PUT /v2/projects/{project_id}/issues/batch-update](https://support.huaweicloud.com/api-projectman/BatchUpdateIssues.html)                                                   | codeartsreq:workitem:update               | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:update               | -      |
| [DELETE /v4/projects/{project_id}/domains/{domain_id}](https://support.huaweicloud.com/api-projectman/CancelProjectDomain.html)                                              | codeartsreq:configuration:delete          | -      |
| [PUT /v1/planservice/projects/{project_id}/plans/{plan_id}/status](https://support.huaweicloud.com/api-projectman/ChangePlanStatus.html)                                     | codeartsreq:plan:update                   | -      |
| -                                                                                                                                                                            | codeartsreq:rawRequirement:update         | -      |
| [POST /v3/{project_id}/custom-fields](https://support.huaweicloud.com/api-projectman/CreateCustomfields.html)                                                                | codeartsreq:custom:create                 | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/review](https://support.huaweicloud.com/api-projectman/CreateIpdChangeReviewForm.html)                                     | codeartsreq:review:create                 | -      |
| -                                                                                                                                                                            | codeartsreq:featureSet:create             | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/modules](https://support.huaweicloud.com/api-projectman/CreateIpdModule.html)                                              | codeartsreq:configuration:create          | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/process-instances](https://support.huaweicloud.com/api-projectman/CreateIpdProcessInstance.html)                           | codeartsreq:workflow:create               | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/issues](https://support.huaweicloud.com/api-projectman/CreateIpdProjectIssue.html)                                         | codeartsreq:workitem:create               | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/issues/{issue_id}/attachments/upload](https://support.huaweicloud.com/api-projectman/CreateIpdProjectIssueAttachment.html) | codeartsreq:attachment:upload             | -      |
| -                                                                                                                                                                            | codeartsreq:tag:create                    | -      |
| [POST /v4/projects/{project_id}/issue](https://support.huaweicloud.com/api-projectman/CreateIssueV4.html)                                                                    | codeartsreq:workitem:create               | -      |
| [POST /v4/projects/{project_id}/iteration](https://support.huaweicloud.com/api-projectman/CreateIterationV4.html)                                                            | codeartsreq:iteration:create              | -      |
| [POST /v1/planservice/projects/{project_id}/plans](https://support.huaweicloud.com/api-projectman/CreatePlans.html)                                                          | codeartsreq:plan:create                   | -      |
| -                                                                                                                                                                            | codeartsreq:project:create                | -      |
| -                                                                                                                                                                            | codeartsreq:release:create                | -      |
| [POST /v4/projects/{project_id}/domain](https://support.huaweicloud.com/api-projectman/CreateProjectDomain.html)                                                             | codeartsreq:configuration:create          | -      |
| [POST /v4/projects/{project_id}/module](https://support.huaweicloud.com/api-projectman/CreateProjectModule.html)                                                             | codeartsreq:configuration:create          | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/plan/snapshots](https://support.huaweicloud.com/api-projectman/CreateSprintSnapshots.html)                                 | codeartsreq:iteration:update              | -      |
| [POST /v4/projects/{project_id}/system/issue](https://support.huaweicloud.com/api-projectman/CreateSystemIssueV4.html)                                                       | codeartsreq:workitem:create               | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/work-items/{workitem_id}/work-hour](https://support.huaweicloud.com/api-projectman/CreateWorkHourOpenApi.html)             | codeartsreq:workhour:create               | -      |
| [DELETE /v4/projects/{project_id}/issues/{issue_id}/attachments/{attachment_id}](https://support.huaweicloud.com/api-projectman/DeleteAttachment.html)                       | codeartsreq:attachment:upload             | -      |
| [DELETE /v1/ipdprojectservice/projects/{project_id}/feature-sets/{feature_set_id}](https://support.huaweicloud.com/api-projectman/DeleteFeatureSetApi.html)                  | codeartsreq:featureSet:delete             | -      |
| [DELETE /v1/ipdprojectservice/projects/{project_id}/review/{review_id}](https://support.huaweicloud.com/api-projectman/DeleteIpdChangeReviewForm.html)                       | codeartsreq:review:delete                 | -      |
| [DELETE /v2/ipdprojectservice/projects/{project_id}/images](https://support.huaweicloud.com/api-projectman/DeleteIpdImageInIssue.html)                                       | codeartsreq:workitem:update               | -      |
| [DELETE /v1/ipdprojectservice/projects/{project_id}/tags/{label_id}](https://support.huaweicloud.com/api-projectman/DeleteIpdLabel.html)                                     | codeartsreq:tag:delete                    | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:delete          | -      |
| [DELETE /v1/ipdprojectservice/projects/{project_id}/process-instances/{review_id}](https://support.huaweicloud.com/api-projectman/DeleteIpdProcessInstance.html)             | codeartsreq:workflow:delete               | -      |
| [DELETE /v4/projects/{project_id}/issues/{issue_id}](https://support.huaweicloud.com/api-projectman/DeleteIssueV4.html)                                                      | codeartsreq:workitem:delete               | -      |
| [DELETE /v4/projects/{project_id}/iterations/{iteration_id}](https://support.huaweicloud.com/api-projectman/DeleteIterationV4.html)                                          | codeartsreq:iteration:delete              | -      |
| -                                                                                                                                                                            | codeartsreq:project:delete                | -      |
| -                                                                                                                                                                            | codeartsreq:member:delete                 | -      |
| -                                                                                                                                                                            | codeartsreq:release:delete                | -      |
| [DELETE /v4/projects/{project_id}/modules/{module_id}](https://support.huaweicloud.com/api-projectman/DeleteProjectModule.html)                                              | codeartsreq:configuration:delete          | -      |
| [DELETE /v1/projects/{project_id}/work-items/{issue_id}/work-hour/{workhour_id}](https://support.huaweicloud.com/api-projectman/DeleteWorkHourOpenApi.html)                  | codeartsreq:workhour:delete               | -      |
| [GET /v4/projects/{project_id}/issues/{issue_id}/attachments/{attachment_id}](https://support.huaweicloud.com/api-projectman/DownloadAttachment.html)                        | codeartsreq:attachment:download           | -      |
| [GET /v4/projects/{project_id}/image-file](https://support.huaweicloud.com/api-projectman/DownloadImageFile.html)                                                            | codeartsreq:attachment:download           | -      |
| -                                                                                                                                                                            | codeartsreq:attachment:download           | -      |
| [GET /v2/ipdprojectservice/projects/{project_id}/images](https://support.huaweicloud.com/api-projectman/DownloadIpdImageInIssue.html)                                        | codeartsreq:workitem:get                  | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/attachments/download/{id}](https://support.huaweicloud.com/api-projectman/DownloadIpdIssueAttachment.html)                  | codeartsreq:attachment:get                | -      |
| -                                                                                                                                                                            | codeartsreq:plan:export                   | -      |
| -                                                                                                                                                                            | codeartsreq:plan:export                   | -      |
| -                                                                                                                                                                            | codeartsreq:plan:import                   | -      |
| [GET /v4/projects/{project_id}/issues/{issue_id}/associated-issues](https://support.huaweicloud.com/api-projectman/ListAssociatedIssues.html)                                | codeartsreq:workitem:list                 | -      |
| [GET /v4/projects/{project_id}/issues/{issue_id}/associate-test-cases](https://support.huaweicloud.com/api-projectman/ListAssociatedTestCases.html)                          | codeartsreq:workitem:get                  | -      |
| [GET /v4/projects/{project_id}/issues/{issue_id}/associated-wikis](https://support.huaweicloud.com/api-projectman/ListAssociatedWikis.html)                                  | codeartsreq:attachment:list               | -      |
| [POST /v4/issues/child-issue-list](https://support.huaweicloud.com/api-projectman/ListChildIssuesV4.html)                                                                    | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:plan:import                   | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/review/issues/{issue_id}/approvers](https://support.huaweicloud.com/api-projectman/ListIpdChangeReviewIssueApprovers.html)  | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:get                  | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/fields](https://support.huaweicloud.com/api-projectman/ListIpdProjectFields.html)                                           | codeartsreq:configuration:list            | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/issues/query](https://support.huaweicloud.com/api-projectman/ListIpdProjectIssues.html)                                    | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:project:list                  | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/review/query](https://support.huaweicloud.com/api-projectman/ListIpdReviewForms.html)                                      | codeartsreq:review:list                   | -      |
| [GET /v4/programs/{program_id}/irs/{ir_id}/children](https://support.huaweicloud.com/api-projectman/ListIrChildren.html)                                                     | codeartsreq:developmentRequirement:list   | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:developmentRequirement:list   | -      |
| [GET /v4/projects/{project_id}/issues/{issue_id}/associated-commits](https://support.huaweicloud.com/api-projectman/ListIssueAssociatedCommits.html)                         | codeartsreq:workitem:get                  | -      |
| [GET /v4/projects/{project_id}/issues/{issue_id}/comments](https://support.huaweicloud.com/api-projectman/ListIssueCommentsV4.html)                                          | codeartsreq:workitem:list                 | -      |
| [POST /v4/projects/{project_id}/issues/custom-fields](https://support.huaweicloud.com/api-projectman/ListIssueCustomFields.html)                                             | codeartsreq:custom:list                   | -      |
| [GET /v4/projects/{project_id}/issue/{issue_id}/records](https://support.huaweicloud.com/api-projectman/ListIssueRecordsV4.html)                                             | codeartsreq:workitem:list                 | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/plan/snapshots/issues/{issue_id}](https://support.huaweicloud.com/api-projectman/ListIssueSprintSnapshots.html)             | codeartsreq:iteration:list                | -      |
| [GET /v4/projects/{project_id}/issues](https://support.huaweicloud.com/api-projectman/ListIssuesSfV4.html)                                                                   | codeartsreq:workitem:list                 | -      |
| [POST /v4/projects/{project_id}/issues](https://support.huaweicloud.com/api-projectman/ListIssuesV4.html)                                                                    | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:release:get                   | -      |
| -                                                                                                                                                                            | codeartsreq:plan:list                     | -      |
| [GET /v1/planservice/projects/{project_id}/plans/query](https://support.huaweicloud.com/api-projectman/ListPlan.html)                                                        | codeartsreq:plan:list                     | -      |
| [GET /v1/planservice/projects/{project_id}/plans/{plan_id}](https://support.huaweicloud.com/api-projectman/ListPlanDetail.html)                                              | codeartsreq:plan:get                      | -      |
| -                                                                                                                                                                            | codeartsreq:plan:get                      | -      |
| [GET /v4/programs/{program_id}/fields](https://support.huaweicloud.com/api-projectman/ListProgramFields.html)                                                                | codeartsreq:project:get                   | -      |
| -                                                                                                                                                                            | codeartsreq:member:list                   | -      |
| -                                                                                                                                                                            | codeartsreq:project:list                  | -      |
| -                                                                                                                                                                            | codeartsreq:member:list                   | -      |
| -                                                                                                                                                                            | codeartsreq:release:get                   | -      |
| -                                                                                                                                                                            | codeartsreq:iteration:list                | -      |
| -                                                                                                                                                                            | codeartsreq:release:list                  | -      |
| [GET /v4/programs](https://support.huaweicloud.com/api-projectman/ListPrograms.html)                                                                                         | codeartsreq:project:list                  | -      |
| [GET /v4/projects/{project_id}/bug-statistic](https://support.huaweicloud.com/api-projectman/ListProjectBugStaticsV4.html)                                                   | codeartsreq:defect:list                   | -      |
| [GET /v4/projects/{project_id}/demand-statistic](https://support.huaweicloud.com/api-projectman/ListProjectDemandStaticV4.html)                                              | codeartsreq:developmentRequirement:list   | -      |
| [GET /v4/projects/{project_id}/domains](https://support.huaweicloud.com/api-projectman/ListProjectDomains.html)                                                              | codeartsreq:configuration:list            | -      |
| [GET /v4/projects/{project_id}/issues/records](https://support.huaweicloud.com/api-projectman/ListProjectIssuesRecordsV4.html)                                               | codeartsreq:workitem:list                 | -      |
| [GET /v4/projects/{project_id}/iterations](https://support.huaweicloud.com/api-projectman/ListProjectIterationsV4.html)                                                      | codeartsreq:iteration:list                | -      |
| [GET /v4/projects/{project_id}/modules](https://support.huaweicloud.com/api-projectman/ListProjectModules.html)                                                              | codeartsreq:configuration:list            | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/users](https://support.huaweicloud.com/api-projectman/ListProjectUsers.html)                                                | codeartsreq:member:list                   | -      |
| [POST /v4/projects/work-hours](https://support.huaweicloud.com/api-projectman/ListProjectWorkHours.html)                                                                     | codeartsreq:workhour:list                 | -      |
| [GET /v4/projects/{project_id}/work-hours-type](https://support.huaweicloud.com/api-projectman/ListProjectWorkHoursType.html)                                                | codeartsreq:workhour:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:developmentRequirement:list   | -      |
| [POST /v4/programs/{program_id}/rr-status](https://support.huaweicloud.com/api-projectman/ListRrStatus.html)                                                                 | codeartsreq:configuration:list            | -      |
| [GET /v4/programs/{program_id}/rrs](https://support.huaweicloud.com/api-projectman/ListRrs.html)                                                                             | codeartsreq:rawRequirement:list           | -      |
| [GET /v4/projects/{project_id}/statuses](https://support.huaweicloud.com/api-projectman/ListScrumProjectStatuses.html)                                                       | codeartsreq:configuration:list            | -      |
| [POST /v4/issues/duration](https://support.huaweicloud.com/api-projectman/ListSpecIssueStayTimes.html)                                                                       | codeartsreq:workitem:get                  | -      |
| [GET /v4/projects/{project_id}/work-items/status-records](https://support.huaweicloud.com/api-projectman/ListWorkitemStatusRecordsV4.html)                                   | codeartsreq:workitem:get                  | -      |
| [GET /v4/projects/{project_id}/work-items](https://support.huaweicloud.com/api-projectman/ListWorkitems.html)                                                                | codeartsreq:workitem:list                 | -      |
| [PUT /v1/ipdprojectservice/projects/{project_id}/review/{review_id}](https://support.huaweicloud.com/api-projectman/PutIpdChangeReviewForm.html)                             | codeartsreq:review:update                 | -      |
| [PUT /v2/ipdprojectservice/projects/{project_id}/review/{review_id}](https://support.huaweicloud.com/api-projectman/PutIpdChangeReviewFormV2.html)                           | codeartsreq:review:update                 | -      |
| -                                                                                                                                                                            | codeartsreq:rawRequirement:update         | -      |
| [POST /v4/issues](https://support.huaweicloud.com/api-projectman/SearchIssues.html)                                                                                          | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:plan:get                      | -      |
| -                                                                                                                                                                            | codeartsreq:plan:list                     | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/feature-set/query](https://support.huaweicloud.com/api-projectman/ShowBaselineSnapshots.html)                               | codeartsreq:featureSet:list               | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| [GET /v4/user](https://support.huaweicloud.com/api-projectman/ShowCurUserInfo.html)                                                                                          | codeartsreq:member:get                    | -      |
| [GET /v4/projects/{project_id}/user-role](https://support.huaweicloud.com/api-projectman/ShowCurUserRole.html)                                                               | codeartsreq:project:list                  | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/issue/get-attached-wikis](https://support.huaweicloud.com/api-projectman/ShowIpdAttachedWiki.html)                          | codeartsreq:attachment:get                | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/attachments](https://support.huaweicloud.com/api-projectman/ShowIpdAttachmentByWorkItemId.html)                             | codeartsreq:attachment:list               | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| [GET /v2/ipdprojectservice/projects/{project_id}/issues/{issue_id}](https://support.huaweicloud.com/api-projectman/ShowIpdIssueDetailV2.html)                                | codeartsreq:workitem:get                  | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/process-instances/{review_id}](https://support.huaweicloud.com/api-projectman/ShowIpdProcessInstance.html)                  | codeartsreq:workflow:get                  | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/process-instances/query](https://support.huaweicloud.com/api-projectman/ShowIpdProcessInstances.html)                      | codeartsreq:workflow:list                 | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/review/{review_id}](https://support.huaweicloud.com/api-projectman/ShowIpdReviewForm.html)                                  | codeartsreq:review:get                    | -      |
| -                                                                                                                                                                            | codeartsreq:member:list                   | -      |
| -                                                                                                                                                                            | codeartsreq:tag:get                       | -      |
| [GET /v4/programs/{program_id}/irs/{ir_id}](https://support.huaweicloud.com/api-projectman/ShowIr.html)                                                                      | codeartsreq:developmentRequirement:get    | -      |
| [GET /v4/irs/{ir_id}/histories](https://support.huaweicloud.com/api-projectman/ShowIrHistory.html)                                                                           | codeartsreq:developmentRequirement:get    | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:get                  | -      |
| [GET /v4/projects/{project_id}/issue-completion-rate](https://support.huaweicloud.com/api-projectman/ShowIssueCompletionRate.html)                                           | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| [GET /v4/projects/{project_id}/issues/{issue_id}](https://support.huaweicloud.com/api-projectman/ShowIssueV4.html)                                                           | codeartsreq:workitem:get                  | -      |
| [GET /v4/projects/{project_id}/issues/workflow/config](https://support.huaweicloud.com/api-projectman/ShowIssuesWrokFlowConfig.html)                                         | codeartsreq:workflow:get                  | -      |
| [GET /v4/iterations/{iteration_id}](https://support.huaweicloud.com/api-projectman/ShowIterationV4.html)                                                                     | codeartsreq:iteration:get                 | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:plan:get                      | -      |
| -                                                                                                                                                                            | codeartsreq:project:get                   | -      |
| -                                                                                                                                                                            | codeartsreq:release:get                   | -      |
| [GET /v4/projects/{project_id}/summary](https://support.huaweicloud.com/api-projectman/ShowProjectSummaryV4.html)                                                            | codeartsreq:project:get                   | -      |
| [POST /v4/projects/{project_id}/work-hours](https://support.huaweicloud.com/api-projectman/ShowProjectWorkHours.html)                                                        | codeartsreq:workhour:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:developmentRequirement:get    | -      |
| [GET /v4/rrs/{rr_id}/histories](https://support.huaweicloud.com/api-projectman/ShowRrHistory.html)                                                                           | codeartsreq:rawRequirement:get            | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/snapshots-feature/query](https://support.huaweicloud.com/api-projectman/ShowSnapshotsFeature.html)                          | codeartsreq:featureSet:getBaseline        | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/snapshots/version](https://support.huaweicloud.com/api-projectman/ShowSnapshotsVersion.html)                                | codeartsreq:featureSet:getBaseline        | -      |
| -                                                                                                                                                                            | codeartsreq:dashboard:get                 | -      |
| [POST /v1/ipdprojectservice/projects/tenant/query](https://support.huaweicloud.com/api-projectman/ShowTenantIssueList.html)                                                  | codeartsreq:workitem:list                 | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/work-hour/options](https://support.huaweicloud.com/api-projectman/ShowWorkHourCategory.html)                                | codeartsreq:configuration:get             | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/work-hour/query](https://support.huaweicloud.com/api-projectman/ShowWorkHours.html)                                        | codeartsreq:workhour:get                  | -      |
| [GET /v4/projects/{project_id}/work-items/workflow/config](https://support.huaweicloud.com/api-projectman/ShowWorkItemWrokflowConfig.html)                                   | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:featureSet:update             | -      |
| [PUT /v1/ipdprojectservice/projects/{project_id}/tags/{label_id}](https://support.huaweicloud.com/api-projectman/UpdateIpdLabel.html)                                        | codeartsreq:tag:update                    | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| [PUT /v1/ipdprojectservice/projects/{project_id}/process-instances/{review_id}](https://support.huaweicloud.com/api-projectman/UpdateIpdProcessInstance.html)                | codeartsreq:workflow:update               | -      |
| [PUT /v4/projects/{project_id}/issues/{issue_id}](https://support.huaweicloud.com/api-projectman/UpdateIssueV4.html)                                                         | codeartsreq:workitem:update               | -      |
| [PUT /v4/projects/{project_id}/iterations/{iteration_id}](https://support.huaweicloud.com/api-projectman/UpdateIterationV4.html)                                             | codeartsreq:iteration:update              | -      |
| [PUT /v4/user](https://support.huaweicloud.com/api-projectman/UpdateNickNameV4.html)                                                                                         | codeartsreq:member:update                 | -      |
| -                                                                                                                                                                            | codeartsreq:plan:update                   | -      |
| [PUT /v1/planservice/projects/{project_id}/plans/{plan_id}](https://support.huaweicloud.com/api-projectman/UpdatePlanInfo.html)                                              | codeartsreq:plan:update                   | -      |
| -                                                                                                                                                                            | codeartsreq:plan:update                   | -      |
| -                                                                                                                                                                            | codeartsreq:project:update                | -      |
| -                                                                                                                                                                            | codeartsreq:member:update                 | -      |
| -                                                                                                                                                                            | codeartsreq:release:update                | -      |
| [PUT /v4/projects/{project_id}/domains/{domain_id}](https://support.huaweicloud.com/api-projectman/UpdateProjectDomain.html)                                                 | codeartsreq:configuration:update          | -      |
| [PUT /v4/projects/{project_id}/modules/{module_id}](https://support.huaweicloud.com/api-projectman/UpdateProjectModule.html)                                                 | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:developmentRequirement:update | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| [PUT /v1/projects/{project_id}/work-items/{issue_id}/work-hour/{workhour_id}](https://support.huaweicloud.com/api-projectman/UpdateWorkHourOpenApi.html)                     | codeartsreq:workhour:update               | -      |
| [POST /v4/projects/{project_id}/issues/{issue_id}/attachments/upload](https://support.huaweicloud.com/api-projectman/UploadAttachments.html)                                 | codeartsreq:attachment:upload             | -      |
| [POST /v2/ipdprojectservice/projects/{project_id}/images](https://support.huaweicloud.com/api-projectman/UploadIpdImageInIssue.html)                                         | codeartsreq:workitem:create               | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:create               | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:delete               | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:update               | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:create          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:create          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:create          | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:update               | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:delete          | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:update               | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:project:get                   | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:project:list                  | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:project:get                   | -      |
| -                                                                                                                                                                            | codeartsreq:project:get                   | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:create          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:list                 | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:workflow:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:update               | -      |
| -                                                                                                                                                                            | codeartsreq:workitem:update               | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:update          | -      |
| [POST /v2/projects/{project_id}/issues/{issue_id}/associate-third-party](https://support.huaweicloud.com/api-projectman/AssociateIpdThirdParty.html)                         | codeartsreq:workitem:list                 | -      |
| [PUT /v2/ipdprojectservice/projects/{project_id}/issues/{issue_id}/associated-item](https://support.huaweicloud.com/api-projectman/AssociateIssues.html)                     | codeartsreq:attachment:list               | -      |
| -                                                                                                                                                                            | codeartsreq:plan:delete                   | -      |
| [PUT /v1/ipdprojectservice/projects/{project_id}/issues/batch](https://support.huaweicloud.com/api-projectman/BatchUpdateIpdIssues.html)                                     | codeartsreq:workitem:update               | -      |
| -                                                                                                                                                                            | codeartsreq:plan:baseline                 | -      |
| -                                                                                                                                                                            | codeartsreq:plan:create                   | -      |
| [DELETE /v2/projects/{project_id}/issues/{issue_id}/associate-third-party](https://support.huaweicloud.com/api-projectman/DeleteIpdThirdParty.html)                          | codeartsreq:plan:delete                   | -      |
| -                                                                                                                                                                            | codeartsreq:plan:export                   | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/model-config](https://support.huaweicloud.com/api-projectman/GetModelConfig.html)                                           | codeartsreq:configuration:get             | -      |
| -                                                                                                                                                                            | codeartsreq:plan:import                   | -      |
| [POST /v2/ipdprojectservice/projects/{project_id}/issues/{issue_id}/associated-item](https://support.huaweicloud.com/api-projectman/QueryIssueAssociatedItem.html)           | codeartsreq:workitem:get                  | -      |
| [GET /v1/ipdprojectservice/projects/{project_id}/issues/{issue_id}/history](https://support.huaweicloud.com/api-projectman/ShowIpdIssueHistory.html)                         | codeartsreq:workitem:get                  | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| -                                                                                                                                                                            | codeartsreq:review:get                    | -      |
| -                                                                                                                                                                            | codeartsreq:configuration:list            | -      |
| [GET /v2/projects/{project_id}/issues/{issue_id}/associate-third-party](https://support.huaweicloud.com/api-projectman/ShowIpdThirdPartyAssociated.html)                     | codeartsreq:configuration:get             | -      |
| [PUT /v2/projects/{project_id}/issues/{issue_id}/associate-third-party](https://support.huaweicloud.com/api-projectman/UpdateIpdThirdParty.html)                             | codeartsreq:workitem:update               | -      |
| -                                                                                                                                                                            | codeartsreq:plan:update                   | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/baseline-snapshots/create/batch](https://support.huaweicloud.com/api-projectman/BatchCreateIssueSnapitems.html)            | codeartsreq:workitem:create               | -      |
| [DELETE /v1/ipdprojectservice/projects/{project_id}/baseline-snapshots/batch](https://support.huaweicloud.com/api-projectman/BatchDeleteSnapshots.html)                      | codeartsreq:workitem:delete               | -      |
| [PUT /v1/ipdprojectservice/projects/{project_id}/baseline-snapshots/deletions](https://support.huaweicloud.com/api-projectman/BatchUpdateSnapshotDeletableFlag.html)         | codeartsreq:workitem:update               | -      |
| [POST /v1/ipdprojectservice/projects/{project_id}/baseline-snapshots/query-with-ids](https://support.huaweicloud.com/api-projectman/ListIssueBySnapIds.html)                 | codeartsreq:workitem:get                  | -      |
   
 #### 资源类型（Resource）
CodeArts Req服务不支持在身份策略中的资源中指定资源进行权限控制。如需允许访问CodeArts Req服务，请在身份策略的Resource元素中使用通配符号\*，表示身份策略将应用到所有资源。
 #### 条件（Condition）
**条件键概述**
条件（Condition）是身份策略生效的特定条件，包括[条件键](https://support.huaweicloud.com/usermanual-iam5/iam_01_1287.html)和[运算符](https://support.huaweicloud.com/usermanual-iam5/iam_01_1289.html#iam_01_1289__li13495143171719)。
- 条件键表示身份策略语句的Condition元素中的键值。根据适用范围，分为全局级条件键和服务级条件键。
  - 全局级条件键（前缀为g:）适用于所有操作，在鉴权过程中，云服务不需要提供用户身份信息，系统将自动获取并鉴权。详情请参见：[全局条件键](https://support.huaweicloud.com/usermanual-iam5/iam_01_1287.html)。
  
  - 服务级条件键（前缀通常为服务缩写，如codearts req:）仅适用于对应服务的操作，详情请参见[表3]。
  
  - 单值/多值表示API调用时请求中与条件关联的值数。单值条件键在API调用时的请求中最多包含一个值，多值条件键在API调用时请求可以包含多个值。例如：g:SourceVpce是单值条件键，表示仅允许通过某个VPC终端节点发起请求访问某资源，一个请求最多包含一个VPC终端节点ID值。g:TagKeys是多值条件键，表示请求中携带的所有标签的key组成的列表，当用户在调用API请求时传入标签可以传入多个值。
   
- 运算符与条件键、条件值一起构成完整的条件判断语句，当请求信息满足该条件时，身份策略才能生效。支持的运算符请参见：[运算符](https://support.huaweicloud.com/usermanual-iam5/iam_01_1289.html#iam_01_1289__li13495143171719)。
**CodeArts Req支持的服务级条件键**
CodeArts Req定义了以下可以在自定义身份策略的Condition元素中使用的条件键，您可以使用这些条件键进一步细化身份策略语句应用的条件。
 表3CodeArts Req支持的服务级条件键 
| 服务级条件键                | 类型     | 单值/多值 | 说明                         |
|:---|:---|:---|:---|
| codeartsreq:Model     | string | 单值    | 根据CodeArtsReq需求管理模型筛选访问权限。 |
| codeartsreq:ProjectId | string | 单值    | 根据CodeArts项目ID模型筛选访问权限。    |
   
