Declares an {@see AbilityType::Read} ability on an OData entity set's authored
source class — the custom entity-set class (CustomEntitySetInterface /
EntitySetSourceInterface), or the Eloquent model for a discoverModel set.
Same shape as {@see Access} / {@see Act}: the developer names the ability. The harvest
additionally records which entity set the attribute's class backs (resolved from the
app's ResolverMap — binding->getSourceClass() names this class), so the read authorizer,
given a set name at request time, resolves set → ability → grant. Ability names are unique
per app namespace (as with #[Act]/#[Access]).
Enforced server-side by the SDK read authorizer at the odata read forward-exit: an actor
lacking the ability gets a 403 on a root read, or a pruned $expand + sap-messages
warning. A set whose class carries no #[Read] is open (default-open, mirroring
#[Access]/#[Act]).
The resulting i18n keys for admin UI labels:
Nota Bene: Changing an ability name is a breaking security change.
| Methods | ||
|---|---|---|
public
|
__construct(string $ability, string|BackedEnum $role, string $note)
|
# |
| Properties | |||
|---|---|---|---|
public
|
string
|
$ability
|
# |
public
|
string|BackedEnum
|
$role
|
# |
public
|
string
|
$note
|
# |