{
  "$schema": "http://json-schema.org/schema#", 
  "type": "object", 
  "description": "SubjectAccessReviewSpec is a description of the access request.  Exactly one of ResourceAuthorizationAttributes and NonResourceAuthorizationAttributes must be set", 
  "properties": {
    "user": {
      "type": [
        "string", 
        "null"
      ], 
      "description": "User is the user you're testing for. If you specify \"User\" but not \"Groups\", then is it interpreted as \"What if User were not a member of any groups"
    }, 
    "nonResourceAttributes": {
      "description": "NonResourceAttributes describes information for a non-resource access request", 
      "$ref": "_definitions.json#/definitions/io.k8s.kubernetes.pkg.apis.authorization.v1.NonResourceAttributes"
    }, 
    "resourceAttributes": {
      "description": "ResourceAuthorizationAttributes describes information for a resource access request", 
      "$ref": "_definitions.json#/definitions/io.k8s.kubernetes.pkg.apis.authorization.v1.ResourceAttributes"
    }, 
    "groups": {
      "items": {
        "type": [
          "string", 
          "null"
        ]
      }, 
      "type": [
        "array", 
        "null"
      ], 
      "description": "Groups is the groups you're testing for."
    }, 
    "extra": {
      "additionalProperties": {
        "items": {
          "type": [
            "string", 
            "null"
          ]
        }, 
        "type": [
          "array", 
          "null"
        ]
      }, 
      "type": "object", 
      "description": "Extra corresponds to the user.Info.GetExtra() method from the authenticator.  Since that is input to the authorizer it needs a reflection here."
    }
  }
}