LocksRequest

The domain locks to set or clear.

  • true sets clientTransferProhibited, under which the registry refuses an inbound transfer request for the name. It stops a transfer away; it does not keep a name that nobody renews. The registry writes the status over <domain:update>, so moving this lock in either direction needs the update lock clear first.

  • true sets clientUpdateProhibited, under which the registry refuses every other change to the name until it is cleared, the transfer lock included. It freezes three more things no registry refuses on our behalf: auto-renewal cannot be changed in either direction, the name cannot be reassigned to another team, and its subordinate hosts cannot be replaced, through either the hosts field or PUT /domains/{id}/hosts. It is the one lock that clears itself under its own lock, which is what stops a locked name from being locked for good.

    Both directions travel with other fields, and the order is fixed rather than the order you send. true runs last, after everything the lock would otherwise have frozen, so it means "make this change, then protect the name". false runs first, so it means "unlock the name, then make this change"; the registry confirms the unlock before the next command is sent.

    Send the flag only when the lock is not already where you want it. A flag the domain already satisfies still becomes a governed item, so it collects whatever approvals that lock needs and holds the domain against other changes for as long as the request is open, for a line that will send no command.