rbac

package
v0.5.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 17, 2026 License: Apache-2.0 Imports: 16 Imported by: 0

Documentation

Overview

Package rbac is a platform module: role based access to the gRPC methods of the API, in the model and policy format of taply.

The module decides what a role may call; who the caller is stays with the project. The project's authentication interceptor puts the roles into the context with WithRoles, and asks Public to skip authentication for public methods.

Index

Constants

View Source
const Model = `` /* 222-byte string literal not displayed */

Model is taply's casbin model: a role may call a method matching a keyMatch2 pattern, such as /shop.v1.OrdersService/* for a whole service.

View Source
const Public = "*"

Public is the role that makes a method public: no authentication is needed.

Variables

This section is empty.

Functions

func IsPublic

func IsPublic(app *platform.App, method string) bool

IsPublic reports whether a method needs no authentication, for the project's authentication interceptor.

func RolesFrom

func RolesFrom(ctx context.Context) ([]string, bool)

RolesFrom returns the roles of the caller and whether the caller is authenticated.

func WithRoles

func WithRoles(ctx context.Context, roles ...string) context.Context

WithRoles returns a context carrying the roles of the authenticated caller. The project's authentication interceptor calls it.

Types

type Config

type Config struct{}

Config holds module settings. The module has no environment variables: access rules are code, reviewed and deployed with the service.

func Load

func Load(*confx.Loader) Config

Load reads the module settings from environment variables.

type Enforcer

type Enforcer struct {
	// contains filtered or unexported fields
}

Enforcer answers access questions.

func From

func From(app *platform.App) *Enforcer

From returns the enforcer from the container.

func NewEnforcer

func NewEnforcer(policy string) (*Enforcer, error)

NewEnforcer builds an enforcer from a policy text.

func (*Enforcer) Allowed

func (e *Enforcer) Allowed(roles []string, method string) bool

Allowed reports whether any of the roles may call the method.

func (*Enforcer) Public

func (e *Enforcer) Public(method string) bool

Public reports whether a method needs no authentication.

func (*Enforcer) Rules

func (e *Enforcer) Rules() []Rule

Rules returns the policy.

func (*Enforcer) Unmatched

func (e *Enforcer) Unmatched(methods []string) []Rule

Unmatched returns the rules whose method pattern matches none of the given methods: a renamed method or a typo leaves such a rule granting nothing.

type Module

type Module struct {
	// contains filtered or unexported fields
}

Module implements platform.Module.

func New

func New(_ Config, opts ...Option) *Module

New creates the module.

func (*Module) Init

func (m *Module) Init(_ context.Context, app *platform.App) error

Init reads the policy and puts the access check in front of every call.

func (*Module) Name

func (m *Module) Name() string

func (*Module) Start

func (m *Module) Start(context.Context) error

Start warns about rules that grant nothing because no registered method matches them.

type Option

type Option func(*Module)

Option configures the module.

func WithPolicy

func WithPolicy(text string) Option

WithPolicy gives the module the policy of the project. The generated wiring passes the embedded rbac/policy.csv.

type Rule

type Rule struct {
	Role   string
	Method string // keyMatch2 pattern
	Action string
	Line   int
}

Rule is one line of the policy.

func ParsePolicy

func ParsePolicy(text string) ([]Rule, error)

ParsePolicy reads a policy in taply's CSV format: "p, role, method, action" per line, # comments and empty lines allowed. Every broken line is reported.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL