Documentation
¶
Overview ¶
Package rbac is a platform module: role based access to the gRPC methods of the API, in the model and policy format of taply.
The module decides what a role may call; who the caller is stays with the project. The project's authentication interceptor puts the roles into the context with WithRoles, and asks Public to skip authentication for public methods.
Index ¶
Constants ¶
const Model = `` /* 222-byte string literal not displayed */
Model is taply's casbin model: a role may call a method matching a keyMatch2 pattern, such as /shop.v1.OrdersService/* for a whole service.
const Public = "*"
Public is the role that makes a method public: no authentication is needed.
Variables ¶
This section is empty.
Functions ¶
func IsPublic ¶
IsPublic reports whether a method needs no authentication, for the project's authentication interceptor.
Types ¶
type Config ¶
type Config struct{}
Config holds module settings. The module has no environment variables: access rules are code, reviewed and deployed with the service.
type Enforcer ¶
type Enforcer struct {
// contains filtered or unexported fields
}
Enforcer answers access questions.
func NewEnforcer ¶
NewEnforcer builds an enforcer from a policy text.
type Module ¶
type Module struct {
// contains filtered or unexported fields
}
Module implements platform.Module.
type Option ¶
type Option func(*Module)
Option configures the module.
func WithPolicy ¶
WithPolicy gives the module the policy of the project. The generated wiring passes the embedded rbac/policy.csv.
type Rule ¶
Rule is one line of the policy.
func ParsePolicy ¶
ParsePolicy reads a policy in taply's CSV format: "p, role, method, action" per line, # comments and empty lines allowed. Every broken line is reported.