Documentation
¶
Index ¶
- Constants
- Variables
- func AddCustomFunctions(enforcer addableEnforcer)
- func AddRoleForUser(user string, role ...string) error
- func Check(ctx context.Context, subject, object, action string) bool
- func CheckContext(ctx context.Context, object, action string) bool
- func DeleteAllRolesForUser(user string) error
- func DeleteRole(role string) (bool, error)
- func DeleteRoleForUser(user string, role string) error
- func Enforcer() *casbin.SyncedCachedEnforcer
- func GetActionFromHttpMethod(method string) string
- func GetObjectByTable(resource string) string
- func HasImplicitGrants(subject string) bool
- func HasPermission(ctx context.Context, subject string, attr *models.ABACAttribute, action string) bool
- func Init(ctx context.Context, superUserIDs []string, adapters ...Adapter) error
- func PermsForUser(user string) ([]policy.Permission, error)
- func ReloadPolicy() error
- func RolesForUser(user string) ([]string, error)
- func Stop()
- type Adapter
- type NamespacedNameIDSelector
- type RuleCondition
- type RuleResources
- type Selectors
- type SubjectAccessReviewRequest
- type SubjectAccessReviewResource
- type SubjectAccessReviewResult
- type SubjectAccessSearchRequest
- type SubjectAccessSearchResponse
- type SubjectAccessSearchResult
- type ViewRef
Constants ¶
const MaxSubjectAccessReviewSubjects = 500
Variables ¶
var DefaultModel string
Functions ¶
func AddCustomFunctions ¶ added in v1.0.840
func AddCustomFunctions(enforcer addableEnforcer)
func AddRoleForUser ¶
func CheckContext ¶ added in v1.0.841
func DeleteAllRolesForUser ¶
func DeleteRole ¶
func DeleteRoleForUser ¶
func Enforcer ¶
func Enforcer() *casbin.SyncedCachedEnforcer
func GetActionFromHttpMethod ¶
func GetObjectByTable ¶
func HasImplicitGrants ¶ added in v1.0.1387
HasImplicitGrants reports whether the subject is granted the "everyone" role and, in CheckContext, the viewer role on top of what it was explicitly granted.
Role bindings and federated identities have no implicit grants. A binding must not join "everyone", or every member of the binding would inherit "everyone" through it.
func HasPermission ¶ added in v1.0.841
func PermsForUser ¶
func PermsForUser(user string) ([]policy.Permission, error)
func ReloadPolicy ¶
func ReloadPolicy() error
func RolesForUser ¶
Types ¶
type NamespacedNameIDSelector ¶ added in v1.0.1074
type RuleCondition ¶ added in v1.0.1387
type RuleCondition struct {
// ResourceTypes are the resource types the action accepts as its primary resource.
ResourceTypes []string `json:"resourceTypes"`
// Resource selects the primary resources: a resource must belong to every selection,
// e.g. the rule's Scope and the Scope a RoleBinding narrows it with.
Resource []RuleResources `json:"resource"`
// TargetTypes are the resource types the action accepts as a target.
// Empty when the action doesn't take a target.
TargetTypes []string `json:"targetTypes,omitempty"`
// Target selects the targets: a target must belong to every selection.
// When empty, the rule only matches requests without a target.
Target []RuleResources `json:"target,omitempty"`
// Deny is set for deny rules. A request that doesn't fit the contract,
// or whose selectors can't be evaluated, matches a deny rule.
Deny bool `json:"deny,omitempty"`
}
RuleCondition is the condition of a casbin policy compiled from a Role rule.
It carries the contract of the rule's action, so a request that doesn't fit the contract never matches an allow rule, and always matches a deny rule.
type RuleResources ¶ added in v1.0.1387
type RuleResources map[string][]types.ResourceSelector
RuleResources selects resources by type, like a Scope. A resource belongs to it when a selector of the resource's own type matches the resource.
type Selectors ¶ added in v1.0.840
type Selectors struct {
Playbooks []types.ResourceSelector `json:"playbooks,omitempty"`
Connections []types.ResourceSelector `json:"connections,omitempty"`
Configs []types.ResourceSelector `json:"configs,omitempty"`
Components []types.ResourceSelector `json:"components,omitempty"`
Views []ViewRef `json:"views,omitempty"`
}
Selectors represents the object_selector from a permission and specifies resource selectors for multiple resource types used in ABAC authorization.
For authorization to succeed, all specified resource type selectors must match the corresponding resources in the ABACAttribute. If a selector is specified for a resource type but the attribute lacks that resource, authorization fails. If an attribute provides a resource but no selector exists for that type, the permission is considered non-restrictive for that resource (authorized).
type SubjectAccessReviewRequest ¶ added in v1.0.1305
type SubjectAccessReviewRequest struct {
Resource SubjectAccessReviewResource `json:"resource"`
Action string `json:"action"`
// Supports ["*"], in which case we iterate over all permission subjects in the database.
Subjects []string `json:"subjects"`
}
type SubjectAccessReviewResource ¶ added in v1.0.1305
type SubjectAccessReviewResult ¶ added in v1.0.1305
type SubjectAccessReviewResult struct {
Subject string `json:"subject"`
Allowed bool `json:"allowed"`
Error string `json:"error,omitempty"`
}
func RunSubjectAccessReview ¶ added in v1.0.1305
func RunSubjectAccessReview(ctx context.Context, req SubjectAccessReviewRequest) ([]SubjectAccessReviewResult, error)
type SubjectAccessSearchRequest ¶ added in v1.0.1305
type SubjectAccessSearchRequest struct {
Subject string `json:"subject"`
Action string `json:"action"`
ResourceTypes []string `json:"resource_types,omitempty"`
}
func (*SubjectAccessSearchRequest) Validate ¶ added in v1.0.1305
func (req *SubjectAccessSearchRequest) Validate() error
type SubjectAccessSearchResponse ¶ added in v1.0.1305
type SubjectAccessSearchResponse struct {
Subject string `json:"subject"`
Action string `json:"action"`
ResourceTypes []string `json:"resource_types"`
Total int `json:"total"`
Results []SubjectAccessSearchResult `json:"results"`
}
func RunSubjectAccessSearch ¶ added in v1.0.1305
func RunSubjectAccessSearch(ctx context.Context, req SubjectAccessSearchRequest) (SubjectAccessSearchResponse, error)
type SubjectAccessSearchResult ¶ added in v1.0.1305
type ViewRef ¶ added in v1.0.1074
type ViewRef NamespacedNameIDSelector