rls

package
v1.0.1390 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: Apache-2.0 Imports: 9 Imported by: 1

Documentation

Index

Constants

This section is empty.

Variables

View Source
var GrantTypes = []string{"config", "component", "playbook", "canary", "check"}

GrantTypes are the resource types whose rows are filtered by grants.

Functions

This section is empty.

Types

type Grant added in v1.0.1390

type Grant struct {
	// Scope grants the rows: the resource Scope of a Role rule, or a Scope a Permission names.
	// Empty only for a subject granted every row who impersonates Scopes (see Grants.Impersonate).
	Scope string `json:"scope,omitempty"`

	// Constraint is the resource Scope of the RoleBinding's constraint, which narrows Scope. Empty without one.
	Constraint string `json:"constraint,omitempty"`

	// Impersonated are the Scopes named by the X-Flanksource-Scope header, which narrow the grant further: a row must
	// be in every one of them. Empty when the request doesn't impersonate.
	Impersonated []string `json:"impersonated,omitempty"`
}

Grant admits the rows of a resource type that are in all of its Scopes: Scope, Constraint when it's set, and every Impersonated Scope. Each is a Scope id.

For example, a Role rule reading configs in Scope payments, bound with a constraint on Scope eu, for a request impersonating Scope prod:

Grant{Scope: "<payments>", Constraint: "<eu>", Impersonated: []string{"<prod>"}}  // configs in payments, eu and prod

type Grants added in v1.0.1390

type Grants struct {
	// All admits every row of the type.
	All bool

	// Any admits a row that at least one grant admits.
	Any []Grant
}

Grants are a subject's grants on one resource type: every row (All), or the rows at least one grant admits (Any). A type with no grants, or with neither, lists no rows.

They're marshalled into the claim as "all", or as the list of grants:

"all"
[{"scope": "<prod>"}, {"scope": "<payments>", "constraint": "<eu>"}]  // rows in prod, or in both payments and eu

func AllRows added in v1.0.1390

func AllRows() *Grants

AllRows grants every row of a type.

func NoRows added in v1.0.1390

func NoRows() *Grants

NoRows grants no row of a type.

func (*Grants) Add added in v1.0.1390

func (g *Grants) Add(grant Grant)

Add adds a grant. A grant naming anything but Scope ids, or no Scope, is ignored: it admits nothing.

func (*Grants) Fingerprint added in v1.0.1390

func (g *Grants) Fingerprint() string

Fingerprint identifies the grants.

func (*Grants) Impersonate added in v1.0.1390

func (g *Grants) Impersonate(scopeIDs ...string)

Impersonate narrows the grants to the Scopes named by the X-Flanksource-Scope header: a row must also be in every one of them. Each is added to every grant, and a subject granted every row gets one grant of all of them. Impersonating no Scope, or anything but Scope ids, admits nothing. Nil grants stay nil: they admit nothing.

[{scope: A}].Impersonate(X, Y) => [{scope: A, impersonated: [X, Y]}]
"all".Impersonate(X, Y)        => [{impersonated: [X, Y]}]

func (*Grants) IsEmpty added in v1.0.1390

func (g *Grants) IsEmpty() bool

IsEmpty reports whether no row is granted.

func (Grants) MarshalJSON added in v1.0.1390

func (g Grants) MarshalJSON() ([]byte, error)

MarshalJSON writes the grants as the claim reads them: "all", or the list of grants.

func (*Grants) ScopeIDs added in v1.0.1390

func (g *Grants) ScopeIDs() []string

ScopeIDs returns every Scope the grants name, sorted.

func (*Grants) UnmarshalJSON added in v1.0.1390

func (g *Grants) UnmarshalJSON(data []byte) error

type Payload

type Payload struct {
	Config    *Grants `json:"config,omitempty"`
	Component *Grants `json:"component,omitempty"`
	Playbook  *Grants `json:"playbook,omitempty"`
	Canary    *Grants `json:"canary,omitempty"`
	Check     *Grants `json:"check,omitempty"`

	// View filters views by their own fields. Views aren't covered by stored Scope membership.
	View []Scope `json:"view,omitempty"`

	// Scopes contains the list of scope UUIDs the user has access to.
	// This is used for generated view tables only (for now).
	Scopes []string `json:"scopes,omitempty"`

	Disable bool `json:"disable_rls,omitempty"`
	// contains filtered or unexported fields
}

RLS Payload that's injected postgresl parameter `request.jwt.claims`

Each resource type carries the subject's grants on it (see Grants). A type without grants lists no rows.

func (*Payload) EvalFingerprint

func (t *Payload) EvalFingerprint()

func (*Payload) Fingerprint

func (t *Payload) Fingerprint() string

func (*Payload) GrantsFor added in v1.0.1390

func (t *Payload) GrantsFor(resourceType string) *Grants

GrantsFor returns the grants of a resource type, e.g. "config". Nil when the type has none.

func (Payload) JWTClaims added in v1.0.1074

func (t Payload) JWTClaims() map[string]any

Get the JWT claims that'll be passed on to PostgREST

func (Payload) SetGlobalPostgresSessionRLS added in v1.0.819

func (t Payload) SetGlobalPostgresSessionRLS(db *gorm.DB) error

Injects the payload as sessions parameter

func (*Payload) SetGrants added in v1.0.1390

func (t *Payload) SetGrants(resourceType string, grants *Grants)

SetGrants sets the grants of a resource type, e.g. "config".

func (Payload) SetPostgresSessionRLS added in v1.0.819

func (t Payload) SetPostgresSessionRLS(db *gorm.DB) error

Injects the payload as local parameter

type Scope added in v1.0.1052

type Scope struct {
	Tags   map[string]string `json:"tags,omitempty"`
	Agents []string          `json:"agents,omitempty"`
	Names  []string          `json:"names,omitempty"`
	ID     string            `json:"id,omitempty"`
	Deny   bool              `json:"deny,omitempty"`
}

func (Scope) Fingerprint added in v1.0.1052

func (s Scope) Fingerprint() string

func (Scope) IsEmpty added in v1.0.1052

func (s Scope) IsEmpty() bool

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL