Documentation
¶
Index ¶
- Variables
- type Grant
- type Grants
- type Payload
- func (t *Payload) EvalFingerprint()
- func (t *Payload) Fingerprint() string
- func (t *Payload) GrantsFor(resourceType string) *Grants
- func (t Payload) JWTClaims() map[string]any
- func (t Payload) SetGlobalPostgresSessionRLS(db *gorm.DB) error
- func (t *Payload) SetGrants(resourceType string, grants *Grants)
- func (t Payload) SetPostgresSessionRLS(db *gorm.DB) error
- type Scope
Constants ¶
This section is empty.
Variables ¶
var GrantTypes = []string{"config", "component", "playbook", "canary", "check"}
GrantTypes are the resource types whose rows are filtered by grants.
Functions ¶
This section is empty.
Types ¶
type Grant ¶ added in v1.0.1390
type Grant struct {
// Scope grants the rows: the resource Scope of a Role rule, or a Scope a Permission names.
// Empty only for a subject granted every row who impersonates Scopes (see Grants.Impersonate).
Scope string `json:"scope,omitempty"`
// Constraint is the resource Scope of the RoleBinding's constraint, which narrows Scope. Empty without one.
Constraint string `json:"constraint,omitempty"`
// Impersonated are the Scopes named by the X-Flanksource-Scope header, which narrow the grant further: a row must
// be in every one of them. Empty when the request doesn't impersonate.
Impersonated []string `json:"impersonated,omitempty"`
}
Grant admits the rows of a resource type that are in all of its Scopes: Scope, Constraint when it's set, and every Impersonated Scope. Each is a Scope id.
For example, a Role rule reading configs in Scope payments, bound with a constraint on Scope eu, for a request impersonating Scope prod:
Grant{Scope: "<payments>", Constraint: "<eu>", Impersonated: []string{"<prod>"}} // configs in payments, eu and prod
type Grants ¶ added in v1.0.1390
type Grants struct {
// All admits every row of the type.
All bool
// Any admits a row that at least one grant admits.
Any []Grant
}
Grants are a subject's grants on one resource type: every row (All), or the rows at least one grant admits (Any). A type with no grants, or with neither, lists no rows.
They're marshalled into the claim as "all", or as the list of grants:
"all"
[{"scope": "<prod>"}, {"scope": "<payments>", "constraint": "<eu>"}] // rows in prod, or in both payments and eu
func (*Grants) Add ¶ added in v1.0.1390
Add adds a grant. A grant naming anything but Scope ids, or no Scope, is ignored: it admits nothing.
func (*Grants) Fingerprint ¶ added in v1.0.1390
Fingerprint identifies the grants.
func (*Grants) Impersonate ¶ added in v1.0.1390
Impersonate narrows the grants to the Scopes named by the X-Flanksource-Scope header: a row must also be in every one of them. Each is added to every grant, and a subject granted every row gets one grant of all of them. Impersonating no Scope, or anything but Scope ids, admits nothing. Nil grants stay nil: they admit nothing.
[{scope: A}].Impersonate(X, Y) => [{scope: A, impersonated: [X, Y]}]
"all".Impersonate(X, Y) => [{impersonated: [X, Y]}]
func (Grants) MarshalJSON ¶ added in v1.0.1390
MarshalJSON writes the grants as the claim reads them: "all", or the list of grants.
func (*Grants) UnmarshalJSON ¶ added in v1.0.1390
type Payload ¶
type Payload struct {
Config *Grants `json:"config,omitempty"`
Component *Grants `json:"component,omitempty"`
Playbook *Grants `json:"playbook,omitempty"`
Canary *Grants `json:"canary,omitempty"`
Check *Grants `json:"check,omitempty"`
// View filters views by their own fields. Views aren't covered by stored Scope membership.
View []Scope `json:"view,omitempty"`
// Scopes contains the list of scope UUIDs the user has access to.
// This is used for generated view tables only (for now).
Scopes []string `json:"scopes,omitempty"`
Disable bool `json:"disable_rls,omitempty"`
// contains filtered or unexported fields
}
RLS Payload that's injected postgresl parameter `request.jwt.claims`
Each resource type carries the subject's grants on it (see Grants). A type without grants lists no rows.
func (*Payload) EvalFingerprint ¶
func (t *Payload) EvalFingerprint()
func (*Payload) Fingerprint ¶
func (*Payload) GrantsFor ¶ added in v1.0.1390
GrantsFor returns the grants of a resource type, e.g. "config". Nil when the type has none.
func (Payload) SetGlobalPostgresSessionRLS ¶ added in v1.0.819
Injects the payload as sessions parameter