rego

package
v0.2.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 11, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package rego implements authz.Authorizer with one prepared in-process Rego decision.

New accepts trusted in-memory module source and one ground data reference such as data.codemode.authz.allow. It compiles the modules with Rego v1 semantics, removes every OPA-declared nondeterministic builtin, sets AllowNet to a non-nil empty deny-all host list as defense in depth, treats builtin errors as fatal, and disables print statements. Construction is synchronous. The returned Authorizer is immutable and safe for concurrent Authorize calls.

Removing those builtins takes away runtime network-capable builtins, including http.send, plus DNS, runtime, random, time, and UUID builtins. AllowNet is not the mechanism that removes http.send. New installs no schema set and no schema resolver. Metadata schema["https://example.invalid/schema.json"] is accepted but ignored: there is no validation and no fetch. Metadata with an external $ref: "https://example.invalid/schema.json" asks OPA to load a remote schema and is rejected because remote reference loading is disabled.

Authorize projects only subject.id, capability.id, capability.name, and the borrowed canonical arguments map. A ground decision is either undefined or yields one value, which must be Boolean. Boolean true allows the call, and Boolean false returns authz.ErrDenied. Undefined, non-Boolean, evaluation, and builtin failures are ordinary policy errors. A canceled or expired context returns ctx.Err().

Write a total Boolean decision with default allow := false. Treat unmatched input as an intentional denial, not an undefined result. Module source is trusted deployment configuration. These restrictions reduce evaluator capabilities; they do not isolate CPU, heap, processes, or tenants.

Example

Example constructs the adapter and assigns it to CodeMode options.

package main

import (
	"context"
	"fmt"

	"github.com/meigma/codemode"
	"github.com/meigma/codemode/authz/rego"
)

func main() {
	authorizer, err := rego.New(
		context.Background(),
		"data.codemode.authz.allow",
		map[string]string{
			"authorization.rego": `package codemode.authz

default allow := false

allow if {
	input.subject.id == "example-user"
	input.capability.id == "records.entry.lookup"
	input.arguments.key != "forbidden"
}
`,
		},
	)
	if err != nil {
		panic(err)
	}

	_ = codemode.Options{
		Authorizer: authorizer,
		Limits:     codemode.DefaultLimits(),
	}
	fmt.Println("prepared")

}
Output:
prepared

Index

Examples

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Authorizer

type Authorizer struct {
	// contains filtered or unexported fields
}

Authorizer evaluates one prepared in-process Rego authorization decision.

func New

func New(ctx context.Context, decision string, modules map[string]string) (*Authorizer, error)

New validates a ground data decision, compiles the supplied in-memory Rego modules, and returns an authorizer ready for concurrent use.

func (*Authorizer) Authorize

func (authorizer *Authorizer) Authorize(ctx context.Context, input authz.AuthorizationInput) error

Authorize implements authz.Authorizer.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL