Documentation
¶
Overview ¶
Package ory provides Ory Kratos authentication and Keto authorization client.
Index ¶
- type Client
- func (c *Client) CheckPermission(ctx context.Context, namespace, object, relation, subjectID string) (bool, error)
- func (c *Client) DeleteIdentity(ctx context.Context, id string) error
- func (c *Client) DeleteKetoTuple(ctx context.Context, namespace, object, relation, subjectID string) error
- func (c *Client) KetoCheck(ctx context.Context, req KetoCheckRequest) (bool, error)
- func (c *Client) ListIdentities(ctx context.Context, pageSize int) ([]Identity, error)
- func (c *Client) PermissionRelation() string
- func (c *Client) RoleNamespace() string
- func (c *Client) RoleRelation() string
- func (c *Client) SeedPermissions(ctx context.Context, permissions []PermissionDef) error
- func (c *Client) ValidateJWT(_ context.Context, tokenString string, _ string) (jwt.MapClaims, error)
- func (c *Client) ValidateSession(ctx context.Context, token string) (*Session, error)
- func (c *Client) WriteKetoTuple(ctx context.Context, namespace, object, relation, subjectID string) error
- type Config
- type Identity
- type KetoCheckRequest
- type PermissionDef
- type Session
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client wraps Ory Kratos (auth) and Keto (authorization).
func (*Client) CheckPermission ¶ added in v0.31.0
func (c *Client) CheckPermission(ctx context.Context, namespace, object, relation, subjectID string) (bool, error)
CheckPermission reports whether subjectID has relation on namespace:object according to Keto (a direct check, distinct from the middleware gate).
func (*Client) DeleteIdentity ¶ added in v0.31.0
DeleteIdentity removes a Kratos identity by id (admin API).
func (*Client) DeleteKetoTuple ¶ added in v0.31.0
func (c *Client) DeleteKetoTuple(ctx context.Context, namespace, object, relation, subjectID string) error
DeleteKetoTuple removes a relation tuple from Ory Keto. Keto deletes by query parameters (namespace + object + relation + subject_id). A 404 means the tuple was already absent and is treated as success.
func (*Client) ListIdentities ¶ added in v0.31.0
ListIdentities returns the Kratos identities (up to pageSize, default 250).
func (*Client) PermissionRelation ¶ added in v0.31.0
PermissionRelation returns the Keto relation that grants a permission.
func (*Client) RoleNamespace ¶ added in v0.31.0
RoleNamespace returns the Keto namespace that models role membership.
func (*Client) RoleRelation ¶ added in v0.31.0
RoleRelation returns the Keto relation that grants a role to a subject.
func (*Client) SeedPermissions ¶ added in v0.31.0
func (c *Client) SeedPermissions(ctx context.Context, permissions []PermissionDef) error
SeedPermissions writes the role → permission tuples that let a role reach a permission through a Keto subject set:
<resource>:<action>#<permission_relation>@<role_namespace>:<role>#<role_relation>
Idempotent: Keto's write API returns 201 on create and 409/200 on repeat.
func (*Client) ValidateJWT ¶
func (c *Client) ValidateJWT(_ context.Context, tokenString string, _ string) (jwt.MapClaims, error)
ValidateJWT validates a JWT signed by Ory Kratos using JWKS.
func (*Client) ValidateSession ¶
ValidateSession validates a session cookie or token against Ory Kratos.
type Config ¶
type Config struct {
KratosPublicURL string
// KratosAdminURL is the Kratos admin API, used to manage identities.
// When empty, identity management methods return an error.
KratosAdminURL string
// KetoURL is the base Keto URL, used for both reads (checks) and writes
// when the specific URLs below are empty.
KetoURL string
// KetoReadURL is the Keto read API (checks); defaults to KetoURL.
KetoReadURL string
// KetoWriteURL is the Keto write API (tuples); defaults to KetoURL.
KetoWriteURL string
TTL time.Duration
// RoleNamespace/RoleRelation name the Keto tuple that grants a role
// (default: roles / assignee). PermissionRelation names the relation that
// grants a permission on a resource namespace (default: perform).
RoleNamespace string
RoleRelation string
PermissionRelation string
}
Config holds Ory connection settings.
type Identity ¶ added in v0.31.0
type Identity struct {
ID string `json:"id"`
State string `json:"state"`
Traits map[string]any `json:"traits"`
}
Identity is a Kratos identity as returned by the admin API.
type KetoCheckRequest ¶
KetoCheckRequest defines an authorization check against Ory Keto.
type PermissionDef ¶ added in v0.31.0
PermissionDef declares a role → permission grant seeded into Keto.
type Session ¶
type Session struct {
Identity struct {
ID string `json:"id"`
Traits map[string]any `json:"traits"`
} `json:"identity"`
}
Session holds the validated user session from Kratos.