Documentation
¶
Overview ¶
Package openfga provides the OpenFGA authorization client.
Index ¶
- Variables
- type CheckRequest
- type Checker
- type Client
- func (c *Client) AssignRole(ctx context.Context, user, role string) error
- func (c *Client) Check(ctx context.Context, req CheckRequest) (bool, error)
- func (c *Client) DeleteTuple(ctx context.Context, user, relation, object string) error
- func (c *Client) EnsureDefaultModel(ctx context.Context, resources ResourceActions) (string, error)
- func (c *Client) EnsureModel(ctx context.Context, permissions []PermissionDef) (string, error)
- func (c *Client) SeedPermissions(ctx context.Context, permissions []PermissionDef) error
- func (c *Client) WriteAuthorizationModel(ctx context.Context, model openfga.WriteAuthorizationModelRequest) (string, error)
- func (c *Client) WriteTuple(ctx context.Context, user, relation, object string) error
- type Config
- type PermissionDef
- type ResourceActions
Constants ¶
This section is empty.
Variables ¶
var DefaultActions = []string{"create", "read", "update", "delete", "publish"}
DefaultActions lists the actions granted by DefaultPermissions.
Functions ¶
This section is empty.
Types ¶
type CheckRequest ¶
CheckRequest defines an authorization check.
type Checker ¶
type Checker interface {
Check(ctx context.Context, req CheckRequest) (bool, error)
}
Checker is the interface for authorization checks.
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client wraps OpenFGA SDK for authorization checks.
func (*Client) AssignRole ¶ added in v0.30.0
AssignRole makes a user a member of a role (user → member → role:<role>). Idempotent: re-assigning an existing role is a no-op.
func (*Client) DeleteTuple ¶
DeleteTuple deletes a relationship tuple from OpenFGA.
func (*Client) EnsureDefaultModel ¶ added in v0.30.0
EnsureDefaultModel writes the authorization model matching the SDK conventions: a `user` that is `member` of `role:<name>` inherits `can_<action>` on `<resource>:<action>`. OpenFGA uses the latest model, so this is safe to call on every startup; it returns the new model ID.
func (*Client) EnsureModel ¶ added in v0.30.0
EnsureModel derives the authorization model from the collected permissions and writes it. The base types (`user`, `role`) are always written so the role gate works even with no permissions; resources and actions come from the permissions themselves, so custom actions (e.g. `users:manage`) are covered.
func (*Client) SeedPermissions ¶
func (c *Client) SeedPermissions(ctx context.Context, permissions []PermissionDef) error
SeedPermissions seeds role-permission tuples into OpenFGA. Idempotent: safe to call on every startup. Each action becomes a userset tuple: role:<role>#member → can_<action> → <resource>:<action>, so every member of the role inherits the permission.
func (*Client) WriteAuthorizationModel ¶
func (c *Client) WriteAuthorizationModel(ctx context.Context, model openfga.WriteAuthorizationModelRequest) (string, error)
WriteAuthorizationModel writes an authorization model to OpenFGA.
type PermissionDef ¶
type PermissionDef struct {
Role string `json:"role"`
Resource string `json:"resource"`
Actions []string `json:"actions"`
}
PermissionDef defines a role-to-actions mapping for seeding.
func DefaultPermissions ¶
func DefaultPermissions(resource string) []PermissionDef
DefaultPermissions returns a sensible default set of permissions matching the CRUD entry pattern.
type ResourceActions ¶ added in v0.30.0
ResourceActions maps a resource type to the actions that must exist as `can_<action>` relations on it.