openfga

package
v0.34.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: Apache-2.0 Imports: 6 Imported by: 0

Documentation

Overview

Package openfga provides the OpenFGA authorization client.

Index

Constants

This section is empty.

Variables

View Source
var DefaultActions = []string{"create", "read", "update", "delete", "publish"}

DefaultActions lists the actions granted by DefaultPermissions.

Functions

This section is empty.

Types

type CheckRequest

type CheckRequest struct {
	User     string
	Relation string
	Object   string
}

CheckRequest defines an authorization check.

type Checker

type Checker interface {
	Check(ctx context.Context, req CheckRequest) (bool, error)
}

Checker is the interface for authorization checks.

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client wraps OpenFGA SDK for authorization checks.

func NewClient

func NewClient(cfg Config) (*Client, error)

NewClient creates an OpenFGA client.

func (*Client) AssignRole added in v0.30.0

func (c *Client) AssignRole(ctx context.Context, user, role string) error

AssignRole makes a user a member of a role (user → member → role:<role>). Idempotent: re-assigning an existing role is a no-op.

func (*Client) Check

func (c *Client) Check(ctx context.Context, req CheckRequest) (bool, error)

Check performs an authorization check against OpenFGA.

func (*Client) DeleteTuple

func (c *Client) DeleteTuple(ctx context.Context, user, relation, object string) error

DeleteTuple deletes a relationship tuple from OpenFGA.

func (*Client) EnsureDefaultModel added in v0.30.0

func (c *Client) EnsureDefaultModel(ctx context.Context, resources ResourceActions) (string, error)

EnsureDefaultModel writes the authorization model matching the SDK conventions: a `user` that is `member` of `role:<name>` inherits `can_<action>` on `<resource>:<action>`. OpenFGA uses the latest model, so this is safe to call on every startup; it returns the new model ID.

func (*Client) EnsureModel added in v0.30.0

func (c *Client) EnsureModel(ctx context.Context, permissions []PermissionDef) (string, error)

EnsureModel derives the authorization model from the collected permissions and writes it. The base types (`user`, `role`) are always written so the role gate works even with no permissions; resources and actions come from the permissions themselves, so custom actions (e.g. `users:manage`) are covered.

func (*Client) SeedPermissions

func (c *Client) SeedPermissions(ctx context.Context, permissions []PermissionDef) error

SeedPermissions seeds role-permission tuples into OpenFGA. Idempotent: safe to call on every startup. Each action becomes a userset tuple: role:<role>#member → can_<action> → <resource>:<action>, so every member of the role inherits the permission.

func (*Client) WriteAuthorizationModel

func (c *Client) WriteAuthorizationModel(ctx context.Context, model openfga.WriteAuthorizationModelRequest) (string, error)

WriteAuthorizationModel writes an authorization model to OpenFGA.

func (*Client) WriteTuple

func (c *Client) WriteTuple(ctx context.Context, user, relation, object string) error

WriteTuple writes a relationship tuple to OpenFGA.

type Config

type Config struct {
	APIURL  string
	StoreID string
}

Config holds OpenFGA connection settings.

type PermissionDef

type PermissionDef struct {
	Role     string   `json:"role"`
	Resource string   `json:"resource"`
	Actions  []string `json:"actions"`
}

PermissionDef defines a role-to-actions mapping for seeding.

func DefaultPermissions

func DefaultPermissions(resource string) []PermissionDef

DefaultPermissions returns a sensible default set of permissions matching the CRUD entry pattern.

type ResourceActions added in v0.30.0

type ResourceActions map[string][]string

ResourceActions maps a resource type to the actions that must exist as `can_<action>` relations on it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL