ory

package
v0.34.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package ory provides Ory Kratos authentication and Keto authorization client.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client wraps Ory Kratos (auth) and Keto (authorization).

func NewClient

func NewClient(cfg Config) *Client

NewClient creates an Ory client (Kratos + Keto).

func (*Client) CheckPermission added in v0.31.0

func (c *Client) CheckPermission(ctx context.Context, namespace, object, relation, subjectID string) (bool, error)

CheckPermission reports whether subjectID has relation on namespace:object according to Keto (a direct check, distinct from the middleware gate).

func (*Client) DeleteIdentity added in v0.31.0

func (c *Client) DeleteIdentity(ctx context.Context, id string) error

DeleteIdentity removes a Kratos identity by id (admin API).

func (*Client) DeleteKetoTuple added in v0.31.0

func (c *Client) DeleteKetoTuple(ctx context.Context, namespace, object, relation, subjectID string) error

DeleteKetoTuple removes a relation tuple from Ory Keto. Keto deletes by query parameters (namespace + object + relation + subject_id). A 404 means the tuple was already absent and is treated as success.

func (*Client) KetoCheck

func (c *Client) KetoCheck(ctx context.Context, req KetoCheckRequest) (bool, error)

KetoCheck performs an authorization check against Ory Keto.

func (*Client) ListIdentities added in v0.31.0

func (c *Client) ListIdentities(ctx context.Context, pageSize int) ([]Identity, error)

ListIdentities returns the Kratos identities (up to pageSize, default 250).

func (*Client) PermissionRelation added in v0.31.0

func (c *Client) PermissionRelation() string

PermissionRelation returns the Keto relation that grants a permission.

func (*Client) RoleNamespace added in v0.31.0

func (c *Client) RoleNamespace() string

RoleNamespace returns the Keto namespace that models role membership.

func (*Client) RoleRelation added in v0.31.0

func (c *Client) RoleRelation() string

RoleRelation returns the Keto relation that grants a role to a subject.

func (*Client) SeedPermissions added in v0.31.0

func (c *Client) SeedPermissions(ctx context.Context, permissions []PermissionDef) error

SeedPermissions writes the role → permission tuples that let a role reach a permission through a Keto subject set:

<resource>:<action>#<permission_relation>@<role_namespace>:<role>#<role_relation>

Idempotent: Keto's write API returns 201 on create and 409/200 on repeat.

func (*Client) ValidateJWT

func (c *Client) ValidateJWT(_ context.Context, tokenString string, _ string) (jwt.MapClaims, error)

ValidateJWT validates a JWT signed by Ory Kratos using JWKS.

func (*Client) ValidateSession

func (c *Client) ValidateSession(ctx context.Context, token string) (*Session, error)

ValidateSession validates a session cookie or token against Ory Kratos.

func (*Client) WriteKetoTuple

func (c *Client) WriteKetoTuple(ctx context.Context, namespace, object, relation, subjectID string) error

WriteKetoTuple writes a relation tuple to Ory Keto.

type Config

type Config struct {
	KratosPublicURL string
	// KratosAdminURL is the Kratos admin API, used to manage identities.
	// When empty, identity management methods return an error.
	KratosAdminURL string
	// KetoURL is the base Keto URL, used for both reads (checks) and writes
	// when the specific URLs below are empty.
	KetoURL string
	// KetoReadURL is the Keto read API (checks); defaults to KetoURL.
	KetoReadURL string
	// KetoWriteURL is the Keto write API (tuples); defaults to KetoURL.
	KetoWriteURL string
	TTL          time.Duration
	// RoleNamespace/RoleRelation name the Keto tuple that grants a role
	// (default: roles / assignee). PermissionRelation names the relation that
	// grants a permission on a resource namespace (default: perform).
	RoleNamespace      string
	RoleRelation       string
	PermissionRelation string
}

Config holds Ory connection settings.

type Identity added in v0.31.0

type Identity struct {
	ID     string         `json:"id"`
	State  string         `json:"state"`
	Traits map[string]any `json:"traits"`
}

Identity is a Kratos identity as returned by the admin API.

type KetoCheckRequest

type KetoCheckRequest struct {
	Namespace string
	Object    string
	Relation  string
	SubjectID string
}

KetoCheckRequest defines an authorization check against Ory Keto.

type PermissionDef added in v0.31.0

type PermissionDef struct {
	Role     string
	Resource string
	Action   string
}

PermissionDef declares a role → permission grant seeded into Keto.

type Session

type Session struct {
	Identity struct {
		ID     string         `json:"id"`
		Traits map[string]any `json:"traits"`
	} `json:"identity"`
}

Session holds the validated user session from Kratos.

func (*Session) OrgID added in v0.31.0

func (s *Session) OrgID() string

OrgID extracts the tenant/organization from the identity traits ("org_id"). Returns "" when absent.

func (*Session) Roles added in v0.31.0

func (s *Session) Roles() []string

Roles extracts role names from the identity traits ("roles" as a list of strings). Keto remains the authorization source of truth; this is only a convenience for drivers that mirror roles into traits.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL