rbac

package
v0.148.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 7 Imported by: 0

Documentation

Overview

Package rbac compiles the host's role configuration into the immutable schema the engine authorizes against: each persona's permission catalog, its roles, and the pure grant-resolution core. It depends only on the standard library and iam, and has no database.

A persona is a type of permission group (channel, org, merchant). A permission group is one instance of a persona. root is the persona with exactly one group, the whole site.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Builtins

func Builtins(name iam.Persona, credentials bool) []iam.Perm

Builtins returns the permissions AuthKit registers for a persona: members always, credentials when it has API keys or remote applications, and on root its intrinsic account permissions.

func Covers

func Covers(grants []string, perm iam.Perm) bool

Covers reports whether any grant pattern covers the concrete perm.

Types

type Assignment

type Assignment struct {
	Persona           iam.Persona
	PermissionGroupID string
	Role              iam.Role
}

Assignment is a subject's single role in one permission group, tagged with that group's persona.

type Persona

type Persona struct {
	Name iam.Persona
	// Permissions is the complete catalog: app-declared plus built-ins, sorted.
	Permissions []iam.Perm
	Roles       []Role // declared roles (includes flattened) plus owner
	APIKeys     bool
}

Persona is a compiled persona.

type PersonaSpec

type PersonaSpec struct {
	Name               iam.Persona
	Permissions        []iam.Perm // app-defined catalog; AuthKit adds its built-ins
	RequireMFA         []iam.Perm // permissions or patterns of the catalog that need MFA
	APIKeys            bool
	RemoteApplications bool
}

PersonaSpec is one declared persona, built by the Roles builder: its names are valid by construction.

type Role

type Role struct {
	Name        iam.Role
	Permissions []string
	RequiresMFA bool
}

Role is a compiled role: its grant patterns with includes flattened. RequiresMFA is derived: the grants reach an MFA permission.

type RoleSpec

type RoleSpec struct {
	Name     iam.Role
	Grants   []iam.Perm // permissions or patterns
	Includes []iam.Role // roles of the same persona
}

RoleSpec is one declared role.

type Schema

type Schema struct {
	// contains filtered or unexported fields
}

Schema is the validated, immutable role configuration.

func Default

func Default() *Schema

Default is the root-only schema.

func New

func New(personas []PersonaSpec, roles []RoleSpec) (*Schema, error)

New compiles the declared personas and roles, checking what the builder cannot see while declaring: catalogs, grants, includes and MFA patterns. root always exists; a root entry only adds app permissions and capabilities.

func (*Schema) KnownPermission

func (s *Schema) KnownPermission(perm iam.Perm) bool

KnownPermission reports whether perm is a concrete permission registered in some persona's catalog.

func (*Schema) MFAPermissions

func (s *Schema) MFAPermissions() []iam.Perm

MFAPermissions lists, sorted, the catalog permissions that need MFA.

func (*Schema) Permission

func (s *Schema) Permission(text string) (iam.Perm, bool)

Permission resolves a registered concrete permission read at run time.

func (*Schema) Persona

func (s *Schema) Persona(name iam.Persona) (Persona, bool)

Persona returns a persona's compiled definition.

func (*Schema) PersonaNamed

func (s *Schema) PersonaNamed(name string) (iam.Persona, bool)

PersonaNamed resolves a persona name read at run time.

func (*Schema) Personas

func (s *Schema) Personas() []iam.Persona

Personas returns the persona names, sorted; root is always present.

func (*Schema) RequiresMFA

func (s *Schema) RequiresMFA(grants []string) bool

RequiresMFA reports whether grants reach a permission that needs MFA. MFA follows permissions, not role names: a clone, an include or a root role holding such a permission needs MFA as much as the role that first held it.

func (*Schema) ResolveGrants

func (s *Schema) ResolveGrants(target string, assignments []Assignment) []string

ResolveGrants returns the de-duplicated union of grant patterns a subject holds in the group with id target, across its assignments on that group and on root. Root is the widest scope: a root role's persona permissions apply in every group, but root's own `root:` permissions count only in root itself. Unknown personas and roles contribute nothing (fail closed).

func (*Schema) Role

func (s *Schema) Role(persona iam.Persona, role iam.Role) (Role, bool)

Role returns a catalog role of persona; a role of another persona is not one.

func (*Schema) RoleNamed

func (s *Schema) RoleNamed(persona iam.Persona, name string) (Role, bool)

RoleNamed returns persona's catalog role name.

func (*Schema) Roles

func (s *Schema) Roles(persona iam.Persona) ([]Role, bool)

Roles returns a persona's roles.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL