Documentation
¶
Overview ¶
Package rbac compiles the host's role configuration into the immutable schema the engine authorizes against: each persona's permission catalog, its roles, and the pure grant-resolution core. It depends only on the standard library and iam, and has no database.
A persona is a type of permission group (channel, org, merchant). A permission group is one instance of a persona. root is the persona with exactly one group, the whole site.
Index ¶
- func Builtins(name iam.Persona, credentials bool) []iam.Perm
- func Covers(grants []string, perm iam.Perm) bool
- type Assignment
- type Persona
- type PersonaSpec
- type Role
- type RoleSpec
- type Schema
- func (s *Schema) KnownPermission(perm iam.Perm) bool
- func (s *Schema) MFAPermissions() []iam.Perm
- func (s *Schema) Permission(text string) (iam.Perm, bool)
- func (s *Schema) Persona(name iam.Persona) (Persona, bool)
- func (s *Schema) PersonaNamed(name string) (iam.Persona, bool)
- func (s *Schema) Personas() []iam.Persona
- func (s *Schema) RequiresMFA(grants []string) bool
- func (s *Schema) ResolveGrants(target string, assignments []Assignment) []string
- func (s *Schema) Role(persona iam.Persona, role iam.Role) (Role, bool)
- func (s *Schema) RoleNamed(persona iam.Persona, name string) (Role, bool)
- func (s *Schema) Roles(persona iam.Persona) ([]Role, bool)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Assignment ¶
Assignment is a subject's single role in one permission group, tagged with that group's persona.
type Persona ¶
type Persona struct {
Name iam.Persona
// Permissions is the complete catalog: app-declared plus built-ins, sorted.
Permissions []iam.Perm
Roles []Role // declared roles (includes flattened) plus owner
APIKeys bool
}
Persona is a compiled persona.
type PersonaSpec ¶
type PersonaSpec struct {
Name iam.Persona
Permissions []iam.Perm // app-defined catalog; AuthKit adds its built-ins
RequireMFA []iam.Perm // permissions or patterns of the catalog that need MFA
APIKeys bool
RemoteApplications bool
}
PersonaSpec is one declared persona, built by the Roles builder: its names are valid by construction.
type Role ¶
Role is a compiled role: its grant patterns with includes flattened. RequiresMFA is derived: the grants reach an MFA permission.
type RoleSpec ¶
type RoleSpec struct {
Name iam.Role
Grants []iam.Perm // permissions or patterns
Includes []iam.Role // roles of the same persona
}
RoleSpec is one declared role.
type Schema ¶
type Schema struct {
// contains filtered or unexported fields
}
Schema is the validated, immutable role configuration.
func New ¶
func New(personas []PersonaSpec, roles []RoleSpec) (*Schema, error)
New compiles the declared personas and roles, checking what the builder cannot see while declaring: catalogs, grants, includes and MFA patterns. root always exists; a root entry only adds app permissions and capabilities.
func (*Schema) KnownPermission ¶
KnownPermission reports whether perm is a concrete permission registered in some persona's catalog.
func (*Schema) MFAPermissions ¶
MFAPermissions lists, sorted, the catalog permissions that need MFA.
func (*Schema) Permission ¶
Permission resolves a registered concrete permission read at run time.
func (*Schema) PersonaNamed ¶
PersonaNamed resolves a persona name read at run time.
func (*Schema) RequiresMFA ¶
RequiresMFA reports whether grants reach a permission that needs MFA. MFA follows permissions, not role names: a clone, an include or a root role holding such a permission needs MFA as much as the role that first held it.
func (*Schema) ResolveGrants ¶
func (s *Schema) ResolveGrants(target string, assignments []Assignment) []string
ResolveGrants returns the de-duplicated union of grant patterns a subject holds in the group with id target, across its assignments on that group and on root. Root is the widest scope: a root role's persona permissions apply in every group, but root's own `root:` permissions count only in root itself. Unknown personas and roles contribute nothing (fail closed).