Documentation
¶
Overview ¶
Package rbac compiles the host's role configuration into the immutable schema the engine authorizes against: each persona's permission catalog, its roles, and the pure grant-resolution core. It depends only on the standard library and iam, and has no database.
A persona is a type of permission group (channel, org, merchant). A permission group is one instance of a persona. root is the persona with exactly one group, the whole site.
Index ¶
- Constants
- func Builtins(name iam.Persona, credentials, directory, roles bool) []iam.Perm
- func Catalog(spec PersonaSpec) []iam.Perm
- func Covers(grants []string, perm iam.Perm) bool
- func CoversAll(grants, perms []string) bool
- func CustomName(role iam.Role) string
- func CustomRole(persona iam.Persona, name string) (iam.Role, bool)
- func Expand(catalog, grants []iam.Perm) []iam.Perm
- func IsCustom(role iam.Role) bool
- type Assignment
- type Persona
- type PersonaSpec
- type Role
- type RoleSpec
- type Schema
- func (s *Schema) AssignedRole(persona iam.Persona, role iam.Role, stored []string) (Role, bool)
- func (s *Schema) CustomGrants(persona iam.Persona, grants []iam.Perm) ([]string, error)
- func (s *Schema) KnownPermission(perm iam.Perm) bool
- func (s *Schema) MFAPermissions() []iam.Perm
- func (s *Schema) Permission(text string) (iam.Perm, bool)
- func (s *Schema) Persona(name iam.Persona) (Persona, bool)
- func (s *Schema) PersonaNamed(name string) (iam.Persona, bool)
- func (s *Schema) Personas() []iam.Persona
- func (s *Schema) RequiresMFA(grants []string) bool
- func (s *Schema) ResolveGrants(target string, assignments []Assignment) []string
- func (s *Schema) Role(persona iam.Persona, role iam.Role) (Role, bool)
- func (s *Schema) RoleNamed(persona iam.Persona, name string) (Role, bool)
- func (s *Schema) Roles(persona iam.Persona) ([]Role, bool)
Constants ¶
const ( CustomPrefix = "custom-" // MaxCustomName bounds the name a group gives a custom role. MaxCustomName = 64 // MaxCustomGrants bounds what one custom role holds. MaxCustomGrants = 256 )
A custom role is one a group defines at run time, held only in that group: `<persona>:custom-<name>`. Declared role names never start with CustomPrefix, so the two never meet, whatever a later deploy declares.
Variables ¶
This section is empty.
Functions ¶
func Builtins ¶
Builtins returns the permissions AuthKit registers for a persona: members always, credentials when it has API keys or remote applications, the directory when it has remote applications, roles when its groups define their own, and on root its intrinsic account permissions.
func Catalog ¶ added in v1.1.0
func Catalog(spec PersonaSpec) []iam.Perm
Catalog is a persona's complete catalog: its declared permissions and the built-ins AuthKit registers, sorted.
func CoversAll ¶ added in v1.1.0
CoversAll reports whether grants cover every grant in perms, patterns included.
func CustomName ¶ added in v1.19.0
CustomName is the name a group gave the custom role.
func CustomRole ¶ added in v1.19.0
CustomRole is persona's custom role named name (`storefront` is `<persona>:custom-storefront`); ok is false for an invalid name.
Types ¶
type Assignment ¶
type Assignment struct {
Persona iam.Persona
PermissionGroupID string
Role iam.Role
Custom []string
}
Assignment is a subject's single role in one permission group, tagged with that group's persona. Custom is what a custom role grants as the group stores it, nil when the group defines no such role.
type Persona ¶
type Persona struct {
Name iam.Persona
// Permissions is the complete catalog: app-declared plus built-ins, sorted.
Permissions []iam.Perm
Roles []Role // declared roles (includes flattened) plus owner
APIKeys bool
// RemoteApplications: the persona's groups control remote applications
// and hold their users' directory.
RemoteApplications bool
// CustomRoles: the persona's groups define roles of their own.
CustomRoles bool
}
Persona is a compiled persona.
type PersonaSpec ¶
type PersonaSpec struct {
Name iam.Persona
Permissions []iam.Perm // app-defined catalog; AuthKit adds its built-ins
RequireMFA []iam.Perm // permissions or patterns of the catalog that need MFA
APIKeys bool
RemoteApplications bool
CustomRoles bool
}
PersonaSpec is one declared persona, built by the Roles builder: its names are valid by construction.
type Role ¶
Role is a compiled role: its grant patterns with includes flattened. RequiresMFA is derived: the grants reach an MFA permission.
type RoleSpec ¶
type RoleSpec struct {
Name iam.Role
Grants []iam.Perm // permissions or patterns
Includes []iam.Role // roles of the same persona
}
RoleSpec is one declared role.
type Schema ¶
type Schema struct {
// contains filtered or unexported fields
}
Schema is the validated, immutable role configuration.
func New ¶
func New(personas []PersonaSpec, roles []RoleSpec) (*Schema, error)
New compiles the declared personas and roles, checking what the builder cannot see while declaring: catalogs, grants, includes and MFA patterns. root always exists; a root entry only adds app permissions and capabilities.
func (*Schema) AssignedRole ¶ added in v1.19.0
AssignedRole is the role a subject holds in a group of persona: a declared role, or a custom role with stored, what the group stores for it (nil: the group defines none). A custom role confers only the grants a declared role of the persona could hold, and nothing once the persona stops defining custom roles.
func (*Schema) CustomGrants ¶ added in v1.19.0
CustomGrants validates what a custom role of persona would hold and returns it de-duplicated, in order: permissions or namespace-anchored patterns that a declared role of the persona may hold (a persona role its own persona's, a root role any persona's), each matching a catalog permission. A custom role includes no other role.
func (*Schema) KnownPermission ¶
KnownPermission reports whether perm is a concrete permission registered in some persona's catalog.
func (*Schema) MFAPermissions ¶
MFAPermissions lists, sorted, the catalog permissions that need MFA.
func (*Schema) Permission ¶
Permission resolves a registered concrete permission read at run time.
func (*Schema) PersonaNamed ¶
PersonaNamed resolves a persona name read at run time.
func (*Schema) RequiresMFA ¶
RequiresMFA reports whether grants reach a permission that needs MFA. MFA follows permissions, not role names: a clone, an include or a root role holding such a permission needs MFA as much as the role that first held it.
func (*Schema) ResolveGrants ¶
func (s *Schema) ResolveGrants(target string, assignments []Assignment) []string
ResolveGrants returns the de-duplicated union of grant patterns a subject holds in the group with id target, across its assignments on that group and on root. Root is the widest scope: a root role's persona permissions apply in every group, but root's own `root:` permissions count only in root itself. Unknown personas and roles contribute nothing (fail closed).