rbac

package
v1.20.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 11, 2026 License: MIT Imports: 7 Imported by: 0

Documentation

Overview

Package rbac compiles the host's role configuration into the immutable schema the engine authorizes against: each persona's permission catalog, its roles, and the pure grant-resolution core. It depends only on the standard library and iam, and has no database.

A persona is a type of permission group (channel, org, merchant). A permission group is one instance of a persona. root is the persona with exactly one group, the whole site.

Index

Constants

View Source
const (
	CustomPrefix = "custom-"
	// MaxCustomName bounds the name a group gives a custom role.
	MaxCustomName = 64
	// MaxCustomGrants bounds what one custom role holds.
	MaxCustomGrants = 256
)

A custom role is one a group defines at run time, held only in that group: `<persona>:custom-<name>`. Declared role names never start with CustomPrefix, so the two never meet, whatever a later deploy declares.

Variables

This section is empty.

Functions

func Builtins

func Builtins(name iam.Persona, credentials, directory, roles bool) []iam.Perm

Builtins returns the permissions AuthKit registers for a persona: members always, credentials when it has API keys or remote applications, the directory when it has remote applications, roles when its groups define their own, and on root its intrinsic account permissions.

func Catalog added in v1.1.0

func Catalog(spec PersonaSpec) []iam.Perm

Catalog is a persona's complete catalog: its declared permissions and the built-ins AuthKit registers, sorted.

func Covers

func Covers(grants []string, perm iam.Perm) bool

Covers reports whether any grant pattern covers the concrete perm.

func CoversAll added in v1.1.0

func CoversAll(grants, perms []string) bool

CoversAll reports whether grants cover every grant in perms, patterns included.

func CustomName added in v1.19.0

func CustomName(role iam.Role) string

CustomName is the name a group gave the custom role.

func CustomRole added in v1.19.0

func CustomRole(persona iam.Persona, name string) (iam.Role, bool)

CustomRole is persona's custom role named name (`storefront` is `<persona>:custom-storefront`); ok is false for an invalid name.

func Expand added in v1.1.0

func Expand(catalog, grants []iam.Perm) []iam.Perm

Expand lists every permission of catalog some grant pattern covers, in catalog order: what a client checks by set membership.

func IsCustom added in v1.19.0

func IsCustom(role iam.Role) bool

IsCustom reports whether role is a custom role's name.

Types

type Assignment

type Assignment struct {
	Persona           iam.Persona
	PermissionGroupID string
	Role              iam.Role
	Custom            []string
}

Assignment is a subject's single role in one permission group, tagged with that group's persona. Custom is what a custom role grants as the group stores it, nil when the group defines no such role.

type Persona

type Persona struct {
	Name iam.Persona
	// Permissions is the complete catalog: app-declared plus built-ins, sorted.
	Permissions []iam.Perm
	Roles       []Role // declared roles (includes flattened) plus owner
	APIKeys     bool
	// RemoteApplications: the persona's groups control remote applications
	// and hold their users' directory.
	RemoteApplications bool
	// CustomRoles: the persona's groups define roles of their own.
	CustomRoles bool
	// OAuthClients: the persona's groups register OAuth clients.
	OAuthClients bool
}

Persona is a compiled persona.

type PersonaSpec

type PersonaSpec struct {
	Name               iam.Persona
	Permissions        []iam.Perm // app-defined catalog; AuthKit adds its built-ins
	RequireMFA         []iam.Perm // permissions or patterns of the catalog that need MFA
	APIKeys            bool
	RemoteApplications bool
	CustomRoles        bool
	OAuthClients       bool
}

PersonaSpec is one declared persona, built by the Roles builder: its names are valid by construction.

type Role

type Role struct {
	Name        iam.Role
	Permissions []string
	RequiresMFA bool
}

Role is a compiled role: its grant patterns with includes flattened. RequiresMFA is derived: the grants reach an MFA permission.

type RoleSpec

type RoleSpec struct {
	Name     iam.Role
	Grants   []iam.Perm // permissions or patterns
	Includes []iam.Role // roles of the same persona
}

RoleSpec is one declared role.

type Schema

type Schema struct {
	// contains filtered or unexported fields
}

Schema is the validated, immutable role configuration.

func Default

func Default() *Schema

Default is the root-only schema.

func New

func New(personas []PersonaSpec, roles []RoleSpec) (*Schema, error)

New compiles the declared personas and roles, checking what the builder cannot see while declaring: catalogs, grants, includes and MFA patterns. root always exists; a root entry only adds app permissions and capabilities.

func (*Schema) AssignedRole added in v1.19.0

func (s *Schema) AssignedRole(persona iam.Persona, role iam.Role, stored []string) (Role, bool)

AssignedRole is the role a subject holds in a group of persona: a declared role, or a custom role with stored, what the group stores for it (nil: the group defines none). A custom role confers only the grants a declared role of the persona could hold, and nothing once the persona stops defining custom roles.

func (*Schema) CustomGrants added in v1.19.0

func (s *Schema) CustomGrants(persona iam.Persona, grants []iam.Perm) ([]string, error)

CustomGrants validates what a custom role of persona would hold and returns it de-duplicated, in order: permissions or namespace-anchored patterns that a declared role of the persona may hold (a persona role its own persona's, a root role any persona's), each matching a catalog permission. A custom role includes no other role.

func (*Schema) KnownPermission

func (s *Schema) KnownPermission(perm iam.Perm) bool

KnownPermission reports whether perm is a concrete permission registered in some persona's catalog.

func (*Schema) MFAPermissions

func (s *Schema) MFAPermissions() []iam.Perm

MFAPermissions lists, sorted, the catalog permissions that need MFA.

func (*Schema) Permission

func (s *Schema) Permission(text string) (iam.Perm, bool)

Permission resolves a registered concrete permission read at run time.

func (*Schema) Persona

func (s *Schema) Persona(name iam.Persona) (Persona, bool)

Persona returns a persona's compiled definition.

func (*Schema) PersonaNamed

func (s *Schema) PersonaNamed(name string) (iam.Persona, bool)

PersonaNamed resolves a persona name read at run time.

func (*Schema) Personas

func (s *Schema) Personas() []iam.Persona

Personas returns the persona names, sorted; root is always present.

func (*Schema) RequiresMFA

func (s *Schema) RequiresMFA(grants []string) bool

RequiresMFA reports whether grants reach a permission that needs MFA. MFA follows permissions, not role names: a clone, an include or a root role holding such a permission needs MFA as much as the role that first held it.

func (*Schema) ResolveGrants

func (s *Schema) ResolveGrants(target string, assignments []Assignment) []string

ResolveGrants returns the de-duplicated union of grant patterns a subject holds in the group with id target, across its assignments on that group and on root. Root is the widest scope: a root role's persona permissions apply in every group, but root's own `root:` permissions count only in root itself. Unknown personas and roles contribute nothing (fail closed).

func (*Schema) Role

func (s *Schema) Role(persona iam.Persona, role iam.Role) (Role, bool)

Role returns a catalog role of persona; a role of another persona is not one.

func (*Schema) RoleNamed

func (s *Schema) RoleNamed(persona iam.Persona, name string) (Role, bool)

RoleNamed returns persona's catalog role name.

func (*Schema) Roles

func (s *Schema) Roles(persona iam.Persona) ([]Role, bool)

Roles returns a persona's roles.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL