authorizer

package
v0.27.0-rc.12 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 1 Imported by: 8

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type DeviceClaims added in v0.17.0

type DeviceClaims struct {
	UID      string `json:"uid"`
	TenantID string `json:"tenant"`
}

DeviceClaims represents the attributes needed to authenticate a device.

type Permission

type Permission int

Permission is one action a role may or may not perform. The values are iota-assigned and carry no meaning outside the process: they are never persisted or sent on the wire, so the list can be reordered.

const (
	DeviceAccept Permission = iota
	DeviceReject
	DeviceUpdate
	DeviceRemove
	DeviceConnect
	DeviceRename
	DeviceDetails
	DeviceCustomFieldUpdate

	TagCreate
	TagUpdate
	TagDelete

	SessionPlay
	SessionClose
	SessionRemove
	SessionDetails
	SessionApprove

	FirewallCreate
	FirewallEdit
	FirewallRemove

	PublicKeyCreate
	PublicKeyEdit
	PublicKeyRemove

	NamespaceUpdate
	NamespaceAddMember
	NamespaceRemoveMember
	NamespaceEditMember
	NamespaceEnableSessionRecord
	NamespaceDelete

	BillingCreateCustomer
	BillingChooseDevices
	BillingAddPaymentMethod
	BillingUpdatePaymentMethod
	BillingRemovePaymentMethod
	BillingCancelSubscription
	BillingCreateSubscription
	BillingGetPaymentMethod
	BillingGetSubscription

	APIKeyCreate
	APIKeyUpdate
	APIKeyDelete

	ProvisioningKeyCreate
	ProvisioningKeyUpdate
	ProvisioningKeyReveal
	ProvisioningKeyList

	ConnectorDelete
	ConnectorUpdate
	ConnectorSet

	TunnelsCreate
	TunnelsDelete

	AccessPolicyManage

	// SSHIdentityAdd allows adding and managing one's own SSH identities.
	// Owner/admin/operator.
	SSHIdentityAdd
	// SSHIdentityManage allows viewing and revoking any member's SSH identities
	// in the namespace (offboarding). Owner/admin only.
	SSHIdentityManage
)

The actions a role can be granted. Grouped by resource, and deliberately finer-grained than the routes: one route may require several, and a role is the set it holds.

type Role

type Role string

Role defines a user access level.

const (
	// RoleInvalid represents an invalid role. Any operation with this role will
	// be rejected.
	RoleInvalid Role = ""
	// RoleObserver represents a namespace observer. An observer can only retrieve device
	// and session details. It holds no [DeviceConnect], so it cannot connect to a device,
	// except by native SSH in the legacy access mode, where no identity reaches the check.
	RoleObserver Role = "observer"
	// RoleOperator represents a namespace operator. An operator has only device-related
	// permissions, excluding the [DeviceRemove] permission. An operator also has the
	// [SessionDetails] permission.
	RoleOperator Role = "operator"
	// RoleAdministrator represents a namespace administrator. An administrator has
	// similar permissions to [RoleOwner] but cannot delete the namespace. They also do
	// not have permission for any billing-related actions.
	RoleAdministrator Role = "administrator"
	// RoleOwner represents a namespace owner. The owner has all permissions.
	RoleOwner Role = "owner"
)

func RoleFromString

func RoleFromString(str string) Role

RoleFromString returns the Role corresponding to the given string. If the string is not a valid role, it returns RoleInvalid.

func (Role) Assignable

func (r Role) Assignable() bool

Assignable reports whether r is a role a person can be given. The switch names every role and takes no default, so a role added later fails the exhaustive check until someone places it.

func (Role) HasAuthority

func (r Role) HasAuthority(passive Role) bool

HasAuthority reports whether the role r has greater or equal authority compared to the passive role. It always returns false if the active role is invalid or if the passive role is RoleOwner. A passive role of RoleInvalid is treated as the lowest rank (code 0); any valid active role outranks it, so HasAuthority returns true. This allows owners (and other privileged members) to repair or remove members whose stored role is empty or corrupted, rather than permanently locking them out. Callers that must reject a passive RoleInvalid (e.g. update-membership) should add that check explicitly at the call site.

func (Role) HasPermission

func (r Role) HasPermission(permission Permission) bool

HasPermission reports whether the role r has the specified permission.

func (Role) Permissions

func (r Role) Permissions() []Permission

Permissions returns all permissions associated with the role r. If the role is RoleInvalid, it returns an empty slice.

func (Role) String

func (r Role) String() string

String converts the given role to its corresponding string. Every role outside the four assignable ones, RoleInvalid included, converts to the empty string, so a caller that must tell an absent role from a real one tests the Role itself rather than this result.

type UserClaims added in v0.17.0

type UserClaims struct {
	ID     string `json:"id"`
	Origin string `json:"origin"`
	// TenantID is the identifier of the tenant to which the claims belongs.
	// It's optional.
	TenantID string `json:"tenant"`
	Role     Role   `json:"-"`
	Username string `json:"name"`
	// MFA indicates whether multi-factor authentication is enabled for the user.
	MFA bool `json:"mfa"`
	// Admin indicates whether the user has administrative privileges.
	Admin bool `json:"admin"`
}

UserClaims represents the attributes needed to authenticate a user.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL