authorization

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 15, 2026 License: MIT Imports: 11 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type AuthorizationManager

type AuthorizationManager struct {
	// contains filtered or unexported fields
}

AuthorizationManager handles role and permission management

func NewAuthorizationManager

func NewAuthorizationManager(db *gorm.DB, cfg config.AuthorizationConfig) (*AuthorizationManager, error)

NewAuthorizationManager creates a new authorization manager. cfg selects where casbin policy/grouping rows live (database via gorm-adapter, or a file via casbin's own file-adapter) and, optionally, a custom RBAC model file — see config.AuthorizationConfig's doc comment. This is the single enforcer shared by AuthorizationManager itself and AuthMiddleware (see middleware.NewAuthMiddleware), replacing what used to be two independently-constructed enforcers.

func (*AuthorizationManager) AssignRole

func (m *AuthorizationManager) AssignRole(ctx context.Context, userID, roleName string, duration *time.Duration) error

AssignRole assigns a role to a user

func (*AuthorizationManager) CreateResource

func (m *AuthorizationManager) CreateResource(ctx context.Context, name, description string, actions []string) error

CreateResource creates a new resource in the catalog.

func (*AuthorizationManager) CreateRole

func (m *AuthorizationManager) CreateRole(ctx context.Context, name, description string, metadata map[string]interface{}) error

CreateRole creates a new role

func (*AuthorizationManager) DeleteResource

func (m *AuthorizationManager) DeleteResource(ctx context.Context, name string) error

DeleteResource removes a resource from the catalog. Does not cascade any casbin p rows referencing this resource name — permissions granted against a resource that's since been deleted from the catalog remain enforceable until explicitly revoked; the catalog is metadata for the dashboard, not the source of truth for what casbin will enforce.

func (*AuthorizationManager) DeleteRole

func (m *AuthorizationManager) DeleteRole(ctx context.Context, name string) error

DeleteRole removes a role and cascades: every user's assignment of this role in casbin's grouping policy (g), every permission granted to this role in casbin's policy store (p), then the roles/role_assignments rows. Order matters — the casbin cascade needs the role name, which is still resolvable before the DB row is gone.

func (*AuthorizationManager) Enforcer

func (m *AuthorizationManager) Enforcer() *casbin.Enforcer

Enforcer returns the shared casbin enforcer, for callers (AuthMiddleware, the management HTTP handlers) that need direct Enforce/policy calls outside the higher-level role/permission methods below.

func (*AuthorizationManager) GetResource

func (m *AuthorizationManager) GetResource(ctx context.Context, name string) (*repositories.Resource, error)

GetResource returns a resource's stored record.

func (*AuthorizationManager) GetRole

func (m *AuthorizationManager) GetRole(ctx context.Context, name string) (*repositories.Role, error)

GetRole returns a role's stored record, including Metadata — consuming apps read this back to check app-defined conventions like a "delegable" flag (nebularcore itself doesn't interpret metadata contents).

func (*AuthorizationManager) GetRolePermissions

func (m *AuthorizationManager) GetRolePermissions(ctx context.Context, roleName string) ([][]string, error)

GetRolePermissions gets all permissions assigned to a role

func (*AuthorizationManager) GetUserRoles

func (m *AuthorizationManager) GetUserRoles(ctx context.Context, userID string) ([]*repositories.Role, error)

GetUserRoles gets all roles assigned to a user

func (*AuthorizationManager) GrantPermission

func (m *AuthorizationManager) GrantPermission(ctx context.Context, roleName, resource, action string) error

GrantPermission grants a permission to a role

func (*AuthorizationManager) HasPermission

func (m *AuthorizationManager) HasPermission(ctx context.Context, userID, resource, action string) (bool, error)

HasPermission checks if a user has a specific permission

func (*AuthorizationManager) HasRole

func (m *AuthorizationManager) HasRole(ctx context.Context, userID, roleName string) (bool, error)

HasRole checks if a user has a specific role

func (*AuthorizationManager) ListAllPolicies

func (m *AuthorizationManager) ListAllPolicies(ctx context.Context) ([][]string, error)

ListAllPolicies returns every policy line in the p store — every role->resource->action grant across all roles.

func (*AuthorizationManager) ListPermissionsForRole

func (m *AuthorizationManager) ListPermissionsForRole(ctx context.Context, roleName string) ([][]string, error)

ListPermissionsForRole is a clarifying alias for GetRolePermissions, matching the naming used elsewhere in this file's new List* methods.

func (*AuthorizationManager) ListResources

func (m *AuthorizationManager) ListResources(ctx context.Context) ([]*repositories.Resource, error)

ListResources returns every resource in the catalog.

func (*AuthorizationManager) ListRoles

func (m *AuthorizationManager) ListRoles(ctx context.Context) ([]*repositories.Role, error)

ListRoles returns every role.

func (*AuthorizationManager) RevokePermission

func (m *AuthorizationManager) RevokePermission(ctx context.Context, roleName, resource, action string) error

RevokePermission revokes a permission from a role

func (*AuthorizationManager) UnassignRole

func (m *AuthorizationManager) UnassignRole(ctx context.Context, userID, roleName string) error

UnassignRole removes a role from a user

func (*AuthorizationManager) UpdateResource

func (m *AuthorizationManager) UpdateResource(ctx context.Context, name, description string, actions []string) error

UpdateResource updates a resource's description/actions. Name is immutable — see ResourceRepository.UpdateResource's doc comment.

func (*AuthorizationManager) UpdateRole

func (m *AuthorizationManager) UpdateRole(ctx context.Context, name, description string, metadata map[string]interface{}) error

UpdateRole updates a role's description/metadata. Name is immutable — see RoleRepository.UpdateRole's doc comment for why.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL