List all users with a relationship to an object
The ListUsers API returns a list of all the users of a specific type that have a relation to a given object.
To arrive at a result, the API uses:
-
Explicit tuples written through the Write API
-
Contextual tuples present in the request
-
Implicit tuples that exist by virtue of applying set theory
For example: document:2021-budget#viewer@document:2021-budget#viewer. In this example, the set of users who are viewers of document:2021-budget are the set of users who are the viewers of document:2021-budget.
An authorization_model_id may be specified in the body. If it is not specified, the latest authorization model ID is used.
Note: We recommend you specify authorization model ID for better performance.
You may also specify contextual_tuples that are treated as regular tuples. Each of these tuples may have an associated condition.
You may also provide a context object used to evaluate the conditioned tuples in the system.
Note: We recommend you provide a value for all the input parameters of all the conditions. This ensures that all tuples be evaluated correctly.
The response contains the related users in an array in the “users” field of the response. These results may include specific objects, usersets or type-bound public access. Each of these types of results is encoded in its own type and not represented as a string.
In cases where a type-bound public access result is returned (e.g. user:*), it cannot be inferred that all subjects
of that type have a relation to the object; it is possible that negations exist and checks should still be queried
on individual subjects to ensure access to that document.
The number of users in the response array are limited by the execution timeout specified in the flag OPENFGA_LIST_USERS_DEADLINE and by the upper bound specified in the flag OPENFGA_LIST_USERS_MAX_RESULTS, whichever is hit first.
The returned users are not sorted, and therefore two identical calls may yield different sets of users.
Path Parameters
Body
Object represents an OpenFGA Object.
An Object is composed of a type and identifier (e.g. 'document:1')
"document:example"
"reader"
The type of results returned. Only accepts exactly one value.
1 element"01G5JAVJ41T49E9TT3SKVS7X1J"
Controls the consistency preference for this request. Default value is UNSPECIFIED, which has the same behavior as MINIMIZE_LATENCY.
UNSPECIFIED, MINIMIZE_LATENCY, HIGHER_CONSISTENCY "MINIMIZE_LATENCY"
Additional request context used to evaluate any ABAC conditions encountered in the query evaluation.
100Response
A successful response.