When to useGranting access with a relationship tuple is a core part of OpenFGA. Without any relationship tuples, any check will fail. You should use:
- authorization model to represent what relations are possible between the users and objects in your system
- relationship tuples to represent the facts about the relationships between users and objects in your system.
Before you start
In order to understand this guide correctly you must be familiar with some OpenFGA Concepts and know how to develop the things that we will list below. Assume that you have the following authorization model.You have a type called
tweet that can have a reader.
Prerequisites and starting model
Prerequisites and starting model
In addition, you will need to know the following:
Direct access
You need to know how to create an authorization model and create a relationship tuple to grant a user access to an object. Learn more →OpenFGA concepts
- A Type: a class of objects that have similar characteristics
- A User: an entity in the system that can be related to an object
- A Relation: is a string defined in the type definition of an authorization model that defines the possibility of a relationship between an object of the same type as the type definition and a user in the system
- An Object: represents an entity in the system. Users’ relationships to it can be define through relationship tuples and the authorization model
- A Relationship Tuple: a grouping consisting of a user, a relation and an object stored in OpenFGA
Step by step
01. Adding direct relationship
For our application, we will give user Anne thereader relationship to a particular tweet. To do so we add a tuple as follows:
Anne can read tweet:1
tweet:1. When we call the Check API to see if Anne has a reader relationship, OpenFGA will say yes.
02. Removing direct relationship
Now let’s change this so that Anne no longer has areader relationship to tweet:1 by deleting the tuple:
With this, we have removed the direct relationship between Anne and tweet:1. And because our type definition for reader does not include any other relations, a call to the Check API will now return a negative response.
Related Sections
Check the following sections for more on how to manage user access.Direct Access
Learn about how to model granting user access to an object.
Modeling Public Access
Learn about how to model granting public access.
How to update relationship tuples
Learn about how to update relationship tuples in SDK.