When to useConcentric relations make the most sense when your domain logic has nested relations, where one having relation implies having another relation.For example:
- all
editorsareviewers - all
managersaremembers - all
device_managersaredevice_renamers
Before You Start
To better understand this guide, you should be familiar with some OpenFGA Concepts and know how to develop the things listed below.Prerequisites and starting model
Prerequisites and starting model
You will start with the authorization model below, it represents a
In addition, you will need to know the following:
document type that can have users related as editor and viewer.Let us also assume that we have a document called “meeting_notes.doc” and bob is assigned as editor to this document.The current state of the system is represented by the following relationship tuples being in the system already:In addition, you will need to know the following:
Modeling User Groups
You need to know how to add users to groups and grant groups access to resources. Learn more →OpenFGA concepts
- A Type: a class of objects that have similar characteristics
- A User: an entity in the system that can be related to an object
- A Relation: is a string defined in the type definition of an authorization model that defines the possibility of a relationship between an object of the same type as the type definition and a user in the system
- An Object: represents an entity in the system. Users’ relationships to it can be define through relationship tuples and the authorization model
- A Relationship Tuple: a grouping consisting of a user, a relation and an object stored in OpenFGA
Step by step
With the current type definition, there isn’t a way to indicate that alleditors of a certain document are also automatically viewers of that document. So for a certain user, in order to indicate that they can both edit and view a certain document, two relationship tuples need to be created (one for editor, and another for viewer).
01. Modify our model to imply editor as viewer
Instead of creating two relationship tuples, we can leverage concentric relationships by defining editors are viewers. Our authorization model becomes the following:viewer of a document are any of:- users that are directly assigned as
viewer - users that have
editorof the document
editor relationship with a certain document implies having a viewer relationship with that same document.
02. Check that editors are viewers
Since we had a relationship tuple that indicates that bob is aneditor of document:meeting_notes.doc, this means bob is now implicitly a viewer of document:meeting_notes.doc.
If we now check: is bob a viewer of document:meeting_notes.doc? we would get the following:
Related Sections
Check the following sections for more on how concentric relationships can be used.Modeling Google Drive
See how to indicate that editors are commenters and viewers in Google Drive.
Modeling GitHub
See how to indicate that repository admins are writers and readers in GitHub.