folder is a parent of a document.
When to useThis design pattern is helpful in the case where there are relationships between different objects. With OpenFGA, so long as both objects are in a type defined in the authorization model, relationship tuples can be added to indicate a relationship between them.For example:
communitiescan containchannelschannelscan containpostschannelscan containthreadsthreadscan containpostsbookshelfcan havebookstripscan havebookingsaccountcan containtransactionsbuildingscan havedoors
Before you start
To better follow this guide, make sure you’re familiar with some OpenFGA Concepts and know how to develop the things listed below. You will start with the authorization model below, it represents adocument type that can have users related as editor, and folder type that can have users related as viewer.
Step by step
01. Create parent relations in document
To represent that afolder can be a parent of a document, we first need to modify our document type definition to allow a parent relation.
02. Add Parent Relationship Tuples
Once the type definition is updated, we can now create the relationship between afolder as a parent of a document. To do this, we will create a new relationship tuple that describes: folder:budgets is a parent of document:may_budget.doc. In OpenFGA, users in the relationship tuples can not only be IDs, but also other objects in the form of type:object_id.
03. Check that parent folders have permissions
Once that relationship tuple is added to OpenFGA, we can check if the relationship is valid by asking the following: “is folder:budgets a parent of document:may_budget.doc?” It is important to note that the current authorization model does not imply inheritance of permissions. Even though folder:budgets is aparent of document:may_budget.doc, it does not inherit the editor relation from parent to document. Meaning editors on folder:budgets are not editors on document:may_budget.doc. Further configuration changes are needed to indicate that and will be tackled in a later guide.
Advanced object to object relationships
Object to object can be used for more advanced use case, such as entitlements. An example use case is to allow subscribers to be entitled to different plans.01. Create authorization model with object to object relationships
To do this, the authorization model will have two types - feature and plan. Typefeature has two relations, associated_plan and access. Relation associated_plan allows associating plans with features while access defines who can access the feature. In our case, the access can be achieved either from
- direct relationship via direct relationship type restrictions. or
this - object to object relationship where a user can access because it is a subscriber_member of a particular plan AND that plan is associated with the feature.
plan as the user of object feature with relationship associated_plan rather than defining feature as the user of object plan with relationship feature. The reason we choose the former is that we want to describe our system in the following plain language:
- A user can access a feature in a plan if they are a subscriber member of a plan that is the associated plan of a feature.
02. Adding relationship tuples
To realize the relationship, we will need to add the following relationship tuples.03. Check to see if access is allowed without direct relationship
To validate that the authorization model and relationship tuples are correct, we can ask the question: We see thatanne is allowed to access feature:data_preview without requiring direct relationship.
04. Disassociating plan from feature
At any point in time,plan:advanced may be disassociated from feature:data_preview.
When this is the case, anne will no longer have access to feature:data_preview even though she is still a subscriber_member of plan:advanced.
Related Sections
Check the following sections for more on how object-to-object relationships can be used.Advanced Modeling Patterns: Entitlements
Learn how to model entitlement access patterns.
Modeling Parent-Child Relationships
Learn how to model parent and child relationships.
Modeling User Groups
Learn how to model user groups.