document if both of these conditions are met:
- they are a member of the organization that owns the document
- they have writer permissions on the document
When to useThis is useful when:
- Limiting certain actions (such as deleting or reading sensitive document) to privileged users.
- Adding restrictions and requiring multiple authorization paths before granting access.
Before You Start
In order to understand this guide correctly you must be familiar with some OpenFGA Concepts and know how to develop the things that we will list below.Prerequisites and starting model
Prerequisites and starting model
You will start with the authorization model below,
it represents a
In addition, you will need to know the following:
document type that can have users
related as writer and organizations related as owner.
Document’s can_write relation is based on whether user is a writer to the document. The organization type can have users related as member.Let us also assume that we have:- A
documentcalled “planning” owned by the ABCorganization. - Becky is a member of the ABC
organization. - Carl is a member of the XYZ
organization. - Becky and Carl both have
writeraccess to the “planning”document.
- organization ABC is the owner of planning document
- Becky is a writer to the planning document
- Carl is a writer to the planning document
- Becky is a member of the organization ABC
- Carl is a member of the organization XYZ
Note that we assign the organization, not the organization’s members, as owner to the planning document.
In addition, you will need to know the following:
Modeling Parent-Child Objects
You need to know how to model access based on parent-child relationships, e.g.: folders and documents. Learn more →Modeling Roles And Permissions
You need to know how to model roles for users at the object level and model permissions for those roles. Learn more →OpenFGA Concepts
- A Type: a class of objects that have similar characteristics
- A User: an entity in the system that can be related to an object
- A Relation: is a string defined in the type definition of an authorization model that defines the possibility of a relationship between an object of the same type as the type definition and a user in the system
- An Object: represents an entity in the system. Users’ relationships to it can be define through relationship tuples and the authorization model
- A Relationship Tuple: a grouping consisting of a user, a relation and an object stored in OpenFGA
- Intersection Operator: the intersection operator can be used to indicate a relationship exists if the user is in all the sets of users
Step By Step
With the above authorization model and relationship tuples, OpenFGA will correctly respond with{"allowed":true} when check is called to see if Carl and Becky can write this document.
We can verify that by issuing two check requests:
What we would like to do is offer a way so that a document can be written by Becky and Carl, but only writers who are also members of the organization that owns the document can remove it.
To do this, we need to:
- Add can_delete relation to only allow writers that are members of the ownership organization
- Verify that our solutions work
01. Add can_delete Relation To Only Allow Writers That Are Members Of The Ownership Organization
The first step is to add the relation definition forcan_delete so that it requires users to be both writer and member of the owner. This is accomplished via the keyword and.
02. Verify That Our Solutions Work
To verify that our solutions work, we need to check that Becky can delete the planning document because she is a writer AND she is a member of organization:ABC that owns the planning document. However, Carl cannot delete the planning document because although he is a writer, Carl is not a member of organization:ABC that owns the planning document.Related Sections
Check the following sections for more on how to model privileged access.Modeling: User Groups
Learn about how to add group members.
Modeling: Blocklists
Learn about how to set block lists.
Modeling: Public Access
Learn about model public access.