When to usePublic access allows your application to grant every user in the system access to an object. You would add a relationship tuple with type-bound public access when:
- sharing a
documentpublicly to indicate that everyone canviewit - a public
pollis created to indicate that anyone canvoteon it - a blog
postis published and anyone should be able toreadit - a
videois made public for anyone towatch
Before You Start
In order to understand this guide correctly you must be familiar with some OpenFGA Concepts and know how to develop the things that we will list below. Assume that you have the following authorization model. You have a type calleddocument that can have a view relation.
Step By Step
In previous guides, we have shown how to indicate that objects are related to users or objects. In some cases, you might want to indicate that everyone is related to an object (for example when sharing a document publicly).01. Create A Relationship Tuple
To do this we need to create a relationship tuple using the type bound public access. The type bound public access syntax is used to indicate that all users of a particular type have a relation to a specific object. Let us create a relationship tuple that states: any user can view document:company-psa.doc02. Check That The Relationship Exists
Once the above relationship tuple is added, we can check if bob cabview document:company-psa.doc. OpenFGA will return { "allowed": true } even though no relationship tuple linking bob to the document was added. That is because the relationship tuple with user:* as the user made it so every object of type user (such as user:bob) can view the document, making it public.
Related Sections
Check the following sections for more on how to model with OpenFGA.Modeling: Getting Started
Learn about how to get started with modeling.
Configuration Language
Learn about OpenFGA Configuration Language.
Modeling Blocklists
Learn about model block lists.