.fga.yaml contains tests for OpenFGA authorization models. If you are using Visual Studio Code as your IDE, install the OpenFGA extension to enable syntax coloring and validation.
For complete details on the .fga.yaml store file format, see Store File Format.
Define the model and tuples
.fga.yaml files have the following top level items:
The example below defines a model and tuples:
Write tests
Always write tests to verify that the calls your application will make return the results you expect. A good test covers scenarios that verify every relation. Tests have the following structure:Write Check tests
Check tests verify the results of the check API calls to validate access requirements for a user. Each check verification has the following structure:
The following example adds multiple check verifications in every test:
Write List Objects tests
A good test covers scenarios that specify every relation for every object type that your application will need to call the list-objects API for. The following verifies the expected results using thelist_objects option in OpenFGA tests:
user:anne has access to the organization:acme as a member and is not an admin of any organization. It also checks that user:peter, given the current time is February 1st 2024, 0:10 AM, is not related to any organization as a member, but is related to organization:acme as an admin.
Write List Users tests
List users tests verify the results of the list-users API to validate the users who or do not have access to an object Each list users verification has the following structure:
In order to simplify test writing, the following syntax is supported for the various object types included in
users from the API response:
<type>:<id>to represent a userset that is a user<type>:<id>#<relation>to represent a userset that is a relation on a type<type>:*to represent a userset that is a type bound public access for a type
list_users option in OpenFGA tests:
organization:acme, given the current time is February 2nd 2024, it has ‘user:anne’ as a member, nobody as an admin. If we tried with current time being February 1st 2024, then user:peter would be listed as an admin
Testing with Modular Models
If you are using Modular Models, you need to use thefga.mod as the model_file.
You can define tests for each model in separate .fga.yaml files, all of which should reference the common fga.mod model. Shared relationship tuples can be placed in a separate file and included using the tuple_file option. If needed, you can split tuples across multiple shared files and include them with the tuple_files option. Additionally, each .fga.yaml file can include module-specific tuples inline.
Running tests
Tests are run using themodel test CLI command. For instructions on installing the OpenFGA CLI, visit the OpenFGA CLI Github repository.
Running tests using GitHub Actions
Use the OpenFGA Model Testing Action to run tests from CI/CD flows in GitHub. Set the path to the.fga.yaml file as the store-file-path parameter when configuring the action:
Related Sections
Check the following sections for more on how to learn how to write tests.Use the FGA CLI
Learn how to use the FGA CLI.
Super Admin Example
Define a model and tests for modeling a super-admin role.
Banking Example
Define a model and tests for banking application.
Entitlements Example
Define a model and tests for B2B application entitlements.