When to useRelationship tuples can specify that an entire group has a relation to an object, which is helpful when you want to encompass a set of users with the same relation to an object. For example:
- Grant
vieweraccess to a group ofengineersinroadmap.doc - Create a
block_listofmemberswho can’t access adocument - Sharing a
documentwith ateam - Granting
vieweraccess to aphototofollowersonly - Making a
fileviewable for alluserswithin anorganization - Restricting access from or to
usersin a certainlocale
Before you start
Familiarize yourself with the OpenFGA Concepts. Assume you have the following authorization model. : you have an object calleddocument that users can relate to as an editor.
Step By Step
There are possible use cases where a group of users have a certain role on or permission to an object. For example,members of a certain team could have an editor relation to a certain document.
To represent this in OpenFGA:
- Introduce the concept of a
teamto the authorization model. → - Add users as
membersto theteam. → - Assign the
teammembers a relation to an object. → - Check an individual member’s access to the object. →
01. Introduce the concept of a team to the authorization model
First, define the objectteam in your authorization model. In this use case, a team can have members, so you make the following changes to the authorization model:
02. Add users as members to the team
You can now assign users asmembers of teams. Create a new relationship tuple that states user:alice is a member of team:writers.
03. Assign the team members a relation to an object
To represent groups, use thetype:object_id#relation format, which represents the set of users related to the type:object_id as a certain relation. For example, team:writers#members represents the set of users related to the team:writers object as members.
In order to assign members of a team a relation to a document, create the following relationship tuple stating that members of team:writers are editors of document:meeting_notes.doc.
04. Check an individual member’s access to an object
Now that you have:- a relationship tuple indicating that
aliceis amemberofteam:writers - a relationship tuple indicating that
membersofteam:writersare editors ofdocument:meeting_notes.doc
is alice an editor of document:meeting_notes.doc returns the following:
The chain of resolution is:
aliceismemberofteam:writersmembers ofteam:writersareeditors ofdocument:meeting_notes- therefore,
aliceiseditorofdocument:meeting_notes
Related Sections
Check the following sections for more information on user groups.Managing Group Membership
Learn how to add and remove users from groups
Modeling Google Drive
See how User Groups can be used to share documents within a domain in the Google Drive use-case.
Modeling GitHub
Granting teams permissions to a repo in the GitHub use-case.