带域的 RBAC API
带域 RBAC 的便捷 API:按域划分范围的用户—角色和权限操作。它是 Management API 的子集。下文中,e 是加载了支持域的 model 的 Enforcer 实例。
参考
e, err := NewEnforcer("examples/rbac_with_domains_model.conf", "examples/rbac_with_domains_policy.csv")
const e = await newEnforcer('examples/rbac_with_domains_model.conf', 'examples/rbac_with_domains_policy.csv')
$e = new Enforcer('examples/rbac_with_domains_model.conf', 'examples/rbac_with_domains_policy.csv');
e = casbin.Enforcer("examples/rbac_with_domains_model.conf", "examples/rbac_with_domains_policy.csv")
var e = new Enforcer("examples/rbac_with_domains_model.conf", "examples/rbac_with_domains_policy.csv");
let mut e = Enforcer::new("examples/rbac_with_domains_model.conf", "examples/rbac_with_domains_policy.csv").await?;
Enforcer e = new Enforcer("examples/rbac_with_domains_model.conf", "examples/rbac_with_domains_policy.csv");
GetUsersForRoleInDomain
返回在指定域中拥有指定角色的所有用户。
res := e.GetUsersForRoleInDomain("admin", "domain1")
const res = e.getUsersForRoleInDomain("admin", "domain1")
res = e.get_users_for_role_in_domain("admin", "domain1")
GetRolesForUserInDomain
返回指定用户在该域中被分配的所有角色。
res := e.GetRolesForUserInDomain("alice", "domain1")
const res = e.getRolesForUserInDomain("alice", "domain1")
res = e.get_roles_for_user_in_domain("alice", "domain1")
List<String> res = e.getRolesForUserInDomain("admin", "domain1");
GetPermissionsForUserInDomain
返回该用户或角色在指定域中的所有权限(policy 规则)。
res := e.GetPermissionsForUserInDomain("alice", "domain1")
List<List<String>> res = e.getPermissionsForUserInDomain("alice", "domain1");
AddRoleForUserInDomain
在域中为用户分配该角色。如果分配已存在,返回 false。
ok, err := e.AddRoleForUserInDomain("alice", "admin", "domain1")
ok = e.add_role_for_user_in_domain("alice", "admin", "domain1")
boolean ok = e.addRoleForUserInDomain("alice", "admin", "domain1");
DeleteRoleForUserInDomain
在域中移除用户的该角色。如果该关联原本不存在,返回 false。
ok, err := e.DeleteRoleForUserInDomain("alice", "admin", "domain1")
boolean ok = e.deleteRoleForUserInDomain("alice", "admin", "domain1");
DeleteRolesForUserInDomain
移除用户在域中的所有角色。如果该用户在域中没有角色,返回 false。
ok, err := e.DeleteRolesForUserInDomain("alice", "domain1")
GetAllUsersByDomain
返回在指定域中至少拥有一个角色的所有用户。如果 model 中没有域,返回为空。
res := e.GetAllUsersByDomain("domain1")
DeleteAllUsersByDomain
移除指定域中的所有用户—角色分配。如果 model 中没有域,返回 false。
ok, err := e.DeleteAllUsersByDomain("domain1")
DeleteDomains
移除指定域中的所有用户和角色。不带参数时,清空所有域。
ok, err := e.DeleteDomains("domain1", "domain2")