pub struct AuthzCasbinPlugin {
enforcer: Arc<Enforcer>,
username_header: String,
}Expand description
Evaluates each request against a compiled Casbin model + policy.
Fields§
§enforcer: Arc<Enforcer>The compiled enforcer, shared read-only across requests.
username_header: StringLowercased header the subject falls back to when no consumer identity is attached.
Implementations§
Source§impl AuthzCasbinPlugin
impl AuthzCasbinPlugin
Sourcepub fn from_config(
config: &HashMap<String, Value>,
_resources: &Arc<PluginResources>,
) -> Result<Self, String>
pub fn from_config( config: &HashMap<String, Value>, _resources: &Arc<PluginResources>, ) -> Result<Self, String>
Builds the plugin from node config, compiling the enforcer eagerly.
Accepted keys (one of the two source pairs is required, matching
APISIX’s oneOf):
model_path(string) +policy_path(string): load the Casbin model and policy from files on the gateway host.model(string) +policy(string): inline Casbin model config and CSV policy text (loaded via Casbin’s in-memory string adapter).username_header(string, default"x-user"): header the subject is read from when no consumer identity (consumer.name) is present; lowercased for the case-insensitive header map.
Fails fast if neither source pair is fully provided or if Casbin rejects the model/policy.
# inline model + policy
- id: authz
type: authz-casbin
config:
username_header: x-user
model: |
[request_definition]
r = sub, obj, act
[policy_definition]
p = sub, obj, act
[role_definition]
g = _, _
[policy_effect]
e = some(where (p.eft == allow))
[matchers]
m = g(r.sub, p.sub) && r.obj == p.obj && r.act == p.act
policy: |
p, admin, /data, GET
g, alice, admin# model + policy files on the gateway host
- id: authz
type: authz-casbin
config:
model_path: /etc/featherbit/model.conf
policy_path: /etc/featherbit/policy.csv
username_header: x-userSourcefn subject(&self, ctx: &Context) -> String
fn subject(&self, ctx: &Context) -> String
Resolves the Casbin subject: the attached consumer identity if present,
else the configured header, else "anonymous".
Sourcefn deny(ctx: Context) -> Result<PluginOutput, PluginExecutionError>
fn deny(ctx: Context) -> Result<PluginOutput, PluginExecutionError>
Builds the 403 denial carrying the context so the graph engine routes through the error port.
Trait Implementations§
Source§impl Plugin for AuthzCasbinPlugin
impl Plugin for AuthzCasbinPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Unique identifier for the plugin type (e.g., “proxy-rewrite”, “upstream”).
Source§fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Executes the plugin logic against the request/response context. Read more
Auto Trait Implementations§
impl Freeze for AuthzCasbinPlugin
impl !RefUnwindSafe for AuthzCasbinPlugin
impl Send for AuthzCasbinPlugin
impl Sync for AuthzCasbinPlugin
impl Unpin for AuthzCasbinPlugin
impl UnsafeUnpin for AuthzCasbinPlugin
impl !UnwindSafe for AuthzCasbinPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more