caddy-authz

Caddy-authz is a middleware for Caddy that blocks or allows requests based on access control policies.

Github星跟踪图

Caddy-authz Build Status Coverage Status GoDoc

Caddy-authz is an authorization middleware for Caddy, it's based on https://github.com/casbin/casbin.

Installation

go get github.com/casbin/caddy-authz

Caddyfile syntax

http://localhost:80 {
    authz "/folder/to/caddy_binary/authz_model.conf" "/folder/to/caddy_binary/authz_policy.csv"
    ...
}

The authz directive specifies the path to Casbin model file (.conf) and Casbin policy file (.csv). The Casbin model file describes access control models like ACL, RBAC, ABAC, etc. The Casbin policy file describes the authorization policy rules. For how to write these files, please refer to: https://github.com/casbin/casbin#get-started

A working example

  1. cd into the folder of caddy binary.

  2. Put your Casbin model file authz_model.conf and Casbin policy file authz_policy.csv into this folder.

  3. Add authz directive to your Caddyfile like:

http://localhost:80 {
    authz "authz_model.conf" "authz_policy.csv"
    root "/my-website.net"
}
  1. Run caddy and enjoy.

Note: This plugin only supports HTTP basic authentication to get the logged-in user name, if you use other kinds of authentication like OAuth, LDAP, etc, you may need to customize this plugin.

How to control the access

The authorization determines a request based on {subject, object, action}, which means what subject can perform what action on what object. In this plugin, the meanings are:

  1. subject: the logged-on user name
  2. object: the URL path for the web resource like "dataset1/item1"
  3. action: HTTP method like GET, POST, PUT, DELETE, or the high-level actions you defined like "read-file", "write-blog"

For how to write authorization policy and other details, please refer to the Casbin's documentation.

Getting Help

License

This project is under Apache 2.0 License. See the LICENSE file for the full license text.

主要指标

概览
名称与所有者casbin/caddy-authz
主编程语言Go
编程语言Go (语言数: 1)
平台
许可证Apache License 2.0
所有者活动
创建于2017-05-27 05:31:36
推送于2023-08-06 14:09:08
最后一次提交2021-01-30 20:51:55
发布数4
最新版本名称v2.0.0 (发布于 )
第一版名称v1.0.0 (发布于 )
用户参与
星数243
关注者数3
派生数15
提交数29
已启用问题?
问题数6
打开的问题数0
拉请求数7
打开的拉请求数0
关闭的拉请求数3
项目设置
已启用Wiki?
已存档?
是复刻?
已锁定?
是镜像?
是私有?