Chuyển tới nội dung chính

Casbin Authorization

fluvius.casbin integrates policy evaluation through PolicyManager, PolicyRequest, PolicyResponse, and the SQL-backed PolicySchema.

from fluvius.casbin import PolicyManager
from fluvius.domain import Domain


class OrdersDomain(Domain):
__namespace__ = "orders"
__aggregate__ = OrdersAggregate
__policymgr__ = PolicyManager

Commands with policy_required = True are checked before processing. For simpler authorization, command metadata can declare roles_required; those roles come from the active profile and are distinct from IAM realm roles used by API zones.

Set FLUVIUS_CASBIN_MODEL_PATH to the model configuration. Persist and seed application policies through the owning application's migration/bootstrap process, and deny access when policy metadata is missing rather than silently allowing it.