RBAC with Domains
Role definition with domains
In Casbin, roles can be domain-scoped: the same user can have different roles in different domains (tenants). That fits multi-tenant and cloud systems where one user works in many tenants.
Use a role definition with three elements; the third is the domain:
[role_definition]
g = _, _, _
The third field is the domain. Example policy:
p, admin, tenant1, data1, read
p, admin, tenant2, data2, read
g, alice, admin, tenant1
g, alice, user, tenant2
So: admin in tenant1 can read data1. Alice is admin in tenant1 and user in tenant2; she can read data1 but not data2 (only admin in tenant2 can read data2).
Matcher: include the domain in g and require it to match:
[matchers]
m = g(r.sub, p.sub, r.dom) && r.dom == p.dom && r.obj == p.obj && r.act == p.act