📄️ Choosing a Model
ACL, RBAC, ABAC, ReBAC and PBAC compared on one example: what each decides on, strengths, weaknesses, when to choose it, and how to combine RBAC with ABAC.
📄️ Supported Models
Access control models supported by Casbin - ACL, RBAC, RBAC with domains, ABAC, ReBAC, PBAC, BLP, Biba, LBAC, OrBAC, UCON, RESTful, IP match, deny-override and priority.
📄️ Model Syntax
Casbin model syntax reference - request, policy, role and effect definitions and matchers in CONF files, with operators and examples.
📄️ Effector
The Casbin Effector interface combines the effects of all matching policy rules into one decision, for allow-override, deny-override, priority and custom effects.
📄️ Functions
Built-in Casbin matcher functions - keyMatch, keyMatch2-5, regexMatch, ipMatch, globMatch and key extraction - and how to register your own custom functions.
🗃️ RBAC
5 items
📄️ ReBAC
Relationship-based access control (ReBAC) with Casbin - authorize users through their relationships to resources and resource types.
📄️ ABAC
Attribute-based access control (ABAC) with Casbin - pass structs or objects to Enforce() and compare their attributes, such as the resource owner, directly in the matcher.
📄️ PBAC
Policy-based access control (PBAC) in Casbin - store rule expressions in policy and evaluate them at runtime with eval() for context-dependent decisions.
🗃️ MAC
3 items
📄️ OrBAC
Implement organisation-based access control (OrBAC) in Casbin - roles, activities and views mapped to concrete users, actions and objects per organization.
📄️ Priority Model
Resolve conflicting rules with the Casbin priority model - implicit priority by policy order, explicit priority fields, and role-hierarchy-based priority.
📄️ Usage Control (UCON)
Usage control (UCON) with Casbin - authorizations, obligations and conditions that are checked continuously during use, with mutable attributes.
📄️ Super Administrator
Суперадміністратор є адміністратором всієї системи. Це може бути використано в моделях, таких як RBAC, ABAC та RBAC з доменами.