Repository navigation
Nexus PDP: error responses on the AuthZen API, and the Nexus PDP API key in the how-tos #661
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
eef8aff
db345d3
bd3a8f7
c7c6b7d
267d0a1
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -10,8 +10,8 @@ Call `permit.check()` from your backend to decide whether a user can perform an | |
| ## Prerequisites | ||
|
|
||
| - A Permit.io policy with at least one resource, action, and role ([Configure your first RBAC policy](/overview/configure-your-first-rbac-policy)) | ||
| - Your environment API key ([Get your API key](/overview/get-api-key)) | ||
| - A Permit SDK client connected to a PDP ([Run the PDP](/overview/run-pdp)) | ||
| - Your environment API key ([Get your API key](/overview/get-api-key)). On [Permit Nexus PDP](/concepts/pdp/nexus-pdp), use the environment's [Nexus PDP API key](/concepts/pdp/nexus-pdp-deployment#prerequisites) instead. | ||
| - A Permit SDK client connected to a PDP ([Run the PDP](/overview/run-pdp), or [Deploy Nexus PDP](/concepts/pdp/nexus-pdp-deployment) for Nexus PDP) | ||
|
|
||
| The examples on this page use the Node.js SDK. The other Permit SDKs take the same arguments: `permit.check()` in Python and Java, and `permit.Check()` in Go. | ||
|
|
||
|
|
@@ -96,7 +96,7 @@ const permitted = await permit.check( | |
| ``` | ||
|
|
||
| :::note ABAC needs a container PDP | ||
| The Cloud PDP doesn't evaluate ABAC policies. Run a container PDP for attribute-based checks. See [Cloud PDP capabilities](/concepts/pdp/cloud-pdp-capabilities). | ||
| The Cloud PDP and Nexus PDP don't evaluate ABAC policies. On Nexus PDP, a check against a policy that uses condition sets, user sets, or resource sets returns a deny, not an error. Run a container PDP for attribute-based checks. See [Cloud PDP capabilities](/concepts/pdp/cloud-pdp-capabilities) and [Nexus PDP feature parity](/concepts/pdp/nexus-pdp-feature-parity#abac). | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [LOW] The deny applies to the Cloud PDP too, and only to access that an ABAC rule would grant Problem: This sentence is the wording the previous review suggested, taken from Nexus PDP feature parity. It has two gaps:
Suggestion: The Cloud PDP and Nexus PDP don't evaluate ABAC policies. On both PDP types, a rule that uses condition sets, user sets, or resource sets never grants access: a check that only such a rule allows returns `false`, not an error. Checks that a role grants still return `true`. Run a container PDP for attribute-based checks. See [Cloud PDP capabilities](/concepts/pdp/cloud-pdp-capabilities) and [Nexus PDP feature parity](/concepts/pdp/nexus-pdp-feature-parity#abac).The warning in Nexus PDP feature parity (line 61) uses the same wording and needs the same change. |
||
| ::: | ||
|
|
||
| To store attributes in Permit instead of passing them on every check, see [Load custom data](/how-to/manage-data/loading-data). | ||
|
|
@@ -161,10 +161,10 @@ In the Node.js SDK, the fourth argument of `permit.check()` is the context objec | |
|
|
||
| ## Call the PDP API directly \{#using-the-api} | ||
|
|
||
| Without an SDK, send the check to the PDP's `POST /allowed` endpoint. Pass your environment API key in the `Authorization: Bearer` header and the check in the JSON body. | ||
| Without an SDK, send the check to the PDP's `POST /allowed` endpoint. Pass your environment API key in the `Authorization: Bearer` header and the check in the JSON body. On Nexus PDP, pass the Nexus PDP API key instead. | ||
|
|
||
| ```bash | ||
| curl -X POST https://<your-permit-pdp-url>/allowed \ | ||
| curl -X POST <your-permit-pdp-url>/allowed \ | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [MEDIUM] The sample still fails after the URL fix: Problem: This commit makes the sample URL work, but the body on line 171 sends
The paragraph above the sample tells readers to send it to any of the three PDP types, so everyone who copies it gets Suggestion: In its own commit, as STYLE_GUIDE.md "Code samples" asks, change the body: curl -X POST <your-permit-pdp-url>/allowed \
-H "Content-Type: application/json" \
-H "Authorization: Bearer <your-permit-api-key>" \
-d '{
"user": { "key": "john@permit.io" },
"action": "create",
"resource": {
"type": "document",
"tenant": "companyA"
},
"context": {}
}' |
||
| -H "Content-Type: application/json" \ | ||
| -H "Authorization: Bearer <your-permit-api-key>" \ | ||
| -d '{ | ||
|
|
@@ -178,7 +178,7 @@ curl -X POST https://<your-permit-pdp-url>/allowed \ | |
| }' | ||
| ``` | ||
|
|
||
| Replace `<your-permit-pdp-url>` with the address of your container PDP (for example, `http://localhost:7766`) or the Cloud PDP (`https://cloudpdp.api.permit.io`). | ||
| Replace `<your-permit-pdp-url>` with the address of your container PDP (for example, `http://localhost:7766`) or the Cloud PDP (`https://cloudpdp.api.permit.io`). For Nexus PDP, use the address of its authorization API ([Deploy Nexus PDP](/concepts/pdp/nexus-pdp-deployment)). | ||
|
EliMoshkovich marked this conversation as resolved.
|
||
|
|
||
| The response body contains an `allow` field. `"allow": true` means the user is permitted. | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[MEDIUM] On the Cloud PDP and Nexus PDP, the ABAC item returns the ReBAC item's result, not a deny
Problem: The second item in the sample below sends the same user key, action and resource instance (
document:${document.id}) as the first item, plus the user'stierattribute. The Cloud PDP and Nexus PDP skip ABAC rules, but they still evaluate RBAC and ReBAC for every item, and neither model reads user attributes (the Cloud PDP and Nexus PDP source is in cloud-pdp). So on both PDP types the second result always equals the first:truewhen a role on the document or a tenant role grantsedit,falseotherwise. "The ABAC item returns a deny" holds only when the first item is denied too.A reader who tries the example on Nexus PDP and gets
[true, true]would conclude that the tier rule matched. The note's conclusion (only the ReBAC check can allow the edit) is right, but the stated reason is not. "On them" also doesn't name the PDP types (STYLE_GUIDE.md: explicit names over pronouns).Suggestion: