Cerbos

Cerbos (latest)

CerbosService

Cerbos Policy Decision Point

Check Deprecated

[Deprecated: Use CheckResources API instead] Check whether a principal has permissions to perform the given actions on a set of resource instances.

Request Body schema: application/json required
requestId string
Optional application-specific ID useful for correlating logs for analysis.
actions
required
Array of strings non-empty unique
List of actions being performed on the set of resources.
principal
required
object (enginev1Principal)
A person or application attempting to perform the actions on the set of resources.
resource
required
object (v1ResourceSet)
Set of resources to check
includeMeta boolean
Opt to receive request processing metadata in the response.
auxData object (cerbosrequestv1AuxData)
Structured auxiliary data useful for evaluating the request

Responses

200

A successful response.

default

An unexpected error response.

Request samples

Content type

application/json

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"actions": ["view:public",

"comment"

],

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"

],

"attr": {"beta_tester": true

},

"scope": "acme.corp"

},

"resource": {"kind": "album:object",

"policyVersion": "default",

"instances": {"XX125": {"attr": {"owner": "bugs_bunny",

"public": false,

"flagged": false

}

},

"XX225": {"attr": {"owner": "daffy_duck",

"public": true,

"flagged": false

}

}

},

"scope": "^(^$|\.|0(\.\w)*)$"

},

"includeMeta": true,

"auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX",

"keySetId": "my-keyset"

}

}
}`

### Response samples

- 200
- default

Content type

application/json

```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"resourceInstances": {"XX125": {"actions": {"view:*": "EFFECT_ALLOW",

"comment": "EFFECT_ALLOW"

},

},

"XX225": {"actions": {"view:*": "EFFECT_DENY",

"comment": "EFFECT_DENY"

},

}

},

"meta": {"resourceInstances": {"XX125": {"actions": {"view:*": {"matched_policy": "album:object:default"

},

"comment": {"matched_policy": "album:object:default"

}

},

"effective_derived_roles": ["owner"

]

},

"XX225": {"actions": {"view:*": {"matched_policy": "album:object:default"

},

"comment": {"matched_policy": "album:object:default"

}

}

}

}

}

}`

### Check resources

Check a principal's permissions to a batch of heterogeneous resources and actions.

##### Request Body schema: application/json  required

|     |     |
| --- | --- |
| requestId | string<br>Optional application-specific ID useful for correlating logs for analysis. |
| includeMeta | boolean<br>Add request processing metadata to the response. |
| principal<br>required | object (enginev1Principal) <br>A person or application attempting to perform the actions on the set of resources. |
| resources<br>required | Array of objects (CheckResourcesRequestResourceEntry)  non-empty  unique <br>List of resources and actions. |
| auxData | object (cerbosrequestv1AuxData) <br>Structured auxiliary data useful for evaluating the request |

### Responses

**200**

A successful response.

**default**

An unexpected error response.

### Request samples

- Payload

Content type

application/json

```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"includeMeta": true,

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"

],

"attr": {"beta_tester": true

},

"scope": "acme.corp"

},

"resources": [{"actions": ["view",

"comment"

],

"resource": {"kind": "album:object",

"policyVersion": "default",

"id": "XX125",

"attr": {"owner": "bugs_bunny",

"public": false,

"flagged": false

}

}

}],

"keySetId": "my-keyset"

}

}
}`

### Response samples

- 200
- default

Content type

application/json

```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"results": [{"resource": {"Id": "XX125",

"kind": "album:object"

},

"actions": {"view": "EFFECT_ALLOW",

"comment": "EFFECT_DENY"

}

}],

"cerbosCallId": "string"

}`

### Check resource batch Deprecated

[Deprecated: Use CheckResources API instead] Check a principal's permissions to a batch of heterogeneous resources and actions.

##### Request Body schema: application/json  required

|     |     |
| --- | --- |
| requestId | string<br>Optional application-specific ID useful for correlating logs for analysis. |
| principal<br>required | object (enginev1Principal) <br>A person or application attempting to perform the actions on the set of resources. |
| resources<br>required | Array of objects (CheckResourceBatchRequestBatchEntry)  non-empty  unique <br>List of resources and actions. |
| auxData | object (cerbosrequestv1AuxData) <br>Structured auxiliary data useful for evaluating the request |

### Responses

**200**

A successful response.

**default**

An unexpected error response.

### Request samples

- Payload

Content type

application/json

```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"

],

"attr": {"beta_tester": true

},

"scope": "acme.corp"

},

"resources": [{"actions": ["view",

"comment"

],

"resource": {"kind": "album:object",

"policyVersion": "default",

"id": "XX125",

"attr": {"owner": "bugs_bunny",

"public": false,

"flagged": false

}

}

}],

"keySetId": "my-keyset"

}

}
}`

### Response samples

- 200
- default

Content type

application/json

```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"results": [{"resourceId": "XX125",

"actions": {"view": "EFFECT_ALLOW"

}

}],

"cerbosCallId": "string"

}`

### Plan resources

Produce a query plan with conditions that must be satisfied for accessing a set of instances of a resource.

##### Request Body schema: application/json  required

|     |     |
| --- | --- |
| requestId | string<br>Optional application-specific ID useful for correlating logs for analysis. |
| action | string<br>Action to be applied to each resource in the list. |
| actions | Array of strings unique <br>List of actions to generate the query plan for. Mutually exclusive with the singular action field. Must contain at least one action and all actions must be unique. |
| principal<br>required | object (enginev1Principal) <br>A person or application attempting to perform the actions on the set of resources. |
| resource<br>required | object (v1PlanResourcesInputResource) |
| auxData | object (cerbosrequestv1AuxData) <br>Structured auxiliary data useful for evaluating the request |
| includeMeta | boolean<br>Opt to receive request processing metadata in the response. |

### Responses

**200**

A successful response.

**default**

An unexpected error response.

### Request samples

- Payload

Content type

application/json

```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"action": "view:public",

"actions": ["view:public",

"edit:profile"

],

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"

],

"attr": {"beta_tester": true

},

"scope": "acme.corp"

},

"resource": {"kind": "album:object",

"attr": {"property1": null,

"property2": null

},

"policyVersion": "default",

"scope": "^(^$|\.|0(\.\w)*)$"

},

"keySetId": "my-keyset"

}

},

"includeMeta": true

}
}`

### Response samples

- 200
- default

Content type

application/json

```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"action": "string",

"actions": ["view:public",

"edit:profile"

],

"resourceKind": "album:object",

"policyVersion": "default",

"filter": {"kind": "KIND_UNSPECIFIED",

"condition": {"value": null,

"expression": {"operator": "string",

"operands": [{}]

},

"variable": "string"

}

},

"meta": {"filterDebug": "string",

"matchedScope": "string",

"matchedScopes": {"property1": "string",

"property2": "string"

}

},

"validationErrors": [{"path": "string",

"message": "string",

"source": "SOURCE_UNSPECIFIED"

}],

"cerbosCallId": "string"

}`

### Get server information

Get information about the server e.g. server version

### Responses

**200**

A successful response.

**default**

An unexpected error response.

### Response samples

- 200
- default

Content type

application/json

```json
{"version": "string",

"commit": "string",

"buildDate": "string"

}`

### CerbosAdminService

Cerbos administration service

### List audit log entries

##### Authorizations:

_BasicAuth_

##### path Parameters

|     |     |
| --- | --- |
| kind<br>required | string<br>Enum:"KIND_UNSPECIFIED"KIND_ACCESS"KIND_DECISION"<br>Kind of log entry |

##### query Parameters

|     |     |
| --- | --- |
| tail | integer <int64> <br>Last N entries. |
| between.start<br>required | string <date-time> <br>Start date in ISO 8601 format. |
| between.end<br>required | string <date-time> <br>End date in ISO 8601 format. |
| since | string<br>Entries since N hours/minutes ago |
| lookup | string^[0123456789ABCDEFGHJKMNPQRSTVWXYZ]{26}$<br>By Call ID |

### Responses

**200**

A successful response.(streaming responses)

**default**

An unexpected error response.

### Response samples

- 200
- default

Content type

application/json

```json
{"result": {"accessLogEntry": {"callId": "string",

"timestamp": "2019-08-24T14:15:22Z",

"peer": {"address": "string",

"authInfo": "string",

"userAgent": "string",

"forwardedFor": "string"

},

"metadata": {"property1": {"values": ["string"]

},

"property2": {"values": ["string"]

}

},

"method": "string",

"statusCode": 0,

"oversized": true,

"policySource": {"blob": {"bucketUrl": "string",

"prefix": "string"

},

"database": {"driver": "DRIVER_UNSPECIFIED"

},

"disk": {"directory": "string"

},

"git": {"repositoryUrl": "string",

"branch": "string",

"subdirectory": "string"

},

"hub": {"label": "string",

"deploymentId": "string",

"playgroundId": "string",

"localBundle": {"path": "string"

},

"embeddedBundle": {"ruleId": "string",

"scopes": ["string"]

}

},

"embeddedPdp": {"url": "string",

"commitHash": "string",

"builtAt": "2019-08-24T14:15:22Z"

}

}

},

"decisionLogEntry": {"callId": "string",

"timestamp": "2019-08-24T14:15:22Z",

"peer": {"address": "string",

"authInfo": "string",

"userAgent": "string",

"forwardedFor": "string"

},

"inputs": [{"requestId": "string",

"resource": {"kind": "album:photo",

"policyVersion": "default",

"id": "XX125",

"attr": {"owner": "bugs_bunny"

},

"scope": "acme.corp"

},

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"

],

"attr": {"beta_tester": true

},

"scope": "acme.corp"

},

"actions": ["string"],

"auxData": {"jwt": {"property1": null,

"property2": null

}

}

}],

"outputs": [{"requestId": "string",

"resourceId": "string",

"actions": {"property1": {"effect": "EFFECT_UNSPECIFIED",

"policy": "string",

"scope": "string"

},

"property2": {"effect": "EFFECT_UNSPECIFIED",

"policy": "string",

"scope": "string"

}

},

"effectiveDerivedRoles": ["string"],

"validationErrors": [{"path": "string",

"message": "string",

"source": "SOURCE_UNSPECIFIED"

}],

"outputs": [{"src": "resource.expense.v1/acme#rule-001",

"val": "some_string"}]

}],

"error": "string",

"checkResources": {"inputs": [{"requestId": "string",

"resource": {"kind": "album:photo",

"policyVersion": "default",

"id": "XX125",

"attr": {"owner": "bugs_bunny"},

"scope": "acme.corp"},

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"],

"attr": {"beta_tester": true},

"scope": "acme.corp"},

"actions": ["string"],

"auxData": {"jwt": {"property1": null,"property2": null}}}],

"outputs": [{"requestId": "string",

"resourceId": "string",

"actions": {"property1": {"effect": "EFFECT_UNSPECIFIED",

"policy": "string",

"scope": "string"},

"property2": {"effect": "EFFECT_UNSPECIFIED",

"policy": "string",

"scope": "string"}},

"effectiveDerivedRoles": ["string"],

"validationErrors": [{"path": "string",

"message": "string",

"source": "SOURCE_UNSPECIFIED"}],

"outputs": [{"src": "resource.expense.v1/acme#rule-001","val": "some_string"}]}},

"error": {"code": 0,

"message": "string",

"details": [{"@type": "string","property1": null,"property2": null}]}

}

}