#access-control #authorization #security #sdk #open #scalable #documentation

bin+lib cerbos

Rust SDK for working with Cerbos: an open core, language-agnostic, scalable authorization solution

6 releases (3 breaking)

0.4.5 Apr 15, 2024
0.4.2 Nov 27, 2023
0.4.1 Jul 10, 2023
0.3.0 Jun 7, 2023
0.1.0 May 2, 2022

#395 in Encoding

Download history 6/week @ 2024-02-16 22/week @ 2024-02-23 8/week @ 2024-03-01 20/week @ 2024-03-08 6/week @ 2024-03-15 12/week @ 2024-03-29 4/week @ 2024-04-05 161/week @ 2024-04-12 23/week @ 2024-04-19 10/week @ 2024-05-03

194 downloads per month

Apache-2.0

440KB
6.5K SLoC

Cerbos Rust SDK

Rust client library for Cerbos: the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.

Usage

cargo add cerbos

The client can be used either asynchronously or synchronously by instantiating CerbosAsyncClient or CerbosSyncClient respectively.

use cerbos::sdk::attr::attr;
use cerbos::sdk::model::{Principal, Resource};
use cerbos::sdk::{CerbosAsyncClient, CerbosClientOptions, CerbosEndpoint, Result};

#[tokio::main]
async fn main() -> Result<()> {
    let opt = CerbosClientOptions::new(CerbosEndpoint::HostPort("localhost", 3593));
    let mut client = CerbosAsyncClient::new(opt).await?;

    let principal = Principal::new("alice", ["employee"])
        .with_policy_version("20210210")
        .with_attributes([
            attr("department", "marketing"),
            attr("geography", "GB"),
            attr("team", "design"),
        ]);

    let resource = Resource::new("XX125", "leave_request")
        .with_policy_version("20210210")
        .with_attributes([
            attr("department", "marketing"),
            attr("geography", "GB"),
            attr("team", "design"),
            attr("owner", "alice"),
            attr("approved", true),
            attr("id", "XX125"),
        ]);

    let resp = client
        .is_allowed("view:public", principal, resource, None)
        .await?;

    println!("Allowed={:?}", resp);

    Ok(())
}

Development

Running tests

cerbos run --set=storage.disk.directory=resources/store -- cargo test

Dependencies

~10–20MB
~273K SLoC