RoleBasedAuthorizer class

A role-based Authorizer with a small, predictable policy:

  • principals with the admin role may open sessions on any node;
  • otherwise the principal must hold a role listed in the node's allow-roles label (a comma-separated list), e.g. allow-roles: developer,ci;
  • a node with no allow-roles label is admin-only.

This ships as the Hub default so authorization fails closed.

Implemented types

Constructors

RoleBasedAuthorizer({String adminRole = 'admin', String allowRolesLabel = 'allow-roles'})
Creates a role-based authorizer.
const

Properties

adminRole → String
The role that grants access to every node.
final
allowRolesLabel → String
The node label whose value lists the roles allowed on that node.
final
hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

canOpenSession({required Principal principal, required NodeDescriptor node, required SessionMode mode}) → Future<bool>
Whether principal may open a session in mode on node.
override
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited