graphql-authz is a Casbin authorization middleware for GraphQL.js
npm install graphql-authz
// or
yarn add graphql-authzThis package should use with graphql and graphql-middleware
To limit access to each endpoint, you can use casbin policy or graphql directive.
In the policy method, you can use casbin policy like
p,user,project.members,queryp,roleb,project.members.tickets.id,queryto restricted access to each endpoint.
In the directive method, you can use directive can to do the same thing.
Here's a minimal example. You can find the full example in the tests/server.test.ts
import{applyMiddleware}from'graphql-middleware';import{newMiddleware,CanDirective}from'graphql-authz';import{newEnforcer}from'casbin';import{ApolloServer}from'apollo-server';import{makeExecutableSchema}from'@graphql-tools/schema';import{CasbinContextEnforcerKey}from'../src';// After graphql-js 14.0.0, you should manually define directive in the SDL.consttypeDefs=`directive @can(who: String!) on FIELD_DEFINITIONtype User { id: ID! @can(who: "user") name: String @can(who: "someone")}`;constresolvers={// something};constschemaWithDirective=makeExecutableSchema({
typeDefs,
resolvers,schemaDirectives: {can: CanDirective,},});// If you want to use directive, this is necessary.// You can ignore this in the policy only method.constenforcer=awaitnewEnforcer('tests/casbin.conf','tests/policy.csv');// As for now, you should use model tests/casbin.conf to initialize enforcer.// For more info about enforcer, plz refer to https://github.com/casbin/node-casbinconstmiddleware=awaitnewMiddleware({ctxMember: 'user',// middleware will get current user role from the graphql context[ctxMember]enforcer: enforcer,// Casbin Instance});// Apply middlware to graphql schemaconstschemaWithDirectiveMiddleware=applyMiddleware(schemaWithDirective,middleware);constserver=newApolloServer({schema: schemaWithDirectiveMiddleware,context: ({ req })=>{// Provide necessary info in the context.consttoken=req.headers.authorization||'';// Try to retrieve a user with the tokenconstuser=getUser(token);consta: any={};a[CasbinContextEnforcerKey]=enforcer;a['user']=user;returna;},});This project is under Apache 2.0 License. See the LICENSE file for the full license text.