From 7fe62e4735ad319c3d2c40f6f0c6f8039991c9bd Mon Sep 17 00:00:00 2001 From: nafisfaysal Date: Fri, 23 Aug 2019 19:43:01 +0600 Subject: [PATCH] Implement casbin adapter for go-pg/pg --- README.md | 67 +++++++++- adapter.go | 276 +++++++++++++++++++++++++++++++++++++++ adapter_test.go | 106 +++++++++++++++ config/config.go | 91 +++++++++++++ env-sample.txt | 3 + examples/rbac_model.conf | 15 +++ examples/rbac_policy.csv | 5 + go.mod | 15 +++ go.sum | 174 ++++++++++++++++++++++++ pgexample/main.go | 32 +++++ 10 files changed, 782 insertions(+), 2 deletions(-) create mode 100644 adapter.go create mode 100644 adapter_test.go create mode 100644 config/config.go create mode 100644 env-sample.txt create mode 100644 examples/rbac_model.conf create mode 100644 examples/rbac_policy.csv create mode 100644 go.mod create mode 100644 go.sum create mode 100644 pgexample/main.go diff --git a/README.md b/README.md index 0b29a71..ee6c29f 100644 --- a/README.md +++ b/README.md @@ -1,2 +1,65 @@ -# casbin-pg-adapter -A go-pg adapter for casbin +Go-pg Adapter +==== + +Go-pg Adapter is the [Go-pg](https://github.com/go-pg/pg) adapter for [Casbin](https://github.com/casbin/casbin). With this library, Casbin can load policy from PostgreSQL or save policy to it. + +## Installation + + go get github.com/MonedaCacao/casbin-pg-adapter + +## Env Variables + +Populate .env with necessary environment variable values: + + $ nano .env + +``` +DATABASE_ADDRESSES= +DATABASE_USER_NAME= +DATABSE_USER_PASSORD= +``` + +## Simple Postgres Example + +```go +package main + +import ( + pgadapter "github.com/MonedaCacao/casbin-pg-adapter" + "github.com/casbin/casbin" +) + +func main() { + // Initialize a Go-pg adapter and use it in a Casbin enforcer: + // The adapter will use the Postgres database named "casbin". + // If it doesn't exist, the adapter will create it automatically. + a, _ := pgadapter.NewAdapter() // Your driver and data source. + + // Or you can use an existing DB "abc" like this: + // The adapter will use the table named "casbin_rule". + // If it doesn't exist, the adapter will create it automatically. + + e := casbin.NewEnforcer("examples/rbac_model.conf", a) + + // Load the policy from DB. + e.LoadPolicy() + + // Check the permission. + e.Enforce("alice", "data1", "read") + + // Modify the policy. + // e.AddPolicy(...) + // e.RemovePolicy(...) + + // Save the policy back to DB. + e.SavePolicy() +} +``` + +## Getting Help + +- [Casbin](https://github.com/casbin/casbin) + +## License + +This project is under Apache 2.0 License. See the [LICENSE](LICENSE) file for the full license text. diff --git a/adapter.go b/adapter.go new file mode 100644 index 0000000..a21ce62 --- /dev/null +++ b/adapter.go @@ -0,0 +1,276 @@ +package pgadapter + +import ( + "github.com/MonedaCacao/casbin-pg-adapter/config" + "github.com/casbin/casbin/model" + "github.com/casbin/casbin/persist" + "github.com/go-pg/pg" + "github.com/go-pg/pg/orm" + "log" + "strings" +) + +const ( + tableExistsErrorCode = "ERROR #42P07" +) + +// CasbinRule represents a rule in Casbin. +type CasbinRule struct { + Id int + PType string + V0 string + V1 string + V2 string + V3 string + V4 string + V5 string +} + +// Adapter represents the github.com/go-pg/pg adapter for policy storage. +type Adapter struct { + db *pg.DB +} + +// finalizer is the destructor for Adapter. +func finalizer(a *Adapter) {} + +// NewAdapter is the constructor for Adapter. +// The adapter will automatically create a DB named "casbin" +func NewAdapter() (*Adapter, error) { + a := Adapter{} + + // Open the DB, create it if not existed. + err := a.open() + if err != nil { + return nil, err + } + + return &a, nil +} + +func (a *Adapter) createDatabase() error { + var err error + var db *pg.DB + + env := config.GetEnvVariables() + cfg := config.GetConfig(*env) + + db = pg.Connect(&pg.Options{ + Addr: cfg.DatabaseAddresses, + User: cfg.DatabaseUsername, + Password: cfg.DatabseUserPassord, + }) + + defer db.Close() + + _, err = db.Exec("CREATE DATABASE casbin") + if err != nil { + log.Println("can't create database", err) + return err + } + + return nil +} + +func (a *Adapter) open() error { + var err error + var db *pg.DB + + env := config.GetEnvVariables() + cfg := config.GetConfig(*env) + + err = a.createDatabase() + if err != nil { + panic(err) + } + + db = pg.Connect(&pg.Options{ + Addr: cfg.DatabaseAddresses, + User: cfg.DatabaseUsername, + Password: cfg.DatabseUserPassord, + Database: "casbin", + }) + + a.db = db + + return a.createTable() +} + +func (a *Adapter) close() error { + err := a.db.Close() + if err != nil { + return err + } + + a.db = nil + return nil +} + +func (a *Adapter) createTable() error { + err := a.db.CreateTable(&CasbinRule{}, &orm.CreateTableOptions{ + Temp: false, + }) + if err != nil { + errorCode := err.Error()[0:12] + if errorCode != tableExistsErrorCode { + return err + } + } + return nil +} + +func (a *Adapter) dropTable() error { + err := a.db.DropTable(&CasbinRule{}, &orm.DropTableOptions{}) + if err != nil { + return err + } + + return nil +} + +func loadPolicyLine(line *CasbinRule, model model.Model) { + const prefixLine = ", " + var sb strings.Builder + + sb.WriteString(line.PType) + if len(line.V0) > 0 { + sb.WriteString(prefixLine) + sb.WriteString(line.V0) + } + if len(line.V1) > 0 { + sb.WriteString(prefixLine) + sb.WriteString(line.V1) + } + if len(line.V2) > 0 { + sb.WriteString(prefixLine) + sb.WriteString(line.V2) + } + if len(line.V3) > 0 { + sb.WriteString(prefixLine) + sb.WriteString(line.V3) + } + if len(line.V4) > 0 { + sb.WriteString(prefixLine) + sb.WriteString(line.V4) + } + if len(line.V5) > 0 { + sb.WriteString(prefixLine) + sb.WriteString(line.V5) + } + + persist.LoadPolicyLine(sb.String(), model) +} + +// LoadPolicy loads policy from database. +func (a *Adapter) LoadPolicy(model model.Model) error { + var lines []*CasbinRule + + if _, err := a.db.Query(&lines, `SELECT * FROM casbin_rules`); err != nil { + return err + } + + for _, line := range lines { + loadPolicyLine(line, model) + } + + return nil +} + +func savePolicyLine(ptype string, rule []string) *CasbinRule { + line := &CasbinRule{PType: ptype} + + l := len(rule) + if l > 0 { + line.V0 = rule[0] + } + if l > 1 { + line.V1 = rule[1] + } + if l > 2 { + line.V2 = rule[2] + } + if l > 3 { + line.V3 = rule[3] + } + if l > 4 { + line.V4 = rule[4] + } + if l > 5 { + line.V5 = rule[5] + } + + return line +} + +// SavePolicy saves policy to database. +func (a *Adapter) SavePolicy(model model.Model) error { + err := a.dropTable() + if err != nil { + return err + } + err = a.createTable() + if err != nil { + return err + } + + var lines []*CasbinRule + + for ptype, ast := range model["p"] { + for _, rule := range ast.Policy { + line := savePolicyLine(ptype, rule) + lines = append(lines, line) + } + } + + for ptype, ast := range model["g"] { + for _, rule := range ast.Policy { + line := savePolicyLine(ptype, rule) + lines = append(lines, line) + } + } + + err = a.db.Insert(&lines) + return err +} + +// AddPolicy adds a policy rule to the storage. +func (a *Adapter) AddPolicy(sec string, ptype string, rule []string) error { + line := savePolicyLine(ptype, rule) + err := a.db.Insert(line) + return err +} + +// RemovePolicy removes a policy rule from the storage. +func (a *Adapter) RemovePolicy(sec string, ptype string, rule []string) error { + line := savePolicyLine(ptype, rule) + err := a.db.Delete(line) + return err +} + +// RemoveFilteredPolicy removes policy rules that match the filter from the storage. +func (a *Adapter) RemoveFilteredPolicy(sec string, ptype string, fieldIndex int, fieldValues ...string) error { + line := &CasbinRule{PType: ptype} + + idx := fieldIndex + len(fieldValues) + if fieldIndex <= 0 && idx > 0 { + line.V0 = fieldValues[0-fieldIndex] + } + if fieldIndex <= 1 && idx > 1 { + line.V1 = fieldValues[1-fieldIndex] + } + if fieldIndex <= 2 && idx > 2 { + line.V2 = fieldValues[2-fieldIndex] + } + if fieldIndex <= 3 && idx > 3 { + line.V3 = fieldValues[3-fieldIndex] + } + if fieldIndex <= 4 && idx > 4 { + line.V4 = fieldValues[4-fieldIndex] + } + if fieldIndex <= 5 && idx > 5 { + line.V5 = fieldValues[5-fieldIndex] + } + + err := a.db.Delete(line) + return err +} diff --git a/adapter_test.go b/adapter_test.go new file mode 100644 index 0000000..28f9cd7 --- /dev/null +++ b/adapter_test.go @@ -0,0 +1,106 @@ +package pgadapter + +import ( + "github.com/casbin/casbin" + "github.com/casbin/casbin/util" + "log" + "testing" +) + +func testGetPolicy(t *testing.T, e *casbin.Enforcer, res [][]string) { + t.Helper() + myRes := e.GetPolicy() + log.Print("Policy Got: ", myRes) + + if !util.Array2DEquals(res, myRes) { + t.Error("Policy Got: ", myRes, ", supposed to be ", res) + } +} + +func initPolicy(t *testing.T) { + // Because the DB is empty at first, + // so we need to load the policy from the file adapter (.CSV) first. + e := casbin.NewEnforcer("examples/rbac_model.conf", "examples/rbac_policy.csv") + + a, err := NewAdapter() + if err != nil { + panic(err) + } + + // This is a trick to save the current policy to the DB. + // We can't call e.SavePolicy() because the adapter in the enforcer is still the file adapter. + // The current policy means the policy in the Casbin enforcer (aka in memory). + err = a.SavePolicy(e.GetModel()) + if err != nil { + panic(err) + } + + // Clear the current policy. + e.ClearPolicy() + testGetPolicy(t, e, [][]string{}) + + // Load the policy from DB. + err = a.LoadPolicy(e.GetModel()) + if err != nil { + panic(err) + } + testGetPolicy(t, e, [][]string{{"alice", "data1", "read"}, {"bob", "data2", "write"}, {"data2_admin", "data2", "read"}, {"data2_admin", "data2", "write"}}) +} + +func testSaveLoad(t *testing.T) { + // Initialize some policy in DB. + initPolicy(t) + // Note: you don't need to look at the above code + // if you already have a working DB with policy inside. + + // Now the DB has policy, so we can provide a normal use case. + // Create an adapter and an enforcer. + // NewEnforcer() will load the policy automatically. + a, _ := NewAdapter() + e := casbin.NewEnforcer("examples/rbac_model.conf", a) + testGetPolicy(t, e, [][]string{{"alice", "data1", "read"}, {"bob", "data2", "write"}, {"data2_admin", "data2", "read"}, {"data2_admin", "data2", "write"}}) +} + +func testAutoSave(t *testing.T) { + // Initialize some policy in DB. + initPolicy(t) + // Note: you don't need to look at the above code + // if you already have a working DB with policy inside. + + // Now the DB has policy, so we can provide a normal use case. + // Create an adapter and an enforcer. + // NewEnforcer() will load the policy automatically. + a, _ := NewAdapter() + e := casbin.NewEnforcer("examples/rbac_model.conf", a) + + // AutoSave is enabled by default. + // Now we disable it. + e.EnableAutoSave(false) + + // Because AutoSave is disabled, the policy change only affects the policy in Casbin enforcer, + // it doesn't affect the policy in the storage. + e.AddPolicy("alice", "data1", "write") + // Reload the policy from the storage to see the effect. + e.LoadPolicy() + // This is still the original policy. + testGetPolicy(t, e, [][]string{{"alice", "data1", "read"}, {"bob", "data2", "write"}, {"data2_admin", "data2", "read"}, {"data2_admin", "data2", "write"}}) + + // Now we enable the AutoSave. + e.EnableAutoSave(true) + + // Because AutoSave is enabled, the policy change not only affects the policy in Casbin enforcer, + // but also affects the policy in the storage. + e.AddPolicy("alice", "data1", "write") + // Reload the policy from the storage to see the effect. + e.LoadPolicy() + // The policy has a new rule: {"alice", "data1", "write"}. + testGetPolicy(t, e, [][]string{{"alice", "data1", "read"}, {"bob", "data2", "write"}, {"data2_admin", "data2", "read"}, {"data2_admin", "data2", "write"}, {"alice", "data1", "write"}}) + testGetPolicy(t, e, [][]string{{"alice", "data1", "read"}, {"bob", "data2", "write"}, {"data2_admin", "data2", "read"}, {"data2_admin", "data2", "write"}, {"alice", "data1", "write"}}) +} + +func TestAdapters(t *testing.T) { + // You can also use the following way to use an existing DB "abc": + testSaveLoad(t) + + testAutoSave(t) +} diff --git a/config/config.go b/config/config.go new file mode 100644 index 0000000..a1ce09b --- /dev/null +++ b/config/config.go @@ -0,0 +1,91 @@ +package config + +import ( + "os" + "path/filepath" + + log "github.com/inconshreveable/log15" + "github.com/spf13/viper" +) + +// Config contains the config.yml settings +type Config struct { + DatabaseAddresses string + DatabaseUsername string + DatabseUserPassord string + Database string +} + +// Env contains the environment variables +type Env struct { + Environment string + DatabasePassword string + ProjectRootPath string +} + +// GetEnvVariables gets the environment variables and returns a new env struct +func GetEnvVariables() *Env { + viper.AutomaticEnv() + viper.SetDefault("go_env", "development") + viper.SetDefault("database_password", "") + + // Get the current environment + environment := viper.GetString("go_env") + + log.Info("Initializing", "ENVIROMENT", environment) + + // Get the enviroment variables + log.Info("Obtaining env variables") + databasePassword := viper.GetString("database_password") + + env := &Env{ + Environment: environment, + DatabasePassword: databasePassword, + // Secret: secret, + } + + return env +} + +// GetConfig reads the configuration file and returns a new config +func GetConfig(env Env) *Config { + viper.SetConfigName("config") + viper.SetConfigType("yaml") + viper.AddConfigPath(".") + viper.AddConfigPath(env.ProjectRootPath) + + log.Info("Reading config file") + err := viper.ReadInConfig() + if err != nil { + log.Error("Missing configuration file.", "Error:", err) + os.Exit(1) + } + + var config Config + + err = viper.UnmarshalKey(env.Environment, &config) + if err != nil { + panic("Unable to unmarshal config") + } + + return &config +} + +// GetTestingEnvVariables returns env variables for testing +func GetTestingEnvVariables() *Env { + + wd, err := os.Getwd() + if err != nil { + panic(err) + } + + // Since we are loading configuration files from the root dir, when running from main package + // this is fine but for testing we need to find the root dir + dir := filepath.Dir(wd) + + for dir[len(dir)-24:] != "gopg-casbin-adapter" { + dir = filepath.Dir(dir) + } + + return &Env{Environment: "test", ProjectRootPath: dir} +} diff --git a/env-sample.txt b/env-sample.txt new file mode 100644 index 0000000..de60b6f --- /dev/null +++ b/env-sample.txt @@ -0,0 +1,3 @@ +DATABASE_ADDRESSES= +DATABASE_USER_NAME= +DATABSE_USER_PASSORD= \ No newline at end of file diff --git a/examples/rbac_model.conf b/examples/rbac_model.conf new file mode 100644 index 0000000..eb2ffaf --- /dev/null +++ b/examples/rbac_model.conf @@ -0,0 +1,15 @@ +[request_definition] +r = sub, obj, act + +[policy_definition] +p = sub, obj, act + +[role_definition] +g = _, _ +g2 = _, _ + +[policy_effect] +e = some(where (p.eft == allow)) + +[matchers] +m = g(r.sub, p.sub) && r.obj == p.obj && r.act == p.act \ No newline at end of file diff --git a/examples/rbac_policy.csv b/examples/rbac_policy.csv new file mode 100644 index 0000000..f93d6df --- /dev/null +++ b/examples/rbac_policy.csv @@ -0,0 +1,5 @@ +p, alice, data1, read +p, bob, data2, write +p, data2_admin, data2, read +p, data2_admin, data2, write +g, alice, data2_admin \ No newline at end of file diff --git a/go.mod b/go.mod new file mode 100644 index 0000000..cfb9032 --- /dev/null +++ b/go.mod @@ -0,0 +1,15 @@ +module github.com/MonedaCacao/casbin-pg-adapter + +go 1.12 + +require ( + github.com/casbin/casbin v1.9.1 + github.com/go-pg/pg v8.0.5+incompatible + github.com/inconshreveable/log15 v0.0.0-20180818164646-67afb5ed74ec + github.com/jinzhu/inflection v1.0.0 // indirect + github.com/mattn/go-colorable v0.1.2 // indirect + github.com/onsi/ginkgo v1.8.0 // indirect + github.com/onsi/gomega v1.5.0 // indirect + github.com/spf13/viper v1.4.0 + mellium.im/sasl v0.2.1 // indirect +) diff --git a/go.sum b/go.sum new file mode 100644 index 0000000..0d74cb6 --- /dev/null +++ b/go.sum @@ -0,0 +1,174 @@ +cloud.google.com/go v0.26.0/go.mod h1:aQUYkXzVsufM+DwF1aE+0xfcU+56JwCaLick0ClmMTw= +github.com/BurntSushi/toml v0.3.1 h1:WXkYYl6Yr3qBf1K79EBnL4mak0OimBfB0XUf9Vl28OQ= +github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03qcyfWMU= +github.com/Knetic/govaluate v3.0.1-0.20171022003610-9aa49832a739+incompatible h1:1G1pk05UrOh0NlF1oeaaix1x8XzrfjIDK47TY0Zehcw= +github.com/Knetic/govaluate v3.0.1-0.20171022003610-9aa49832a739+incompatible/go.mod h1:r7JcOSlj0wfOMncg0iLm8Leh48TZaKVeNIfJntJ2wa0= +github.com/OneOfOne/xxhash v1.2.2/go.mod h1:HSdplMjZKSmBqAxg5vPj2TmRDmfkzw+cTzAElWljhcU= +github.com/alecthomas/template v0.0.0-20160405071501-a0175ee3bccc/go.mod h1:LOuyumcjzFXgccqObfd/Ljyb9UuFJ6TxHnclSeseNhc= +github.com/alecthomas/units v0.0.0-20151022065526-2efee857e7cf/go.mod h1:ybxpYRFXyAe+OPACYpWeL0wqObRcbAqCMya13uyzqw0= +github.com/armon/consul-api v0.0.0-20180202201655-eb2c6b5be1b6/go.mod h1:grANhF5doyWs3UAsr3K4I6qtAmlQcZDesFNEHPZAzj8= +github.com/beorn7/perks v0.0.0-20180321164747-3a771d992973/go.mod h1:Dwedo/Wpr24TaqPxmxbtue+5NUziq4I4S80YR8gNf3Q= +github.com/beorn7/perks v1.0.0/go.mod h1:KWe93zE9D1o94FZ5RNwFwVgaQK1VOXiVxmqh+CedLV8= +github.com/casbin/casbin v1.9.1 h1:ucjbS5zTrmSLtH4XogqOG920Poe6QatdXtz1FEbApeM= +github.com/casbin/casbin v1.9.1/go.mod h1:z8uPsfBJGUsnkagrt3G8QvjgTKFMBJ32UP8HpZllfog= +github.com/cespare/xxhash v1.1.0/go.mod h1:XrSqR1VqqWfGrhpAt58auRo0WTKS1nRRg3ghfAqPWnc= +github.com/client9/misspell v0.3.4/go.mod h1:qj6jICC3Q7zFZvVWo7KLAzC3yx5G7kyvSDkc90ppPyw= +github.com/coreos/bbolt v1.3.2/go.mod h1:iRUV2dpdMOn7Bo10OQBFzIJO9kkE559Wcmn+qkEiiKk= +github.com/coreos/etcd v3.3.10+incompatible/go.mod h1:uF7uidLiAD3TWHmW31ZFd/JWoc32PjwdhPthX9715RE= +github.com/coreos/go-semver v0.2.0/go.mod h1:nnelYz7RCh+5ahJtPPxZlU+153eP4D4r3EedlOD2RNk= +github.com/coreos/go-systemd v0.0.0-20190321100706-95778dfbb74e/go.mod h1:F5haX7vjVVG0kc13fIWeqUViNPyEJxv/OmvnBo0Yme4= +github.com/coreos/pkg v0.0.0-20180928190104-399ea9e2e55f/go.mod h1:E3G3o1h8I7cfcXa63jLwjI0eiQQMgzzUDFVpN/nH/eA= +github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= +github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/dgrijalva/jwt-go v3.2.0+incompatible/go.mod h1:E3ru+11k8xSBh+hMPgOLZmtrrCbhqsmaPHjLKYnJCaQ= +github.com/dgryski/go-sip13 v0.0.0-20181026042036-e10d5fee7954/go.mod h1:vAd38F8PWV+bWy6jNmig1y/TA+kYO4g3RSRF0IAv0no= +github.com/fsnotify/fsnotify v1.4.7 h1:IXs+QLmnXW2CcXuY+8Mzv/fWEsPGWxqefPtCP5CnV9I= +github.com/fsnotify/fsnotify v1.4.7/go.mod h1:jwhsz4b93w/PPRr/qN1Yymfu8t87LnFCMoQvtojpjFo= +github.com/ghodss/yaml v1.0.0/go.mod h1:4dBDuWmgqj2HViK6kFavaiC9ZROes6MMH2rRYeMEF04= +github.com/go-kit/kit v0.8.0/go.mod h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as= +github.com/go-logfmt/logfmt v0.3.0/go.mod h1:Qt1PoO58o5twSAckw1HlFXLmHsOX5/0LbT9GBnD5lWE= +github.com/go-logfmt/logfmt v0.4.0/go.mod h1:3RMwSq7FuexP4Kalkev3ejPJsZTpXXBr9+V4qmtdjCk= +github.com/go-pg/pg v8.0.5+incompatible h1:+USAV4GOW4mlX1tt1DsEQ1ZSqVkrkDlPPG+t4DqzpAA= +github.com/go-pg/pg v8.0.5+incompatible/go.mod h1:a2oXow+aFOrvwcKs3eIA0lNFmMilrxK2sOkB5NWe0vA= +github.com/go-stack/stack v1.8.0 h1:5SgMzNM5HxrEjV0ww2lTmX6E2Izsfxas4+YHWRs3Lsk= +github.com/go-stack/stack v1.8.0/go.mod h1:v0f6uXyyMGvRgIKkXu+yp6POWl0qKG85gN/melR3HDY= +github.com/gogo/protobuf v1.1.1/go.mod h1:r8qH/GZQm5c6nD/R0oafs1akxWv10x8SbQlK7atdtwQ= +github.com/gogo/protobuf v1.2.1/go.mod h1:hp+jE20tsWTFYpLwKvXlhS1hjn+gTNwPg2I6zVXpSg4= +github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q= +github.com/golang/groupcache v0.0.0-20190129154638-5b532d6fd5ef/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc= +github.com/golang/mock v1.1.1/go.mod h1:oTYuIxOrZwtPieC+H1uAHpcLFnEyAGVDL/k47Jfbm0A= +github.com/golang/protobuf v1.2.0/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U= +github.com/golang/protobuf v1.3.1 h1:YF8+flBXS5eO826T4nzqPrxfhQThhXl0YzfuUPu4SBg= +github.com/golang/protobuf v1.3.1/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U= +github.com/google/btree v1.0.0/go.mod h1:lNA+9X1NB3Zf8V7Ke586lFgjr2dZNuvo3lPJSGZ5JPQ= +github.com/google/go-cmp v0.2.0/go.mod h1:oXzfMopK8JAjlY9xF4vHSVASa0yLyX7SntLO5aqRK0M= +github.com/gorilla/websocket v1.4.0/go.mod h1:E7qHFY5m1UJ88s3WnNqhKjPHQ0heANvMoAMk2YaljkQ= +github.com/grpc-ecosystem/go-grpc-middleware v1.0.0/go.mod h1:FiyG127CGDf3tlThmgyCl78X/SZQqEOJBCDaAfeWzPs= +github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0/go.mod h1:8NvIoxWQoOIhqOTXgfV/d3M/q6VIi02HzZEHgUlZvzk= +github.com/grpc-ecosystem/grpc-gateway v1.9.0/go.mod h1:vNeuVxBJEsws4ogUvrchl83t/GYV9WGTSLVdBhOQFDY= +github.com/hashicorp/hcl v1.0.0 h1:0Anlzjpi4vEasTeNFn2mLJgTSwt0+6sfsiTG8qcWGx4= +github.com/hashicorp/hcl v1.0.0/go.mod h1:E5yfLk+7swimpb2L/Alb/PJmXilQ/rhwaUYs4T20WEQ= +github.com/hpcloud/tail v1.0.0 h1:nfCOvKYfkgYP8hkirhJocXT2+zOD8yUNjXaWfTlyFKI= +github.com/hpcloud/tail v1.0.0/go.mod h1:ab1qPbhIpdTxEkNHXyeSf5vhxWSCs/tWer42PpOxQnU= +github.com/inconshreveable/log15 v0.0.0-20180818164646-67afb5ed74ec h1:CGkYB1Q7DSsH/ku+to+foV4agt2F2miquaLUgF6L178= +github.com/inconshreveable/log15 v0.0.0-20180818164646-67afb5ed74ec/go.mod h1:cOaXtrgN4ScfRrD9Bre7U1thNq5RtJ8ZoP4iXVGRj6o= +github.com/jinzhu/inflection v1.0.0 h1:K317FqzuhWc8YvSVlFMCCUb36O/S9MCKRDI7QkRKD/E= +github.com/jinzhu/inflection v1.0.0/go.mod h1:h+uFLlag+Qp1Va5pdKtLDYj+kHp5pxUVkryuEj+Srlc= +github.com/jonboulle/clockwork v0.1.0/go.mod h1:Ii8DK3G1RaLaWxj9trq07+26W01tbo22gdxWY5EU2bo= +github.com/julienschmidt/httprouter v1.2.0/go.mod h1:SYymIcj16QtmaHHD7aYtjjsJG7VTCxuUUipMqKk8s4w= +github.com/kisielk/errcheck v1.1.0/go.mod h1:EZBBE59ingxPouuu3KfxchcWSUPOHkagtvWXihfKN4Q= +github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck= +github.com/konsorten/go-windows-terminal-sequences v1.0.1/go.mod h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ= +github.com/kr/logfmt v0.0.0-20140226030751-b84e30acd515/go.mod h1:+0opPa2QZZtGFBFZlji/RkVcI2GknAs/DXo4wKdlNEc= +github.com/kr/pretty v0.1.0 h1:L/CwN0zerZDmRFUapSPitk6f+Q3+0za1rQkzVuMiMFI= +github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo= +github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ= +github.com/kr/text v0.1.0 h1:45sCR5RtlFHMR4UwH9sdQ5TC8v0qDQCHnXt+kaKSTVE= +github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= +github.com/magiconair/properties v1.8.0 h1:LLgXmsheXeRoUOBOjtwPQCWIYqM/LU1ayDtDePerRcY= +github.com/magiconair/properties v1.8.0/go.mod h1:PppfXfuXeibc/6YijjN8zIbojt8czPbwD3XqdrwzmxQ= +github.com/mattn/go-colorable v0.1.2 h1:/bC9yWikZXAL9uJdulbSfyVNIR3n3trXl+v8+1sx8mU= +github.com/mattn/go-colorable v0.1.2/go.mod h1:U0ppj6V5qS13XJ6of8GYAs25YV2eR4EVcfRqFIhoBtE= +github.com/mattn/go-isatty v0.0.8 h1:HLtExJ+uU2HOZ+wI0Tt5DtUDrx8yhUqDcp7fYERX4CE= +github.com/mattn/go-isatty v0.0.8/go.mod h1:Iq45c/XA43vh69/j3iqttzPXn0bhXyGjM0Hdxcsrc5s= +github.com/matttproud/golang_protobuf_extensions v1.0.1/go.mod h1:D8He9yQNgCq6Z5Ld7szi9bcBfOoFv/3dc6xSMkL2PC0= +github.com/mitchellh/mapstructure v1.1.2 h1:fmNYVwqnSfB9mZU6OS2O6GsXM+wcskZDuKQzvN1EDeE= +github.com/mitchellh/mapstructure v1.1.2/go.mod h1:FVVH3fgwuzCH5S8UJGiWEs2h04kUh9fWfEaFds41c1Y= +github.com/mwitkow/go-conntrack v0.0.0-20161129095857-cc309e4a2223/go.mod h1:qRWi+5nqEBWmkhHvq77mSJWrCKwh8bxhgT7d/eI7P4U= +github.com/oklog/ulid v1.3.1/go.mod h1:CirwcVhetQ6Lv90oh/F+FBtV6XMibvdAFo93nm5qn4U= +github.com/onsi/ginkgo v1.6.0/go.mod h1:lLunBs/Ym6LB5Z9jYTR76FiuTmxDTDusOGeTQH+WWjE= +github.com/onsi/ginkgo v1.8.0 h1:VkHVNpR4iVnU8XQR6DBm8BqYjN7CRzw+xKUbVVbbW9w= +github.com/onsi/ginkgo v1.8.0/go.mod h1:lLunBs/Ym6LB5Z9jYTR76FiuTmxDTDusOGeTQH+WWjE= +github.com/onsi/gomega v1.5.0 h1:izbySO9zDPmjJ8rDjLvkA2zJHIo+HkYXHnf7eN7SSyo= +github.com/onsi/gomega v1.5.0/go.mod h1:ex+gbHU/CVuBBDIJjb2X0qEXbFg53c61hWP/1CpauHY= +github.com/pelletier/go-toml v1.2.0 h1:T5zMGML61Wp+FlcbWjRDT7yAxhJNAiPPLOFECq181zc= +github.com/pelletier/go-toml v1.2.0/go.mod h1:5z9KED0ma1S8pY6P1sdut58dfprrGBbd/94hg7ilaic= +github.com/pkg/errors v0.8.0/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= +github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= +github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= +github.com/prometheus/client_golang v0.9.1/go.mod h1:7SWBe2y4D6OKWSNQJUaRYU/AaXPKyh/dDVn+NZz0KFw= +github.com/prometheus/client_golang v0.9.3/go.mod h1:/TN21ttK/J9q6uSwhBd54HahCDft0ttaMvbicHlPoso= +github.com/prometheus/client_model v0.0.0-20180712105110-5c3871d89910/go.mod h1:MbSGuTsp3dbXC40dX6PRTWyKYBIrTGTE9sqQNg2J8bo= +github.com/prometheus/client_model v0.0.0-20190129233127-fd36f4220a90/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA= +github.com/prometheus/common v0.0.0-20181113130724-41aa239b4cce/go.mod h1:daVV7qP5qjZbuso7PdcryaAu0sAZbrN9i7WWcTMWvro= +github.com/prometheus/common v0.4.0/go.mod h1:TNfzLD0ON7rHzMJeJkieUDPYmFC7Snx/y86RQel1bk4= +github.com/prometheus/procfs v0.0.0-20181005140218-185b4288413d/go.mod h1:c3At6R/oaqEKCNdg8wHV1ftS6bRYblBhIjjI8uT2IGk= +github.com/prometheus/procfs v0.0.0-20190507164030-5867b95ac084/go.mod h1:TjEm7ze935MbeOT/UhFTIMYKhuLP4wbCsTZCD3I8kEA= +github.com/prometheus/tsdb v0.7.1/go.mod h1:qhTCs0VvXwvX/y3TZrWD7rabWM+ijKTux40TwIPHuXU= +github.com/rogpeppe/fastuuid v0.0.0-20150106093220-6724a57986af/go.mod h1:XWv6SoW27p1b0cqNHllgS5HIMJraePCO15w5zCzIWYg= +github.com/sirupsen/logrus v1.2.0/go.mod h1:LxeOpSwHxABJmUn/MG1IvRgCAasNZTLOkJPxbbu5VWo= +github.com/soheilhy/cmux v0.1.4/go.mod h1:IM3LyeVVIOuxMH7sFAkER9+bJ4dT7Ms6E4xg4kGIyLM= +github.com/spaolacci/murmur3 v0.0.0-20180118202830-f09979ecbc72/go.mod h1:JwIasOWyU6f++ZhiEuf87xNszmSA2myDM2Kzu9HwQUA= +github.com/spf13/afero v1.1.2 h1:m8/z1t7/fwjysjQRYbP0RD+bUIF/8tJwPdEZsI83ACI= +github.com/spf13/afero v1.1.2/go.mod h1:j4pytiNVoe2o6bmDsKpLACNPDBIoEAkihy7loJ1B0CQ= +github.com/spf13/cast v1.3.0 h1:oget//CVOEoFewqQxwr0Ej5yjygnqGkvggSE/gB35Q8= +github.com/spf13/cast v1.3.0/go.mod h1:Qx5cxh0v+4UWYiBimWS+eyWzqEqokIECu5etghLkUJE= +github.com/spf13/jwalterweatherman v1.0.0 h1:XHEdyB+EcvlqZamSM4ZOMGlc93t6AcsBEu9Gc1vn7yk= +github.com/spf13/jwalterweatherman v1.0.0/go.mod h1:cQK4TGJAtQXfYWX+Ddv3mKDzgVb68N+wFjFa4jdeBTo= +github.com/spf13/pflag v1.0.3 h1:zPAT6CGy6wXeQ7NtTnaTerfKOsV6V6F8agHXFiazDkg= +github.com/spf13/pflag v1.0.3/go.mod h1:DYY7MBk1bdzusC3SYhjObp+wFpr4gzcvqqNjLnInEg4= +github.com/spf13/viper v1.4.0 h1:yXHLWeravcrgGyFSyCgdYpXQ9dR9c/WED3pg1RhxqEU= +github.com/spf13/viper v1.4.0/go.mod h1:PTJ7Z/lr49W6bUbkmS1V3by4uWynFiR9p7+dSq/yZzE= +github.com/stretchr/objx v0.1.1/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= +github.com/stretchr/testify v1.2.2 h1:bSDNvY7ZPG5RlJ8otE/7V6gMiyenm9RtJ7IUVIAoJ1w= +github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs= +github.com/tmc/grpc-websocket-proxy v0.0.0-20190109142713-0ad062ec5ee5/go.mod h1:ncp9v5uamzpCO7NfCPTXjqaC+bZgJeR0sMTm6dMHP7U= +github.com/ugorji/go v1.1.4/go.mod h1:uQMGLiO92mf5W77hV/PUCpI3pbzQx3CRekS0kk+RGrc= +github.com/xiang90/probing v0.0.0-20190116061207-43a291ad63a2/go.mod h1:UETIi67q53MR2AWcXfiuqkDkRtnGDLqkBTpCHuJHxtU= +github.com/xordataexchange/crypt v0.0.3-0.20170626215501-b2862e3d0a77/go.mod h1:aYKd//L2LvnjZzWKhF00oedf4jCCReLcmhLdhm1A27Q= +go.etcd.io/bbolt v1.3.2/go.mod h1:IbVyRI1SCnLcuJnV2u8VeU0CEYM7e686BmAb1XKL+uU= +go.uber.org/atomic v1.4.0/go.mod h1:gD2HeocX3+yG+ygLZcrzQJaqmWj9AIm7n08wl/qW/PE= +go.uber.org/multierr v1.1.0/go.mod h1:wR5kodmAFQ0UK8QlbwjlSNy0Z68gJhDJUG5sjR94q/0= +go.uber.org/zap v1.10.0/go.mod h1:vwi/ZaCAaUcBkycHslxD9B2zi4UTXhF60s6SWpuDF0Q= +golang.org/x/crypto v0.0.0-20180904163835-0709b304e793/go.mod h1:6SG95UA2DQfeDnfUPMdvaQW0Q7yPrPDi9nlGo2tz2b4= +golang.org/x/crypto v0.0.0-20180910181607-0e37d006457b/go.mod h1:6SG95UA2DQfeDnfUPMdvaQW0Q7yPrPDi9nlGo2tz2b4= +golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2 h1:VklqNMn3ovrHsnt90PveolxSbWFaJdECFbxSq0Mqo2M= +golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= +golang.org/x/lint v0.0.0-20181026193005-c67002cb31c3/go.mod h1:UVdnD1Gm6xHRNCYTkRU2/jEulfH38KcIWyp/GAMgvoE= +golang.org/x/lint v0.0.0-20190313153728-d0100b6bd8b3/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc= +golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= +golang.org/x/net v0.0.0-20180906233101-161cd47e91fd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= +golang.org/x/net v0.0.0-20181114220301-adae6a3d119a/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= +golang.org/x/net v0.0.0-20181220203305-927f97764cc3/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= +golang.org/x/net v0.0.0-20190311183353-d8887717615a/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= +golang.org/x/net v0.0.0-20190522155817-f3200d17e092 h1:4QSRKanuywn15aTZvI/mIDEgPQpswuFndXpOj3rKEco= +golang.org/x/net v0.0.0-20190522155817-f3200d17e092/go.mod h1:HSz+uSET+XFnRR8LxR5pz3Of3rY3CfYBVs4xY44aLks= +golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U= +golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sync v0.0.0-20181221193216-37e7f081c4d4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= +golang.org/x/sys v0.0.0-20180830151530-49385e6e1522/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20180905080454-ebe1bf3edb33/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20180909124046-d0be0721c37e/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20181107165924-66b7b1311ac8/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20181116152217-5ac8a444bdc5/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a h1:1BGLXjeY4akVXGgbC9HugT3Jv3hCI0z56oJR5vAMgBU= +golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/sys v0.0.0-20190222072716-a9d3bda3a223 h1:DH4skfRX4EBpamg7iV4ZlCpblAHI6s6TDM39bFZumv8= +golang.org/x/sys v0.0.0-20190222072716-a9d3bda3a223/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= +golang.org/x/text v0.3.0 h1:g61tztE5qeGQ89tm6NTjjM9VPIm088od1l6aSorWRWg= +golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= +golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= +golang.org/x/tools v0.0.0-20180221164845-07fd8470d635/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= +golang.org/x/tools v0.0.0-20190114222345-bf090417da8b/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= +golang.org/x/tools v0.0.0-20190311212946-11955173bddd/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs= +google.golang.org/appengine v1.1.0/go.mod h1:EbEs0AVv82hx2wNQdGPgUI5lhzA/G0D9YwlJXL52JkM= +google.golang.org/genproto v0.0.0-20180817151627-c66870c02cf8/go.mod h1:JiN7NxoALGmiZfu7CAH4rXhgtRTLTxftemlI0sWmxmc= +google.golang.org/grpc v1.19.0/go.mod h1:mqu4LbDTu4XGKhr4mRzUsmM4RtVoemTSY81AxZiDr8c= +google.golang.org/grpc v1.21.0/go.mod h1:oYelfM1adQP15Ek0mdvEgi9Df8B9CZIaU1084ijfRaM= +gopkg.in/alecthomas/kingpin.v2 v2.2.6/go.mod h1:FMv+mEhP44yOT+4EoQTLFTRgOQ1FBLkstjWtayDeSgw= +gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= +gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127 h1:qIbj1fsPNlZgppZ+VLlY7N33q108Sa+fhmuc+sWQYwY= +gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= +gopkg.in/fsnotify.v1 v1.4.7 h1:xOHLXZwVvI9hhs+cLKq5+I5onOuwQLhQwiu63xxlHs4= +gopkg.in/fsnotify.v1 v1.4.7/go.mod h1:Tz8NjZHkW78fSQdbUxIjBTcgA1z1m8ZHf0WmKUhAMys= +gopkg.in/resty.v1 v1.12.0/go.mod h1:mDo4pnntr5jdWRML875a/NmxYqAlA73dVijT2AXvQQo= +gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 h1:uRGJdciOHaEIrze2W8Q3AKkepLTh2hOroT7a+7czfdQ= +gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7/go.mod h1:dt/ZhP58zS4L8KSrWDmTeBkI65Dw0HsyUHuEVlX15mw= +gopkg.in/yaml.v2 v2.0.0-20170812160011-eb3733d160e7/go.mod h1:JAlM8MvJe8wmxCU4Bli9HhUf9+ttbYbLASfIpnQbh74= +gopkg.in/yaml.v2 v2.2.1/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= +gopkg.in/yaml.v2 v2.2.2 h1:ZCJp+EgiOT7lHqUV2J862kp8Qj64Jo6az82+3Td9dZw= +gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= +honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= +mellium.im/sasl v0.2.1 h1:nspKSRg7/SyO0cRGY71OkfHab8tf9kCts6a6oTDut0w= +mellium.im/sasl v0.2.1/go.mod h1:ROaEDLQNuf9vjKqE1SrAfnsobm2YKXT1gnN1uDp1PjQ= diff --git a/pgexample/main.go b/pgexample/main.go new file mode 100644 index 0000000..a8ac057 --- /dev/null +++ b/pgexample/main.go @@ -0,0 +1,32 @@ +package main + +import ( + pgadapter "github.com/MonedaCacao/casbin-pg-adapter" + "github.com/casbin/casbin" +) + +func main() { + // Initialize a Go-pg adapter and use it in a Casbin enforcer: + // The adapter will use the Postgres database named "casbin". + // If it doesn't exist, the adapter will create it automatically. + a, _ := pgadapter.NewAdapter() // Your driver and data source. + + // Or you can use an existing DB "abc" like this: + // The adapter will use the table named "casbin_rule". + // If it doesn't exist, the adapter will create it automatically. + + e := casbin.NewEnforcer("examples/rbac_model.conf", a) + + // Load the policy from DB. + e.LoadPolicy() + + // Check the permission. + e.Enforce("alice", "data1", "read") + + // Modify the policy. + // e.AddPolicy(...) + // e.RemovePolicy(...) + + // Save the policy back to DB. + e.SavePolicy() +}