Custom permissions
MetalSoft’s ABAC (Attribute-Based Access Control) system allows complex, custom rules based on CASL conditions, custom fields, etc.
MetalSoft filters every operation it performs through a process that checks whether the logged-in User has permission to perform a particular Action against a particular Subject (such as an Infrastructure or a Server). MetalSoft assigns each User a Role that includes a list of Permissions, both built-in and custom. For most situations, the built-in permissions are sufficient. More complex situations can require custom permissions.
Creating a custom permission
Section titled “Creating a custom permission”To create a custom permission using the admin UI, perform the following:
- Go to Users & Permissions > Permissions.
- Click Add Permission.
- Fill in the details of the permission as described below.
- Click add permission.
- Go to the Roles tab.
- Click edit on an existing role, or click Add Custom Role.
- Check the checkbox next to the newly created permission at the bottom.
Permission criteria
Section titled “Permission criteria”The Conditions uses the CASL convention. These conditions have 3 parameters:
-
Action One of:
- All actions
- Create
- List
- Read
- Update
- Delete
- Deploy
- Manage
-
Subject This is the subject of an action, typically an object type such as an
Infrastructure. -
Conditions
Conditions are JSON objects that use the CASL mechanism. The following examples use the “Infrastructure” Subject:
Test that the infrastructure has the id 120:
{ "id": 120}Test User field userId equality with a Subject field:
{ "userIdOwner": "{{userId}}"}Test that the infrastructure’s status value is one of active or ordered:
{ "serviceStatus": "{ $in: ['active', 'ordered'] }"}Multiple conditions:
{ "createdAt": "{ $lte: new Date() }", "status": "{ $in: ['active', 'ordered'] }"}Possible operations list:
$eqand$neobject value should equal specified value.$nemeansnot $eq.$ltand$lteobject value should be less than specified value. Can be used for dates, numbers, and strings.$lteis a combination of$ltand$eq, so it is an inclusive check.$gtand$gteobject value should be greater than specified value. Can be used for dates, numbers, and strings.$gteis a combination of$gtand$eq, so it is an inclusive check.$inand$ninChecks that object’s property is of the specified array values. Can be used for single value and for arrays as well. If object’s property is an array, it checks for intersection.$ninmeans not$in.$allChecks that object’s property should contain all elements from the specified array. Can be used for arrays only.$sizeChecks that array length equals the specified value. Can be used for arrays only.$regexAllows testing object’s property value using a regular expression. Can be used for strings only.$existsChecks that property exists in the object.$elemMatchChecks the shape of nested elements. Use the$elemMatchoperator to specify multiple criteria on the elements of an array such that at least one array element satisfies all the specified criteria. If you specify only a single condition in the$elemMatchexpression,$elemMatchis not necessary. See Specify Multiple Conditions for Array Elements for details.
Refer to this resource for more details: Conditions in Depth
Getting the list of fields that can be used for the Subject
Section titled “Getting the list of fields that can be used for the Subject”To get the list of fields available for each Subject, refer to the API documentation of your environment (accessible at https://your-env-hostname/api/v2/swagger) for an up-to-date list of possible objects (scroll towards the bottom).
User-related fields
Section titled “User-related fields”The following custom fields map to the logged-in user’s properties:
{{userId}}- Logged-in user’s ID{{accountId}}- Logged-in user’s account ID
Fields
Section titled “Fields”This field in the form allows you to restrict access to a certain list of fields rather than all fields. This can be used in conjunction with the Conditions field or as standalone.
If none is entered, the User (Principal) operating on the Subject can change all fields.