auth_model.conf 532 B

12345678910111213141516171819202122232425
  1. [request_definition]
  2. r = sub, dom, obj, act
  3. [policy_definition]
  4. p = sub, dom, obj, act, eft
  5. [role_definition]
  6. #角色
  7. g = _, _, _
  8. #菜单
  9. g2 = _, _, _
  10. #部门
  11. g3 = _, _, _
  12. #区域
  13. g4 = _, _, _
  14. #角色管理角色
  15. g5 = _, _, _
  16. #操作权限
  17. g6 = _, _, _
  18. [policy_effect]
  19. e = some(where (p.eft == allow))
  20. [matchers]
  21. m = g(r.sub, p.sub, r.dom) && g2(r.sub, r.dom, p.sub) && g3(r.sub, r.dom, p.sub) && g4(r.sub, r.dom, p.sub) && g5(r.sub, r.dom, p.sub) && g6(r.sub, r.dom, p.sub) && r.dom == p.dom && r.obj == p.obj && r.act == p.act