본문 바로가기
WIKI 기술 지식 베이스

Permissions 서비스

원문 보기 위키 갱신

이 서비스는 플러그인이 permissions 프레임워크에 사용자 동작의 인가(authorization)를 요청할 수 있게 해줘요.

출처: 문서

본문

이 서비스는 플러그인이 permissions 프레임워크에 사용자 동작의 인가(authorization)를 요청할 수 있게 해줘요.

서비스 사용하기

다음 예시는 example 백엔드에서 permissions 서비스를 가져와 사용자 지정 권한 규칙으로 특정 동작을 수행할 수 있는지 확인하는 방법을 보여줘요.

import {
  coreServices,
  createBackendPlugin,
} from '@backstage/backend-plugin-api';
import { NotAllowedError } from '@backstage/errors';
import { AuthorizeResult } from '@backstage/plugin-permission-common';
import Router from 'express-promise-router';

export default createBackendPlugin({
  pluginId: 'example',
  register(env) {
    env.registerInit({
      deps: {
        permissions: coreServices.permissions,
        httpRouter: coreServices.httpRouter,
        httpAuth: coreServices.httpAuth,
      },
      async init({ permissions, httpRouter, httpAuth }) {
        const endpoints = Router();
        endpoints.get('/test-me', (request, response) => {
          // Ask the permissions framework what the decision is for the given
          // permission, for the principal that made the original request. The
          // `httpAuth` service helps us extract those credentials. We authorize
          // a single permission here, so the result will be an array with one
          // element accordingly.
          const permissionResponse = await permissions.authorize(
            [{ permission: myCustomPermission }],
            { credentials: await httpAuth.credentials(request) },
          );
          if (permissionResponse[0].result !== AuthorizeResult.ALLOW) {
            throw new NotAllowedError(
              'You are not permitted to perform this action',
            );
          }
          // TODO: Actual code goes here
        });
        httpRouter.use(endpoints);
      },
    });
  },
});

더 알아보기 (Learn more)