Closed jimmyjames closed 5 months ago
Fossa checks failing, likely false warnings re. licenses, will need to review them.
Due to some fossa license issues with hibernate (uses LPGL), using spring-data-jpa and its h2 is likely going to be problematic (until/if hibernate switches to apache 2.0 as discussed). Closing this PR to rework to remove those dependencies, and also because this PR uses the multi-module structure which we removed due to nexus plugin issues.
Description
Adds a simple example application that uses the FGA Spring Boot Starter. Features:
document:1
anddocument:2
).user:anne
theviewer
relation todocument:1
./documents/{id}
) which uses thefga
bean in a@PreAuthorize
expression to ensure that the user (hard-coded toanne
in this example) has thecan_read
relation to the requested document. If the FGA check returns true, the document is returned to the caller. If the FGA check fails, it will result in a403
.user:anne
as having theowner
relation to the document.This change does not add any tests; https://github.com/jimmyjames/fga-spring-examples has some great examples of writing tests and using the FGA test container; we'll create another issue to do something similar here (may be a good opportunity for a community contribution 😄).
Closes #5
References
5
Review Checklist
main