3 ms·
This is quite possible with the permission layer of the data service in Hasura. Why not add a new role that only 'blah234' and 'blah546' can be part of? All you
by ecthiender 10y ago
This is quite possible with the permission layer of the data service in Hasura. Why not add a new role that only 'blah234' and 'blah546' can be part of? All you have to do is to define permissions on this role.
Also, creating permissions and roles are all exposed via API calls, in case you have a requirement where you need to create these dynamically.
- ojr 10y agoI looked into an api, I don't see how can leverage it in the way I want, yes these roles will have to be created dynamically, pretend a user makes a post and only wants certain users to see the post, a new dynamic role will have to be created every time a user creates a new post?
- tango12 10y agoYou could do that, but you don't need to. The ACL constraint can be any arbitrary SQLish expression that is a boolean. In this case, say select is allowed if: req_user_id is in article.viewers.user_id. This means, if the request's user_id is in the viewers list of the article. It depends on the fact, that you have a relationship called viewers which comes from a table that contains article_id, user_id. The idea is to allow any ACL rule that can be represented as a constraint in your data model.