Requirements
RBAC works alongsideConfig.Organizations. Storage must support organizations: memory, Postgres or MySQL. SQLite does not. Config.Admin requires Config.RBAC, and theauth.New returns ErrAdminRequiresRBAC if it is missing.
Configure
&theauth.RBACConfig{} is valid. Permissions extends the seeded catalog, and DefaultRoles (a []theauth.RoleSeed) replaces the default roles seeded into new organizations. The owner, admin and member names must stay present. New rejects permission names with whitespace or non-ASCII characters, and role seeds that reference an unknown permission.
The seeded catalog includes PermissionUsersRead, PermissionUsersInvite, PermissionUsersAdmin, PermissionRolesRead, PermissionRolesAdmin, PermissionAuditRead, PermissionSAMLAdmin, PermissionSCIMAdmin, PermissionSessionsRevoke and the billing permissions. theauth.SeededPermissions() and theauth.DefaultRoleSeeds() return the full lists.
Use it
Seed the roles for each new organization, then check permissions:PermissionsForUser, GrantRole, RevokeRole, CreateRole, UpdateRole and DeleteRole. SeedPermissions runs lazily, so calling it at startup is optional.
Routes
RBAC itself mounts no routes. When you setConfig.Admin, the admin API mounts at /admin/v1 (change it with AdminConfig.PathPrefix). The role endpoints sit under /admin/v1/organizations/{orgID}:
The same tree also exposes user, session, audit and OAuth account endpoints, each gated by its own permission.
Security notes
RequirePermissionfails closed: no session returns 401, a session without an active organization returns 403 (rbac.no_active_org), and a half-finished second-factor session is refused.- If
Config.RBACis nil the middleware returns 500 on every request, so a missing config shows up in testing. - The system
super_adminrole bypasses every check. Grant it sparingly. GrantRoledoes not verify the actor’s authority. RunRequirePermissionupstream.- Removing or demoting the last owner of an organization is refused with
ErrLastOwner.