PageSourceSearch

https://authress.io/knowledge-base/assets/js/84854286.878e573c.js

js authress.io collected 2026-09-24 18:29:52 UTC 8,993 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkAuthressKnowledgeBase=self.webpackChunkAuthressKnowledgeBase||[]).push([[2361],{3905:(e,t,n)=>{n.d(t,{Zo:()=>c,kt:()=>d});var a=n(67294);function r(e,t,n){return t in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function o(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);t&&(a=a.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),n.push.apply(n,a)}return n}function i(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?o(Object(n),!0).forEach((function(t){r(e,t,n[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):o(Object(n)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))}))}return e}function s(e,t){if(null==e)return{};var n,a,r=function(e,t){if(null==e)return{};var n,a,r={},o=Object.keys(e);for(a=0;a<o.length;a++)n=o[a],t.indexOf(n)>=0||(r[n]=e[n]);return r}(e,t);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);for(a=0;a<o.length;a++)n=o[a],t.indexOf(n)>=0||Object.prototype.propertyIsEnumerable.call(e,n)&&(r[n]=e[n])}return r}var l=a.createContext({}),m=function(e){var t=a.useContext(l),n=t;return e&&(n="function"==typeof e?e(t):i(i({},t),e)),n},c=function(e){var t=m(e.components);return a.createElement(l.Provider,{value:t},e.children)},p={inlineCode:"code",wrapper:function(e){var t=e.children;return a.createElement(a.Fragment,{},t)}},u=a.forwardRef((function(e,t){var n=e.components,r=e.mdxType,o=e.originalType,l=e.parentName,c=s(e,["components","mdxType","originalType","parentName"]),u=m(n),d=r,h=u["".concat(l,".").concat(d)]||u[d]||p[d]||o;return n?a.createElement(h,i(i({ref:t},c),{},{components:n})):a.createElement(h,i({ref:t},c))}));function d(e,t){var n=arguments,r=t&&t.mdxType;if("string"==typeof e||r){var o=n.length,i=new Array(o);i[0]=u;var s={};for(var l in t)hasOwnProperty.call(t,l)&&(s[l]=t[l]);s.originalType=e,s.mdxType="string"==typeof e?e:r,i[1]=s;for(var m=2;m<o;m++)i[m]=n[m];return a.createElement.apply(null,i)}return a.createElement.apply(null,n)}u.displayName="MDXCreateElement"},67268:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>l,contentTitle:()=>i,default:()=>p,frontMatter:()=>o,metadata:()=>s,toc:()=>m});var a=n(87462),r=(n(67294),n(3905));const o={title:"Document repository"},i=void 0,s={unversionedId:"implementation-examples/document-repository",id:"implementation-examples/document-repository",title:"Document repository",description:"The document repository is an service that has two main components, a UI that a user interacts with, and a service by which users or third parties can manage a user's resources through the API.",source:"@site/docs/100-implementation-examples/01-document-repository.md",sourceDirName:"100-implementation-examples",slug:"/implementation-examples/document-repository",permalink:"/knowledge-base/docs/implementation-examples/document-repository",draft:!1,editUrl:"https://gitlab.com/rhosys/authress-public-kb/knowledge-base/-/blob/main/docs/100-implementation-examples/01-document-repository.md",tags:[],version:"current",lastUpdatedAt:1772377859,formattedLastUpdatedAt:"Mar 1, 2026",sidebarPosition:1,frontMatter:{title:"Document repository"},sidebar:"tutorialSidebar",previous:{title:"Implementation examples",permalink:"/knowledge-base/docs/implementation-examples/"},next:{title:"Expense report service",permalink:"/knowledge-base/docs/authorization/example-implementation"}},l={},m=[{value:"Roles",id:"roles",level:2},{value:"Permissions: Allow, Grant, Delegate",id:"permissions-allow-grant-delegate",level:2},{value:"Example implementation",id:"example-implementation",level:2}],c={toc:m};function p(e){let{components:t,...n}=e;return(0,r.kt)("wrapper",(0,a.Z)({},c,n,{components:t,mdxType:"MDXLayout"}),(0,r.kt)("p",null,"The document repository is an service that has two main components, a UI that a user interacts with, and a service by which users or third parties can manage a user's resources through the API."),(0,r.kt)("p",null,"The core concept of the repository is:"),(0,r.kt)("blockquote",null,(0,r.kt)("p",{parentName:"blockquote"},"There are many documents. Each document can have any number of users and each of those users may have different permissions to that document. Users will share documents and change other users\u2019 permissions as well as create, modify, and delete documents. We\u2019ll assume there are two services, one that stores text documents and another than stores complex binary data, text and binary.")),(0,r.kt)("p",null,"Additionally, each account in the document repository has multiple users authorized to access it. Some of them are full ",(0,r.kt)("strong",{parentName:"p"},"Admins")," of the account, which access to manage users, update billing information, or change global configuration for the account. Other users are only ",(0,r.kt)("strong",{parentName:"p"},"Viewers")," which have only limited access to read all the documents in the repository. The rest of the users have some configurable permission on a document by document basis that provides the capability to ",(0,r.kt)("strong",{parentName:"p"},"create"),", ",(0,r.kt)("strong",{parentName:"p"},"update"),", or ",(0,r.kt)("strong",{parentName:"p"},"delete")," existing documents. Depending on the permission assigned to them, they might be able to also ",(0,r.kt)("strong",{parentName:"p"}
1,"share")," that document with other users in the account (and users outside the account)."),(0,r.kt)("p",null,"For further simplicity, this document repository is private per account. Documents created in one account are not available on the public. And conversely, in order to create a document, the user must have the ",(0,r.kt)("inlineCode",{parentName:"p"},"documents:create")," permission."),(0,r.kt)("h2",{id:"roles"},"Roles"),(0,r.kt)("p",null,"The roles associated with the document repository might look like this:"),(0,r.kt)("ul",null,(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("inlineCode",{parentName:"li"},"Admin"),": Contains the permissions ",(0,r.kt)("inlineCode",{parentName:"li"},"\u2736"),". When assigned to a user in an access record, that user full control over that document as well as the ability to change other users permissions to that document."),(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("inlineCode",{parentName:"li"},"Editor"),": Contains the permissions ",(0,r.kt)("inlineCode",{parentName:"li"},"documents:read"),", ",(0,r.kt)("inlineCode",{parentName:"li"},"documents:update"),", ",(0,r.kt)("inlineCode",{parentName:"li"},"documents:delete"),", and ",(0,r.kt)("inlineCode",{parentName:"li"},"documents:share"),". They can make changes to the document as necessary"),(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("inlineCode",{parentName:"li"},"Viewer"),": Contains the permission ",(0,r.kt)("inlineCode",{parentName:"li"},"documents:read"),", when given to a user for a document, they will be able to read the document only."),(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("inlineCode",{parentName:"li"},"Creator")," Contains the permission ",(0,r.kt)("inlineCode",{parentName:"li"},"documents:create"),". Usually given to all users in an account. Users with this permission can create documents. When they create a document, they are given ",(0,r.kt)("inlineCode",{parentName:"li"},"Admin")," to that new document only.")),(0,r.kt)("h2",{id:"permissions-allow-grant-delegate"},"Permissions: Allow, Grant, Delegate"),(0,r.kt)("p",null,"To keep this scenario simple, we'll assume that only the ",(0,r.kt)("inlineCode",{parentName:"p"},"Admin")," role has ",(0,r.kt)("inlineCode",{parentName:"p"},"Grant")," and ",(0,r.kt)("inlineCode",{parentName:"p"},"Delegate"),". That means that an ",(0,r.kt)("inlineCode",{parentName:"p"},"Editor")," cannot assign any roles--",(0,r.kt)("inlineCode",{parentName:"p"},"Editor"),", ",(0,r.kt)("inlineCode",{parentName:"p"},"Viewer"),", or ",(0,r.kt)("inlineCode",{parentName:"p"},"Creator"),"--to other users. To be able to assign a role to a user that user must have ",(0,r.kt)("inlineCode",{parentName:"p"},"Grant")," or ",(0,r.kt)("inlineCode",{parentName:"p"},"Delegate")," on all the permissions in the relevant access record. For more details on ",(0,r.kt)("inlineCode",{parentName:"p"},"Allow"),", ",(0,r.kt)("inlineCode",{parentName:"p"},"Grant"),", and ",(0,r.kt)("inlineCode",{parentName:"p"},"Delete"),", refer to the ",(0,r.kt)("a",{parentName:"p",href:"/knowledge-base/docs/authorization/access-records#user-management-of-permissions"},"access record permissions article"),"."),(0,r.kt)("h2",{id:"example-implementation"},"Example implementation"),(0,r.kt)("p",null,"An example implementation of a document repository using AWS S3 is available on GitHub: ",(0,r.kt)("a",{parentName:"p",href:"https://github.com/Authress/document-library-microservice.js#aws-s3-document-library"},"Document Library Microservice")))}p.isMDXComponent=!0}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.