Roles
ModeratorIM resolves what a user may do through a chain:
user → groups → roles → permissions- A role is a named bundle of permission grants (see Permissions).
- A group is the only carrier of roles — a group holds one or more roles.
- A user belongs to one or more groups, and so inherits the roles those groups carry, and through them the permissions.
A user’s effective grants are the union of the permissions from every role of every group they belong to. The authorization service resolves this chain when deciding a request.
Super_user
Section titled “Super_user”A super_user bypasses the whole chain — they hold every permission and every role without enumerating grants. Use it sparingly; ordinary access should flow through groups and roles.
Why groups carry roles
Section titled “Why groups carry roles”Assigning roles to groups rather than directly to users keeps membership and capability separate: you manage who is in a group independently of what that group can do. Moving a user between groups changes their capabilities without editing roles, and changing a group’s roles updates every member at once.
Managing roles and permissions
Section titled “Managing roles and permissions”Roles and their permission grants are created and adjusted through the authorization service (an
app that manages permissions receives an authz handle on its request context, so it never
imports the service directly). Assigning grants validates each one is a well-formed permission or
wildcard before it is stored.