Repository navigation
Security Access Control
Navigation: Home > Security
ThemisDB's Access Control Framework provides a comprehensive security layer that integrates:
- Role-Based Access Control (RBAC) for permission management
- Authentication via JWT, API tokens, Kerberos, and USB admin auth
- Authorization with fine-grained resource and action controls
- Audit Logging for security event tracking
- ZeroTrustAuthVerifier - Auth-layer continuous verification bridge (token + network + trust score)
- ZeroTrustPolicyEnforcer - Per-request network identity gate (zero-trust layer)
- AccessControlManager - Central coordinator for authentication and authorization
- RBAC - Role and permission management system
- AuthMiddleware - Token validation and authentication
- UserRoleStore - User-to-role mappings
- SecurityContext - Per-request security information
Request β ZeroTrustAuthVerifier (auth-layer: token re-validation + network + trust score)
β ZeroTrustPolicyEnforcer (network+identity gate)
β AuthMiddleware (authenticate)
β AccessControlManager β RBAC/ABAC
β Decision
Zero-trust gate:
ZeroTrustAuthVerifier::verify()(auth module) must be called for every inbound request before RBAC/ABAC evaluation. It re-validates the bearer token via the injectedTokenVerifier, enforces per-identity CIDR network policies, and applies a configurable minimum trust-score threshold. Internally it delegates toZeroTrustPolicyEnforcer::verify()(security module). See zero_trust_policy_enforcer.md for details.
Create RBAC roles configuration (config/rbac_roles.json):
{
"roles": [
{
"name": "admin",
"description": "Full access administrator",
"permissions": [
{"resource": "*", "action": "*"}
],
"inherits": []
},
{
"name": "developer",
"description": "Developer with schema access",
"permissions": [
{"resource": "schema", "action": "read"},
{"resource": "schema", "action": "write"},
{"resource": "data", "action": "read"}
],
"inherits": []
}
]
}Create user-role mappings (config/user_roles.json):
{
"users": [
{
"user_id": "alice@example.com",
"roles": ["admin"],
"attributes": {"department": "IT"}
},
{
"user_id": "bob@example.com",
"roles": ["developer"],
"attributes": {"department": "Engineering"}
}
]
}#include "security/access_control_manager.h"
#include "server/auth_middleware.h"
// Configure access control
themis::security::AccessControlConfig config;
config.rbac_config_path = "config/rbac_roles.json";
config.user_role_store_path = "config/user_roles.json";
config.enable_audit_logging = true;
config.fail_closed = true; // Deny access on errors
// Create manager
auto acm = std::make_shared<themis::security::AccessControlManager>(config);
// Set up auth middleware
auto auth = std::make_shared<themis::AuthMiddleware>();
// Configure JWT or tokens...
acm->setAuthMiddleware(auth);
// Initialize
if (!acm->initialize()) {
// Handle initialization failure
}// Check if bearer token has permission
auto decision = acm->checkAccess(
bearer_token, // Authentication token
"data", // Resource
"write", // Action
client_ip // Source IP (optional)
);
if (decision.granted) {
// Proceed with operation
std::cout << "Access granted: " << decision.reason << std::endl;
} else {
// Deny operation
std::cout << "Access denied: " << decision.reason << std::endl;
}// Step 1: Authenticate
auto context = acm->authenticate(bearer_token, client_ip);
if (!context) {
// Authentication failed
return;
}
// Step 2: Authorize
auto decision = acm->authorize(*context, "keys", "rotate");
if (decision.granted) {
// User has permission to rotate keys
}Resources represent system entities:
-
data- Data operations (tables, documents) -
schema- Schema management -
keys- Encryption key management -
config- System configuration -
audit- Audit log access -
metrics- Metrics and monitoring -
health- Health check endpoints -
*- Wildcard (all resources)
Actions represent operations:
-
read- Read/view access -
write- Create/update access -
delete- Delete access -
execute- Execute operations (queries, functions) -
rotate- Rotate keys -
*- Wildcard (all actions)
Permissions are expressed as resource:action pairs:
-
data:read- Read data -
data:write- Write data -
keys:rotate- Rotate encryption keys -
*:*- Full access to everything
-
Permissions: Full access (
*:*) - Use Case: System administrators
- Permissions: Data operations, key management, audit read
- Inherits: analyst
- Use Case: Operations team
- Permissions: Read-only data and audit access
- Inherits: readonly
- Use Case: Data analysts
- Permissions: Schema management, query execution
- Use Case: Application developers
- Permissions: Metrics and health checks only
- Use Case: Monitoring systems, external viewers
Roles can inherit permissions from other roles:
{
"name": "operator",
"permissions": [
{"resource": "keys", "action": "rotate"}
],
"inherits": ["analyst"]
}In this example, operator gets:
- Direct:
keys:rotate - Inherited from
analyst:data:read,audit:read,metrics:read - Inherited from
readonly(via analyst):health:read
Add custom authorization logic:
config.custom_authorizer = [](
const themis::security::SecurityContext& ctx,
const std::string& resource,
const std::string& action
) -> themis::security::AccessDecision {
// Allow operations team access during business hours
if (ctx.hasGroup("operations")) {
auto hour = getCurrentHour();
if (hour >= 9 && hour <= 17) {
return themis::security::AccessDecision::Allow(
"Operations team access during business hours"
);
}
}
// Fall through to RBAC
return themis::security::AccessDecision::Deny("");
};The SecurityContext contains per-request security information:
struct SecurityContext {
std::string user_id; // e.g., "alice@example.com"
std::vector<std::string> roles; // e.g., ["admin", "developer"]
std::vector<std::string> groups; // e.g., ["engineering", "ops"]
std::string session_id; // Session identifier
std::string source_ip; // Request source IP
std::unordered_map<std::string, std::string> attributes;
bool hasRole(const std::string& role) const;
bool hasGroup(const std::string& group) const;
};All access decisions are automatically logged when enable_audit_logging = true:
{
"event_type": "access_control",
"timestamp": 1674392400000,
"user_id": "alice@example.com",
"roles": ["admin"],
"source_ip": "192.168.1.100",
"resource": "keys",
"action": "rotate",
"decision": "allow",
"reason": "Permission granted via RBAC",
"applied_permissions": ["*:*"]
}acm->assignRole("charlie@example.com", "developer");acm->revokeRole("charlie@example.com", "developer");auto roles = acm->getUserRoles("charlie@example.com");
for (const auto& role : roles) {
std::cout << "Role: " << role << std::endl;
}auto perms = acm->getUserPermissions("charlie@example.com");
for (const auto& perm : perms) {
std::cout << "Permission: " << perm.toString() << std::endl;
}// After modifying config files
if (acm->reloadConfiguration()) {
std::cout << "Configuration reloaded" << std::endl;
}Monitor access control metrics:
const auto& metrics = acm->getMetrics();
std::cout << "Auth success: " << metrics.authentication_success << std::endl;
std::cout << "Auth failure: " << metrics.authentication_failure << std::endl;
std::cout << "Authz success: " << metrics.authorization_success << std::endl;
std::cout << "Access denied: " << metrics.access_denied << std::endl;-
Fail Closed: Always set
fail_closed = truein production - Least Privilege: Assign minimal required roles to users
- Audit Everything: Enable audit logging for compliance
- Regular Reviews: Periodically review user-role assignments
- Strong Authentication: Use JWT with proper validation, not static tokens
- Cache Decisions: Results are not cached by default - implement caching if needed
-
Batch Operations: Use
getUserPermissions()once instead of repeatedauthorize()calls - Efficient Configs: Keep role hierarchies simple (max 3-4 levels)
- Backup Configs: Version control RBAC and user-role files
- Test Changes: Test role changes in non-production first
- Monitor Metrics: Set up alerts on high denial rates
- Gradual Rollout: Use custom authorizer for gradual permission changes
// In HTTP request handler
std::string auth_header = request.getHeader("Authorization");
auto token = themis::AuthMiddleware::extractBearerToken(auth_header);
if (!token) {
return response.status(401).send("Missing authorization");
}
auto decision = acm->checkAccess(*token, "data", "read", request.getIP());
if (!decision.granted) {
return response.status(403).send("Access denied: " + decision.reason);
}
// Proceed with operation// In gRPC interceptor
grpc::Status CheckAuthorization(
grpc::ServerContext* context,
const std::string& resource,
const std::string& action
) {
auto metadata = context->client_metadata();
auto auth_it = metadata.find("authorization");
if (auth_it == metadata.end()) {
return grpc::Status(grpc::UNAUTHENTICATED, "No auth token");
}
std::string token = std::string(auth_it->second.data(), auth_it->second.size());
auto bearer_token = themis::AuthMiddleware::extractBearerToken(token);
if (!bearer_token) {
return grpc::Status(grpc::UNAUTHENTICATED, "Invalid auth token");
}
auto decision = acm->checkAccess(*bearer_token, resource, action);
if (!decision.granted) {
return grpc::Status(grpc::PERMISSION_DENIED, decision.reason);
}
return grpc::Status::OK;
}- Check user's assigned roles:
acm->getUserRoles(user_id) - Check role's permissions:
acm->getUserPermissions(user_id) - Verify RBAC config is loaded correctly
- Check audit logs for decision details
- Enable DEBUG logging to see permission checks
- Verify file paths are correct
- Check JSON syntax with a validator
- Ensure files are readable by the process
- Check logs for specific error messages
- Reduce role inheritance depth
- Implement decision caching layer
- Use custom authorizer for frequent checks
- Consider moving static permissions to compile-time
- Zero-Trust Policy Enforcer
- RBAC Documentation
- Authentication Middleware
- Security Overview
- Audit Logging
ThemisDB 1.9.0-beta Β· Home Β· Module-Index Β· GitHub Β· Issues
ThemisDB 1.9.0-beta Β· Home Β· Wiki-Index Β· Module-Index Β· FAQ Β· Quick-Reference Β· GitHub Β· Issues Β· Discussions Β· License
- Home
- Hero Articles
- All Wiki Pages
- FAQ
- Edition Comparison
- Repository README
- Changelog
- Roadmap
- Versioning
- Integration Mapping
- Overview
- Readme
- Appendix D Feature Status
- Appendix E Incident Runbooks
- Appendix F AQL Cheatsheet
- Appendix G Configuration
- Appendix H Glossary
- Appendix I Troubleshooting
- Appendix Literatur
- Chapter 00 Genesis
- Chapter 01 Introduction
- Chapter 02 Architecture
- Chapter 03 Multimodel
- Chapter 04 Installation
- Chapter 05 Relational
- Chapter 06 Graph
- Chapter 07 Document
- Chapter 08 Storage Layer
- Chapter 08 Vector
- Chapter 09 Timeseries
- Chapter 10 Enterprise
- Chapter 11 Realtime
- Chapter 12 Computervision
- Chapter 13 Fulltext
- Chapter 14 Geospatial
- Chapter 15 Analytics
- Chapter 16 Ml
- Chapter 16 Sharding
- Chapter 17 LLM Integration
- Chapter 17 Scaling
- Chapter 18 HA
- Chapter 18 Ml
- Chapter 19 Monitoring
- Chapter 19 Monitoring Observability
- Chapter 20 Backup
- Chapter 20 Performance
- Chapter 21 Auth
- Chapter 21 Performance
- Chapter 22 Clients
- Chapter 22 Encryption
- Chapter 23 Testing Qa
- Chapter 24 Ai Ethics
- Chapter 25 Devops Infrastructure
- Chapter 26 Migration Legacy
- Chapter 27 Troubleshooting
- Chapter 28 AQL Reference
- Chapter 29 Analytics Process Mining
- Chapter 30 Deployment Operations
- Chapter 31 API Protocols
- Chapter 32 API Design Rest Principles
- Chapter 32 AQL Oop Implementation
- Chapter 33 Best Practices
- Chapter 34 Query Optimization
- Chapter 35 Data Modeling Patterns
- Chapter 36 Security Hardening
- Chapter 37 Ecosystem Integration
- Chapter 38 Observability Sre
- Chapter 39 Performance Tuning Cookbook
- Chapter 40 Data Governance Compliance
- Chapter 41 Hands On Labs
- Chapter 42 Docs Assistant Usage
- Chapter MVCC Hlc
- Cover
- Cover Book
- Index
- Preface
- Test Links Example
- Batch Operations
- Best Practices
- CRUD Tutorial
- Custom Document Ingestion
- Getting Started Tutorial
- Interactive Examples
- Schema Design
- Video Tutorials
- AQL Reference
- AQL Examples
- AQL Overview
- AQL Feature Roadmap
- AQL Geospatial Guide
- AQL LLM Migration Guide
- AQL API
- AQL Grammar (EBNF)
- AQL Root Overview
- AQL Examples (root)
- API Reference
- API Module README
- OpenAPI Overview
- Client SDK Overview
- SDK Overview
- Operations
- Operations Overview
- Operations Runbook
- Operations Handbook
- ThemisCtl Admin Guide
- Pipeline E2E SOPs
- Docker Overview
- Docker Hub README
- Helm Overview
- Packaging Overview
- Operator Overview
- Security Policy
- Production Hardening Checklist
- Security Hardening Guide
- Encryption Key Management
- Access Control Framework
- Zero Trust Policy
- API Authentication & Authorization
- HSM Production Setup
- PKCS11 Integration
- DSGVO / SOC2 Checklist
- Access Model Runbooks
- Access Model Dashboard
- Maturity Automation Runbook
- Access Review Automation
- Access Model Dashboard
- Access Model Runbooks
- Rights Revocation
- Dr Checklists
- Dr Testing
- Incident Response Playbook
- Incident Response Testing
- GPU Oom Recovery
- Grammar Debugging
- Metrics Scrape Troubleshooting
- Model Swap Procedure
- Quota Tuning
- Subagent Deployment
- Logging Configuration
- Content Model
- Crypto & Keys
- Feature Flags Reference
- Modular Architecture Roadmap
- Modularization Guide
- Module Architecture Index
- PostgreSQL Wire Protocol
- Query Scheduling
- Raft Consensus Design
- Resource Pooling
- Source Directory Guide
- Unified Access Model
- E1 001 Layered Retrieval Design
- E1 002 Ann Abstraction Strategy
- E1 003 Tensor Summary Types
- E1 004 Lora Package Distinction
- E1 005 Model Switch Compatibility
- E1 006 Federated Tensor Summaries
- E2 001 Evaluation Framework Design
- E2 002 Hardware Profile Strategy
- E2 003 Query Planner Routing Model
- E2 004 Approximation Governance Rules
- E2 005 Cross Layer Fallback Confidence Policy
- E3 001 Distributed Tensor Design
- E3 002 Manifest Coordination Strategy
- E3 003 Recovery And Erasure Choice
- E3 004 Tensor Fabric Infrastructure
- Contributing
- Contributing (root)
- Code of Conduct
- Support
- Maintainers
- CTest Guide
- Build Quick Reference
- Developer Wiki Index
- Build / Test / CI
- Module Index
- Branching Strategy
- Release Strategy
- CI Policy Gates Wave C
- Disabled Stub Policy
- Docs PR Policy
- GA Promotion Sign Off
- Github Milestones Setup
- Governance Policies Phase1
- GPU Self Hosted Runner Requirements
- Hardening Phase 1 2 Summary 2026 09 23
- Maturity Claim Verification Checklist
- Maturity Evidence Registry
- Merge Gate Bot Config
- Merge Gate Status Live
- Phase 1 Closure Report
- Phase 1 Infrastructure Deployment
- Phase 1 Infrastructure Deployment Complete
- Phase 3 Baseline Capture
- Phase 3 Refinement Spec
- Phase 4 Sign Off And Closure
- Phase Closure Policy
- Phase Dependency Graph
- Phase3 Enforcement Runbook
- Plugin Submodule Rollback
- PR Version Targeting
- PR Version Targeting Backfill
- Production Ready 2026 Delivery Plan
- Publish Workflow Audit 2026 09 23
- Query Module Status
- Readme
- Release Governance
- Release Promotion Gate Policy
- Release Validation Checklist
- Root Hygiene Policy
- SBOM Approved Versions
- Security Compliance Audit Report 2026 08 10
- Security Module 5671 Evidence Summary
- Sharding P6 Residual Risk Acceptance
- Sourcecode Compliance Governance
- Src Module Documentation Compliance 2026 09 20
- Updates Development Status Sign Off
- Wave C Implementation Complete
- Wave C Implementation Plan
- Wave C Ml Exit Gate Sign Off
- Wave C Policy Gate Evidence
- Wiki Publish Tracking Guide
- Blob Storage
- Cuda
- Ethics Ai
- Exporters
- Huggingface
- Image Analysis
- Importers
- RPC
- Scraper
- Themisdb Ai Watermark Detector
- User Storage Encrypted
- Chimera Architecture
- Chimera Future
- Chimera Readme
- Chimera Roadmap
- Covina Fastapi Ingestion Architecture
- Covina Fastapi Ingestion Future
- Covina Fastapi Ingestion Roadmap
- Vcc Base Architecture
- Vcc Base Future
- Vcc Base Roadmap
- Vcc Clara Ingestion Architecture
- Vcc Clara Ingestion Future
- Vcc Clara Ingestion Roadmap
- Vcc Veritas Architecture
- Vcc Veritas Future
- Vcc Veritas Roadmap
- 01 Hello World
- 02 Todo App
- 03 Contact Manager
- 04 Inventory System
- 05 Time Series Monitor
- 06 Graph Social Network
- 07 Vector Search Documents
- 08 Dms Erp System
- 09 Iot Sensor Network
- 10 Drone Image Analysis
- 11 Blog Wiki
- 12 Expense Tracker
- 13 Recipe Manager
- 14 Ecommerce Catalog
- 15 Event Management
- 16 Kanban Board
- 17 Crm
- 18 Realtime Chat
- 19 Recommendation Engine
- 20 Smart Home
- 21 Coding Platform
- 22 AQL Diagram Tool
- 23 Traveling Salesman
- 24 Moral Philosophy Debates
- API Versioning
- Distributed Sharding
- Feedback Plugins
- Geo
- Gnn
- Image Analysis
- Legal Lora Training
- LLM
- Lora Sync
- Migration
- Nlp
- Performance
- Railway
- Replication
- Rope Visualization
- Sample Product Config
- Security
- Client SDK Overview
- Quickstart
- Sdk Enhancements
- Sdk Implementation Summary
- Test Suite Readme
- Go
- Java
- Javascript
- Php
- Python
- Ruby
- Rust
- Typescript
- 01 Grundlegende Operationen
- 02 AQL Queries
- 03 Graph Daten
- 04 Multimodell Anwendung
- 01 Quickstart Guide
- 02 AQL Referenz Kurzuebersicht
- 03 Datenmodellierung Guide
- 04 Uebungsaufgaben
- 05 Best Practices Guide
- Training Documents
- Training Overview
- 01 Einfuehrung Und Uebersicht
- 02 Datenmodelle Und Architektur
- 03 AQL Abfragesprache
- 04 Installation Und Setup
- 05 Anwendungsbeispiele
- Training Presentations
- Dependencies Readme
- Processmonitor Readme
- Themis.admintools.shared Readme
- Themis.aqlquerybuilder Readme
- Themis.aqlquerybuilder Roadmap
- Themis.auditlogviewer Readme
- Themis.auditlogviewer Roadmap
- Themis.classificationdashboard Readme
- Themis.classificationdashboard Roadmap
- Themis.compliancereports Readme
- Themis.compliancereports Roadmap
- Themis.gisviewer.controlpanel Readme
- Themis.gisviewer.controlpanel Roadmap
- Themis.impactanalysisviewer Readme
- Themis.impactanalysisviewer Roadmap
- Themis.ingestiontool Readme
- Themis.ingestiontool Roadmap
- Themis.keyrotationdashboard Readme
- Themis.keyrotationdashboard Roadmap
- Themis.piimanager Readme
- Themis.piimanager Roadmap
- Themis.retentionmanager Readme
- Themis.retentionmanager Roadmap
- Themis.sagaverifier Readme
- Themis.sagaverifier Roadmap
- Themis.usbadmintool Readme
- Themis.usbadmintool Roadmap
- Architecture Generator Readme
- CI Readme
- CI Roadmap
- Compiler Diagnostics Readme
- Compiler Diagnostics Roadmap
- Completion Readme
- Copilot Ollama Router Readme
- Copilot Ollama Router Roadmap
- Gnn Readme
- Gnn Roadmap
- Rope Visualizer Readme
- Rope Visualizer Roadmap
- Tco Calculator Readme
- Tco Calculator Roadmap
- Tests Readme
- Tests Roadmap
- Themis Config Wx Readme
- Themis Docs Builder Readme
- Wikipedia Ingestion Readme
- Ai Metadata And Provenance
- Build / Test / CI
- Governance And Roadmap
- Developer Wiki Index
- Module Direct Doxygen Check
- Module Doxygen Baseline Summary
- Module Doxygen Batch
- Module Doxygen Coverage Summary
- Module Doxygen Smoke Summary
- Modules And Apis
- Retrieval Direct Doxygen Check
- Soll Ist Gap Summary
- Wiki Delta Report