Relation tuples checking error #136
Replies: 2 comments
|
Hello @Rudkovskiy427 can you please share the steps to reproduce this on a fresh install? if the relationships do not change the response should be consistent.
So Keto always responded as expected or was there flaky behaviour? it sounds like it might be a bug in permission handling in your app rather than a flaky response from Keto? |
|
This sounds more like an operational or consistency issue than a modeling issue, assuming the tuples and namespace config are really unchanged. The first thing I would check is whether every Keto instance is using the exact same database and the exact same namespace configuration. Intermittent For this model, the tuples should look conceptually like this: And the permission check should be against the computed permission relation, for example: {
"namespace": "docs",
"object": "document1_uuid",
"relation": "edit",
"subject_id": "user1_uuid"
}The namespace config must explicitly connect I would investigate in this order: 1. Confirm the exact tuples during a false result When the check returns keto relation-tuple listor query the read API for: If the tuple is missing only sometimes, that points to database, replication, or instance routing. 2. Check load balancing If you run multiple Keto pods or containers, temporarily pin traffic to one instance. If the problem disappears, compare: across all instances. 3. Increase check depth Group based permissions require subject set expansion. If your real graph is deeper than the simplified example, pass an explicit If increasing depth fixes it, the issue is graph traversal depth, not tuple storage. 4. Turn on debug logs around the check path Normal access logs will not show why expansion failed. Enable more verbose logs and look specifically for expansion depth, subject set traversal, or storage errors. 5. Be cautious with v0.12.0-alpha.0 That version is very old and alpha. If this is production or production like, I would strongly recommend testing on a current supported Keto or Ory Permissions release. There have been many changes since that alpha series, and intermittent authorization behavior is not something I would try to debug long term on an alpha build. So the likely causes are: I would start by pinning to one Keto instance and checking the tuple list at the exact moment |
Uh oh!
There was an error while loading. Please reload this page.
I am using Ory Keto v0.12.0-alpha.0 to implement the following relationships in a service:
User1 is a member of Group1; Group1 has the editors relation to Document1.
Therefore, User1 should be able to edit Document1.
The problem is that, periodically, when checking User1's permissions using the GET relation-tuples/check endpoint:
the response returns allowed=false instead of true. Notably, for some time, the check returns true as expected, and then, unexpectedly, it starts returning false—indicating the user no longer has permission to edit the document—but then it goes back to normal, and the user regains access.
During all this, the relationships between User1, Group1, and Document1 do not change. Reviewing the logs provided no insight—what I saw were just the responses to the relation-tuples/check requests.
Please advise what might be causing this issue and where to look. I'd like to note that all relationships between the entities are correctly set, yet the user's access occasionally disappears.
All reactions