User-restricted access to data - Algolia
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Sometimes, you don’t want your users to search your entire index, but only a subset that concerns them. You can restrict content to a specific user, a set of users, a group, or everyone. Handling access within an index allows to have a fine-grained control over who can search and view what content. This doesn’t mean you need one index per user. By generating a secured API key for the current user, you can restrict the records they can retrieve.
Add an attribute for filtering in your dataset
Algolia is schemaless and doesn’t have any concept of relationships between objects, so you need to put all the relevant information in each record. Take a dataset for corporate documents as an example. The index contains the entire list of documents for the company, but has dedicated access control to restrict who can view content. Consider different users in this company: Angela, Mike, and Ruth. Angela is an executive, Mike the accountant, and Ruth is an engineer.
JSON
[
{
"title": "Financial record Q3 and pipeline forecast",
"visible_by": ["Angela", "group/Finance", "group/Shareholders"],
"objectID": "myID1",
"content": "..."
},
{
"title": "Compliance audit check-list",
"visible_by": ["group/Finance"],
"objectID": "myID2",
"content": "..."
},
{
"title": "Strategic partnership with BigCompany",
"visible_by": ["Angela"],
"objectID": "myID3",
"content": "..."
},
{
"title": "New company-wide healthcare coverage benefits",
"visible_by": ["group/Everybody"],
"objectID": "myID4",
"content": "..."
},
{
"title": "Ruth's personal TODO list",
"visible_by": ["Ruth"],
"objectID": "myID5",
"content": "..."
}
]
Each record has a visible_by attribute, which has a list of users or groups. Only listed users and groups can see the specific record, with the group Everybody visible by anyone. When searching through it, only allowed people should be able to find those records.
Set up user-restricted access
To restrict access, configure an attribute for filtering, generate secured API keys with embedded filters, and optionally hide the attribute from API responses.
Make the attribute filterable
To run the code examples on this page, install the latest API client. To make your visible_by attribute filterable, add it in attributesForFaceting.
C#
var response = await client.SetSettingsAsync(
"INDEX_NAME",
new IndexSettings { AttributesForFaceting = new List<string> { "filterOnly(visible_by)" } }
);
JavaScript
const response = await client.setSettings({
indexName: 'INDEX_NAME',
indexSettings: { attributesForFaceting: ['filterOnly(visible_by)'] },
});
Add and remove users
Whenever someone needs to change the access rights of a record, you need to update the visible_by attribute.
C#
var response = await client.PartialUpdateObjectAsync(
"INDEX_NAME",
"OBJECT_ID",
new Dictionary<string, List<string>>
{
{
"visible_by",
new List<string> { "Angela", "group/Finance", "group/Shareholders" }
},
}
);
Generate a secured API key
Frontend search can be vulnerable to malicious users who can tweak the request to impersonate another user and see content they shouldn’t have access to. To prevent this, generate a secured API key on the backend with filters (users can’t alter these filters).
C#
var response = client.GenerateSecuredApiKey(
"2640659426d5107b6e47d75db9cbaef8",
new SecuredApiKeyRestrictions { Filters = "visible_by:group/Finance" }
);
Make sensitive attributes inaccessible
When using a secured API key with an embedded filter, users can only retrieve content they’re allowed to access. Since the API returns the visible_by attribute for each record, they can find out what other users have the same access for this record if they inspect the response. To mitigate this privacy concern, use the unretrievableAttributes parameter.
C#
var response = await client.SetSettingsAsync(
"INDEX_NAME",
new IndexSettings { UnretrievableAttributes = new List<string> { "visible_by" } }
);
Search the subset
You can now search on the frontend using the API key generated from your backend. This API key has an embedded filter on the visible_by attribute, so you have a guarantee that the current user only sees results that they’re allowed to access.