# Disallowing writes to default graph

**URL:** <https://community.stardog.com/t/disallowing-writes-to-default-graph/3583>\
**Category:** Support\
**Created:** [February 21, 2022, 12:56pm UTC](https://community.stardog.com/t/disallowing-writes-to-default-graph/3583 "2022-02-21T12:56:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rca](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.stardog.com/rca/32/1139_2.png) [@rca](https://community.stardog.com/u/rca)\
**Post date:** [February 21, 2022, 12:56pm UTC](https://community.stardog.com/t/disallowing-writes-to-default-graph/3583/1 "2022-02-21T12:56:05Z")

</div>

We're trying to set up a database so that users can write only to specific named graphs, not the default graph. We're not having much luck.

With permissions like this:

```auto
+---------------+-------------------+-------------+
| Resource Type | Resource Name | Permissions |
+---------------+-------------------+-------------+
| db | SBAR-593 | --R---- |
| metadata | SBAR-593 | ---W--- |
| named-graph | messages | --RW--- |
+---------------+-------------------+-------------+

```

Trying to insert something:

```nohighlight
PREFIX dc: <http://purl.org/dc/elements/1.1/>
PREFIX ns: <http://SBAR-593/ns#>

INSERT DATA
{ GRAPH ns:messages { <http://SBAR-593/message2> ns:title "The Hitchhiker's Guide to the Galaxy" }} 

```

Fails with "User does not have write permissions for the index. User identification "SBAR-593"; index name "SBAR-593". Giving the user write on SBAR-593 will make the insert succeed, but this is not what we want.

Can we not prevent writes to the default graph while only granting them on specific named graphs?

---

<div class="post-metadata">

**Author:** ![rca](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.stardog.com/rca/32/1139_2.png) [@rca](https://community.stardog.com/u/rca)\
**Post date:** [February 23, 2022, 1:52pm UTC](https://community.stardog.com/t/disallowing-writes-to-default-graph/3583/2 "2022-02-23T13:52:56Z")

</div>

Just FYI, I've also opened this as a support case with Stardog after posting here. I'll post the solution as well once there is one (it could be that we misunderstood the security model).

---

<div class="post-metadata">

**Author:** ![PaulJackson](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.stardog.com/pauljackson/32/243_2.png) [@PaulJackson](https://community.stardog.com/u/PaulJackson)\
**Post date:** [February 24, 2022, 5:20pm UTC](https://community.stardog.com/t/disallowing-writes-to-default-graph/3583/3 "2022-02-24T17:20:59Z")

</div>

Sounds like you want [named graph security](https://docs.stardog.com/operating-stardog/security/named-graph-security).

You could grant write access to only specific named graphs or to `tag:stardog:api:context:named` which includes everything but the default graph (`tag:stardog:api:context:default`).

-Paul

---

<div class="post-metadata">

**Author:** ![rca](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.stardog.com/rca/32/1139_2.png) [@rca](https://community.stardog.com/u/rca)\
**Post date:** [February 28, 2022, 7:36am UTC](https://community.stardog.com/t/disallowing-writes-to-default-graph/3583/4 "2022-02-28T07:36:29Z")

</div>

Thanks, we do have named graph security enabled but I was told `security.named.graphs.empty.allows.access` needs to be disabled for this to prevent writes to the default graph. I might be able to try this today and I can report if it works in this constellation.

---

<div class="post-metadata">

**Author:** ![rca](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.stardog.com/rca/32/1139_2.png) [@rca](https://community.stardog.com/u/rca)\
**Post date:** [March 1, 2022, 8:13am UTC](https://community.stardog.com/t/disallowing-writes-to-default-graph/3583/5 "2022-03-01T08:13:38Z")

</div>

The trick is indeed:

- `security.named.graphs.empty.allows.access` needs to be `false`
- The user needs write permission on the database and any relevant named graphs

This way, writes to the default graph will be rejected. It seems `security.named.graphs.empty.allows.access` is an undocumented option, I think it would be good to document it so this behavior becomes clearer.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex030/uploads/stardog/original/2X/e/ed66b48a616f505106a4acde3c9cee7e6da9bc67.svg) [@system](https://community.stardog.com/u/system)\
**Post date:** [March 15, 2022, 8:14am UTC](https://community.stardog.com/t/disallowing-writes-to-default-graph/3583/6 "2022-03-15T08:14:33Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
