4 ms·
access_by_lua is a very nice feature. I had an idea for microservice deployments: to send all incoming requests through an authenticator script, that will veri
by rahilb 11y ago
access_by_lua is a very nice feature.
I had an idea for microservice deployments: to send all incoming requests through an authenticator script, that will verify request tokens with the auth-server, and extract the user's context to some other request parameter (e.g. custom header). The benefit would be that all microservices no longer need to worry about the authorisation of incoming requests, as this is abstracted away to nginx. In this way we know that if a request reaches the target service, it has already been authorised, thus simplifying the services and removing the dependency on the auth-server, and decreasing the burden of testing these services. It works nicely.
The (very rough) script is here: https://gist.github.com/rahilb/73362f663a028f1f986c https://gist.github.com/rahilb/73362f663a028f1f986c
- brickcap 11y agoThis is a great idea actually. I do something like that myself where I've exposed a couchdb instance publically but the access through it is controlled by access_by_lua. I use basic authentication instead of token based auth but the principle is the same.
- awinder 11y agoRight on. I've implemented that sort of pattern in a couple of jobs in the last few years and its seemed to work out well. The abstraction between 1 piece of code needing to know & understand oauth vs. every piece of code is a total win in my book.
- onetwotree 11y agoSee my toplevel post. Our customers love using `access_by_lua` to delegate authentication and authorization to our service. Obviously you can use your own authorization and and access control to accomplish the same thing, in the same way.