4 ms·
Does anyone have a great example of an app that just has sane AuthN and AuthZ examples with users and some sort of basic crud operations? I've been working prof
by _virtu 9y ago
Does anyone have a great example of an app that just has sane AuthN and AuthZ examples with users and some sort of basic crud operations? I've been working professionally as a software engineer for five years and of the two companies I've worked at, the user role checking was custome roled and spread all throughout the stack. I feel like I've never seen a good example of something like this that's more complex than just user can or cannot edit. Something that entails groups and read/write permissions on those groups for userse. Right now, I'm working on an Elixir API, but it seems like most of the user role checking and builtins are all meant for AIO webapps instead of APIs.
- sk5t 9y agoIt sounds like you're thinking of proper object ACLs, which get pretty complex quickly--see Spring domain object security, Windows / NTFS / Active Directory DACLs, or the often-challenging permission system in AWS. These draw in some common ideas like having a taxonomy to identify the principal and security context, the target of the operation, the operation itself, the object's security parent, whether or not ACEs can be inherited from the parent, and whether to audit success and/or failure conditions.
- deoxxa 9y agoAhhh. That rabbit hole is deep. Buckle up if you're going in because it starts ugly and gets worse. I've spent quite some time exploring the caverns of XACML (eXtensible Access Control Markup Language), even going so far as writing a limited implementation of it in JavaScript. It's infinitely flexible, extremely capable, horrendously complex, and just about the least fun standard to work with. Sure as heck gets the job done though. Just get yourself used to writing and debugging XML and you'll be fine. I've also looked in great detail at Amazon's IAM policies. These are significantly simpler, and heavily inspired my current favourite library, ladon [1]. I recently wrote a GraphQL API and I found that GraphQL mutations and field accesses mapped nicely to policies in ladon. [1]: https://github.com/ory/ladon https://github.com/ory/ladon