4 ms·
Lately I am thinking about building a framework for web APIs where the database stores the owner, group and other's rights for each entity. The framework will t
by thdrdt 6y ago
Lately I am thinking about building a framework for web APIs where the database stores the owner, group and other's rights for each entity. The framework will then fetch data based on the user and fills the models based on the rights set for each field.
Exactly for the reason shown in the article.
I believe right now it is still too difficult to do this in any framework. That's why developers take shortcuts and just expose all entity data or just make a mistake and forget about it.
Does anyone know if such a framework already exists? So per field rights, not per entity rights.
- throwawaynothx 6y agoor... GraphQL.
- thdrdt 6y agoHow does GraphQL fix the problem of showing different fields depending on rights?
- mulmen 6y agoTake a look at Postgres roles, I think they are similar to what you describe. This should allow you to set row level permissions per user. Not sure how well that scales. I know postgrest uses it. https://www.postgresql.org/docs/12/user-manag.html https://www.postgresql.org/docs/12/user-manag.html
- efreak 6y agoI think the Windows registry has this, doesn't it? Not really applicable to this use case, and do far as I know it's world-readable (acls are applied for writing, not reading) but it does have per-key ACLs (not sure about per-field).