3 ms·
> What aspect of this makes it "highly scalable"? The idea is to put all data in one place, and then aggressively optimise for answering queries about that dat
by samjs 5y ago
> What aspect of this makes it "highly scalable"?
The idea is to put all data in one place, and then aggressively optimise for answering queries about that data. For authorization you're pretty much always asking specific reachability questions. That's where the design of the index comes into it.
> Also, I was wondering: Are ALL permissions stored as an Object::relation pair? i.e. do you need to register permissions for all new entities relationships, or do you have some way of storing more dynamic permissions?
In Zanzibar, there is a configuration format for computing relationships dynamically. E.g. "anyone who is an editor of a document is a viewer of a document". I'm not sure if they implemented something like that.
If you're interested, I wrote a guide on relationship-based access control that includes a section on how Zanzibar(-like) systems fit in: https://www.osohq.com/academy/authorization-academy-chapter-4-modeling-relationships https://www.osohq.com/academy/authorization-academy-chapter-...