4 ms·
One point I haven't seen covered is complexity. Carta seems to have an extremely complex authorization scheme but I wouldn't say that's the common case. Many o
by somethingAlex 5y ago
One point I haven't seen covered is complexity.
Carta seems to have an extremely complex authorization scheme but I wouldn't say that's the common case. Many organizations can get by using simple role + account based permissions.
If you are a member of this account then you have access to the resources this account owns minus anything you can't access because you don't have role X or Y. Oftentimes the account based permissions boil down to where clauses in SQL statements. The role based permissions can be mapped to scopes in a JWT or similar.
Anything beyond that can be done with if statements in your "parse user input" function or simply caught later on resulting in a 4XX error.
I know at my particular organization, even when we have cross-account sharing, it's heuristic based. It's simple enough to just apply it in the application code. Stuff like "did this user's organization receive this shipment?"
I feel like you have to be either a very large organization trying to make sure people do things consistently or have a very, very granular permissions model to even embark on making the decision of "build a whole authorization product in house or outsource it?"
- somethingAlex 5y agoEDIT: the last sentence refers to the context of authorization systems. Not completely in general.