3 ms·
(Full transparency: I'm CTO/cofounder of Oso, a series A startup building an open source framework for authorization) Super interesting how many companies are
by samjs 5y ago
(Full transparency: I'm CTO/cofounder of Oso, a series A startup building an open source framework for authorization)
Super interesting how many companies are building authorization systems based on Zanzibar suddenly! This is a bit of a shameless plug, but I just wrote a blog post earlier today talking through how to build Zanzibar from scratch in ~150 lines of code: https://news.ycombinator.com/item?id=28076549 https://news.ycombinator.com/item?id=28076549
Not many people talk about how Zanzibar requires you re-architect your application around authorization when you really don't need to do that at all. Any sufficiently powerful authorization framework can handle the same flexibility. If not more, since most Zanzibar implementations can't handle simple attribute-based controls (e.g. anyone can read a document if its public). Which means you'll end up implementing a bunch of authorization logic in your app anyway.
---
Edit to add: I realise in hindsight I got a bit too absorbed in thinking about the Zanzibar part to say congrats on the launch! It's awesome to see the space heating up, and love to see more focus on the developer experience :)
- kkajla 5y agoThanks for the response! It is interesting to see the surge in popularity of Zanzibar. Completely agree that Zanzibar itself isn't too difficult to implement (especially since Google published a paper on it). It does provide great flexibility though. I don't agree with your point that it requires developers to re-architect their systems or that it doesn't handle attribute-based controls well. If anything, I think Zanzibar actually helps developers enforce the best authz practices in their system. This becomes increasingly helpful as an application changes or grows in complexity. To be clear, Warrant isn't just a Zanzibar implementation. We're building Authz as a service with devxp as the central focus.
- samjs 5y agoYeah, to be clear I think the Zanzibar authorization model is great! Super helpful to think about authorization logic in terms of relationships. To give a simple example of an attribute-based control that is tough with the service model: if you want to express "anybody can read a document if it's public", then you need to push that "public" field into the service. Every attribute that you want to use for authorization becomes something that you need to either move or synchronise into the service. Or you leave that logic in the application.