5 ms·
Unless you happen to be using PostgreSQL, in which case some tools like Hasura and Graphile can automate all of that.
by rlili 4y ago
Unless you happen to be using PostgreSQL, in which case some tools like Hasura and Graphile can automate all of that.
- deleted 4y ago[deleted]
- criddell 4y agoI’ve never used those tools, but I don’t see how you can automate away authorization issues. The GraphQL spec[1] says authorization in the GraphQL layer is fine for prototyping or toy programs, but for a production system it needs to be in the business logic layer. [1]: https://graphql.org/learn/authorization/ https://graphql.org/learn/authorization/
- gavinray 4y agoIn Hasura, you authenticate externally -- can be custom API endpoint that signs a JWT/auth webhook, or an auth provider like Auth0, Okta, Firebase, Keycloak, etc. Doesn't matter, just have to return some claims values. You can then use these claims values in your authorization (permissions) layer. IE, when a user logs in, you can sign a claim with "X-Hasura-User-ID" = 1, and "X-Hasura-Org-ID" = 5, and then put rules on tables like: > "Role USER can SELECT rows in table 'user' WHEN X-Hasura-User-ID = user.id" > "Role USER can SELECT rows in table 'organization' WHEN X-Hasura-Org-Id = organization.id" There's more depth to it than this, but this is the gist of it.
- pycal 4y agothis is really powerful stuff when working with a CISO “the data itself defines who may access it”
- golergka 4y agoYou just handle this part my your code and leave the rest to Hasura.
- RedShift1 4y agoPostgreSQL and other databases have fine grained authorization controls down to the column level, what more does one need?
- jseban 4y agoYeah this must be one of the most underused features ever. People don't realise that you can solve little bobby tables by just setting the permissions correctly in the database.
- littlecranky67 4y agoYou cannot model every business constraint in DB permissions; Stuff like "If customer X has less than 3 active contracts, new contract activations require sign-off of Manager of at least level Y" etc.
- RedShift1 4y agoThat can absolutely be done via triggers or limit access by using functions for certain operations instead of direct table access
- littlecranky67 4y agoAnd how do you unit test triggers? Yes you can do it in a ton of ways, but you just end up scattering your business layer all over the database, the GraphQL adapter, API gateways etc. The alternative is just to create a dedicated BE service endpoint (in whatever you prefer, REST,HTTP/JSON,SOAP, gRPC etc.), which does the required checks for you. Triggers, functions or whatever you use are just code; yes, that is my pitch: Have your buisness logic in code, ideally in a dedicated BE API endpoint instead in the DB.
- criddell 4y agoThat’s the path I ended up taking. The GraphQL resolvers had no idea idea there was a database. They talked to a layer that understood all the business objects and that sat on top of a layer that understood authorization and only that layer had any connection to the data store.
- pier25 4y agoAnd now you're adding an extra layer you don't control with its own set of problems.
- underbluewaters 4y agoUsing postgraphile for my current big project is the best technical choice I've ever made. There's been the occasional obscure sql incantation to learn but otherwise has been so much more productive than hand-crafting REST endpoints.