Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
samjs
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
samjs
5y ago
Well this was fun to see! I'm the CTO of Oso, where we're building Polar (the second of the links mentioned https://docs.osohq.com/ ). I have a few really minor nitpicks, so will try and make up for it by adding to
32.
▲
by
samjs
5y ago
Thank you! We're looking forward to sharing more about Oso cloud too :)
33.
▲
by
samjs
5y ago
Indeed ;) https://news.ycombinator.com/item?id=28559608
34.
▲
by
samjs
5y ago
It's actually a pretty great question! As others have mentioned, authorization often requires both a single method to authorize "can the user perform this action on this resource" as well as more flexible versions like "
35.
▲
Building a runtime reflection system for Rust
(osohq.com)
9 points
by
samjs
5y ago
|
0 comments
36.
▲
by
samjs
5y ago
If you're interested in resource-based rbac [1] with list endpoints [2], Oso supports both! You're right, it's a tough problem, we've invested a ton of time to make this work well without needing to rearchitect your app.
37.
▲
by
samjs
5y ago
Oh, and if you’d be up for sharing any more info on how authorization _is_ done at fb, I’d love to chat. Email is in my profile :)
38.
▲
by
samjs
5y ago
Hey! Thanks for the correction. I’ll get on updating that.
39.
▲
by
samjs
5y ago
Hey! Yep, you can totally use a policy engine like XACML or OPA with Zanzibar. We talk about that a little further down in the post. The "public" example was meant to be a simple example of attribute-based access control but you c
40.
▲
by
samjs
5y ago
Thank you! You might also enjoy the series we've been writing, Authorization Academy: https://www.osohq.com/developers/authorization-academy It builds up a bit more gently and introduces a lot more concepts than I
41.
▲
by
samjs
5y ago
Thanks! I'll pass it on to the team :D I've got to say, the folks at Intercom made it particularly fun. They were sending us traces and graphs from their internal systems when we trying to figure out some issues with them (e.g. we
42.
▲
Why Authorization Is Hard
(osohq.com)
303 points
by
samjs
5y ago
|
49 comments
43.
▲
by
samjs
5y ago
Thank you! Pundit is awesome, they did such a great job with it and we drew a lot of inspiration from it. We're heavily focusing on adoption of the open source product right now for helping developers with application authorization. We
44.
▲
by
samjs
5y ago
Yeah, to be clear I think the Zanzibar authorization model is great! Super helpful to think about authorization logic in terms of relationships. To give a simple example of an attribute-based control that is tough with the service model: if
45.
▲
by
samjs
5y ago
As a founder of a startup building an authorization product, I can definitely say it's super appealing to build this as a service! It makes for a an easier story around monetising it. When we were building Oso [1], we were optimising f
46.
▲
by
samjs
5y ago
(Full transparency: I'm CTO/cofounder of Oso, a series A startup building an open source framework for authorization) Super interesting how many companies are building authorization systems based on Zanzibar suddenly! This is a bi
47.
▲
Building Google Zanzibar from Scratch
(osohq.com)
10 points
by
samjs
5y ago
|
0 comments
48.
▲
by
samjs
5y ago
> It's crazy this still is part of the stack where there are no great solutions. Seems like a few others have come to the same conclusion :) We're working on this at Oso ( https://osohq.com ) - I'm the CTO. Oso i
49.
▲
by
samjs
5y ago
> What aspect of this makes it "highly scalable"? The idea is to put all data in one place, and then aggressively optimise for answering queries about that data. For authorization you're pretty much always asking specific
50.
▲
by
samjs
5y ago
<3 Thank you!
51.
▲
by
samjs
5y ago
I've been writing about application authorization here: https://www.osohq.com/academy/chapter-2-architecture (I'm CTO at Oso, but these guides are not Oso specific). It covers this in the later part of the gu
52.
▲
by
samjs
5y ago
Thank you for the kind words! I'm pretty sure I know who you are in the slack, so I'll follow up with you there about the blog post :)
53.
▲
Show HN: Authorization Academy – guides for building application authorization
(osohq.com)
15 points
by
samjs
5y ago
|
3 comments
54.
▲
by
samjs
5y ago
Hi HN! I'm one of the founders of Oso, an open source library for authorization (someone posted us here a little while ago: https://news.ycombinator.com/item?id=25440741 ). Over time, we've gotten a lot of question
55.
▲
by
samjs
6y ago
> But authorization is rather tightly coupled to your service, and outsourcing that part would be much more of a challenge -- keeping authorization rules up-to-date with external systems is a difficult dependency management problem. Stro
56.
▲
by
samjs
6y ago
My colleague pointed out that we do actually already include the dynamic libs as part of the release artifacts: https://github.com/osohq/oso/releases/tag/v0.9.0 However, without the header file right now
57.
▲
by
samjs
6y ago
Hey Rongxin! Thanks :) It's been a fun ride. I'm going to drop you a message, it's been far too long...
58.
▲
by
samjs
6y ago
> It would be great if that was provided and had a stable ABI + .so for the rust code that I could install through a .deb or .rpm instead of building through cargo. This would be a great option. That's effectively how our build pipe
59.
▲
by
samjs
6y ago
No problem! These are fantastic questions. Agreed! And I strongly recommend to anyone thinking about doing so to join our slack [1] and come chat with us :) We'll be happy to share our thoughts on this. All these questions are also tem
60.
▲
by
samjs
6y ago
Hey! oso CTO here. Thanks for giving it a try! Were you using this in a Rust project, or building it from scratch for some other language? For the latter, we do provide libraries for Python, Ruby, Java, Nodejs with the Rust core precompiled
More ›