Discussion about this post

User's avatar
Tariq Shaikh's avatar

Great article. Any particular reason you did not select a well known policy language like opa, alfa/xacml, cedar, etc.. OR better still a graph db to authorize access. The logic above kinda implies a graph anyway.

Nipun's avatar

I had a question:

The article says, the performance remained excellent but previously without ABAC, the authorization decisions were made locally within each service but later, it required attribute fetching which would require calls to Service DataSource for fetching it, then how did the performance remain almost same? Before implementing this, how did you estimate the performance effect of attribute fetching?

No posts

Ready for more?