Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Authorization best practice OEP needed #479

Closed
robrap opened this issue May 12, 2023 · 5 comments
Closed

Authorization best practice OEP needed #479

robrap opened this issue May 12, 2023 · 5 comments
Labels

Comments

@robrap
Copy link
Contributor

robrap commented May 12, 2023

It would be great to have an Authorization best practice OEP that works much like OEP-4: Authentication, which is less about making decisions than being an index of ADRs, documents, and introductory text regarding our Authorization best practices.

However, at this time, those best practices may be somewhat controversial because we are lacking said document. This issue can be used to collect documentation, comments, etc. regarding this topic in preparation for some future OEP.

Here is some context of what exists today:

@robrap
Copy link
Contributor Author

robrap commented Jun 1, 2023

Here is a newer Google doc on Roles and Permissions that is a WIP at this point.

@hsinkoff
Copy link
Member

Tech Spec related to the RBAC project.

@sarina sarina added the discovery Pre-work to determine if an idea is feasible label May 17, 2024
@sarina
Copy link
Contributor

sarina commented May 17, 2024

I think an Authorization OEP is a good idea, but as a project we're pretty far away from it. Adding the Discovery label to it and tagging @feanil and @ormsbee to keep in the backs of our minds as we approach the R&P work.

@robrap
Copy link
Contributor Author

robrap commented May 17, 2024

I'm not sure if 100% of this is covered, but it was already completed with this OEP: https://open-edx-proposals.readthedocs.io/en/latest/best-practices/oep-0066-bp-authorization.html

@sarina
Copy link
Contributor

sarina commented May 20, 2024

Ha! I only saw OEP-9 in the right sidebar listed as obsolete and didn't follow the link to OEP-66. Thanks Robert!

@sarina sarina closed this as completed May 20, 2024
@sarina sarina added merged and removed discovery Pre-work to determine if an idea is feasible labels May 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants