braunse

braunse

Hi ElixirForum,

I was looking for a library to help me implement authorization in a principled way, and looking around, I liked the simplicity of authorize, but I wanted to try out my own variation on the theme.

So yesterday I published auval_office, a flexible AUthorization policy eVALuator.

What’s in the box?

When you define a policy module like this:

defmodule My.Policy
  use AuvalOffice.Policy

  rule ...
  rule ...
  rule ...
end

then auval_office will augment your policy with an authorize function:

case My.Policy.authorize(subject, object, action) do
  {:ok, rule_id, parameters} -> # allowed
  {:error, rule_id, parameters} -> # not allowed
end

What’s different from other authorization packages?

  • auval_office is self-contained.

    It has no dependency on phoenix or ecto. It includes no plug for your web pipeline. You decide if authorization should be a domain responsiblity or a web layer responsibility, and where authorization-related data should be stored.

  • auval_office does not favor one access control model.

    It is flexible enough to implement lots of different access-control schemes, but favors none of them. I believe it offers enough flexibility to implement Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC) and Access Control Lists (ACLs), and combinations of those models.

  • auval_office justifies its decisions.

    The return value of the authorize function includes the ID of the rule that made the decision, and you can return parameters from the rule to augment that information. This enables the user to build historical audit trails, answering questions like “Who changed that data, and why was that allowed at the time?”

  • auval_office can consider context.

    The authorize function has an optional context parameter, where you can provide a map of additional information items to consider when making an authorization decision:

    My.Policy.authorizer(subject, object, action, %{moon_in_house: :seventh})
    

    auval_office also includes a fetcher facility, that enables you to fetch necessary context values at authorization time. Just include a fetch in your policy:

    defmodule My.Policy do
      use AuvalOffice.Policy
    
      fetch :fetch_user_group_memberships, :groups, subject: %User{id: id} do
        groups = Accounts.get_groups_by_user_id(id)
        {:ok, groups}
      end
    
      rule ...
    end
    

    Before evaluating the policy, auval_office will check if a :groups item is present in the context, and if not, will call the fetcher you defined to add the :groups to the context.

Links

Where Next? Top

Trending in Announcing Top

woylie
Flop is an Elixir library that applies filtering, ordering and pagination parameters to your Ecto queries. offset-based pagination with...
New
MRdotB
I needed to reuse React components from my Chrome extension in my Phoenix/LiveView backend. I noticed that for Svelte/Vue, there are live...
New
woylie
I released Doggo, a collection of unstyled Phoenix components. https://github.com/woylie/doggo Features Unstyled Phoenix components....
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
anuaralfetahe
Hello Published a new library - ProcessHub! ProcessHub is a library designed to manage process distribution within the Elixir cluster. ...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New

Other Trending Topics Top

mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
webofbits
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself. My main conc...
#ai
New
sergio
It’s not that it’s vocabulary is too advanced. It’s something worse. I get lost trying to follow even a paragraph written by Claude. It’...
New
AstonJ
This showed up on my feed.. anyone heard of it? Just hype? Ox Alpha is a reasoning model designed for coding, sustained ag...
New
bartblast
Hey folks, I just published a post about Hologram’s funding and where the project goes next - the short version: Curiosum as Main Spons...
New
sorenone
Today we’re releasing Oban for Python. Not an Oban client in Python. Not a pythonx wrapper embedded in Elixir. Nope, it’s a fully operati...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews