apache / apache/couchdb

Redesign CouchDB security system

Open
#1,504 3 comments 0 reactions 0 assignees View on GitHub
enhancement roadmap security
Dominant language
Erlang
Stars
7k
Forks
1.1k
Avg merge
1d 16h
Merged PRs (30d)
9

Description

@janl:
>
> * closed by default
> * more fine-grained permissions
> * more options for delegated authentication
>
> Our security system is slowly grown and not coherently designed. We should start over. I have many ideas and opinions, but they are out of scope for this. I think everybody here agrees that we can do better. This *very likely* will *not* include per-document ACLs as per the often stated issues with that approach in our data model.

@davisp:
>Big +1 on this. The auth stuff in our code base is hard to follow and difficult to hold in my brain. Taking a step back to redesign from the ground up would be super awesome.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points; begin by mapping CouchDB's existing security and authentication implementation. Review the goals of closed-by-default access, finer-grained permissions, and delegated authentication, while noting that per-document ACLs are out of scope. Done would require an agreed redesign scope and implementation plan.

Written by the indexing model from the issue text.

Assessment

Tech stack
erlang
Domain
authentication, authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.