Redesign CouchDB security system
- Dominant language
- Erlang
- Stars
- 7k
- Forks
- 1.1k
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 9
Description
@janl:
>
> * closed by default
> * more fine-grained permissions
> * more options for delegated authentication
>
> Our security system is slowly grown and not coherently designed. We should start over. I have many ideas and opinions, but they are out of scope for this. I think everybody here agrees that we can do better. This *very likely* will *not* include per-document ACLs as per the often stated issues with that approach in our data model.
@davisp:
>Big +1 on this. The auth stuff in our code base is hard to follow and difficult to hold in my brain. Taking a step back to redesign from the ground up would be super awesome.
Contributor guide
Research direction
The issue names no files, tests, or entry points; begin by mapping CouchDB's existing security and authentication implementation. Review the goals of closed-by-default access, finer-grained permissions, and delegated authentication, while noting that per-document ACLs are out of scope. Done would require an agreed redesign scope and implementation plan.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- erlang
- Domain
- authentication, authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100