Clarify DB security requirements
Open
prc
task
- Dominant language
- HTML
- Stars
- 25
- Forks
- 14
- PR merge metrics
- No merged PRs in 30d
Description
In the docs and [PRC report](https://docs.google.com/document/d/1VP7sLqijKvaEraVEAZrxQAa-3VP--AETeWOV5g7-s6U/edit?pli=1#):
> Using Search to give low-level access to a database as a data layer for high-level tools is only going to be scalable (in terms of number of high-level tools)and only feasible for federation atop if database security is handled at low levels, and is not the responsibility of each of the high-level services atop. What is the security model for, e.g., the database contains data from multiple datasets only one of which the requester has access to? How is that handled by a Search implementation? Needs clarification.
Contributor guide
Assessment
This issue has not been assessed yet.