spinframework / spinframework/spin
Authorization for Spin components
Open
Nobody has claimed this yet.
documentation
enhancement
- Dominant language
- Rust
- Stars
- 6.5k
- Forks
- 310
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 24
Description
Currently, there is no concept of authorization in Spin.
A component is invoked whenever its trigger receives a request, and at no point is checked where the event is coming from, or who generated it.
How should this work?
cc @fibonacci1729
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are identified; begin by clarifying the authorization model for requests reaching Spin components. Done would require an agreed design for checking where events come from and who generated them.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust, wasm
- Domain
- authorization
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100