spring-projects / spring-projects/spring-security

Consider introducing a new authorization rules model

Open
#13,277 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

theme: partner-use-cases type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

We should consider introducing a new authorization rules model.

Defining the authorization rules should be simple and natural and more importantly should work with any "secured resource". The "secured resource" could be any of the following: a web endpoint, an object instance, a method on an object instance, a group of object instances, etc.

We should also ensure that other 3rd party authorization libraries/frameworks can be plugged-in as extension implementations.

Related gh-13266

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing related issue gh-13266 and the existing Spring Security authorization model. Clarify how rules should apply to each listed secured-resource type and how third-party authorization libraries could provide extension implementations; the work is done when that model and its integration boundaries are agreed.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.