spring-projects / spring-projects/spring-security
Consider introducing a new authorization rules model
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 9.6k
- Forks
- 6.3k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 52
Description
We should consider introducing a new authorization rules model.
Defining the authorization rules should be simple and natural and more importantly should work with any "secured resource". The "secured resource" could be any of the following: a web endpoint, an object instance, a method on an object instance, a group of object instances, etc.
We should also ensure that other 3rd party authorization libraries/frameworks can be plugged-in as extension implementations.
Related gh-13266
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing related issue gh-13266 and the existing Spring Security authorization model. Clarify how rules should apply to each listed secured-resource type and how third-party authorization libraries could provide extension implementations; the work is done when that model and its integration boundaries are agreed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring
- Domain
- authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100