Skip to content

Allow finer grained authorization #5

Description

@darioteixeira

Presently, RIP accepts the definition of an authorize function per service. This is not granular enough, as some services may allow public access to read-only methods like GET while requiring the enforcement of stricter authorization for methods like POST or PUT.

We should keep the service-wide authorize function as fallback, but allow also the definition of custom authorization functions for particular methods.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions