Decisions#
The following ADRs are a record of all decisions made as a part of developing this library.
- 0001: Purpose of This Repo
- 0002: Authorization (AuthZ) Model Foundations
- 0003: JWT usage
- 0004: Authorization Technology Selection
- 0005: Architecture for Authorization (AuthZ) and Data Modeling
- 0007: Enforcement mechanisms - current user permission checks from MFEs and other remote clients
- 0008: Compatibility scheme with the current system
- 0009: AuthZ for Course Authoring Implementation Plan
- 0010: AuthZ for Course Authoring - Feature Flag Implementation Details
- 0011: AuthZ for Course Authoring - Migration Process Details
- 0012: Auditability for Authorization Changes
- 0012: Glob Support For Role Assignments
- 0013: Course Authoring - Automatic Migration Triggered by Course Authoring Flag
- 0014: Visible Role Assignment Queries Without Casbin Enforce Calls
- 0015: Expose Course-Authoring Waffle Flag State via REST API
- 0016: Keep Static and Dynamic Roles Separate
- 0017: Define Static Roles and Permissions in an Authorization Schema
- 0018: Define the Authorization Schema Lifecycle
- 0019: Discover and Load Authorization Schemas During Deployment
- 0020: Translate Static Authorization Display Text Through OEP-58
- 0021: Expose Authorization Definitions Through APIs
- 0022: Defer Permission Implication and Role Inheritance
- 0023: Extend Static Roles Without Replacing Their Definitions
- 0024: API Contract for User-Grouped Role Assignments
- 0025: Track the Source of Compiled Static Authorization Definitions