Похожие чаты

Hello, i was wondering what is the advantage of using

casbin-auth (RBAC) over a naive implementation ? right now i'm sending a string to each handler and simply compare it to users role

4 ответов

13 просмотров

If it feels too naive then you can use Okta

mohammad- Автор вопроса
сумбула
If it feels too naive then you can use Okta

sorry but this isn't really an answer to my question, okta is just another library like casbin(probably except that casbin is just authorization , not authentication), my question is why would i want to use an authorization library ?

mohammad
sorry but this isn't really an answer to my questi...

Your application might be used by various roles such as admin, super admin, customer, boss etc. Customer shouldn't be able to use apis of admins. To provide this you need to come up with role based authorization. In that case libraries like casbin, okta can help you. If you don't want to use any of them, you can create your own role checker

mohammad- Автор вопроса
сумбула
Your application might be used by various roles su...

thanks again, but still not the answer, i know what role based access control is and why it is used. let me give an example on what i want to know , so instead of authorization , let's say authentication , i can surely implement authentication myself, but sometimes there are some tricky points that i might miss , for example storing password in plain text in database, just a silly example, it's possible that authentication libraries would take care of that now , what problems can a authorization library solve compared to just comparing user role with a string ?

Похожие вопросы

Обсуждают сегодня

А кто-то пробовал, уезжая из Эстонии получить э-рез и продолжить вести предпринимательскую деятельность внутри Эстонии, используя свой OÜ?
Lalalashechki Lalala
62
At which price point will BCH, an ASIC mined coin, be succeptible to reorg attacks because of low hashrate? $10? $1? $0.1? $0.01?
Kishniev
18
Is Kadena onto something special? No one really knows. Good luck!
Bright Uncle Stephen EqualBet
40
зачем же переименовывать ? чтобы кол-во участников возросло или вдруг IBM от этого снова на свифте начнет кодить ? Я не понимаю что страшного в том что свифт гавно, если это т...
Oleh Nerzh
10
Гайз, кто-нибудь пробовал запустить probe-rs под камень, которого нет в probe-rs? Мб есть какой-нибудь пример у кого... Через target-gen попробовал сгенерировать chip-descript...
Максим Смирнов
2
я не магистр хаскеля, но разве не может лейзи тип конвертнуться в не-лейзи запросив вычисление содержимого прям при инициализации?
deadgnom32 λ madao
100
здравствуйте. совершаю вот такую вещь: strcpy(line, (char)current_number); где current number — неподписанный шорт, line — массив чаров. ругань следующая: main.c:29:30: error...
Roberto's Ширгозиев
13
I hodl ocean for a long time. Is there new development that I should read?
A33
9
Hello VIC team, I had previously used the “wallet.tomochain.com” with a ledger connection. Unfortunately, the site is no longer accessible and the ledger account is not visibl...
carpe noctem
7
How is any merchant expected to know where his customers' money comes from? Surely criminals may give cash to their wife to go to the grocery store
Maybe
8
Карта сайта