-
Notifications
You must be signed in to change notification settings - Fork 35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Authorization best practice OEP needed #479
Comments
Here is a newer Google doc on Roles and Permissions that is a WIP at this point. |
Tech Spec related to the RBAC project. |
I'm not sure if 100% of this is covered, but it was already completed with this OEP: https://open-edx-proposals.readthedocs.io/en/latest/best-practices/oep-0066-bp-authorization.html |
Ha! I only saw OEP-9 in the right sidebar listed as obsolete and didn't follow the link to OEP-66. Thanks Robert! |
It would be great to have an Authorization best practice OEP that works much like OEP-4: Authentication, which is less about making decisions than being an index of ADRs, documents, and introductory text regarding our Authorization best practices.
However, at this time, those best practices may be somewhat controversial because we are lacking said document. This issue can be used to collect documentation, comments, etc. regarding this topic in preparation for some future OEP.
Here is some context of what exists today:
edx-rbac
.Provisional
status to show something aspirational.The text was updated successfully, but these errors were encountered: