openfga / roadmap

OpenFGA Public Roadmap
2 stars 0 forks source link

Additional OpenFGA API Authorization Options #30

Open aaguiarz opened 1 year ago

aaguiarz commented 1 year ago

OpenFGA currently supports pre-shared keys and OIDC for authenticating calls to the APIs. Those credentials are global, and allow performing any action in any store.

We want to provide more granularity for authorizing calls to the OpenFGA API. Some scenarios:

This RFC discusses different alternatives in more depth https://github.com/openfga/rfcs/pull/10

cafaray commented 6 months ago

[Possible Typo] Should it be: "OpenFGA currently supports pre-shared keys and OIDC for authenticating calls to the APIs" Current: "OpenFGA currently supports pre-shared keys and ODIC for authenticating calls to the APIs"

tylernix commented 6 months ago

[Possible Typo] Should it be: "OpenFGA currently supports pre-shared keys and OIDC for authenticating calls to the APIs" Current: "OpenFGA currently supports pre-shared keys and ODIC for authenticating calls to the APIs"

Thank you @cafaray. Fixed.

jakeyheath commented 2 months ago

If there is any desire to have help implementing this feature, my team would love to volunteer! Not sure how far along the RFC process has progressed, but if you have guidance on how to contribute back here, please reach out.