Stateful authorization is an anti-pattern Guest post by Alex Olivier, Product Lead at Cerbos. The state involved is about the principal (usually a user, but could be a machine-token, service account, or any other identity) and the resource being accessed. For both of these, there is a unique ID and attributes.

4m read time From cncf.io
Post cover image
Table of contents
Stateful authorizationStateless authorization

Sort: