TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Evolving to Enterprise-Grade Permissions

26 pointsby sajithwalmost 6 years ago

3 comments

yodonalmost 6 years ago
At the risk of making sweeping generalizations, the people who build permission systems tend to be very different from the people who sit at a desk and set permissions for people.<p>Those who build permission systems commonly think very deeply about the process and can hold tremendously complex permission systems in their head. The people who are tasked with setting permissions in the real world tend to view anything else as a more important part of their job to think about and tend to default to either granting permissions broadly so they aren&#x27;t bothered again or granting permissions minimally so they aren&#x27;t blamed for things.<p>A small number of well designed and well named roles is unfortunately commonly better in practice than a highly powerful and flexible fully configurable turing complete granular permissions management system.
评论 #20179742 未加载
评论 #20179781 未加载
fabian2kalmost 6 years ago
The reasoning about only allowing additive permission is something I&#x27;ve had pretty strong opinions, and it&#x27;s nice to see that other people agree with this. Permissions gets incredibly complicated very fast even in the best case, and any additional complexity can easily confuse users.<p>Their use case feels a bit too micro-managed for my taste, but that is certainly a matter of opinion. And if their customers demand this, it&#x27;s hard to convince them otherwise. My preference is to handle certain more subtle cases like their &quot;only DNA design team can edit sequences, but Research team can edit metadata&quot; as a convention, not a hard rule enforced by the application. And if you have a good history of changes, it still allows for transparency about who edited what.
flevoursalmost 6 years ago
Interesting article and really close to what we’ll need to do at my company soon!<p>I wonder if there are any open-source projects that operate in this realm and provide an off the shelf solution to this.<p>I’m thinking that it could be something like a small server to store the policies and a few libs in various languages to interpret them.<p>This could or could not be tied to a user management system.
评论 #20178863 未加载
评论 #20178851 未加载