Skip to content

Revisit AuthManager design #191

Description

@sunng87

Currently we have AuthManager as a basic gateway to authn and authz. In #186 , it also opens a connection between AuthManager and pg_catalog, which may block #189 .

I haven't got a clear idea for myself at what scope we have support for authn/authz in this library. This ideal situation is user can bring their own StartupHandler for authn, while use a decorator or interceptor for query handlers to archive authz. This approach will discouple auth concept completely from this library so we can make this library solid and generic enough for its core features.

Let me know about your ideas.

Activity

  1. mjgarton commented on Sep 26, 2025

    @mjgarton
    Collaborator

    When I implemented #186 I only connected it with AuthManager because I noticed AuthManager was there already. The roles table implementation could have that connection removed and be made simpler and more hard coded for now if it unblocks #189. We can make it better again later.

    I personally don't use the AuthManager capabilities, so I don't have a strong view about how that should work, but decoupling it completely from this library seems sensible.

  2. sunng87 commented on Sep 26, 2025

    @sunng87
    MemberAuthor

    My quick idea is to define a trait say ContextDataProvider for pg_catalog, which can provide roles for pg_roles. We will also use current AuthManager as an implementation.

  3. added a commit that references this issue on Dec 16, 2025
    690a499
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions