Jonathan Hope
12/12/2022, 9:27 PMJoey
12/12/2022, 9:29 PMread_all_resources
is "simple" (no intersections or exclusions or caveats), the LR should be (fairly) performant with the single batched hopJoey
12/12/2022, 9:29 PMCheckPermission
if the user is a platform admin and, if so, just list all resources directlyJoey
12/12/2022, 9:30 PMplatform
or resources will be distributed amongst those `platform`'s?Jonathan Hope
12/12/2022, 9:33 PMJoey
12/12/2022, 9:35 PMJoey
12/12/2022, 9:35 PMJonathan Hope
12/12/2022, 9:35 PMJoey
12/12/2022, 9:41 PMJonathan Hope
12/12/2022, 9:45 PMJonathan Hope
12/13/2022, 5:01 PMJoey
12/13/2022, 5:02 PMJonathan Hope
12/13/2022, 5:08 PMyetitwo
12/13/2022, 5:44 PMyetitwo
12/13/2022, 5:45 PMyetitwo
12/13/2022, 5:45 PMJoey
12/13/2022, 5:50 PMdefinition role {
permission can_modify = ...
}
Joey
12/13/2022, 5:51 PMJoey
12/13/2022, 5:51 PMyetitwo
12/13/2022, 5:51 PMyetitwo
12/13/2022, 5:52 PMJoey
12/13/2022, 5:52 PMyetitwo
12/13/2022, 5:52 PMJoey
12/13/2022, 5:52 PMyetitwo
12/13/2022, 5:52 PMJoey
12/13/2022, 5:52 PMJoey
12/13/2022, 5:52 PMcheck role:somerole can_modify user:whatever
yetitwo
12/13/2022, 5:53 PMyetitwo
12/13/2022, 5:53 PMowner
which is created when the role is created?Joey
12/13/2022, 5:53 PM