been thinking about how to selectively declare access control policies as granular and as narrow as a single fact, wish i had an answer

read an article that basically concluded the document centric model and rest architecture is insufficient for this unless you put one fact per document which is patently ridiculous

the other thing is where to even put those documents. some resources ought to be dynamic views, or possibly all documents can be thought of as views but to some extent hardcoded

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/trwnh/statuses/114271826407920893 on your instance and quote it. (Note that quoting is not supported in Mastodon.)