Skip to Content
API Security in Action
book

API Security in Action

by Neil Madden
January 2021
Intermediate to advanced
576 pages
18h 9m
English
Manning Publications
Content preview from API Security in Action

8 Identity-based access control

This chapter covers

  • Organizing users into groups
  • Simplifying permissions with role-based access control
  • Implementing more complex policies with attribute-based access control
  • Centralizing policy management with a policy engine

As Natter has grown, the number of access control list (ACL; chapter 3) entries has grown too. ACLs are simple, but as the number of users and objects that can be accessed through an API grows, the number of ACL entries grows along with them. If you have a million users and a million objects, then in the worst case you could end up with a billion ACL entries listing the individual permissions of each user for each object. Though that approach can work with fewer users, it becomes more ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Advanced API Security: OAuth 2.0 and Beyond

Advanced API Security: OAuth 2.0 and Beyond

Prabath Siriwardena
Logging in Action

Logging in Action

Phil Wilkins

Publisher Resources

ISBN: 9781617296024Supplemental ContentPublisher SupportOtherPublisher WebsiteSupplemental ContentPurchase Link