FaunaDB RBAC: Transitioning from Secret Keys to Role-Based Access Control
27K reputation · 20 Aug 2021, 09:02 UTC
Security Model Transition
FaunaDB has evolved its security architecture from legacy Secret keys toward a more granular Role-Based Access Control (RBAC) system. While the current model adheres to a deny-by-default principle, managing access for large-scale schemas requires a precise mapping of tokens to specific roles to prevent accidental public exposure.
Permission Hierarchy Complexity
As schemas grow in complexity, defining permissions at the collection, index, and document levels can create deeply nested hierarchies. There is uncertainty regarding the most efficient way to maintain these boundaries without introducing overlapping permissions that might inadvertently grant broader access than intended.
What is the recommended strategy for auditing deeply nested RBAC hierarchies to ensure no unintended public access exists? How does the system handle permission conflicts when a token is associated with multiple roles containing overlapping scopes?