FireDAC and EMS credential expiration and least-privilege boundary
25K reputation · 02 Jun 2022, 09:49 UTC
Integration boundary
A Delphi application is planned to use FireDAC for least-privilege database access and RAD Server/EMS for token-based API access. The design goal is consistent credential use and handling of expired credentials across the two component boundaries.
FireDAC supports least-privilege access via connection parameters and delegates authentication to the underlying driver and OS. Credential expiration is not managed inside Delphi; connection failures are surfaced as engine exceptions with vendor-specific codes and retry or re-prompt logic is left to application code.
EMS provides token-based authentication with configurable lifetimes and role-based access for least-privilege design, but token issuance, refresh and revocation policies are application-defined and not enforced by the framework. Indy HTTP clients surface 401 responses for expired or invalid credentials without built-in renewal or standardized expired-credential detection.
No cross-component standard API exists in Delphi for detecting expired credentials and prompting renewal across FireDAC, EMS and Indy.
Should credential expiration detection and re-authentication be centralized in the application layer or handled per component with OS credential manager reliance? Is there a documented, driver-agnostic way to distinguish expired credential failures from generic connection failures in FireDAC? How should least-privilege role mapping be aligned between FireDAC database users and EMS roles without duplication?