-
Notifications
You must be signed in to change notification settings - Fork 10
Open
Description
The claims can come from a few different sources:
- The
remote business logicservice - The HTTP request itself (as part of the payload submitted by the client)
- Configuration of Themis
- Time based claims
With the way Themis is assembled today there is a priority ordering as below:
- Time based claims (applied last, not overwritten)
- Configuration based claims
- HTTP request based claims
- Claims from the
remote business logicservice
Since the remote business logic service is given the HTTP request claims, it should be allowed to adjust/overwrite claims since it (in theory) will know better that the requesting agent.
I'll propose we change the processing order to be as follows:
- Time based claims (applied last, not overwritten)
- Configuration based claims
- Claims from the
remote business logicservice - HTTP request based claims
Metadata
Metadata
Assignees
Labels
No labels