Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Discussion: Is providing reason reasonable? #163

Open
independentid opened this issue Oct 3, 2024 · 0 comments
Open

Discussion: Is providing reason reasonable? #163

independentid opened this issue Oct 3, 2024 · 0 comments

Comments

@independentid
Copy link
Contributor

In a de-coupled PDP/PEP environment, it is difficult to conceive how a PDP can convey reason (admin or user) values except in the case of specific "deny" policies.

If a PDP system is default deny unless permitted, then most responses can have no reason because no permission was matched.

What other information could or should be provided (e.g. count of policies reviewed)?

If it is useful to give a reason for denial, is it useful to give reason for permission (e.g. which policy permitted the action)?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant