ES07 - Access Control
Revisions
- Initial version v1 (March 4, 2026).
| Version | Date | Changelog |
|---|---|---|
| 2.1 | 2026-03-15 | Updates the pipeline to not use Origin header. |
| 1.1 | 2026-03-16 | |
| 1.0 | 2026-03-04 | Initial version. |
Summary
In addition to ES02 - Authentication and Authorization, this specification adds details to how permissions are done, and what to do when hydrating the session with a set of permissions.
Permission Model
Policy Statements
Permissions are calculated via policy statements:
{ "actions": ["permissions:name"], "effect": "allow" }
Actions are in the form of namespacing by resources, such as modifiers:read to allow reading modifiers. Wildcard actions are supported up to the lowest common denominator:
modifiers:*will matchmodifiers:read,modifiers:writeor such, but won’t match againstmenus:*.menus:12:*will matchmenus:12:read,menus:12:updateand such, but won’t match againstmenus:13:readormenus:read.*matches against everything.
Deny-First Calculations
Denial effect ALWAYS takes priority over allow effect. If only ONE single policy matches, and it’s a denial effect but there are multiple policies that have an allow effect, you are unauthorized.
Wildcard permissions also take priority over the granular permissions.