Architecture
Three services, one explicit enforcement point
Identity authenticates the user, Policy evaluates a configured rule, and the API that owns the data enforces the decision. Neither Identity nor Policy automatically protects an application endpoint.
Verifies the bearer access token and checks the session is still active in PostgreSQL. It returns the authenticated user's ID and role.
Accepts a server-authenticated evaluation request. It maps the verified role through the API principal's configured role-to-domain mapping and decides whether the target is allowed.
Returns protected data only after an explicit allow. A deny becomes 403; an unavailable or malformed upstream response becomes 503.
Trust boundaries
- The user's access token is sent to Identity for validation; the example does not forward that token to Policy.
- The Policy service token is held by the API server and must never be sent to a browser.
- Policy trusts the authenticated API principal and its configured role mappings, not caller-supplied clearance or source-domain claims.
- The API owns protected data and must enforce every decision before returning it.
Data and policy
Identity persists accounts and revocable sessions in PostgreSQL. Password hashing, refresh rotation, and session revocation stay in Identity. Policy configuration defines clearance domains, compartments, trusted API principals, and optional role mappings. Policy changes can be checked with the policy validation command before restart.
The Rust/Diesel example is a read-only integration experiment against the Identity schema. It demonstrates typed queries but does not own authentication or become another source of truth.
Failure behavior
- Missing, forged, expired, or revoked Identity credentials are rejected.
- Policy denial does not return protected data.
- Identity or Policy unavailability fails closed; the example returns a service error instead of serving data.
- Applications integrating the services must independently preserve these checks on every protected route.
See the runnable quickstart, policy configuration, and security limitations.