Skip to content

Use OPA Server caller identity in OPA policy #518

Discussion options

You must be logged in to vote

That's correct. Propagating data from the request context assumes that there is a request context, and not making such an assumption allows the same policy to be evaluated in any context and by any tool available in the OPA toolchain or even ecosystem, like opa test, opa eval, opa bench, opa exec, and so on.

I suppose an authorization policy could be made to work so that it was allowed to contribute data to the input object of the regular policy evaluation, but I'm not entirely sure what that would look like.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@HenriBlacksmith
Comment options

@anderseknert
Comment options

Answer selected by anderseknert
@HenriBlacksmith
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants