opa-spring-security
opa-spring-security copied to clipboard
Document design decisions
Voting has a huge drawback that you can't pass the reason for denial. Also, if you keep authorization policies decoupled (as you should when using OPA), I don't think there should be a case where OPA's decision can be outvoted.
We should document (great!) design choices like the above, either in the README.md file or a separate DESIGN.md, or somewhere.