Skip to content

feat(contracts): add authorization contracts - #12

Merged
ponchanon merged 1 commit into
mainfrom
dev
Aug 11, 2026
Merged

ponchanon merged 1 commit into
mainfrom
dev

Conversation

@ponchanon

@ponchanon ponchanon commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Establishes the foundational authorization contracts for OpenHealthOS
as part of Epic 5 Phase 5.3.

Changes

  • Added Permission
  • Added AuthorizationDecision
  • Added AuthorizationContextDto
  • Added resource-level authorization context
  • Added tenant and organization authorization context

Architecture

Authorization is intentionally separated from authentication.

Identity answers:

Who is calling?

Authorization answers:

What is this identity requesting access to?

The authorization context currently contains:

  • Identity
  • Permission
  • Resource type
  • Resource identifier
  • Tenant
  • Organization

Design Principles

  • Permissions use stable string identifiers rather than enums.
  • Authorization contracts do not depend on ASP.NET Core.
  • Authorization contracts do not depend on OpenIddict.
  • Authorization contracts do not depend on JWT implementation.
  • Authorization contracts do not depend on persistence.
  • Resource-level authorization is supported.
  • Tenant-aware authorization is supported.

Validation

  • dotnet build --no-incremental succeeds.
  • git diff --check succeeds.
  • No authorization-related compiler or analyzer warnings.

Known Repository Warning

The repository continues to report NU1903 for
Microsoft.OpenApi 2.0.0. This is tracked separately as a dependency/security
remediation task.

@ponchanon
ponchanon merged commit 38807bb into main Aug 11, 2026
1 check passed
@ponchanon
ponchanon deleted the dev branch August 11, 2026 04:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant