Skip to content

Docs: clarify that SpiceDB permission checks do not observe external OAuth-layer revocation #3279

Description

@Dhruvagnihotri

SpiceDB behaves exactly per its documented guarantees, so this is a documentation request, not a bug report. When SpiceDB is composed with a separate OAuth 2.0 delegation layer (a common pattern), revoking a credential at the OAuth layer does not affect a SpiceDB permission check for a subject whose relationship still exists in the graph. Operators composing the two layers can wrongly assume OAuth revocation "turns off" downstream ReBAC access. Would a short note in the docs (e.g., in the consistency / access-control-composition guidance) help set that expectation? Details and a reproducible measurement are in a paper we can link.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions