Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 0 additions & 7 deletions content/docs/dev-guide/authorization.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -13,13 +13,6 @@ keywords:
image: /img/mg-preview.png
---

<Callout type="warn" title="SpiceDB is gone — authorization now runs through Atom">
No SpiceDB container exists in `docker-compose.yaml`, and the old per-entity relations/permissions
schema and REST role management API (`/<entity_type>/<entity_id>/roles`) no longer apply.
Authorization is now owned entirely by **Atom** — see [Overview](/dev-guide/entities) for its
entity model.
</Callout>

## The model

Atom answers one question: *can subject S perform action A on object O?*
Expand Down
11 changes: 5 additions & 6 deletions content/docs/dev-guide/dev-tools/authentication.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,11 @@ keywords:
image: /img/mg-preview.png
---

<Callout type="warn">
This page describes the previous JWT/Google-OIDC authentication model issued directly by
`magistrala.auth`. That service is gone — authentication now goes through **Atom**, and
day-to-day API access uses Atom-issued bearer tokens or Personal Access Tokens (PATs). See
[API](/dev-guide/api) for the current sign-in/token flow and [Personal Access Tokens](/user-guide/pats)
for PATs. The content below is kept for historical reference only.
<Callout type="info">
User sign-in and day-to-day API access now go through **Atom**-issued bearer tokens or
[Personal Access Tokens](/user-guide/pats) — see [API](/dev-guide/api) for the current
sign-in/token flow. The [Mutual TLS](#mutual-tls-authentication-with-x509-certificates) section
below still applies for device/client certificate authentication.
</Callout>

## User authentication
Expand Down
14 changes: 7 additions & 7 deletions content/docs/dev-guide/dev-tools/authorization.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -14,15 +14,15 @@ image: /img/mg-preview.png
---


<Callout type="warn">
This page describes the previous SpiceDB-backed authorization model (`domains`/`clients`
terminology, SpiceDB schema language). SpiceDB has been replaced — authorization now goes through
**Atom**, and the public entities are **Workspaces**/**Devices**. See
[Authorization](/dev-guide/authorization) for the current model. The content below is kept for
historical reference only.
<Callout type="info">
Authorization is provided by **Atom**, over the public **Workspaces**/**Devices** entities — see
[Authorization](/dev-guide/authorization) for the current permission model. The domain/client/channel
walkthrough below illustrates the same role and hierarchy concepts using the platform's earlier
terminology; the [Personal Access Tokens](#magistrala-personal-access-token-pat-authentication)
section further down is current.
</Callout>

Magistrala allows for fine-grained control over user permissions, taking into account hierarchical relationships between entities workspaces, groups, channels, and devices. The structure and functionality of an authorization system previously implemented using [SpiceDB](https://github.com/authzed/spicedb) and its associated [schema language](https://authzed.com/docs/reference/schema-lang) — now superseded by Atom.
Magistrala allows for fine-grained control over user permissions, taking into account hierarchical relationships between entities workspaces, groups, channels, and devices.

## Domains

Expand Down
Loading
Loading