TemitopeAderibigbe opened a new pull request, #451:
URL: https://github.com/apache/airavata-custos/pull/451

   ## Summary
   
   This PR adds research documentation produced during the Spring 2026 Georgia 
Tech VIP Program security track for Apache Airavata Custos.
   
   ## Related Issue
   AIRAVATA-3978: https://issues.apache.org/jira/browse/AIRAVATA-3978
   
   ## Changes
   - `docs/security-research/README.md` — Overview of the security track 
research scope and key findings
   - `docs/security-research/identity-platform-notes.md` — Research notes on 
six identity/authentication platforms (Auth0, WorkOS, WSO2 Asgardeo, Amazon 
Cognito, Eggshell, Keycloak) covering core features, architecture, and 
user-facing authorization engine patterns
   - `docs/security-research/zanzibar-paper-notes.md` — Notes on the Google 
Zanzibar paper (USENIX ATC 2019) covering the relation tuple data model, 
consistency model, API, system architecture, and direct relevance to Custos 
Project 2 (Dynamic Access Policy & Enforcement Engine)
   
   ## Key Findings
   - Custos currently handles authentication via Keycloak but has no 
general-purpose authorization engine for attribute or policy-based access 
decisions
   - Among platforms reviewed, only Keycloak and WorkOS FGA offer true 
engine-side enforcement — the rest rely on application-side token claim checking
   - Zanzibar's relation tuple model and per-namespace policy configs directly 
map to Project 2's requirements for per-tenant policies and a centralized 
policy decision service
   - Open Policy Agent (OPA) and AWS Cedar are strong candidates as the policy 
evaluation engine for Project 2


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to