chore: sync content to repo (#9372)

Co-authored-by: kamranahmedse <4921183+kamranahmedse@users.noreply.github.com>
This commit is contained in:
github-actions[bot]
2025-11-19 11:39:25 +00:00
committed by GitHub
co-authored by kamranahmedse
parent 9d82f3fc99
commit 70d0c5e864
8 changed files with 56 additions and 2 deletions
@@ -0,0 +1,8 @@
# Attribute Based Access Control (ABAC) - An Authorization Method in API Design
Attribute Based Access Control (ABAC) is a flexible and powerful authorization method in the realm of API Design. Distinct from Role-Based Access Control (RBAC), which relies on predefined roles and permissions, ABAC uses attributes to build policies and make decisions. These attributes can be associated with the user, the action they want to perform, targeted resources, or the environment. With ABAC, finer-grained access control can be achieved, thereby improving the security and efficiency of APIs. This approach is widely used in complex and dynamic environments where access control requirements can be multifaceted and deeply context-dependent.
Visit the following resources to learn more:
- [@article@What is Attribute Based Access Control?](https://www.okta.com/uk/blog/2020/09/attribute-based-access-control-abac/)
- [@article@Attribute Based Access Control](https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction_attribute-based-access-control.html)
@@ -1,8 +1,9 @@
# Best Practices in API Design
API design has rapidly emerged as a vital component of software development. When designing an API, it is crucial to follow best practices to ensure optimization, scalability, and efficiency. The best practices in API design revolve around principles such as simplicity, consistency, security, and proper documentation among others. These practices not only smoothens the development process but also makes the API more user-friendly, stable, and easily maintainable. Thus, following the best practices in API design is not an option but rather a must for developers and organizations looking to create APIs that last longer and perform better.
API design has rapidly emerged as a vital component of software development. When designing an API, it is crucial to follow best practices to ensure optimization, scalability, and efficiency. The best practices in API design revolve around principles such as simplicity, consistency, security, and proper documentation, among others. These practices not only smooth the development process but also make the API more user-friendly, stable, and easily maintainable. Thus, following the best practices in API design is not an option but rather a must for developers and organizations looking to create APIs that last longer and perform better.
Visit the following resources to learn more:
- [@roadmap@API Security Best Practices](https://roadmap.sh/api-security-best-practices)
- [@article@Best Practices for REST API Design](https://stackoverflow.blog/2020/03/02/best-practices-for-rest-api-design/)
- [@article@Best Practices in API Design](https://swagger.io/resources/articles/best-practices-in-api-design/)
@@ -0,0 +1,9 @@
# Discretionary Access Control (DAC)
Discretionary Access Control (DAC) is an access control model where access to resources is determined by the owner of the resource. The owner has the discretion to grant or deny access to other users or groups. This means that users can control who has access to the resources they own, allowing for flexible and personalized access management.
Visit the following resources to learn more:
- [@article@Guide to Discretionary Access Control (DAC) With Examples](https://builtin.com/articles/discretionary-access-control)
- [@article@Discretionary Access Control (DAC)](https://www.caldersecurity.co.uk/discretionary-access-control-dac/)
- [@video@Discretionary Access Control](https://www.youtube.com/watch?v=KyCamjQd0Mk)
@@ -0,0 +1,9 @@
# Mandatory Access Control (MAC)
Mandatory Access Control (MAC) is a security model where the operating system or security kernel controls access to resources based on a fixed set of rules and security clearances. Unlike discretionary access control (DAC) where users can grant access to resources they own, in MAC, access is determined by a central authority. Each resource and user is assigned a security label, and access is granted only if the user's label dominates the resource's label, ensuring a strict and centrally managed security policy.
Visit the following resources to learn more:
- [@article@mandatory access control (MAC)](https://www.techtarget.com/searchsecurity/definition/mandatory-access-control-MAC)
- [@article@Mandatory access control defined](https://nordlayer.com/learn/access-control/mandatory-access-control/)
- [@video@Mandatory Access Control](https://www.youtube.com/watch?v=E4CsEDEyauY)
@@ -0,0 +1,9 @@
# Policy-Based Access Control (PBAC)
Policy-Based Access Control (PBAC) is an authorization method that determines access rights based on a set of policies. Instead of directly assigning permissions to users or roles, PBAC evaluates requests against these policies, which define the conditions under which access is granted or denied. These policies can consider various attributes of the user, the resource being accessed, and the environment to make fine-grained authorization decisions.
Visit the following resources to learn more:
- [@article@Policy-Based Access Control (PBAC) – The Complete Know How for Organizations](https://heimdalsecurity.com/blog/policy-based-access-control/)
- [@article@Policy Based Access Control (PBAC) Explained](https://www.pingidentity.com/en/resources/blog/post/policy-based-access-control.html)
- [@video@What is PBAC? Policy Based Access Control Explainer by PlainID](https://www.youtube.com/watch?v=b7Nc5LzByuc)
@@ -8,4 +8,4 @@ Visit the following resources to learn more:
- [@article@Throttle](https://developer.mozilla.org/en-US/docs/Glossary/Throttle)
- [@article@Debounce](https://developer.mozilla.org/en-US/docs/Glossary/Debounce)
- [@article@What is rate limiting? | Rate limiting and bots](https://www.cloudflare.com/en-gb/learning/bots/what-is-rate-limiting/)
- [@video@Rate Limiting techniques visualization](https://smudge.ai/blog/ratelimit-algorithms)
- [@video@Rate Limiting techniques visualization](https://smudge.ai/blog/ratelimit-algorithms)
@@ -0,0 +1,9 @@
# Role Based Access Control (RBAC) in API Design
Role-Based Access Control (RBAC) is a method of managing authorization in API design that assigns system access to users based on their role within an organization. RBAC is crucial in controlling which endpoints a user can call, and what operations they are allowed to execute. In the context of API design, RBAC ensures appropriate levels of access for different types of users to guarantee data security and integrity. It simplifies the process of security administration by assigning privileges based on a user's job function, rather than on an individual basis.
Visit the following resources to learn more:
- [@article@Role-Based Access Control](https://auth0.com/docs/manage-users/access-control/rbac)
- [@article@What is Role-based Access Control (RBAC)?](https://www.redhat.com/en/topics/security/what-is-role-based-access-control)
- [@video@Role-based Access Control (RBAC) vs. Attribute-based Access Control (ABAC)](https://www.youtube.com/watch?v=rvZ35YW4t5k)
@@ -0,0 +1,9 @@
# ReBAC
Relationship-Based Access Control (ReBAC) is an authorization model that determines access rights based on the relationships between users and resources. Instead of relying solely on roles or attributes, ReBAC considers the connections and associations between entities within a system. This allows for fine-grained control over who can access what, based on their relationship to the data or resources in question.
Visit the following resources to learn more:
- [@article@How to Implement Relationship Based Access Control (ReBAC)](https://www.freecodecamp.org/news/implement-relationship-based-access-control/)
- [@article@Relationship-based Access Control (ReBAC)](https://docs.aserto.com/docs/authorization-basics/authorization-models/rebac)
- [@video@Understanding Relationship Based Access Control (ReBAC)](https://www.youtube.com/watch?v=xCqpxiPXnCk)