From 70d0c5e864939ceb7a7bc910076a66539e5fbe59 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 19 Nov 2025 11:39:25 +0000 Subject: [PATCH] chore: sync content to repo (#9372) Co-authored-by: kamranahmedse <4921183+kamranahmedse@users.noreply.github.com> --- .../api-design/content/abac@dZTe_kxIUQsc9N3w920aR.md | 8 ++++++++ .../content/best-practices@q1yaf-RbHIQsOqfzjn4k4.md | 3 ++- .../api-design/content/dac@_BXgYUlaYfpYrryXTw5n2.md | 9 +++++++++ .../api-design/content/mac@tl1wXmOaj_zHL2o38VygO.md | 9 +++++++++ .../api-design/content/pbac@nJWtUyn9bljh3T-q_adJK.md | 9 +++++++++ .../content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md | 2 +- .../api-design/content/rbac@wFsbmMi5Ey9UyDADdbdPW.md | 9 +++++++++ .../api-design/content/rebac@CCcY8UsGdd2pdBYHt9L4o.md | 9 +++++++++ 8 files changed, 56 insertions(+), 2 deletions(-) create mode 100644 src/data/roadmaps/api-design/content/abac@dZTe_kxIUQsc9N3w920aR.md create mode 100644 src/data/roadmaps/api-design/content/dac@_BXgYUlaYfpYrryXTw5n2.md create mode 100644 src/data/roadmaps/api-design/content/mac@tl1wXmOaj_zHL2o38VygO.md create mode 100644 src/data/roadmaps/api-design/content/pbac@nJWtUyn9bljh3T-q_adJK.md create mode 100644 src/data/roadmaps/api-design/content/rbac@wFsbmMi5Ey9UyDADdbdPW.md create mode 100644 src/data/roadmaps/api-design/content/rebac@CCcY8UsGdd2pdBYHt9L4o.md diff --git a/src/data/roadmaps/api-design/content/abac@dZTe_kxIUQsc9N3w920aR.md b/src/data/roadmaps/api-design/content/abac@dZTe_kxIUQsc9N3w920aR.md new file mode 100644 index 000000000..ca59aa5a5 --- /dev/null +++ b/src/data/roadmaps/api-design/content/abac@dZTe_kxIUQsc9N3w920aR.md @@ -0,0 +1,8 @@ +# Attribute Based Access Control (ABAC) - An Authorization Method in API Design + +Attribute Based Access Control (ABAC) is a flexible and powerful authorization method in the realm of API Design. Distinct from Role-Based Access Control (RBAC), which relies on predefined roles and permissions, ABAC uses attributes to build policies and make decisions. These attributes can be associated with the user, the action they want to perform, targeted resources, or the environment. With ABAC, finer-grained access control can be achieved, thereby improving the security and efficiency of APIs. This approach is widely used in complex and dynamic environments where access control requirements can be multifaceted and deeply context-dependent. + +Visit the following resources to learn more: + +- [@article@What is Attribute Based Access Control?](https://www.okta.com/uk/blog/2020/09/attribute-based-access-control-abac/) +- [@article@Attribute Based Access Control](https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction_attribute-based-access-control.html) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/best-practices@q1yaf-RbHIQsOqfzjn4k4.md b/src/data/roadmaps/api-design/content/best-practices@q1yaf-RbHIQsOqfzjn4k4.md index f40c604dc..520b62ba5 100644 --- a/src/data/roadmaps/api-design/content/best-practices@q1yaf-RbHIQsOqfzjn4k4.md +++ b/src/data/roadmaps/api-design/content/best-practices@q1yaf-RbHIQsOqfzjn4k4.md @@ -1,8 +1,9 @@ # Best Practices in API Design -API design has rapidly emerged as a vital component of software development. When designing an API, it is crucial to follow best practices to ensure optimization, scalability, and efficiency. The best practices in API design revolve around principles such as simplicity, consistency, security, and proper documentation among others. These practices not only smoothens the development process but also makes the API more user-friendly, stable, and easily maintainable. Thus, following the best practices in API design is not an option but rather a must for developers and organizations looking to create APIs that last longer and perform better. +API design has rapidly emerged as a vital component of software development. When designing an API, it is crucial to follow best practices to ensure optimization, scalability, and efficiency. The best practices in API design revolve around principles such as simplicity, consistency, security, and proper documentation, among others. These practices not only smooth the development process but also make the API more user-friendly, stable, and easily maintainable. Thus, following the best practices in API design is not an option but rather a must for developers and organizations looking to create APIs that last longer and perform better. Visit the following resources to learn more: +- [@roadmap@API Security Best Practices](https://roadmap.sh/api-security-best-practices) - [@article@Best Practices for REST API Design](https://stackoverflow.blog/2020/03/02/best-practices-for-rest-api-design/) - [@article@Best Practices in API Design](https://swagger.io/resources/articles/best-practices-in-api-design/) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/dac@_BXgYUlaYfpYrryXTw5n2.md b/src/data/roadmaps/api-design/content/dac@_BXgYUlaYfpYrryXTw5n2.md new file mode 100644 index 000000000..c9b2b58a6 --- /dev/null +++ b/src/data/roadmaps/api-design/content/dac@_BXgYUlaYfpYrryXTw5n2.md @@ -0,0 +1,9 @@ +# Discretionary Access Control (DAC) + +Discretionary Access Control (DAC) is an access control model where access to resources is determined by the owner of the resource. The owner has the discretion to grant or deny access to other users or groups. This means that users can control who has access to the resources they own, allowing for flexible and personalized access management. + +Visit the following resources to learn more: + +- [@article@Guide to Discretionary Access Control (DAC) With Examples](https://builtin.com/articles/discretionary-access-control) +- [@article@Discretionary Access Control (DAC)](https://www.caldersecurity.co.uk/discretionary-access-control-dac/) +- [@video@Discretionary Access Control](https://www.youtube.com/watch?v=KyCamjQd0Mk) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/mac@tl1wXmOaj_zHL2o38VygO.md b/src/data/roadmaps/api-design/content/mac@tl1wXmOaj_zHL2o38VygO.md new file mode 100644 index 000000000..40a056272 --- /dev/null +++ b/src/data/roadmaps/api-design/content/mac@tl1wXmOaj_zHL2o38VygO.md @@ -0,0 +1,9 @@ +# Mandatory Access Control (MAC) + +Mandatory Access Control (MAC) is a security model where the operating system or security kernel controls access to resources based on a fixed set of rules and security clearances. Unlike discretionary access control (DAC) where users can grant access to resources they own, in MAC, access is determined by a central authority. Each resource and user is assigned a security label, and access is granted only if the user's label dominates the resource's label, ensuring a strict and centrally managed security policy. + +Visit the following resources to learn more: + +- [@article@mandatory access control (MAC)](https://www.techtarget.com/searchsecurity/definition/mandatory-access-control-MAC) +- [@article@Mandatory access control defined](https://nordlayer.com/learn/access-control/mandatory-access-control/) +- [@video@Mandatory Access Control](https://www.youtube.com/watch?v=E4CsEDEyauY) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/pbac@nJWtUyn9bljh3T-q_adJK.md b/src/data/roadmaps/api-design/content/pbac@nJWtUyn9bljh3T-q_adJK.md new file mode 100644 index 000000000..e3d84aead --- /dev/null +++ b/src/data/roadmaps/api-design/content/pbac@nJWtUyn9bljh3T-q_adJK.md @@ -0,0 +1,9 @@ +# Policy-Based Access Control (PBAC) + +Policy-Based Access Control (PBAC) is an authorization method that determines access rights based on a set of policies. Instead of directly assigning permissions to users or roles, PBAC evaluates requests against these policies, which define the conditions under which access is granted or denied. These policies can consider various attributes of the user, the resource being accessed, and the environment to make fine-grained authorization decisions. + +Visit the following resources to learn more: + +- [@article@Policy-Based Access Control (PBAC) – The Complete Know How for Organizations](https://heimdalsecurity.com/blog/policy-based-access-control/) +- [@article@Policy Based Access Control (PBAC) Explained](https://www.pingidentity.com/en/resources/blog/post/policy-based-access-control.html) +- [@video@What is PBAC? Policy Based Access Control Explainer by PlainID](https://www.youtube.com/watch?v=b7Nc5LzByuc) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md b/src/data/roadmaps/api-design/content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md index 00ed7e7ee..b150e2ca1 100644 --- a/src/data/roadmaps/api-design/content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md +++ b/src/data/roadmaps/api-design/content/rate-limiting@O7wjldZ3yTA2s_F-UnJw_.md @@ -8,4 +8,4 @@ Visit the following resources to learn more: - [@article@Throttle](https://developer.mozilla.org/en-US/docs/Glossary/Throttle) - [@article@Debounce](https://developer.mozilla.org/en-US/docs/Glossary/Debounce) - [@article@What is rate limiting? | Rate limiting and bots](https://www.cloudflare.com/en-gb/learning/bots/what-is-rate-limiting/) -- [@video@Rate Limiting techniques visualization](https://smudge.ai/blog/ratelimit-algorithms) +- [@video@Rate Limiting techniques visualization](https://smudge.ai/blog/ratelimit-algorithms) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/rbac@wFsbmMi5Ey9UyDADdbdPW.md b/src/data/roadmaps/api-design/content/rbac@wFsbmMi5Ey9UyDADdbdPW.md new file mode 100644 index 000000000..14e18d1e5 --- /dev/null +++ b/src/data/roadmaps/api-design/content/rbac@wFsbmMi5Ey9UyDADdbdPW.md @@ -0,0 +1,9 @@ +# Role Based Access Control (RBAC) in API Design + +Role-Based Access Control (RBAC) is a method of managing authorization in API design that assigns system access to users based on their role within an organization. RBAC is crucial in controlling which endpoints a user can call, and what operations they are allowed to execute. In the context of API design, RBAC ensures appropriate levels of access for different types of users to guarantee data security and integrity. It simplifies the process of security administration by assigning privileges based on a user's job function, rather than on an individual basis. + +Visit the following resources to learn more: + +- [@article@Role-Based Access Control](https://auth0.com/docs/manage-users/access-control/rbac) +- [@article@What is Role-based Access Control (RBAC)?](https://www.redhat.com/en/topics/security/what-is-role-based-access-control) +- [@video@Role-based Access Control (RBAC) vs. Attribute-based Access Control (ABAC)](https://www.youtube.com/watch?v=rvZ35YW4t5k) \ No newline at end of file diff --git a/src/data/roadmaps/api-design/content/rebac@CCcY8UsGdd2pdBYHt9L4o.md b/src/data/roadmaps/api-design/content/rebac@CCcY8UsGdd2pdBYHt9L4o.md new file mode 100644 index 000000000..56bd5daa5 --- /dev/null +++ b/src/data/roadmaps/api-design/content/rebac@CCcY8UsGdd2pdBYHt9L4o.md @@ -0,0 +1,9 @@ +# ReBAC + +Relationship-Based Access Control (ReBAC) is an authorization model that determines access rights based on the relationships between users and resources. Instead of relying solely on roles or attributes, ReBAC considers the connections and associations between entities within a system. This allows for fine-grained control over who can access what, based on their relationship to the data or resources in question. + +Visit the following resources to learn more: + +- [@article@How to Implement Relationship Based Access Control (ReBAC)](https://www.freecodecamp.org/news/implement-relationship-based-access-control/) +- [@article@Relationship-based Access Control (ReBAC)](https://docs.aserto.com/docs/authorization-basics/authorization-models/rebac) +- [@video@Understanding Relationship Based Access Control (ReBAC)](https://www.youtube.com/watch?v=xCqpxiPXnCk) \ No newline at end of file