by cmorgan8506 on 5/25/20, 2:54 PM with 0 comments
Particularly when the individual object permissions can be in the thousands.
Example:
Service A contains thousands of objects for which a user can have access to any number of. While Service B has meta data that relates to objects in Service A. If the user makes a direct request to Service B for a set of objects, how does Service B check if the user has permission to access metadata for the requested objects from Service A.