7. Authentication and authorization
Authorization controls API calls, management operations and document access. The application handles login and credentials. Dataway obtains users through IdentityProvider and checks operation permissions through AuthorizationCheck.
Request flow
- The application validates credentials such as Cookies or JWTs.
IdentityProviderreturns aUserIdentity. - Dataway selects the request's
Operationand callsAuthorizationCheck.check(identity, operation). - Allowed operations proceed. Denied operations raise
DatawayException(401, "Unauthorized"); the host framework handles the response.
The default checker uses the identity's preset permissions. Host login interceptors control access to console pages and static assets.
Usage guide
- Identity integration: Choose a preset and connect application users.
- Authorization: Review permissions and extend checks.