Skip to main content

7. Authentication and authorization

Authorization controls API calls, management operations and document access. The application handles login and credentials. Dataway obtains users through IdentityProvider and checks operation permissions through AuthorizationCheck.

Request flow​

  1. The application validates credentials such as Cookies or JWTs. IdentityProvider returns a UserIdentity.
  2. Dataway selects the request's Operation and calls AuthorizationCheck.check(identity, operation).
  3. Allowed operations proceed. Denied operations raise DatawayException(401, "Unauthorized"); the host framework handles the response.

The default checker uses the identity's preset permissions. Host login interceptors control access to console pages and static assets.

Usage guide​