Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Opa has always treated security very carefully, as it was one of the original project goals. Strong static typing + the original native backend makes Opa one of the best candidates for secure web app. We're not vocal about this, but the company behind Opa has customers in the defense sector (in Europe, PRISM totally unrelated) for this reason.


By security, I mean user permissions... ex: User A can't edit records beloning to User B, but Manager C can see them both, and Admin D can see everything.

Many of these "Simple" frameworks that transparently pass stuff to the client-side forgo roles, accounts and ownership hierarchies.


In Opa, you have too mechanisms that combined provide probably a very high level of security in this sense too: 1) Algebraic constructs, so that the typing system checks properties like permissions automatically 2) Client "guards", aka protected values that can't be transmitted to the client, which Opa checks automatically.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: