TemitopeAderibigbe opened a new pull request, #451: URL: https://github.com/apache/airavata-custos/pull/451
## Summary This PR adds research documentation produced during the Spring 2026 Georgia Tech VIP Program security track for Apache Airavata Custos. ## Related Issue AIRAVATA-3978: https://issues.apache.org/jira/browse/AIRAVATA-3978 ## Changes - `docs/security-research/README.md` — Overview of the security track research scope and key findings - `docs/security-research/identity-platform-notes.md` — Research notes on six identity/authentication platforms (Auth0, WorkOS, WSO2 Asgardeo, Amazon Cognito, Eggshell, Keycloak) covering core features, architecture, and user-facing authorization engine patterns - `docs/security-research/zanzibar-paper-notes.md` — Notes on the Google Zanzibar paper (USENIX ATC 2019) covering the relation tuple data model, consistency model, API, system architecture, and direct relevance to Custos Project 2 (Dynamic Access Policy & Enforcement Engine) ## Key Findings - Custos currently handles authentication via Keycloak but has no general-purpose authorization engine for attribute or policy-based access decisions - Among platforms reviewed, only Keycloak and WorkOS FGA offer true engine-side enforcement — the rest rely on application-side token claim checking - Zanzibar's relation tuple model and per-namespace policy configs directly map to Project 2's requirements for per-tenant policies and a centralized policy decision service - Open Policy Agent (OPA) and AWS Cedar are strong candidates as the policy evaluation engine for Project 2 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
