Interesting. My initial feeling is this is weird - acl in ORM. But it kinda makes sense with a second thought. Rules are closer to the source of the problem (schema). It can probably remove lots of headaches securing things at an upper layer. Not sure how well this scales when you have tons of rule though.
Thank you for the recognition. We have some production users who have hundreds of policy rules. While they mentioned that having visual tools for new users to quickly understand the policy would be beneficial, overall it is functioning well. They state that it is more transparent and efficient compared to the traditional approach.
The current approach relies on schema and code generation, which is not possible in Drizzle. We could have used decorators and string literals to achieve this, but that would negatively impact the developer experience. Therefore, at least for now it's not in our plan.
Good write up. If I were to build a new SaaS and I’m not anticipating lots of users and concurrency. Regardless the single writer concern, does it suffice as the main storage? What’s is the consistency guarantee?
Is there any plan for Drizzle support?