APPLICATION SURFACE

APIs, auth & access

RAIQL keeps security and exposure intent next to the domain model so those requirements are part of the compiled contract.

CRUD generation intent

CREATE CRUD Invoice;

This marks the entity for create, read, update and delete service generation.

API exposure

CREATE API Invoice;

API declarations are stored separately from CRUD intent so a model can exist without automatically being exposed.

Authentication

ADD AUTHENTICATION JWT, GOOGLE;

Authentication values are symbolic capabilities in the IR. A stack-specific generator decides how each mechanism is implemented.

Roles

ADD ROLE ADMIN, MANAGER, USER;

Roles are normalized and deduplicated by the compiler.

Permissions

ALLOW ADMIN CREATE Invoice, READ Invoice, UPDATE Invoice, DELETE Invoice;
ALLOW USER READ Invoice;

The role used by an ALLOW statement must already be declared. Each permission records an action and a target entity.

Continue exploring RAIQLOpen the playground →