Published on

Today I Learnt: Getting Started with Oso Authorization in Node.js

Authors
  • Mehdi Akiki avatar
    Name
    Mehdi Akiki
    Twitter

Oso provides a concise policy language (Polar) for authorization. Treat authentication as who you are, and Oso policies decide what the identity can do.

Quick example (Express + Oso):

// install: npm i oso express
const express = require("express");
const { Oso } = require("oso");

const oso = new Oso();
oso.loadStr(`allow(actor, action, resource) if actor.role = "admin";`);

const app = express();
app.get("/invoices/:id", async (req, res) => {
  const user = { id: 1, role: "admin" }; // from auth middleware
  const invoice = { id: +req.params.id, ownerId: 1 };
  const allowed = await oso.isAllowed(user, "read", invoice);
  res.status(allowed ? 200 : 403).json(invoice);
});

Tips:

  • Keep policies declarative and small.
  • Use resources that represent domain objects, not HTTP routes.
  • Run policy tests — Oso supports unit-testing Polar rules.

Resources: Oso docs for Polar language and SDK usage per language.

I build and scale reliable production systems. Open to full-time and freelance work with U.S.-based teams that value ownership and execution.

Got something in mind?

Book a Discovery Call