WSAG Meetup #7
Join us for the seventh Warsaw Software Architecture Group meetup hosted by Jit Team! Talks on whether "Magic: the Gathering" will save IT, Context Engineering patterns, and what to do when RBAC is not enough.
About This Event
Join us for the seventh WSAG meetup, this time hosted by Jit Team! Three talks await you: Michał (Hans) Hadrysiak will check whether "Magic: the Gathering" will save IT, Tomasz Ducin will present Context Engineering patterns, and Kamil Kiełbasa will show what to do when the RBAC model is no longer enough.
This is a great opportunity to meet fellow software architects, share knowledge, and continue building our local architecture community.
Agenda
- 18:00
Will "Magic: the Gathering" Save IT?
Michał (Hans) Hadrysiak, Senior Full Stack Engineer (Makimo)
in Polish40 minAI takes over more and more of what we do, so the work itself is no longer as stimulating as it used to be. How can we make up for this deficit of effort so our brains don't atrophy? The answer may lie in cards, or more precisely in the game Magic: the Gathering. - 18:50
Context Engineering Patterns
Tomasz Ducin
in Polish40 minTalk description will be announced soon. - 19:40
When RBAC Is Not Enough?
Kamil Kiełbasa, .NET Tech Lead (Jit Team)
in Polish40 minOne day, some of the editors of a large CMS stopped being able to log in. Not more slowly, but at all. Other accounts worked flawlessly, and the application logs were silent, so at first glance it looked like magic. We spent half a day debugging it, and the cause turned out to be painfully mundane and had nothing to do with the login code. As usual, it all started much earlier, at the whiteboard, when we were modelling permissions. Starting from that outage, we'll move on to three authorization models, RBAC, ABAC and ReBAC, and see where each of them breaks. Why RBAC handles the question "is this user an editor" but falls over on "can this editor touch this particular article". We'll talk about Casbin.NET as a lightweight in-process library, about Google's Zanzibar, and about SpiceDB, which actually runs in our project, with a live demo from the terminal. Finally, an honest look at the costs, because a separate authorization service is not a free lunch. You'll leave with an answer to the question of whether your authorization problem can still be solved with a fat role, or whether it's time to reach for a graph. - 20:30
Closing & Networking
Final Q&A and networking