Users have different permissions on different resources(They are called sites in our app) (which can grow over time). Also, there is a separate microservice that stores sites information in a separate dynamodb table. Permissions are calculated based on the groups a user is in. The backend will need to check for permissions always before an action is performed. I am looking to find the most efficient way to store permissions so that the permission check won't be redundant/taxing on the application.
So far our backend is all REST microservices. These are the options I have considered:
JWT Token: Do not wish to store permission on each resource in JWT token because the resource list will grow and it may hit the 8Kb header limit. That is risky.
DynamoDB: If we were to store permissions of each user in a DynamoDB table that is owned by the User microservice, that will mean a REST call to the endpoint from every other microservice which creates tight coupling between other microservices and user microservice and also adds an additional network trip.
DAX: Same issue as above
Elastic cache: Is it not managed so we will need to introduce a VPC in the application which I personally don't like.
API gateway caching: I guess it will do Authorization caching i.e requests with the same JWT token will be able to leverage the cache. Our JWT tokens are only cached for 5 minutes though so I am guessing it will hit the DB and calculate every 5 minutes. Also, this will again mean a REST call to the endpoint from every other microservice which creates tight coupling between other microservices and user microservice(that will have this endpoint) and also adds an additional network trip
Custom authorizer: Caches the policy for 5 minutes but we want the change in permissions to be real-time. Also, we have a strict policy that DynamoDB tables are owned by their respective microservices and that we do not read/write to DynamoDB from outside of the service. Since the authorizer is not going to be writing to the table, it will not be the owners and thus becomes dependent on a microservice that owns the table.also leads to cyclic dependency because all our microservices depend on the custom authorizer.
Am I missing something? What's the best way to handle this?