I'm configuring Keycloack for SSO purpose. Right now I'd like to implement Spring Security with ABAC support. For example, I'd like to secure REST API endpoint which is responsible for inviting a user on interview. Such endpoint accepts candidateUserId and interviewId parameters.
In order to grant or deny access to the caller, I need to check that the authenticated user belongs to the same organization that the interview object and have the corresponding role. The issue - that I don't have such information prepared in user and resource attributes and have to fetch it via a couple additional calls to database via Spring Data methods. So, currently I'm trying to understand how and where to implement such validation logic… is it possible to create the corresponding ABAC policies in Keycloack or ABAC policies directly in Spring Security or just place such validation logic directly inside my API/services code. Please advise.