This is the repo for the Muni Town Arbiter, an authorization server for ATProto designed to power the permissions and policies for Roomy and other ATProto community / group software.
Documentation is limited and things are changing frequently. You can find more information about the arbiter in Zicklag's Leaflets.
Plans for upcoming changes to the arbiter design.
The latest design ( at the time of writing ) uses a firewall-like list of policies that are exectued in order to route / protect requests. The system allows higher priority policies to intercept requests before lower priority ones can, but it is not sufficient for preventing a particular policy in the list from being able to handle requests of a certain kind that you do not want it to.
For example, suppose that you want to install a policy, but it's a Roomy policy
so you want to make sure it can only operate on endpoints starting with space.roomy..
We can re-use the scope concept that we have for reducing the scope of a proxy endpoint
to optionally reduce the scope of installed policies in the layer. This allows you to
say: I want to install this policy, but only allow it to handle requests in this scope.
If a request is outside of scope for a policy, then the policy will automaticall pass
on the request, without running the policy.