vulns.co
/
GKData.io MCP

OpenFGA · 1 min read

OpenFGA query consistency: authorization decisions need sufficiently fresh state

Authorization correctness includes the age of relationship state used for a decision. OpenFGA documents a latency-oriented mode that can reuse cached results and a higher-consistency mode that bypasses the cache. With caching enabled, an immediate permission check may miss a relationship update.

Open the reference Implementation GuideReviewed 2026-10-03

How to use this reference

Editorial lesson: specify when permission changes must become observable and align decision freshness with that requirement. Review cache invalidation and performance assumptions together; a newly issued request does not necessarily use newly changed authorization state.

Before reading

  • Relationship-based authorization and cache consistency concepts

Context and limits

  • The documentation says caching is disabled by default. Do not assume every deployment returns cached authorization decisions.
  • Its illustrative timestamp branch appears inconsistent with the prose; this record does not reproduce or endorse that example.
  • Consistency tokens are described as future work. This guidance establishes neither a deployment-specific freshness guarantee nor evidence of an incident.

Sources and provenance

  1. Query Consistency Modes OpenFGA · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software