Re: Google Docs as capabilities as data
David Barbour <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAAOQMStJur2HkmPSatggXtU=j4obu=SWmNcLPL1KE6SfFvmiSA@mail.gmail.com> |
On Mon, Jan 27, 2014 at 7:22 PM, Dirk Pranke <[email protected]> wrote: > 6) Figure out how to generate the right webkeys > 7) send out *multiple* emails w/ the right web keys > >From the user experience perspective, all we actually need is step 7. I envision a 'send doc to' page for each document that records (persistently) with whom you've previously sent capabilities to the document (and with which permissions) and also allows revocation. In addition, it could have a 'create webkey' button that you may tag (e.g. with a petname) as you wish. > from the "lazy developer" standpoint, you can understand why someone > implementing a new system would implement either the single-web-key flow or > the commonplace flow first, then maybe the other, and never quite get to > the "use webkeys for everything" flow, I think. > Well, a typical "lazy developer" knows very little about security and thus tends to use whatever is conventional. But, for those who already understand them, webkeys are a great deal easier and simpler to implement than the authentication mechanisms needed for ACLs. Best, Dave _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk