Re: Google Docs as capabilities as data

David Barbour <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAAOQMStJur2HkmPSatggXtU=j4obu=SWmNcLPL1KE6SfFvmiSA@mail.gmail.com>
On Mon, Jan 27, 2014 at 7:22 PM, Dirk Pranke <[email protected]> wrote:

> 6) Figure out how to generate the right webkeys
> 7) send out *multiple* emails w/ the right web keys
>

>From the user experience perspective, all we actually need is step 7. I
envision a 'send doc to' page for each document that records (persistently)
with whom you've previously sent capabilities to the document (and with
which permissions) and also allows revocation. In addition, it could have a
'create webkey' button that you may tag (e.g. with a petname) as you wish.


> from the "lazy developer" standpoint, you can understand why someone
> implementing a new system would implement either the single-web-key flow or
> the commonplace flow first, then maybe the other, and never quite get to
> the "use webkeys for everything" flow, I think.
>

Well, a typical "lazy developer" knows very little about security and thus
tends to use whatever is conventional. But, for those who already
understand them, webkeys are a great deal easier and simpler to implement
than the authentication mechanisms needed for ACLs.

Best,

Dave

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.