Re: Joins on capabilities that have passed through different membranes
<[email protected]> Tue, 5 Jan 2016 08:24:55 -0800
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAG7xX7oWXu2xt_z-PVQbctoVaf-96JHNE+2M6QtuK8b64PTg4Q@mail.gmail.com> |
--===============5000144133759417524== Content-Type: multipart/alternative; boundary=089e013a2a26973127052898ad9a --089e013a2a26973127052898ad9a Content-Type: text/plain; charset=UTF-8 On Tue, Jan 5, 2016 at 4:41 AM, David Bruant <[email protected]> wrote: > Can you provide a concrete example of why one would want to perform the >> join instead of just using the two capabilities separately? >> > I'm going to take a guess. This is a problem we talked about extensively during the early parts of the Caja project, and discussed with our security PMs. From what I recall, we did not have a good answer. * Let's say I have a document I own and have read/write access to. Let's call my capability to it [rwdoc]. * I share a read-only cap to that document with Kenton. I say something like, "Hey Kenton, check out this stuff I wrote up at [rodoc]. Regards." * Months later, Kenton replies to me, saying, "Hey Ihab, I think you need to add the following information to [rodoc], because some new stuff came up! Kthxbai." * The cap [rodoc] arrives in my user agent -- browser or whatever. Now what? There is no simple "correct" solution. -> If my user agent automatically amplifies it to [rwdoc], that means the agent has ambient authority. In fact, that's what happens with browsers and cookies today! And when you make the situation a bit more complex, with Kenton's original example, you end up with the joining problem he has raised. -> If my user agent does nothing, then I have "two ways" to get to one logical document, and we don't know how to explain this state of affairs to end-users. I think this is a UX research problem. :) Ihab -- Ihab A.B. Awad, Palo Alto, CA --089e013a2a26973127052898ad9a Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">= On Tue, Jan 5, 2016 at 4:41 AM, David Bruant <span dir=3D"ltr"><<a href= =3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>>= </span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .= 8ex;border-left:1px #ccc solid;padding-left:1ex"><span><blockquote class=3D= "gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding= -left:1ex">Can you provide a concrete example of why one would want to perf= orm the join instead of just using the two capabilities separately?<br></bl= ockquote></span></blockquote><div><br></div><div>I'm going to take a gu= ess. This is a problem we talked about extensively during the early parts o= f the Caja project, and discussed with our security PMs. From what I recall= , we did not have a good answer.</div><div><br></div><div>* Let's say I= have a document I own and have read/write access to. Let's call my cap= ability to it [rwdoc].</div><div><br></div><div>* I share a read-only cap t= o that document with Kenton. I say something like, "Hey Kenton, check = out this stuff I wrote up at [rodoc]. Regards."</div><div><br></div><d= iv>* Months later, Kenton replies to me, saying, "Hey Ihab, I think yo= u need to add the following information to [rodoc], because some new stuff = came up! Kthxbai."</div><div><br></div><div>* The cap [rodoc] arrives = in my user agent -- browser or whatever. Now what? There is no simple "= ;correct" solution.</div><div><br></div><div>-> If my user agent au= tomatically amplifies it to [rwdoc], that means the agent has ambient autho= rity. In fact, that's what happens with browsers and cookies today! And= when you make the situation a bit more complex, with Kenton's original= example, you end up with the joining problem he has raised.</div><div><br>= </div><div>-> If my user agent does nothing, then I have "two ways&= quot; to get to one logical document, and we don't know how to explain = this state of affairs to end-users.</div><div><br></div><div>I think this i= s a UX research problem. :)</div><div><br></div><div>Ihab</div><div><br></d= iv><div>--=C2=A0<br></div></div><div>Ihab A.B. Awad, Palo Alto, CA</div> </div></div> --089e013a2a26973127052898ad9a-- --===============5000144133759417524== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk --===============5000144133759417524==--