Re: Authorization
alex black <[email protected]>
| Newsgroups | gmane.comp.lib.binarycloud.devel |
|---|---|
| Message-ID | <[email protected]> |
> I'm not sure what you are saying with the phrase. I do also not know > what > a central policy could enforce in bc. > The data object should have some authorization requirements available, > yes. Currently we can only really expect to enforce policy on uris and php files - data objects imply a persistence layer. We could do something for SimpleEntity since it uses fairly standard methods... > If there is nothing to require by the dataobject, than it is apperently > anonymous. Whatever 'being anonymous' means. Yep - but then that's a single query and a response. > It looks a bit paranoid to show your ID first every time you enter the > postoffice. Eeeh ? Heh - point taken but in this case we're dealing with a whole campus of buildings - so we need to check first if the building is restricted and _then_ ask for ID only if it is. :) _a