Re: ZEO authorization model?
Jason Madden <[email protected]>
| Newsgroups | gmane.comp.web.zope.zodb |
|---|---|
| Message-ID | <[email protected]> |
> On May 25, 2016, at 13:18, Jim Fulton <[email protected]> wrote: > IMO, you're reading too many semantics into this. ... > I don't agree, or at least, I think a server authorization model might > be useful even if there isn't separate protection of the client side. I think you're right and I'm wrong. I was working with a confused threat model, stemming, I think, from conflating the ZEO client and the server. Tempting as that is, due to how tightly coupled they are and by the very nature of ZODB as a distributed memory, it's incorrect. There is still a client, a server, and separation between them with communications mediated by a protocol (that in principle anyone could implement). Jason -- You received this message because you are subscribed to the Google Groups "zodb" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.