incubator-imperius-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From David Wood <daw...@us.ibm.com>
Subject ACL policies
Date Wed, 27 Aug 2008 13:42:13 GMT
I sent something on this topic a couple of weeks ago and did not get a 
response, so I'll try again with perhaps a bit more motivation...

We would like to be able to implement ACL policies in SPL that do not 
depend on implementation-dependent anchor classes to capture the results 
of the decision.  My suggestion is to use the condition statement 
evaluation results to implement ACL policies.  If people agree, then we 
need to be able to retrieve the result of the condition evaluation after 
policy evaluation.  Currently all that is returned by SPLPolicy.evaluate() 
is a status code (error, success, not evaluated), but we could simply 
change this to return a new EvaluationStatus object that contains the 
condition results, current status value, and any other data that might be 
useful in the future. 

If I don't hear from anyone that this is a bad idea and would not be 
acceptable in Imperius, I guess I'll go ahead and try implementing this.

David Wood 
Network Server System Software Group
IBM TJ Watson Research Center
dawood@us.ibm.com
914-784-5123 (office), 914-396-6515 (mobile)

Mime
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message