portals-jetspeed-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "David Sean Taylor" <da...@bluesunrise.com>
Subject RE: Security 1.4: more implement[eo]r feedback on provider APIs
Date Tue, 06 Aug 2002 16:23:49 GMT
Jan,

I don't have a problem with adding a 'context' (current user) parameter to
the interfaces.

Could you send your proposed changes to the interfaces to this list?
That way we can have the other developers comment on your proposal.

Thanks,

David

> -----Original Message-----
> From: Jan Grant [mailto:Jan.Grant@bristol.ac.uk]
> Sent: Tuesday, August 06, 2002 5:52 AM
> To: Jetspeed Developers List
> Subject: RE: Security 1.4: more implement[eo]r feedback on provider APIs
>
>
> On Mon, 5 Aug 2002, David Sean Taylor wrote:
>
> > I believe at first you only wanted to change the logout method.
> Am I correct
> > to say that now you want to change all the security calls to
> explicity pass
> > in the current user?
>
> Basically, my first pass was with authentication only, because logout
> stood out from the crowd. I took a closer look at the other interfaces;
> in the light of that, I think that wherever the current user has a
> (potential) bearing on security provider decisions (ie, where the
> javadoc says "provider may use current user from context to determine
> whether to do this" or words to that effect), then the user should be
> passed as part of the interface.
>
> This principally came to light when I was trying to create a
> multiplexing security provider (basically a "Composite" that was
> supported by a composite JetspeedUser) and ran into trouble using the
> supplied turbine provider with it.
>
>
>
> --
> jan grant, ILRT, University of Bristol. http://www.ilrt.bris.ac.uk/
> Tel +44(0)117 9287088 Fax +44 (0)117 9287112 RFC822 jan.grant@bris.ac.uk
> Scrabble gematria: "BIBLE" = "DOGMA"
>
>
> --
> To unsubscribe, e-mail:
<mailto:jetspeed-dev-unsubscribe@jakarta.apache.org>
For additional commands, e-mail:
<mailto:jetspeed-dev-help@jakarta.apache.org>



--
To unsubscribe, e-mail:   <mailto:jetspeed-dev-unsubscribe@jakarta.apache.org>
For additional commands, e-mail: <mailto:jetspeed-dev-help@jakarta.apache.org>


Mime
View raw message