Table of Contents

Time/Place

This meeting is a hybrid teleconference and IRC chat. Anyone is welcome to join...here's the info:

  • Time: 11:00am Eastern Daylight Time US (UTC-4)
  • ReadyTalk:
    • U.S.A/Canada toll free: 866-740-1260, participant code: 2257295
    • International toll free:
      • http://www.readytalk.com/intl
      • Use the above link and input 2257295 and the country you are calling from to get your  country's toll-free dial-in number
      • Once on the call, enter participant code 2257295
  • IRC:

Attendees

Agenda

Previous Actions

Minutes

3.7 Release Update
  1. Scott found a few problems
    • Classpath is so long that windows does not have a long enough buffer
    • Java6/7 testing
    • getDataFromWeb defaults to using 8080
      • This issue is still outstanding
  2. Update again next Thursday
  3. Note: Scott will be working on f4 opportunistically once 3.7 is out
Fedora 3 -> 4 upgrade
  1. Considering a few options
    • Federating over f3 objects/datastreams
    • Federating over f3 HTTP-API - first draft
  2. Other items to be addressed
    • Versioning
    • Audit
  3. Will we need a full list of pids?
    • There is a "pagable" interface for paging through the children
  4. FilesystemConnector does not sanitize paths
AuthN/Z
  1. Implementing client-facing side of authZ
  2. Targeting "pre-authenticated" scenario
  3. Starting with a mock of the pep
  4. PEP is over the entire set of modeshape operations
  5. Repo managers can control access with their own PEPs
  6. Could potentially expose "access control manager" service
    • Native to JCR
  7. Wisc, working on a simple XACML rules engine
    • Concerned with speed/performance
    • Rules stored outside of f4
    • Will likely be choosing an existing XACML engine project
    • Example usecase: embargo etd for five years for the history department
  8. Noting, embargo is a common usecase
  9. UVa, would like to integrate institutional IdP
    • Shibboleth, and PubCookie
  10. Colorado Alliance, using XACML
    • Have user-classes, and different roles across the repo
    • Need to ensure that Islandora supports access control design
  11. There is a need to be able to check the access controls at any point in the repo
  12. Follow-up meeting
    • We will set up a follow-up AuthN/Z meeting

Actions

  • Andrew Woods to setup follow-up meeting on topic of AuthN/Z
#trackbackRdf ($trackbackUtils.getContentIdentifier($page) $page.title $trackbackUtils.getPingUrl($page))
  • No labels