Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

TimeItemWhoNotes
5minOverview, review goals & wiki pageGreg
5minReview AuthZ delegate apiMike 
5minXACML Policies and JBoss PDPGreg 
20minIdentify some XACML implementation alternativesAll

Starting out we favor an internal PDP (configured as a bean within the webapp). The code can be in a separate project.

 

15minRole inheritance/persistence (Hydra rights, rbacl, XACML etc..)Greg 
15minWhat can we do in this sprint?All 

Action Items

  •  Kevin S. Clarke Investigate what data is available on incoming authz requests for newly created objects, i.e. in Session
  •  Do we have enough information via the Path parameter to determine access for metadata? (Implementation-specific identification of readable metadata)
  •  Eric James Identify trade-offs for different acl persistence strategies.

...