Attendees

General

Agenda

  1. AuthN/Z Design and Use cases

Minutes

Topics

  1. Transparency in security in REST interface
  2. Clearly defined extension points, and prioritization
  3. We are not securing URLs, we are securing objects/datastreams... the model
  4. Short-term goals
  5. Persistence should be unified?

Transparency in security in REST interface

  1. In f3 it is difficult for Islandora to use security
  2. Desire for something that is easy to use from the API level
  3. Would like to not have two security layers
  4. Is there an example that demonstrates these principles
  5. Suggestion that security may not be appropriate at the Fedora level
  6. Interest in the ability to create a responsive UI
  7. Would like to introspect objects, or sets of content
  8. Enforcing security on f4 objects will require multiple calls within the app
  9. We need to seriously consider performance
  10. Reflecting on unix and DBs

Clearly defined extension points, and prioritization

  1. Want to avoid requiring users to learn new tools
  2. Need unified, simple, consistent tooling
  3. Get agreement on what frameworks will be used

We are not securing URLs, we are securing objects/datastreams... the model

  1. If we secure the model, we are securing the URLs
  2. Wisc is unable to support securing obfuscated URLs
  3. The question is, how to do it efficiently

Short-term goals

  1. PEP can be made effective
  2. First cut, store policies within f4
  3. Goal
  4. Two questions
    1. What permissions does this principal have?
    2. What can I do?

Persistence should be unified?

Actions