jackrabbit-oak-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "angela (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (OAK-3003) Improve login performance with huge group membership
Date Tue, 28 Jul 2015 16:28:05 GMT

    [ https://issues.apache.org/jira/browse/OAK-3003?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14644605#comment-14644605

angela commented on OAK-3003:

ok... in case you happen do remember something that could potentially be affected, please
let me know. 

> Improve login performance with huge group membership
> ----------------------------------------------------
>                 Key: OAK-3003
>                 URL: https://issues.apache.org/jira/browse/OAK-3003
>             Project: Jackrabbit Oak
>          Issue Type: Improvement
>          Components: core
>            Reporter: angela
>            Assignee: angela
>              Labels: performance
>         Attachments: OAK-3003.patch, OAK-3003_2.patch, OAK-3003_3.patch, group_cache_in_userprincipalprovider.txt
> As visible when running {{LoginWithMembershipTest}} default login performance (which
uses the {{o.a.j.oak.security.principal.PrincipalProviderImpl}} to lookup the complete set
of principals) suffers when a given user is member of a huge number of groups (see also OAK-2690
for benchmark data).
> While using dynamic group membership (and thus a custom {{PrincipalProvider}} would be
the preferable way to deal with this, we still want to optimize {{PrincipalProvider.getPrincipals(String
userId}} for the default implementation.
> With the introduction of a less generic implementation in OAK-2690, we might be able
to come up with an optimization that makes use of the very implementation details of the user
management while at the same time being able to properly secure it as we won't need to extend
the public API.

This message was sent by Atlassian JIRA

View raw message