jackrabbit-oak-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "angela (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (OAK-8190) Dedicated authorization for system users
Date Mon, 15 Apr 2019 07:18:00 GMT

    [ https://issues.apache.org/jira/browse/OAK-8190?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16817613#comment-16817613

angela commented on OAK-8190:

initial commit of the wip: revision 1857551.

> Dedicated authorization for system users
> ----------------------------------------
>                 Key: OAK-8190
>                 URL: https://issues.apache.org/jira/browse/OAK-8190
>             Project: Jackrabbit Oak
>          Issue Type: New Feature
>          Components: security
>            Reporter: angela
>            Assignee: angela
>            Priority: Major
> in a oak setup with immutable mounts we would like to be able to cover system users and
their permissions with a separate mount. while setting up a mount for system users is feasible
out of the box, this doesn't apply for the default access control content created for the
associated system user principals, which due to the nature of the default authorization implementation
will be distributed across the repository. in addition any entries created for any system
user principal may be collocated in a mutable policy with entries for regular principals and
where the order is crucial for the resulting effective permissions.Therefore it would be desirable
if in a mount-based setup system users and their permission setup were to be collocated in
the same mount.
> [~stillalex], fyi

This message was sent by Atlassian JIRA

View raw message