IS Team,

IIRC, one point that was mentioned during the meeting was a chained login
mechanism: where a user logging in was checked against each user store
until he's authenticated by one. Did I note this down correctly?

If so, and if we utilize this in, say WSO2 Cloud or in a massive App
Factory deployment, this may end up being a performance issue; especially
if you keep hitting it with invalid credentials.

Can we optimize this? Say using a key-value store where key=> username, value
=> array of user stores. Perhaps if the no. of keys is an issue, it could
also be a hash of the user name (collisions are not a concern). The goal is
to minimize the number of stores checked and to know immediately when a
username is invalid.


On Thu, Dec 19, 2013 at 1:26 PM, Prabath Siriwardena <[email protected]>wrote:

> Participants : Azeez, Srinath, Sameera,SameeraP Manoj, Kishanthan,Johann,
> Venura, Ishara, Chamath, Darshana, Pradeep, Prabath
>
> - Overall we agreed on the design.
> - Separate out IdentityService API in to tow top level APIs - one for
> store administration and another for user/group/role/permission
> administration
> - Authenticated user should be independent from the Authorization Store
> - JAAS implementation
>
> Next steps :
>
> - Commit the API code to Git
> - File based implementation for C5
> - Validate the API with further implementations with LDAP/AD
> - Documentation
>
> Will schedule another review in January.
>
> Thanks a lot everyone for your time..!
>
> Thanks & regards,
> -Prabath
>
>
> On Tue, Dec 17, 2013 at 3:15 PM, Johann Nallathamby <[email protected]>wrote:
>
>>  more details 
>> »<https://www.google.com/calendar/event?action=VIEW&eid=bTh1ZmxrY2p0YmlhaDcwZm51MDJvYnJoaWsgcHJhYmF0aEB3c28yLmNvbQ&tok=MTUjam9oYW5uQHdzbzIuY29tZjI0MmRkYzUxYWI1ZGViMWRlZDU4ZjdkZWZiNzkzODdiNzNmMWQ4Nw&ctz=Asia/Colombo&hl=en>
>> Carbon 5 User API Design Review
>> Carbon 5 User Core API Design - Public Review
>> *When*
>> Thu Dec 19, 2013 11am – 12pm Colombo
>> *Where*
>> LK 5th Floor Meeting Room - Garage 
>> (map<http://maps.google.lk/maps?q=LK+5th+Floor+Meeting+Room+-+Garage&hl=en>
>> )
>> *Calendar*
>> [email protected]
>> *Who*
>>  •
>> Johann Nallathamby - organizer
>> •
>> Chamath Gunawardana
>> •
>> [email protected]
>> •
>> Paul Fremantle
>> •
>> Dimuthu Leelarathne
>> •
>> Darshana Gunawardana
>> •
>> Sameera Jayasoma
>> •
>> Asela Pathberiya
>> •
>> Prabath Siriwardana
>> •
>> Srinath Perera
>> •
>> Afkham Azeez
>> •
>> Sanjiva Weerawarana
>> •
>> Dulanja Liyanage
>> •
>> Sumedha Rubasinghe
>> •
>> Ishara Karunarathna
>> *Attachments*
>>  
>> c5-user-core-api-highlevel-design.png<https://lh6.googleusercontent.com/DiBqCFm-4bjETgEgayV1xMMJ9zxe-NWrMl2MLEzcBhjGjCf3foc2nDDo8dcHorwC9MdBBBREPSmKrtxsbP-FDMo=s400>
>>
>> Going?   *Yes
>> <https://www.google.com/calendar/event?action=RESPOND&eid=bTh1ZmxrY2p0YmlhaDcwZm51MDJvYnJoaWsgcHJhYmF0aEB3c28yLmNvbQ&rst=1&tok=MTUjam9oYW5uQHdzbzIuY29tZjI0MmRkYzUxYWI1ZGViMWRlZDU4ZjdkZWZiNzkzODdiNzNmMWQ4Nw&ctz=Asia/Colombo&hl=en>
>> - Maybe
>> <https://www.google.com/calendar/event?action=RESPOND&eid=bTh1ZmxrY2p0YmlhaDcwZm51MDJvYnJoaWsgcHJhYmF0aEB3c28yLmNvbQ&rst=3&tok=MTUjam9oYW5uQHdzbzIuY29tZjI0MmRkYzUxYWI1ZGViMWRlZDU4ZjdkZWZiNzkzODdiNzNmMWQ4Nw&ctz=Asia/Colombo&hl=en>
>> - No
>> <https://www.google.com/calendar/event?action=RESPOND&eid=bTh1ZmxrY2p0YmlhaDcwZm51MDJvYnJoaWsgcHJhYmF0aEB3c28yLmNvbQ&rst=2&tok=MTUjam9oYW5uQHdzbzIuY29tZjI0MmRkYzUxYWI1ZGViMWRlZDU4ZjdkZWZiNzkzODdiNzNmMWQ4Nw&ctz=Asia/Colombo&hl=en>*
>>     more options 
>> »<https://www.google.com/calendar/event?action=VIEW&eid=bTh1ZmxrY2p0YmlhaDcwZm51MDJvYnJoaWsgcHJhYmF0aEB3c28yLmNvbQ&tok=MTUjam9oYW5uQHdzbzIuY29tZjI0MmRkYzUxYWI1ZGViMWRlZDU4ZjdkZWZiNzkzODdiNzNmMWQ4Nw&ctz=Asia/Colombo&hl=en>
>>
>> Invitation from Google Calendar <https://www.google.com/calendar/>
>>
>> You are receiving this email at the account [email protected] because you
>> are subscribed for invitations on calendar [email protected].
>>
>> To stop receiving these notifications, please log in to
>> https://www.google.com/calendar/ and change your notification settings
>> for this calendar.
>>
>
>
>
> --
> Thanks & Regards,
> Prabath
>
> Twitter : @prabath
> LinkedIn : http://www.linkedin.com/in/prabathsiriwardena
>
> Mobile : +94 71 809 6732
>
> http://blog.facilelogin.com
> http://blog.api-security.org
>
> _______________________________________________
> Architecture mailing list
> [email protected]
> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture
>
>


-- 

------------------------------

*Sameera Perera*
Senior Manager, Engineering (Platform TG)
gtalk: [email protected]
Tel : 94 11 214 5345
Fax :94 11 2145300
*WSO2, Inc.* <http://wso2.com/>
lean.enterprise.middleware
_______________________________________________
Architecture mailing list
[email protected]
https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Reply via email to