Hi,

AFAIU we apply permission for API entity. API does not know anything about
publisher and store. The permission model (Role/group based ) should handle
the visibility at the store and publisher. The permission assigned to API
should be generic. There should not be separate permissions for publisher
and store in the API. If we are keeping  two sets of permission for API,
then we are binding the API entity to publisher and store. I think that is
not a good design.

Thanks!
Rajith

On Wed, Mar 15, 2017 at 10:47 AM, Pubudu Gunatilaka <[email protected]>
wrote:

> Hi,
>
> Based on the recent queries we got, users try to bring the tenancy model
> for managing APIs. For an example there can be two developers who create
> APIs for two departments such as marketing and enginnering. Basic idea is
> that those APIs are only visible for particular group in store which we can
> achieve. On the other hand same thing is expected in publisher side as well.
>
> Only concern I see here is whether we support this kind of a separation in
> APIM 3.0.
>
> Thank you!
>
>
> On Wed, Mar 15, 2017 at 9:54 AM Roshan Wijesena <[email protected]> wrote:
>
>>
>> On Wed, Mar 15, 2017 at 12:48 AM, Uvindra Dias Jayasinha <
>> [email protected]> wrote:
>>
>> How can we support this by only sticking to the new permission model? We
>> need to make the API visible in the store side but hide it on the publisher
>> side(other publisher users).
>>
>>
>> As I understood, your requirement is to hide an API from other developers
>> in publisher but in the store that should be visible to everyone is it? In
>> that case, if other publishers log into the store they still can see other
>> APIs no?
>>
>>
>> --
>> Roshan Wijesena.
>> Senior Software Engineer-WSO2 Inc.
>> Mobile: *+94719154640 <+94%2071%20915%204640>*
>> Email: [email protected]
>> *WSO2, Inc. :** wso2.com <http://wso2.com/>*
>> lean.enterprise.middleware.
>> _______________________________________________
>> Architecture mailing list
>> [email protected]
>> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture
>>
> --
> *Pubudu Gunatilaka*
> Committer and PMC Member - Apache Stratos
> Software Engineer
> WSO2, Inc.: http://wso2.com
> mobile : +94774078049
>
>
> _______________________________________________
> Architecture mailing list
> [email protected]
> https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture
>
>


-- 
Rajith Roshan
Software Engineer, WSO2 Inc.
Mobile: +94-72-642-8350 <%2B94-71-554-8430>
_______________________________________________
Architecture mailing list
[email protected]
https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Reply via email to