2013/3/6 Lars Krapf <[email protected]>:
> if time-based access control
> is really needed.
Time based access restriction is one of the main use cases as Mike has
explained repeatedly.

> This is also an example of how this feature would weaken
> security. In order to allow access to a resource within a certain
> time-frame, you will have to open access completely on repository
> level, so the whole access control would depend on the Sling layer,
No, this is wrong - as I mentioned in my first post here and as has
been explained over and over again since Mike came up with the
proposal, this is an additional filter. The intention is not to
replace ACLs.

I'm really wondering why we are having this discussion over and over
again - we agreed some months ago to implement this feature in Sling.
Now Mike has started work and immediately everyone and his dog is
going back to the old discussion. :(

Carsten
-- 
Carsten Ziegeler
[email protected]

Reply via email to