[
https://issues.apache.org/jira/browse/SLING-4888?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
angela updated SLING-4888:
--------------------------
Attachment: SLING-4888_2.patch
additional patch: untested default implementation in
{{AbstractSlingRepository2}}. Note: I deliberately didn't mark the new method
{{final}} as I have the feeling that implementations against a specific
repository implementation could provide an optimized solution, therefore just
leaving this as the 'default'.
> Add SlingRepository.impersonateFromService
> ------------------------------------------
>
> Key: SLING-4888
> URL: https://issues.apache.org/jira/browse/SLING-4888
> Project: Sling
> Issue Type: New Feature
> Components: JCR
> Reporter: angela
> Attachments: SLING-4888.patch, SLING-4888_2.patch
>
>
> as discussed before it it would be generally preferable to perform
> event-based with the original subject that triggered the event instead of
> using a clone of the privileged session that was used to register the event
> listener.
> using the original subject (instead of just using the privileged session)
> will ultimately always results in the same piece of code which consists of
> - {{SlingRepository.loginService}} or {{SlingRepository.loginAdministrative}}
> followed by
> - {{Session.impersonate}} to obtain a session associated with the original
> subject
> - {{Session.logout}} for the privileged session
> - {{Session.logout}} for the impersonated session
> To ease the usage of the original subject, which usually would be preferable
> from a security point of view, I would like to suggest to introduce
> {{SlingRepository.impersonateFromService}}, which not only reduced the total
> amount of code to be written but also helped developers to move away from
> using {{loginAdministrative}}. Furthermore an implementation may also take
> advantage of implementation details and avoid the duplicate authentication
> altogether.
> Initial proposal of the API extension -> see attached patch
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)