For a specific use case in my employer's organization I did some initial work on opening up Gremlin Server to authorization plugins. It would certainly be stimulating to enable a wider audience to use this work by contributing it to Apache TinkerPop. But I realize that, given the complexity of authorization and its dependence on other TinkerPop features, it is certainly not obvious that the TinkerPop team would want to support it. The more so because of indications that the TinkerPop team wants to move to a more focussed re-implementation based on recent theoretical and managerial insights (TP4).

To facilitate a discussion whether or not to support authorization for Gremlin Server in some way, I have written a concrete proposal published at https://yaaics.blogspot.com/2020/06/proposing-authorization-for-gremlin.html

I hope you can give it some attention and formulate your arguments in favor or against it on the dev mailing list, or maybe provide perspectives on an alternative proposal.

Best wishes,    Marc



Reply via email to