For a specific use case in my employer's organization I did some initial
work on opening up Gremlin Server to authorization plugins. It would
certainly be stimulating to enable a wider audience to use this work by
contributing it to Apache TinkerPop. But I realize that, given the
complexity of authorization and its dependence on other TinkerPop
features, it is certainly not obvious that the TinkerPop team would want
to support it. The more so because of indications that the TinkerPop
team wants to move to a more focussed re-implementation based on recent
theoretical and managerial insights (TP4).
To facilitate a discussion whether or not to support authorization for
Gremlin Server in some way, I have written a concrete proposal published
at
https://yaaics.blogspot.com/2020/06/proposing-authorization-for-gremlin.html
I hope you can give it some attention and formulate your arguments in
favor or against it on the dev mailing list, or maybe provide
perspectives on an alternative proposal.
Best wishes, Marc
- [DISCUSS] Proposing authorization for Gremlin Server Marc de Lignie
-