Two topics here :-)

About access control. I worked with SUNs XACML implementation and it has a
very good Java API. It is not necessary to bother about the XML stuff, the
library does it behind the scenes. The only thing I wanted to point out is
that if we add access control features we should discuss the current access
control system. (I am not insisting on XACML, but it is powerful).

About security system confusion. What about packaging the LDAP and JDBC
stuff as an extension ?.  And yes,  the documentation is not finished and
some docs are not up to date. I am working on this in my spare time if
possible.

Cheers
Christilan




2013/6/12 Andrea Aime <[email protected]>

> On Wed, Jun 12, 2013 at 4:37 PM, Justin Deoliveira 
> <[email protected]>wrote:
>
>> I agree with Andrea that i would be weary of complexity here, even if we
>> do try to hide it from users. We took this approach with the authentication
>> changes and imo it is not all that user friendly compared to other systems
>> that offer similar authentication options.
>>
>> Unless you spend a lot of time designing the user interface up
>> front undoubtedly development complexity will creep through. Case in point:
>> currently the user needs to know what user group and role services are. For
>> power users this may not be an issue, they probably like the flexibility,
>> but for the average user it's confusing.
>>
>
> Agreed, make a workshop recently and people were confused by the many
> options available (why are there multiple services, why are role services
> separate, why is LDAP showing up in multiple places and so on): for a power
> user it makes sense, but for the common one it's a maze to get lost in.
>
> Cheers
> Andrea
>
>
> --
> ==
> Our support, Your Success! Visit http://opensdi.geo-solutions.it for more
> information.
> ==
>
> Ing. Andrea Aime
> @geowolf
> Technical Lead
>
> GeoSolutions S.A.S.
> Via Poggio alle Viti 1187
> 55054  Massarosa (LU)
> Italy
> phone: +39 0584 962313
> fax: +39 0584 1660272
> mob: +39  339 8844549
>
> http://www.geo-solutions.it
> http://twitter.com/geosolutions_it
>
> -------------------------------------------------------
>



-- 
DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH
------------------------------------------------------------------------------
This SF.net email is sponsored by Windows:

Build for Windows Store.

http://p.sf.net/sfu/windows-dev2dev
_______________________________________________
Geoserver-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Reply via email to