Thanks Rajinimaski for the reposnse. Agree that if the changes are frequent, then first option wouldn't work efficiently. Also the other challenge is that in our case for each resource, it is easy/efficient to get a list of changes since last checkpoint (because of our model of deployment of customer databases) rather than getting a snapshot of allowed/disallowed across all customers for each resource.
In your PostFilter implementation, do you cache the acls in memory, then they get updated periodically externally to solr and the post filter just uses the cache or something along these lines? -- View this message in context: http://lucene.472066.n3.nabble.com/Document-Security-Model-Question-tp4101078p4102664.html Sent from the Solr - User mailing list archive at Nabble.com.