On Sun, Mar 1, 2009 at 2:44 PM, Sergei Beilin <[email protected]> wrote: > > Hello, Gustavo! > >> Therefore, unfortunately the only way to get closer to a MAC policy is to >> cover all your controller actions with predicate checkers -- which of course >> has little/nothing to do with MAC; in fact, attaching predicate checkers to >> controllers is anti-MAC. :( > > Hm. If I subclass from a RestController, add some repoze.what magic > there to disable access to it (let's call it MACRestController), and > then subclass *all* my RESTful controller from that > MACREstController?... > >> If, on the other hand, what you want is a DAC policy whereby a predicate >> checker covers the whole application, then that's perfectly possible. For >> example, you can force that to grant access to any controller, users must be >> logged in (but of course, some URls like "/login" must be whitelisted). Is >> this want you want? It's not a MAC policy strictly speaking because it's not >> a >> "access is denied unless told otherwise" approach, but it's very similar. > > I think it will work for me for some time until repoze.what v2 with > MAC will be released. And that will be the time to refactor the whole > application ;)
I'm sorry you guys lost me on the acronyms, I'm not a huge auth guy..... But I think this "MACRestController" that you are talking about is something I'm going to need very soon for an important app I'm writting, could you share this code? --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "TurboGears" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [email protected] For more options, visit this group at http://groups.google.com/group/turbogears?hl=en -~----------~----~----~----~------~----~------~--~---

