Re: [PROPOSAL]: Improve OQL Method Invocation Security

2019-07-01 Thread Juan José Ramos
Hello Jake, Thanks for your reply. Some comments below, inline. *>> Premature optimization can be bad but so can ignoring it. Most importantly here is to define the scope of an authorization. This will need to be defined as part of the API/SPI. If I was to implement one of these authorizers I wou

Re: [PROPOSAL]: Improve OQL Method Invocation Security

2019-07-01 Thread Jacob Barrett
> On Jul 1, 2019, at 6:55 AM, Juan José Ramos wrote: > >> Can we safely assume that some caching of authorization requests will >> be performed? What will the scope and lifetime of this caching be? Are the >> authentication rules and modules assumed to be immutable at runtime? All of >> this w

Re: [PROPOSAL]: Improve OQL Method Invocation Security

2019-07-01 Thread Juan José Ramos
Hello Jake, *>> You asked people to comment in both the wiki and the emails but you didn’t include comments from the wiki below.* I never said I was going to reply to comments in the wiki and to the email thread at the same time on the same day. I didn't forget your comments, BTW, I was going to a