Re: [PROPOSAL]: Improve OQL Method Invocation Security

2019-06-28 Thread Juan José Ramos
Hello all, Below are some answers/comments to the questions and feedback gathered during the last round, along with some final ideas at the end of the email. [Aaron]: There is almost always trade-off between security and ease-of-use. The pr

Re: [PROPOSAL]: Improve OQL Method Invocation Security

2019-06-28 Thread Jacob Barrett
Juan, You asked people to comment in both the wiki and the emails but you didn’t include comments from the wiki below. I have two issues, the first I raised in the wiki is what about caching the authentication lookups: > Can we safely assume that some caching of authorization requests will be