Re: Security Assurance

2006-01-10 Thread Mladen Turk
Marsh David W Maj AFIT/ENG wrote: What I would consider useful is a 'compile time note' There would have to be a way to capture design intent through explicit markers (or perhaps an inference) identifying both the protected code and those code segments that are allowed to access the protected

RE: Security Assurance

2006-01-10 Thread Marsh David W Maj AFIT/ENG
Mladen Turk wrote: > Marsh David W Maj AFIT/ENG wrote: > > Tomcat Developers, > > > > While I understand that the libraries and extensions used by Tomcat > > *should* provide that assurance, what would happen if someone > > inadvertently wrote some code that could create a new object with > > ri

Re: Security Assurance

2006-01-10 Thread Mladen Turk
Marsh David W Maj AFIT/ENG wrote: Tomcat Developers, While I understand that the libraries and extensions used by Tomcat *should* provide that assurance, what would happen if someone inadvertently wrote some code that could create a new object with rights never intended by developers? What I w