Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-10410

Add a new authorization manager component that take care of external context

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 6.0.1
    • Fix Version/s: 6.1-rc-1
    • Component/s: Security
    • Labels:
      None
    • Difficulty:
      Unknown
    • Similar issues:

      Description

      Using the directly the AuhorizationManager to check access is not appropriate since it does not take into account contextual aspect, like the dropPermission feature, or the upcoming signed script feature.

      Using the XWikiCachingRightService from component is not pratical since it depends on old core and this is not a component.

      So we need a new component, independent of old core that take into account the context to provide authorization.

        Attachments

          Activity

            People

            • Assignee:
              softec Denis Gervalle
              Reporter:
              softec Denis Gervalle
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Date of First Response: