On Sat, Jan 29, 2011 at 11:17 AM, Danushka Menikkumbura
<danus...@wso2.com>wrote:

> It means action is denied. In security if it is not authorized that means
>> denied.
>>
>
> I do not think so. If the authorisation manager sees that the action is
> nether allowed nor denied, then it should abstain from saying anything and
> let the application act accordingly.
>
Lets take two scenarios.

1. Application has not set the authorizes details
2. Application has set the action to deny.

in both cases authorization manger returns false. (Obviously it can not
return true).

Then how you determine which case has cause authorization manger to return
false?

thanks,
Amila.


>
> Thanks,
> Danushka
>
>
> _______________________________________________
> Carbon-dev mailing list
> Carbon-dev@wso2.org
> http://mail.wso2.org/cgi-bin/mailman/listinfo/carbon-dev
>
>
_______________________________________________
Carbon-dev mailing list
Carbon-dev@wso2.org
http://mail.wso2.org/cgi-bin/mailman/listinfo/carbon-dev

Reply via email to