Hi Andrea, thanks for the long answer.

1) Chris wanted me to create an additional GSIP for Spring Security,  
originally I had GSIP 54 included in GSIP 53.

2) If you like I could add some sentences regarding Acegi Security.

3) The primary focus is pluggable authentication. Authorization is a  
later challenge.

4) The plan is to integrate Spring Security 2.0 and have  
authentication/authorization as it is. I only want to have Spring  
Security 2.0 in the trunk. After this has happened, I plan to make a  
public deployment of geoserver (like my build farm) to demonstrate  
progress to all developers. This is the point in time to dig deeper  
into the material and think about the concrete design. But as a  
prerequisite I need Spring Security on trunk, otherwise design ideas  
are more theoretical, no possibility to check something out.



Quoting Andrea Aime <andrea.a...@geo-solutions.it>:

> On Wed, Oct 20, 2010 at 4:39 PM,  <christian.muel...@nvoe.at> wrote:
>>
>> http://geoserver.org/display/GEOS/GSIP+54+Upgrade+Geoserver+security+to+Spring+Security+2.0
>
> If one reads the proposal he might think GeoServer uses its own
> authentication implementation, however
> that is not true, it uses Acegi, which is the old Spring Security,
> however it does so in a way that is not
> pluggable and that should be amended.
>
> Also, the proposal talks about "security" generically, and at one
> point about authentication/authorization.
> I'm +1 on making the authentication mechanism be pluggable and use
> Spring Security 2.0,
> but not on making the authorization use Spring Security instead: the
> authorization should be eventually
> made more pluggable, but I find the Spring Security way of doing
> authorization quite obscure.
>
> For both authentication and authorization I would like to see a design
> of how you want to modify the
> code to make it pluggable.
>
> I'm +1 on using Spring Security 2.0, however that by itself does not
> make much of a GSIP, I don't want
> for people to think that any implementation using Spring Security 2.0
> will be accepted because
> of the vote on the GSIP: a specific design will have to be provided
> and voted separately.
>
> Cheers
> Andrea
>
>
>> Christian
>>
>> ----------------------------------------------------------------
>> This message was sent using IMP, the Internet Messaging Program.
>>
>>
>>
>> ------------------------------------------------------------------------------
>> Nokia and AT&T present the 2010 Calling All Innovators-North America contest
>> Create new apps & games for the Nokia N8 for consumers in  U.S. and Canada
>> $10 million total in prizes - $4M cash, 500 devices, nearly $6M in marketing
>> Develop with Nokia Qt SDK, Web Runtime, or Java and Publish to Ovi Store
>> http://p.sf.net/sfu/nokia-dev2dev
>> _______________________________________________
>> Geoserver-devel mailing list
>> Geoserver-devel@lists.sourceforge.net
>> https://lists.sourceforge.net/lists/listinfo/geoserver-devel
>>
>>
>
>
>
> --
> -----------------------------------------------------
> Ing. Andrea Aime
> Senior Software Engineer
>
> GeoSolutions S.A.S.
> Via Poggio alle Viti 1187
> 55054  Massarosa (LU)
> Italy
>
> phone: +39 0584962313
> fax:     +39 0584962313
>
> http://www.geo-solutions.it
> http://geo-solutions.blogspot.com/
> http://www.linkedin.com/in/andreaaime
> http://twitter.com/geowolf
>
> -----------------------------------------------------
>



----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.



------------------------------------------------------------------------------
Nokia and AT&T present the 2010 Calling All Innovators-North America contest
Create new apps & games for the Nokia N8 for consumers in  U.S. and Canada
$10 million total in prizes - $4M cash, 500 devices, nearly $6M in marketing
Develop with Nokia Qt SDK, Web Runtime, or Java and Publish to Ovi Store 
http://p.sf.net/sfu/nokia-dev2dev
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Reply via email to