[ https://issues.apache.org/jira/browse/GEODE-6994?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16961921#comment-16961921 ]
Juan Ramos edited comment on GEODE-6994 at 11/14/19 2:35 PM: ------------------------------------------------------------- -Make sure the documentation is 100% clear about using {{cache.xml}} and having a different {{MethodInvocationAuthorizer}} configured per member. See [this|https://github.com/apache/geode/pull/4161#discussion_r339253155] for details.- See GEODE-7452 instead. was (Author: jujoramos): Make sure the documentation is 100% clear about using {{cache.xml}} and having a different {{MethodInvocationAuthorizer}} configured per member. See [this|https://github.com/apache/geode/pull/4161#discussion_r339253155] for details. > Documentation for OQL Method Invocation Security > ------------------------------------------------ > > Key: GEODE-6994 > URL: https://issues.apache.org/jira/browse/GEODE-6994 > Project: Geode > Issue Type: New Feature > Components: docs > Reporter: Juan Ramos > Assignee: Juan Ramos > Priority: Major > Labels: GeodeCommons > > Delete the [Method Invocations > Section|https://github.com/apache/geode/blob/rel/v1.9.0/geode-docs/developing/query_select/the_where_clause.html.md.erb#L238-L262] > and add a new page, on which detailed documentation should be added about > the following: > * The new _OQL Method Invocation Security feature_. > * How to configure the new _OQL Method Invocation Security feature_. > * Each Out of Box Implementation: pros, cons and *_security risks_* > associated with each one (check the table within the > [Introduction|https://cwiki.apache.org/confluence/display/GEODE/OQL+Method+Invocation+Security#OQLMethodInvocationSecurity-Summary] > for details). > * Interface {{MethodInvocationAuthorizer}} and how/when the user needs to > provide its own. Requirement about the thread-safety and performance of the > implementation. > * Deprecation of the system property > {{QueryService.allowUntrustedMethodInvocation}} and how it can be replaced by > one of the Out of Box Implementations. -- This message was sent by Atlassian Jira (v8.3.4#803005)