[RESULT] [VOTE] SLING-10147 Require WebConsoleSecurityProvider2 service to exist?

2021-03-26 Thread Eric Norman
Hi, Time to tally the votes. These were the results : +1B: Bertrand Delacretaz, Eric Norman, Julian Sedding +1A: Konrad Windszus Since 1B was the more preferred solution I will proceed with merging the PR with those changes and close the 1A PR. FYI: Per discussions on the SLING-10147 JIRA tick

Re: [VOTE] SLING-10147 Require WebConsoleSecurityProvider2 service to exist?

2021-03-01 Thread Julian Sedding
+1B - I think the simpler solution is acceptable Regards Julian On Mon, Mar 1, 2021 at 7:29 PM Eric Norman wrote: > > +1B would be my slight preference. NOTE: that I have also > opened FELIX-6390 to ask for changes suggested by Julian that would make > that solution cover more scenarios. > > Un

Re: [VOTE] SLING-10147 Require WebConsoleSecurityProvider2 service to exist?

2021-03-01 Thread Eric Norman
+1B would be my slight preference. NOTE: that I have also opened FELIX-6390 to ask for changes suggested by Julian that would make that solution cover more scenarios. Unfortunately, we haven't gotten much closer to any consensus as the only people who have voted are the people who have already di

Re: [VOTE] SLING-10147 Require WebConsoleSecurityProvider2 service to exist?

2021-02-25 Thread Bertrand Delacretaz
Hi Eric, Thanks for presenting both options! On Wed, Feb 24, 2021 at 10:00 PM Eric Norman wrote: ... > B. PR #7 > ... > [X ] +1B Approve the solution from PR #7 .. I'm in favor of that one as it's less code. The only do

Re: [VOTE] SLING-10147 Require WebConsoleSecurityProvider2 service to exist?

2021-02-25 Thread Konrad Windszus
I am fine with both solutions but I have a slight preference for A. I am not sure that every WebConsoleSecurity Provider2 implementation works if called inside Sling. Some filters or request dispatcher includes may lead to hiding the credentials, so that the authenticate method may return false

[VOTE] SLING-10147 Require WebConsoleSecurityProvider2 service to exist?

2021-02-24 Thread Eric Norman
RE: SLING-10147 - scripting variables implementation details are exposed to not authorized users The comments from the issue have revealed different opinions on the best way to solve this. You may review the comments in jira for the details. I