Re: [Geoserver-devel] Pluggable Security

2008-07-08 Thread David Winslow
Hi all, I had a chat with Andrea in the IRC channel about this proposal, and decided it's not really worth a GSIP at this point. The new plan is to continue discussion on an RnD page (http://geoserver.org/display/GEOS/Pluggable+Authentication+Mechanisms) and hopefully come up with a proposal

Re: [Geoserver-devel] Pluggable Security

2008-07-08 Thread Andrea Aime
David Winslow ha scritto: ... > We use HTTP basic auth for authentication in OWS services, and a 'custom' > (not > really, since it's provided by Acegi) form + cookie system for the admin > page. > These share the roles database (which is used for authorization, but not > sufficient for deter

Re: [Geoserver-devel] Pluggable Security

2008-07-08 Thread David Winslow
On Tuesday 08 July 2008 12:43:42 Andrea Aime wrote: > David Winslow ha scritto: > > Hi all, > > > > I started writing this email before I realized how long it would be, so I > > have copied what I was originally going to say into > > http://geoserver.org/display/GEOS/GSIP+25+-+Pluggable+Authenticat

Re: [Geoserver-devel] Pluggable Security

2008-07-08 Thread Andrea Aime
David Winslow ha scritto: > Hi all, > > I started writing this email before I realized how long it would be, so I > have > copied what I was originally going to say into > http://geoserver.org/display/GEOS/GSIP+25+-+Pluggable+Authentication+Mechanisms > > on the wiki. This is just me musing

[Geoserver-devel] Pluggable Security

2008-07-08 Thread David Winslow
Hi all, I started writing this email before I realized how long it would be, so I have copied what I was originally going to say into http://geoserver.org/display/GEOS/GSIP+25+-+Pluggable+Authentication+Mechanisms on the wiki. This is just me musing on bugs (http://jira.codehaus.org/browse/GE