Re: Secure realm of internal APIs to prevent costly access control lookups

2013-03-25 Thread Jukka Zitting
Hi Lukas, On Mon, Mar 25, 2013 at 5:09 PM, Lukas Eder lukas.e...@gmail.com wrote: Are there any such plans in OAK? Yes, but not exactly as you outline. Instead of having a special secure realm or other special modes that allows things like JCR API calls without access restrictions, we've built

Re: Secure realm of internal APIs to prevent costly access control lookups

2013-03-25 Thread Lukas Eder
Hi Jukka, 2013/3/25 Jukka Zitting jukka.zitt...@gmail.com: Hi Lukas, On Mon, Mar 25, 2013 at 5:09 PM, Lukas Eder lukas.e...@gmail.com wrote: Are there any such plans in OAK? Yes, but not exactly as you outline. Instead of having a special secure realm or other special modes that allows

Re: Secure realm of internal APIs to prevent costly access control lookups

2013-03-25 Thread Lukas Eder
2013/3/25 Jukka Zitting jukka.zitt...@gmail.com: Hi, On Mon, Mar 25, 2013 at 5:36 PM, Lukas Eder lukas.e...@gmail.com wrote: Let me put it bluntly. On a Unix system, sudo is so much more useful than going to the hard drive with a magnet and applying some Tesla magic, to bypass access control