Re: [UMP] Request for Last Call

On Thu, Apr 8, 2010 at 5:08 AM, Arthur Barstow <art.barstow@nokia.com> wrote:

> We also have the Comparison of CORS and UMP document:
>
>  http://www.w3.org/Security/wiki/Comparison_of_CORS_and_UM
>
> If we are going to continue with two separate specs, I think it is important
> re expectations from Members and the Public, for there to be consensus on
> the relationship(s) between the two models e.g. why do we have two models,
> where do the models intersect, what use cases can only be met with one of
> the models, why they can't these two models be merged into a single model,
> etc.

Hi Arthur, I think I'm a bit confused about what you mean by "model"
here. The web's current access control model is based on ambient
authority, due to the combination of the Same Origin Policy and the
cross-origin presentation of cookies (resulting in CSRF and
clickjacking). Adding to this a spec that says:

  if (some flag) {
    send messages without ambient authority tokens
    and teach developers to use explicit authority tokens
  } else {
    send messages with additional ambient authority tokens
    and teach developers "don't be a deputy"
  }

may result is one spec. But this spec would still represent two
different models. CORS as a whole is not a model. It is simply an
operational spec that enables one to switch between mechanisms derived
from (at least) two different access control models.


-- 
    Cheers,
    --MarkM

Received on Thursday, 8 April 2010 14:37:16 UTC