Re: Bindings and permissions

Lisa Dusseault wrote:
> I guess our mis-alignment is partly based on whether ACL supports 
> dynamic ACL inheritance.  Since I know of more than one server 
> supporting ACL that does dynamic inheritance, I figure that whether or 
> not ACL theoretically supports dynamic inheritance, in practice it does.

Then that server has chosen an ACL model that is undefined under RFC3744.

> Still, I would argue that's irrelevant.  Doesn't a client have an 
> expectation that when it does a BIND request
>  - that the resource being bound doesn't become less accessible, or more 
> accessible, as a result of the request; in other words that the BIND 
> request has reasonably predictable side effects
>     - regardless of whether the server supports ACL spec
>     - regardless of whether the server supports dynamic inheritance, 
> which as you say isn't really discoverable?

All of these are good questions, but I don't see how BIND can possibly 
answer that, when even the behavior for single bindings is not defined 
within any IETF spec.

Best regards, Julian

Received on Monday, 23 January 2006 17:48:35 UTC