W3C home > Mailing lists > Public > w3c-dist-auth@w3.org > April to June 2007

Re: PROPFIND Depth:1 and ACLs

From: Tim Olsen <tolsen718@gmail.com>
Date: Tue, 15 May 2007 09:00:45 -0400
Message-ID: <4be80d840705150600s605b4cd5l32797018e9c365c3@mail.gmail.com>
To: werner.donne@re.be
Cc: "Julian Reschke" <julian.reschke@gmx.de>, w3c-dist-auth@w3.org

On 5/15/07, Werner Donné <werner.donne@re.be> wrote:
> That is true. You have to join with the ACEs granting or
> denying the "read", "read-acl", "read-current-user-privilege-set"
> and "all" privileges. The result set should then be matched
> with the current user. This can't be part of the same join,
> because of group memberships.

They can be part of the same join if you keep a separate table of the
transitive closure of group memberships.

-Tim
Received on Tuesday, 15 May 2007 13:00:48 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 2 June 2009 18:44:15 GMT