Re: Comment: untrusted environments and security

> My suggestion is that XProc explicitly allows implementations to run
> with (implementation-specific) heightened security.  Certain steps 
> can throw a dynamic error if they would otherwise violate the 
> security policy for the environment that the pipeline is running in.
> XProc need not define the security requirements, nor even what the 

Oops, pressed send too soon...  What I meant to say was "nor even what the 
precise dynamic error code should be".  In other words, all I am 
suggesting is a broader acceptance of what a conforming processor is.

Received on Monday, 24 September 2007 07:53:41 UTC