<?xml version="1.0" encoding="UTF-8"?>











<rss version="2.0" xmlns:jf="http://www.jivesoftware.com/xmlns/jiveforums/rss">



<channel>
    <title>Support Forums: Message List - Gabriel: New open source security framework</title>
    <link>http://www.theserverside.com</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    
        <generator>Jive Forums Silver 5.5.30 (www.jivesoftware.com)</generator>
    
    <pubDate>Tue, 21 May 2013 05:13:44 -0400</pubDate>


    <item>

        <title>OSAccess</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[About a year ago, I looked at the OSAccess library:<br><br><a href="http://www.opensymphony.com/osaccess/" target="_blank">http://www.opensymphony.com/osaccess/</a><br><br>I decided not to use it because I didn't think there was a <br>large community of...]]></description>
        

        <pubDate>Sat, 24 Jul 2004 16:47:31 -0400</pubDate>

        

        <jf:creationDate>Sat, 24 Jul 2004 16:47:31 -0400</jf:creationDate>
        <jf:modificationDate>Sat, 24 Jul 2004 16:47:31 -0400</jf:modificationDate>
        <jf:date>Jul 24, 2004</jf:date>
        <jf:author>Sean Sullivan</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>dynamic JAAS-based security framework for webapps</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[hi!,<br>this solution is implemented in the project called jGuard (<a href="http://sourceforge.net/projects/jguard" target="_blank">http://sourceforge.net/projects/jguard</a>).<br><br>jGuard is based on JAAS, and permit to use it in a web application...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 12:31:02 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 12:31:02 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 12:31:02 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>diabolo512 diabolo512</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Instance/Class based authorization</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[What you state is true. I did implement my own Policy and one of things I needed to address is continued support for sun's Policy (sun.security.provider.PolicyFile) implementation. What I did was to encapsulate PolicyFile in my own Policy implementation....]]></description>
        

        <pubDate>Thu, 22 Jul 2004 12:08:33 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 12:08:33 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 12:08:33 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Suhail M. Ahmed</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Gabriel?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[As far as I remember, no matter what your credentials are, there is no way past Gabriel back into paradise....I am not sure that this is not a little bit too restrictive for your average security framework...<br><br>Keep up the good work, Karl]]></description>
        

        <pubDate>Thu, 22 Jul 2004 11:54:53 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 11:54:53 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 11:54:53 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Karl Banke</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Instance/Class based authorization</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[Hi!<br><br>Indeed this is a very good article. Sean, you always have resources handy. A warning for those wanting to extends JAAS to implement instance based authorization. This solution implies the implementation of a new policy file, but this new...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 11:48:22 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 11:48:22 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 11:48:22 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>javier castanon</jf:author>
        <jf:replyCount>2</jf:replyCount>
    </item>


    <item>

        <title>Instance/Class based authorization</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[<blockquote>How can you extend JAAS to support instance-based authorization? </blockquote>Extend JAAS for class instance-level authorization<br><br><a href="http://www-106.ibm.com/developerworks/java/library/j-jaas/"...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 11:08:53 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 11:08:53 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 11:08:53 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Sean Sullivan</jf:author>
        <jf:replyCount>3</jf:replyCount>
    </item>


    <item>

        <title>Instance/Class based authorization</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[<blockquote>We've been looking at options for solving this kind of problem generically, and have come up empty. Each example of this seems to be based on application-specific data, and is tightly bound to the data access method (ie. &quot;SELECT * FROM...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 10:26:47 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 10:26:47 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 10:26:47 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Rickard Oberg</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Instance/Class based authorization</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[<blockquote>JAAS is also don't have support for instance based authorization, but it's extendable enough to add it manualy.</blockquote>How can you extend JAAS to support instance-based authorization? We've been looking at options for solving this kind...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 10:06:08 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 10:06:08 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 10:06:08 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Timothy High</jf:author>
        <jf:replyCount>5</jf:replyCount>
    </item>


    <item>

        <title>Instance/Class based authorization</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[Hello Stephan,<br>What about instance based authorization. Based on my experience its vital part of the most application.<br>Example, in the forum user makes a post, and only creator (owner) of the post is able to change it. How it is supported by...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 07:32:31 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 07:32:31 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 07:32:31 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Renat Zubairov</jf:author>
        <jf:replyCount>6</jf:replyCount>
    </item>


    <item>

        <title>Instance/Class based authorization</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[Helli Stephan,<br>What about instance based authorization. Based on my experience its vital part of the most application.<br>Example, in the forum user makes a post, and only creator (owner) of the post is able to change it. How it is supported by...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 07:32:19 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 07:32:19 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 07:32:19 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Renat Zubairov</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Gabriel: Principal vs Subject</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[<blockquote>This seems to indicate to me that a Principal directly represents a user. In JAAS etc., a user is represented by a Subject, which may have any number of associated Principals. </blockquote>I was simplifying the scenario. To be more precise,...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 07:21:40 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 07:21:40 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 07:21:40 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Rickard Oberg</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Gabriel: Principal vs Subject</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[<blockquote>The solution we're using right now is to also introduce roles, which is an aggregation of permissions. Roles can then be assigned to principals, which may be single users or groups of users.</blockquote>This seems to indicate to me that a...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 06:38:47 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 06:38:47 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 06:38:47 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Oliver Kamps</jf:author>
        <jf:replyCount>1</jf:replyCount>
    </item>


    <item>

        <title>Gabriel: New open source security framework</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[I always wondered who ever decided that letting a security officer modify a file, that will certainly never gets reloaded at runtime, and specify user access through some Java classes/methods names, instead of business related information, was a good...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 04:39:13 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 04:39:13 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 04:39:13 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Claude Vedovini</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Gabriel: New open source security framework</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[I've found that mapping to permissions instead of principals is not enough. If you've got 100+ principals, and 50+ permissions (and our app do), then you're going to get problems with the overhead of the security administration.<br><br>The solution we're...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 04:13:22 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 04:13:22 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 04:13:22 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Rickard Oberg</jf:author>
        <jf:replyCount>2</jf:replyCount>
    </item>


    <item>

        <title>Gabriel: New open source security framework</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=26961</link>

        

        
            <description><![CDATA[<blockquote>Gabriel is a security framework for Java. By using access control lists and permissions, Gabriel enables components to check access to actions. On top of that Gabriel protects methods like EJB does but without the overhead.It distinguishes...]]></description>
        

        <pubDate>Thu, 22 Jul 2004 02:55:24 -0400</pubDate>

        

        <jf:creationDate>Thu, 22 Jul 2004 02:55:24 -0400</jf:creationDate>
        <jf:modificationDate>Thu, 22 Jul 2004 02:55:24 -0400</jf:modificationDate>
        <jf:date>Jul 22, 2004</jf:date>
        <jf:author>Venkatakrishna Tirumala</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>



</channel>
</rss>

