Action from last week - what do we do with anonymous requests when there is a filter which assumes metadata

Cantor, Scott cantor.2 at osu.edu
Fri Nov 8 11:59:41 EST 2013


On 11/8/13, 11:37 AM, "Rod Widdowson" <rdw at steadingsoftware.com> wrote:

>Scott (I think it was) made the case that a rule like
>"AttributeRequesterInEntityGroup" should just return FALSE (not fail) in
>the
>case where there is no AttributeRequester.  This *only* make a difference
>in
>the negated and deny cases.  What do we think should happen?

I'm open to being overruled, but I did have the view that saying "NOT in
group X" should succeed in the absence of metadata. From the code's PoV,
we have no reason to believe the entity is in that group, so...

I understand the ambiguity, but I also think NOT/Deny rules in general are
always subject to information suppression attacks. Use them at your peril.

-- Scott




More information about the dev mailing list