Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In addition to what the neighbor comment says about authorization, an ACL is an internal service: it provides an “if (the user is allowed to X) then ...” to the business logic code. It's not a user-facing service.


I did assume this system handled authn as well as authz, which was a mistake.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: