Alan Karp

Results 13 issues of Alan Karp

Section 10.4 of https://identity.foundation/decentralized-web-node/spec contains the statement, >and delegation of authorized capabilities to others, if allowed by the owner of a Decentralized Web Node. and 10.4.1 includes, >The object MAY...

artifact: spec
attr: nit

Is it when the write is done or when the write request is received that counts? The fact that Cassandra used Last Write Wins for the latter confuses the issue....

artifact: spec
attr: nit

The current specification allows the capability for a collection to be used when accessing an individual member of that collection, which is a violation of the Principle of Least Privilege....

artifact: spec
attr: security
type: discussion

The example in Section 12.4.1 shows an attestation property under descriptor.ability.conditions that needs additional explanation to distinguish it from the top level attestation property.

This section is empty. Provide content or delete.

artifact: spec
attr: further-clarification-needed
stage: needs review

Revocation is a trickier subject than it first appears. Who has permission to revoke? What can be revoked with that permission? One point that is obvious but should be called...

type: question
artifact: spec
artifact:companion-guide
attr: further-clarification-needed

Timestamps are used in the last write wins commit strategy, but timestamps are unreliable. Clocks on computers exhibit strange behavior, sometimes jumping forward or even backward. A malicious party can...

artifact: spec
attr: security

A capability designates the object and the permission being authorized on that object. The method in the descriptor field specifies a single operation, and all allowed Actions take a single...

The examples don't show the response to the various Actions.

There appears to be no way to retrieve a stored object.