ml-gradle
ml-gradle copied to clipboard
Use privileges over roles in security scaffolding
Describe the RFE
Exercising Privilege to Restrict Content talks about using privileges (like http://marklogic.com/xdmp/privileges/rest-reader) over roles (like rest-reader). I believe that's generally accepted guidance. Assuming so, I propose changing ml-gradle's scaffolding to set up the default roles to use privileges over roles.
I think the title of this issue got it backwards.. :)
You're right, @grtjn! fixed
Removing from 4.3, but will get to this some day. PR would be appreciated!
I'm short of spare time at the moment, but who knows. Do you have pointers to relevant code?
I like doing this, as privileges really are the way to go. Can rethink the generated roles as well. No possibility for a breaking change here as the files are generated and then a user is free to modify them however they see fit.
See https://github.com/marklogic/ml-app-deployer/pull/490