On Tue, Dec 21, 2010 at 11:33 PM, Chris Holmes <cholmes@anonymised.com501…> wrote:
+1 on the GSIP, as long as Mark’s backwards compatibility concerns are addressed, though I’m pretty sure they are. This sounds like a solid step towards an awesome security system.
Yep yep, definitely want to keep backwards compatibility, in fact the default security config implemetation
won’t be changed one bit, the proposal is to make a more powerful security possible, so
we are going to add all the machinery to make it possible but the default implementation
of ResourceAccessManager will back onto the existing implementation, meaning it won’t leverage
per row or attribute filters.
The implementation we’re getting funded for is going to integrate with a in-house external security
manager using SOAP services to communicate with it, so it’s not something we can contribute back,
however these changes should ease up both improving the GS built-in authorization system later
or pluggin in others.
Nice paper too, I’ll definitely be pointing people to it to explain why all the proxy projects aren’t that great. One thing you might consider in the paper is explicitly addressing the one advantage of a proxy - that you can secure many servers. I think with WMS and WFS cascading we now have a great answer to that, since you can back other servers on to the security settings. I like the idea of the WMSLimits being passed back to other GeoServers, so that if someone were to use a GeoServer as a pure proxy it’d be smarter than other GeoServers.
Cool, will add it to the document
Maybe sometime we should strip out all the other functionality from GeoServer and just have WMS/WFS datastores + security enabled and announce the new ‘GS Secure Proxy Project’ 
Ha, yeah, why not. The WFS proxying would be pretty powerful as we’d be able to parse and
chew the data, WMS proxying would not be much better than the existing ones though,
as wms cascading would unfortunately just get back an image…
Cheers
Andrea
Ing. Andrea Aime
Senior Software Engineer
GeoSolutions S.A.S.
Via Poggio alle Viti 1187
55054 Massarosa (LU)
Italy
phone: +39 0584962313
fax: +39 0584962313
http://www.geo-solutions.it
http://geo-solutions.blogspot.com/
http://www.linkedin.com/in/andreaaime
http://twitter.com/geowolf