| ▲ | uncommoncense 2 hours ago | |||||||||||||||||||||||||
What you're describing is essentially what the authorization system would need to do in order to answer the question "can this subject perform this action on this object?". If you're suggesting that the program should receive a list a priori, then there are potential scale issues since that list would need to be exhaustive of both nouns and verbs, which can be a large set. | ||||||||||||||||||||||||||
| ▲ | black_knight an hour ago | parent [-] | |||||||||||||||||||||||||
The point is to flip the burden of proof. Instead of an authorisation system trying to find a reason to give you permission, you have to carry the proof in the form of a “verb”. Which you use when you perform the action. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||