Slotos

joined 2 years ago
[–] Slotos@feddit.nl 1 points 3 weeks ago

I’d probably add that for something like nextcloud granted scopes can be an „orthogonal”–for the lack of a better word–subset of requested scopes.

The set of requestable scopes has to be defined by the system itself, not its specific configuration. E.g. „files:manage”, „talk:manage”, „mail:read” are all general capabilities the system offers.

However, as a user I can have a local configuration that adds granularity to the grants I issue. E.g.: „files:manage in specific folders” or „mail:read for specific domains or groups only” are user trust statements that fit into the capability matrix but add an additional and preferably invisible layer of access control.

It’s a fairly rare feature in the wild and is a potential UX pitfall, but it can be useful as an advanced option on the grant page, or as a separate access control for issued grants.

[–] Slotos@feddit.nl 11 points 3 weeks ago (4 children)

https://oauth.net/articles/authentication/

That aside, why is nextcloud asking for scopes from remote API in the diagram? What is drawn on the diagram has little to do with OAuth scopes, but rather looks like an attempt to wrap ACL repository access into a new vocabulary.

Scopes issued by the OAuth authorization server can be hidden entirely. The issuer doesn’t hold any obligation to share them with authorized party since they are dedicated for internal use and can be propagated via invisible or opaque means.

I really can’t figure out what’s going on with that diagram.

[–] Slotos@feddit.nl 4 points 3 weeks ago

As a Ruby fan having a blast with Elixir, where the hell is anything BEAM related?

The compass is truly political.

[–] Slotos@feddit.nl 12 points 3 weeks ago

I’ve been gradually optimizing towards immediate existential dread over the past few years. Still get distracted sometimes, but I’m getting there.

[–] Slotos@feddit.nl 57 points 4 weeks ago (5 children)

Is king riding barefoot?

[–] Slotos@feddit.nl 7 points 1 month ago

High wealth inequality IIRC.

Which would explain recent pivot to the right. Although that has global factors fueling it that might outweigh anything local.

[–] Slotos@feddit.nl 18 points 1 month ago (4 children)

Are you stupid or are you paid? „Let them have land” is literally the simplest most retarded solution, yet you dare use that descriptor against something else.

Ceding land to Russia doesn’t stop people from dying. Never did, never will do.

I get it, your sorry pathetic ass is tired of war that you’re not affected by. You’d rather sweep a few million lives under the rug and call it peace.

Well, your voice belongs under that very rug.

[–] Slotos@feddit.nl 1 points 1 month ago

Following years of under-investment and despite increasing ticket prices, DB continues to make annual losses.

Ah, so nothing’s gonna change.

[–] Slotos@feddit.nl 2 points 1 month ago (1 children)

Russian allies also don’t give a fuck about red lines.

Whereas Ukraine’s allies were so unwilling to commit, that the war that could’ve been finished in the first year is increasingly likely to transition into EU invasion.

[–] Slotos@feddit.nl 14 points 1 month ago

Would? They already do.

[–] Slotos@feddit.nl 3 points 1 month ago

UIA is effectively defunct. Iran isn’t gonna pay anyone shit. The whole ruling, if it were to be taken seriously, would ground flights in Israel.

This looks „performative”. I hope there are enough assets left for families of the victims to get a reasonable compensation - that is frankly the best way to liquidate assets of a bankrupt company. I don’t actually expect it - creditors tend to strip everything, leaving barely an insult behind.

[–] Slotos@feddit.nl 5 points 1 month ago

You pronounce it yiff, obviously.

view more: ‹ prev next ›