Hacker News new | past | comments | ask | show | jobs | submit login

The set of possible Authorization policies without having some form of Authentication is quite limited ;)

Within ABAC schemes, Authorization is a boolean function over (Request, Principle, Environment). If you zero the Principle, you can still represent a large number of unique policies considering just the Request and the Environment.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
