Hacker News new | past | comments | ask | show | jobs | submit login

> specifies an authorization language where checks can be carried by the token

Why? Wouldn't a developer prefer to implement this inside its application logic anyway?

Edit: I think I figured it out myself: you're likely targeting the case where someone with a certain authorization wants to give someone else a weaker form of that authorization (attenuation).




It could also let your clients do proactive validation without rewriting too much code, seems like?




Consider applying for YC's first-ever Fall batch! Applications are open till Aug 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: