[sugar] Activity versioning schema
Michael Stone
michael
Wed Jul 16 12:54:04 EDT 2008
On Wed, Jul 16, 2008 at 09:10:56AM -0400, Greg Smith wrote:
>Who can gather the consensus and take responsibility for updating the
>wiki if needed?
No one can, yet, because there's a real argument going on between the
people who have to live with the versioning scheme on the infrastructure
and security side and the people who want to use it in the UI.
In particular, there are non-trivial security issues with identifying
activities internally with _anything_ spoofable - i.e. with any
identifier that an activity can 'claim' without reference to some more
primitive sense of identity (e.g. a cryptographic manifest).
Consequently, as I have claimed on the several other occasions when this
discussion has come up, we are _not_ going to decide on an activity
naming and versioning scheme without having written down our use cases
and checked that the proposed design satisfies them.
What _should_ be happening in this thread is the collection of use
cases.
For a "small" selection of the issues involved, please refer to
http://wiki.laptop.org/go/User:Mstone/Commentaries/Bundles_1
http://wiki.laptop.org/go/User:Mstone/Commentaries/Bundles_2
Regards,
Michael
More information about the Sugar-devel
mailing list