chewbranca commented on issue #1246: [DISCUSS] Remove duplicate authorisation check URL: https://github.com/apache/couchdb/pull/1246#issuecomment-377574554 @janl: 0) sounds good, 👍 1) agreed. In principle the check https://github.com/apache/couchdb/blob/884db891de6f7004f31a9a1a9d50b0162b1dca8e/src/chttpd/src/chttpd_auth_request.erl#L94-L96 _seems_ like it should do the right things and obviate the need for the check in `chttp_db:do_db_Req`, so this seems like the right approach, but we'll also want to keep in mind @davisp's point in https://github.com/apache/couchdb/pull/1246#issuecomment-376569046. 2) the blocker for cassim is the current security dichotomy where we have clustered level security in `chttpd`, and shard local security in `couch_db.erl`. We need to remove the shard local security model and then cassim will be rocking. There's been some discussion around this a few times, and the general consensus seems to be folks are on board with dropping the shard local security model. Now we just need to make it happen.
---------------------------------------------------------------- This is an automated message from the Apache Git Service. To respond to the message, please log on GitHub and use the URL above to go to the specific comment. For queries about this service, please contact Infrastructure at: [email protected] With regards, Apache Git Services
