Is it possible to configure Riak so that it is impossible to use the REST API to list all the keys in a bucket?

I would like to use a "capability security" approach where all the keys are unguessable random strings, such that possession of a key gives a client authorization to fetch the data for that key, and a client who does not have the key cannot fetch the data.

However, the ability to list all the keys in a bucket defeats that security model.

Thanks,
__
Eamonn O'Brien-Strain
HP Labs

_______________________________________________
riak-users mailing list
riak-users@lists.basho.com
http://lists.basho.com/mailman/listinfo/riak-users_lists.basho.com

Reply via email to