Re: PrivilegedAction et al and JEP411

2023-06-19 Thread chap
On 2023-06-19 07:48, Peter Firmstone wrote: Having an authorization layer, made it more difficult for attackers to gain access to sensitive information, such as properties, especially if you were using policy files with least privilege principles. Agreed. I hope it did not seem as if my recent

Re: PrivilegedAction et al and JEP411

2023-06-18 Thread chap
On 2023-06-18 08:15, Alan Bateman wrote: Once the SM operating mode goes away then I would expect most usages of privileged actions in the JDK can be removed. Leaving them for an "authorization layer" to instrument would be misleading. Existing usages will quickly bit rot. It would also be a ta