Print

Print


I asked for a change in the markdown but I do also want to bring to your attention that the approach taken is is likely not the best, Turning off validation is specific to ztn usage not to SciToken usage in any sense of the word. This is as much as you said. So, this change does not belong in the SciToken libraries which likely would not have been needed at all if validation is not desired. Additionally, it prevents coming up with say a ytn protocol that does validation and have a ztn protocol without it. Once validation is turned off it is turned off for everyone; which limits future options.

I strongly suggest that the ztn parameter "-tokenlib" which accepts a parameter also accept "-tokenlib=none" which automatically says you do not wish to use the tokenlib and this would turnoff validation. The changes are slightly more complicated but not enough to avoid this approach.

So, I guess what I am saying I would prefer the choice to validate or not to be done in XrdSecProtocolztn.cc as that is the logical place to do it; unless there is another reason that I don't know about.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/xrootd/xrootd/pull/1910#issuecomment-1432552951
You are receiving this because you are subscribed to this thread.

Message ID: <[log in to unmask]>

########################################################################
Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1