<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: SOA and Authorization: What’s so hard about it anyway?</title>
	<atom:link href="http://www.summa-tech.com/blog/2009/07/30/soa-and-authorization-part-1-what%e2%80%99s-so-hard-about-it-anyway/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.summa-tech.com/blog/2009/07/30/soa-and-authorization-part-1-what%e2%80%99s-so-hard-about-it-anyway/</link>
	<description>Summa Blog</description>
	<pubDate>Wed, 08 Feb 2012 05:39:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Beyond Role-Based Access Control &#124; Summa Blog</title>
		<link>http://www.summa-tech.com/blog/2009/07/30/soa-and-authorization-part-1-what%e2%80%99s-so-hard-about-it-anyway/comment-page-1/#comment-2793</link>
		<dc:creator>Beyond Role-Based Access Control &#124; Summa Blog</dc:creator>
		<pubDate>Wed, 03 Nov 2010 18:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.summa-tech.com/blog/?p=1037#comment-2793</guid>
		<description>[...] Row-level Filters Some authorization rules transcend binary permit/deny decisions; they instead state that results of a request be filtered to only those rows a user is authorized to view. For example, perhaps a doctor querying a patient database should only be shown those patients for whom he&#8217;s had contact, and hide the others. Or &#8220;users from San Francisco can only view customers from San Francisco&#8221;. I touched on this distinction between access control and filtering a bit more in a previous post. [...]</description>
		<content:encoded><![CDATA[<p>[...] Row-level Filters Some authorization rules transcend binary permit/deny decisions; they instead state that results of a request be filtered to only those rows a user is authorized to view. For example, perhaps a doctor querying a patient database should only be shown those patients for whom he&#8217;s had contact, and hide the others. Or &#8220;users from San Francisco can only view customers from San Francisco&#8221;. I touched on this distinction between access control and filtering a bit more in a previous post. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nate Miller</title>
		<link>http://www.summa-tech.com/blog/2009/07/30/soa-and-authorization-part-1-what%e2%80%99s-so-hard-about-it-anyway/comment-page-1/#comment-2629</link>
		<dc:creator>Nate Miller</dc:creator>
		<pubDate>Fri, 11 Jun 2010 22:54:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.summa-tech.com/blog/?p=1037#comment-2629</guid>
		<description>Wow - great post. Your questions echo a lot of the same challenges I've been struggling with conceptually in SOA. Where the hell does user authorization code live in an SOA system? The allure of using an ESB entity to play traffic cop in service-to-service requests is powerful, but this of course leads to terrible problems in its own right. Glad to see I'm not the only one struggling with these questions.</description>
		<content:encoded><![CDATA[<p>Wow - great post. Your questions echo a lot of the same challenges I&#8217;ve been struggling with conceptually in SOA. Where the hell does user authorization code live in an SOA system? The allure of using an ESB entity to play traffic cop in service-to-service requests is powerful, but this of course leads to terrible problems in its own right. Glad to see I&#8217;m not the only one struggling with these questions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Northrop</title>
		<link>http://www.summa-tech.com/blog/2009/07/30/soa-and-authorization-part-1-what%e2%80%99s-so-hard-about-it-anyway/comment-page-1/#comment-2570</link>
		<dc:creator>Ben Northrop</dc:creator>
		<pubDate>Mon, 10 May 2010 12:24:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.summa-tech.com/blog/?p=1037#comment-2570</guid>
		<description>Thanks guys!  Part 2 and 3 are in the works now.</description>
		<content:encoded><![CDATA[<p>Thanks guys!  Part 2 and 3 are in the works now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erik</title>
		<link>http://www.summa-tech.com/blog/2009/07/30/soa-and-authorization-part-1-what%e2%80%99s-so-hard-about-it-anyway/comment-page-1/#comment-2568</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Sun, 09 May 2010 07:47:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.summa-tech.com/blog/?p=1037#comment-2568</guid>
		<description>Very informative and interesting! 

Any plans for a follow up on this?</description>
		<content:encoded><![CDATA[<p>Very informative and interesting! </p>
<p>Any plans for a follow up on this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Srinivasan.P</title>
		<link>http://www.summa-tech.com/blog/2009/07/30/soa-and-authorization-part-1-what%e2%80%99s-so-hard-about-it-anyway/comment-page-1/#comment-2515</link>
		<dc:creator>Srinivasan.P</dc:creator>
		<pubDate>Sun, 28 Mar 2010 08:19:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.summa-tech.com/blog/?p=1037#comment-2515</guid>
		<description>Excellent post. Waiting in hope you'll post the Part2 soon...</description>
		<content:encoded><![CDATA[<p>Excellent post. Waiting in hope you&#8217;ll post the Part2 soon&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nitesh Garg</title>
		<link>http://www.summa-tech.com/blog/2009/07/30/soa-and-authorization-part-1-what%e2%80%99s-so-hard-about-it-anyway/comment-page-1/#comment-2493</link>
		<dc:creator>Nitesh Garg</dc:creator>
		<pubDate>Sat, 20 Mar 2010 11:36:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.summa-tech.com/blog/?p=1037#comment-2493</guid>
		<description>Hey Ben! 

This is an excellent post. Hope you find time soon for the follow up post!</description>
		<content:encoded><![CDATA[<p>Hey Ben! </p>
<p>This is an excellent post. Hope you find time soon for the follow up post!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

