summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--yuck.mdwn5
1 files changed, 5 insertions, 0 deletions
diff --git a/yuck.mdwn b/yuck.mdwn
index 08bf0ad..7f46226 100644
--- a/yuck.mdwn
+++ b/yuck.mdwn
@@ -170,6 +170,11 @@ reference in discussions.
from brute-forcing a password by trying many times.
* (TEMPLOCKNOTIFY) Yuck MUST notify an account owner of temporary
locking, out of band.
+* (ACLSIMPLE) It must be easy to understand and reason about ACL
+ rules. It may be good aid this by visualising.
+* (ACLTRY) There must be a way to test ACL rules: if *this* user in
+ *these groups* does *this* operation for *this* resource, is it
+ allowed? This may require additional support from the RP.
# Architecture: the ecosystem