Re: [RFC] Handle ACLs that are neither denied nor allowed

From: Henrik Nordström <henrik_at_henriknordstrom.net>
Date: Tue, 08 May 2012 22:47:50 +0200

tis 2012-05-08 klockan 13:36 -0600 skrev Alex Rousskov:

> There are caveats to using custom ACL keywords (mostly revolving around
> the implicit "negate the last keyword" rule), but this is the wrong
> thread to discuss them.

Yes. There should be a "default action" parameter to the access list
type detailing if the default is "negate / allow / deny". But generally
allow if last_was_a_normal_deny_without_any_extras else deny is
suitable, where deny equals to same action as if the directive is
unspecified in the more complex ones.

Regards
Henrik
Received on Tue May 08 2012 - 20:47:56 MDT

This archive was generated by hypermail 2.2.0 : Wed May 09 2012 - 12:00:04 MDT