2 ms·
The idea of having different declarative security realms is fine but it's not what the Java Security Manager is. The Java Security Manager is an API that allow
by _old_dude_ 5y ago
The idea of having different declarative security realms is fine but it's not what the Java Security Manager is.
The Java Security Manager is an API that allows to intercept and run codes, so devs use it as a Trojan Horse to patch code instead of fixing the root of the issue.
The Java Security Manager should die.
- vitus 5y agoGood news, it is going to die. https://openjdk.java.net/jeps/411 https://openjdk.java.net/jeps/411
- nl 5y ago> The idea of having different declarative security realms is fine but it's not what the Java Security Manager is. But.. it is? The JVM tracks where bytecode was loaded from, and then you can define a policy to limit what that code can do. Here's an example giving read-only access to /etc https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.0/html/how_to_configure_server_security/java_security_manager https://access.redhat.com/documentation/en-us/red_hat_jboss_...