|
Relational NT
A relational database kernel shaped around NT-style object management.
|
manager More...
manager
Evaluates connection claims and object permissions.
Permission checks are intentionally separated from lookup. The object manager can retrieve a candidate object, while this manager decides whether the caller is allowed to use it.
Permissions are strictly capability-based and must be explicitly granted. There is no implicit flow of access rights from a parent namespace entry to its children (no SD inheritance). A caller who holds READ on a multigroup does not thereby hold READ on its constituent relations — that is a separate, explicit capability.