Designating the resource with certificate capabilities

9 views
Skip to first unread message

Alan Karp

unread,
Aug 7, 2026, 6:31:06 PM (9 days ago) Aug 7
to cap-talk, <friam@googlegroups.com>
I'm back again with this topic.  If you recall, in my last message on this topic I concluded that I'm an idiot.  That may be true, but I'm a stubborn one.

To refresh your memory, some certificate capability systems designate resources with the delegation certificate.  Others designate the resource with an identifier of the certificate, such as the hash of its contents.  I have no problem with them.

In other systems, you designate a resource by a string that denotes the name of the resource specified in the delegation certificate.  Most systems avoid name collisions by using URIs or something similar.  My intuition is that this option can lead to confusion, but I hadn't come up with an example until now.

Imagine that Alice delegates to Bob query permission on some resource, say example.com/foo and that Carol delegates update permission to the same resource.  Bob now wants to invoke Dave's service, providing the query permission for the first argument and the update permission for the second.  He has no way to express his intent.

It's a corner case to be sure, but is it convincing enough?

--------------
Alan Karp

Matt Rice

unread,
Aug 8, 2026, 3:59:06 PM (9 days ago) Aug 8
to cap-...@googlegroups.com, <friam@googlegroups.com>
Rather than answer your question, Let me just repeat back what I think
you are saying,
Since we can have multiple certificates designating separate
authorities to the same resource, and those authorities are designated
by a single resource name,
If we classify these as injective/surjective/bijective (as we
discussed while discussing the proposed proof of your rule for
avoiding confused deputy problems)
then we see this is surjective, has multiple arrows pointing from
authority to designation.

Where the arrows bijective function can be traversed going either
direction without ambiguity,
the same is not so for this particular surjective configuration...
Each authority points to a single
designation, but the reverse mapping has a designation which points to
multiple authorities.

If the whole point of designation is to designate authority
unambiguously, this feels like it is doing a bad job at that.
Reply all
Reply to author
Forward
0 new messages