DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
Security models can be very simple (like the Apache Commons one, which simply states it is not safe to provide possibly-malicious input to Commons libraries unless otherwise specified), or grow into an extensive document such as the Apache Airflow one which provides an in-depth description of the capabilities of various roles and the responsibilities of system administrators deploying Airflow.
Examples of things that might be good to include in a security model:
- Are logs intended to be safe to expose to users with read-only authorization, or may they contain credentials?
- If your project has a web interface, are users who have an account with 'admin' authorization on the web interface also trusted to trigger arbitrary OS commands?