Closed jw3 closed 1 year ago
@jw3 In the meeting there was a decision to make objects that are untrusted (U) but allowed (A) orange/warning. If an object is untrusted (Red ST) but allowed should we also mark it orange/warning?
If an object is untrusted (Red ST) but allowed should we also mark it orange/warning?
That sounds right. Any type of U with A is a warning.
Code wise I think orange should be the default fall through color. If something is deny (D) it's red. If it's trusted either (green ST) or (green AT) and allowed (A) then it's green. Anything else should probably be orange. Seem right @jw3?
Code wise I think orange should be the default fall through color. If something is deny (D) it's red. If it's trusted either (green ST) or (green AT) and allowed (A) then it's green. Anything else should probably be orange. Seem right @jw3?
Yes, sounds like that covers all cases
In the context of the Object column the orange color is used for all allowed executions.
Change the color coding to represent: