- pause execution for a policy engine or user input
- variable scope permissions independent of what was requested. eg user needs to allow just this request to /test/myfile.txt or grant /test/* in that moment
- add (ideally also remove) capabilities based on dynamic user input or engine decisions without up front configuration
- not need application support, if apps need to support it the moment the harness uses an external tool the model breaks
deno, workerd and maybe a vm/docker solution with an webdav proxy mount and web-proxy are the only environments i am aware of where systems like this could be build at all, even there, with limitations. (Not writing this to sound absolute but to learn about other options I am missing.)
juancn•1h ago
- Antoine de Saint-Exupéry
grim_io•59m ago
jk