On 15/05/15 11:57, Adam Young wrote: >> It's kind of unfortunate IMHO that the default policy.json files tend >> to give all users access to non-admin APIs, rather than requiring a >> specific role (like "Member"). > Working on that. Come to my policy session! This one, I assume: http://libertydesignsummit.sched.org/event/0c0aa8aa4b99c5f2c1781c7651f8e604#.VVaBEX_U-4M Is there going to be a design summit session related to this stuff as well? >> If OAuth makes all of these problems go away, then +1000 from me :) > No silver bullet. sorry. Dang ;) -ZB