Hacker News new | ask | show | jobs
by jzelinskie 1579 days ago
You're correct. The only thing I'd add is that post filters can also be done without a candidate set of resources by performing individual permission checks for each potential resource. This is slower, but, as I mentioned, it can actually be perform better than you'd think with some tricks.

Apologies for the delayed response.