> DEs should be able but not required to provide their own configuration
> UI - this should be a reusable component like any other, and it should
> work in any compositor regardless of which toolkit it uses.

I agree with you. This should really be DE independent. I can see it in
some place like kdbus with some interface that if an application shares an
API with some requirements, kdbus should enforce them. Compositors/DE's can
in this case register some kind of callback to when kdbus need user
authorization/authentication and then just provide the necessary UI.
