Form Based Security Mechanism

From: ViperDK (noabuse.ViperDK@gmx.net)
Date: 02/13/03


From: "ViperDK" <noabuse.ViperDK@gmx.net>
Date: Thu, 13 Feb 2003 08:36:17 +0100


I have a WebPage which holds security information in a database.
There are [Users], [Roles] and [Rights] and each user can have multiple
roles which are assigned to multiple rights.

Up to now I check whether a user has enough rights to do something manually
with a UserManagement class. In the code it looks like:
um.HasRight(UserRights.ModeratePageNews)

Thats kind a elaborate and i wonder if i could do that more easily.
I think a good mechanism would offer the ability
- to classify specific pages e.g. only to be viewn with the right "Login"
- to place attributes on functions that that throw a security exception and
take the user to the login page or say him that he doesn't have the right to
do what he tried
- make that decisions in the functions itself for mor complicated actions
like i did it up to now

Is Form Autentication offering me this stuff or can i extend it to do that?
>From what i've read from examples that mechanism only knows Roles and Users
and i don't know if i can make this things with it or if it is even meant to
help me on the kind of security i want to implement.

Thx for advise,
ViperDK



Relevant Pages

  • RE: How to allow users to change their password?
    ... be set up to provide the Security dialog window for password changes. ... I'll have to login using their login ... > name/password first. ... See http://www.QBuilt.com for all your database needs. ...
    (microsoft.public.access.security)
  • Re: Enabling telnet, ftp, pop3 for root...
    ... Where did I say ANYTHING about not using authentication. ... You're presenting it like direct root login would be a total security ... DON'T have access to the port. ...
    (alt.os.linux)
  • security bulletins digest
    ... Login using your IT Resource Center User ID and Password. ... Digest Name: daily security bulletins digest ... HPSBTL0112-006 Security vulnerability in Red Hat Korean Installation ... The information in the following Security Bulletin should be acted ...
    (Bugtraq)
  • RE: 2K Server locking 98 users out
    ... >Windows Password. ... domain password but not their Windows password. ... Do you have security ... >successful and failed login attempts? ...
    (Focus-Microsoft)
  • Re: Linked Table-Embed Password
    ... > for the one login was the security. ... Don't confuse data security issues with data integrity issues. ... It may be common, but it's not secure. ... See http://www.QBuilt.com for all your database needs. ...
    (microsoft.public.access.security)