Application level roles + Item level roles... how to do it?

From: Jéjé (willgart_A__at_hotmail_A_.com)
Date: 09/27/05


Date: Mon, 26 Sep 2005 19:06:48 -0400

Hi,

I'm looking for samples to manage system or application level security and
item level security.

I have an intranet application where the users can create & edit some
objects like "Employees".
>From the application level view, the user is authorize or not to create an
employee.
But when the user will create it, he can associate this employee to only
authorized organizationnal units.
After this, the user can edit only employees in authorized organizationnal
units, but he can view (but not edit) all other employees.

So the user has a application role and an orgnizationnal unit role, how to
combine these?

Also, I want to use an operation based access check instead-of a role based
security.
So, I'm trying to play with the AzMan, but this not useable for a "2
dimensions" security.

Today I manage this at the application level, but today a user can edit any
employees, not only authorized one.

(employees is just a sample, I have a lot of objectsand each one as will
have more then simple edition capabilities)

I want to define specific roles for each user/orgnization combination.

I'm using ASP.NET 2.
The integrated membership SQL provider is excellent for the application
level security. But not so good for my needs.

I love AzMan to manage the operations allowed in a role... so if there is
any solution using it... I'll take it ;)

thanks for your help.

jerome.



Relevant Pages

  • Re: Win2K PRO and Drive Access Passwords
    ... allowed access when I edit the Win2K access list? ... If, on each Win98 ... Or is it the machine name as Network ... > Windows 2000 uses a concept called user level security. ...
    (microsoft.public.win2000.networking)
  • Re: Clearing session variable values
    ... I would suggest clearing the state on the first step of an edit. ... another way you can track the state of each wizard is to generate ... in a session key based on that token. ...
    (comp.lang.php)
  • Field Level Security
    ... I am working on a web app that currently has page level security. ... have full access to edit the page otherwise you have read access. ... mayeb 10-20 a page. ...
    (comp.lang.java.programmer)
  • Deny copy/Save As permission
    ... >I have set up a folder on our network which is to store ... >reference material which we do not want employees to be ... >able to edit, copy to disc, 'save as' to any other ...
    (microsoft.public.win2000.security)
  • Help with Dialog box pop ups
    ... I have a dialog box that I want to use with several employees to clock in and ... I need to know how to get an edit box to reference a cell where ... Edit validation which I would use the option of "Number" for the password, ... I cant find a way to get the cell that the ...
    (microsoft.public.excel.programming)