Re: How many roles is too many?



You might want to check out a framework like AzMan. It allows you to map
high level application roles to lower level tasks and operations. Perhaps
the permissions in your app could be represented by operations and groups of
them might roll up into higher level concepts?

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
<Warm.Beer@xxxxxxxxx> wrote in message
news:1150331787.809031.295620@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Thanks for the prompt replies, guys.

I have definitely been turned off storing this amount of relately
static data in the client cookie.

The number and granularity of the permissions set is a business
requirement, so we can't easily remove any flexibility currently used
by our customers. BTW, it's ~1000 users per installation, not total
(my bad!)

I've had a bit of a look into the Membership/Role providers in 2.0, so
will probably proceed down that path, as it gives enough flexibility
without a lot of code.

Cheers,

Brett



.



Relevant Pages

  • Re: Web Single Sign On
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... current Windows credentials to the server, ... This common identity is the user's username used to logon to the ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Changing ADAM user password
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... Running the bind from another W2K3SP1 machine ... support in digest or something like that. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SignOn Problem during Team Foundation WebTest Playback
    ... That sounds likely to me (the query string parameters). ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.windows.server.active_directory)
  • Re: ASP.NET 2.0 WindowsTokenRoleProvider Local Groups Broken
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... There is no Group property on the WindowsIdentity object in .NET 2.0, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Secure SSL with LDAP and AD
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... LDAP over SSL with a third-party certification authority. ... Note that a self signed cert is probably a very poor choice as nothing ...
    (microsoft.public.windows.server.security)