Fine grained security (view but not update)

Discussion started by Søren D, Apr 6, 2009.

  Søren D

    Søren D

    I am looking for good practices for allowing certain user roles to see but
    but update. For instance a user may have access to a certain updateable grid
    but are only allowed to view.

    The far most elegant way would of course be to remove the edit/delete/insert
    links from the view, but a less elegant solution is also sufficient.

    Has anyone published material on the subject or does anyone in here have
    some elegant ideas?


    Søren D, Apr 6, 2009
  Søren D

    Joe Kaplan

    Have you looked at the AzMan framework? It is general purpose application
    level authorization framework that allows you to program very granular
    authorization logic into your applications. It is not coupled to the UI in
    any way, so you would need to implement those bindings yourself but it is a
    generally useful way to consider implementing this type of logic.
    Joe Kaplan, Apr 6, 2009
  Søren D

    Søren D

    Thanks for your reply, but I am actually looking for the practical approach
    to coupling with UI and database

    Søren D, Apr 7, 2009
