473,698 Members | 2,588 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Fine-grained access control

dw
Hello. I've got my LDAP authentication working, and have authorization
working to a great extent as well: I'm limiting who can access the site by
using <allow users="smithj, harrisb, ...."> in the Web.config file.

Is it possible to use this file to also determine who can write to a
particular page and only read from another? The scenario I'm thinking of is
this:

User Page Permission
--------------------------------------------
smithj search.aspx Admin
smithj reports.aspx Read_Only
harrisb search.aspx None
harrisb reports.aspx Admin
........

Can this be accomplished using the User.IsInRole technique or will it
require custom role-management against a SQL database?
Is it possible to make it even more fine-grained, so that a person may have
permission to only view/edit a part of a page? Thanks.
Nov 19 '05 #1
2 1394
You can do it one of several ways:

1. Use <location> in your web.config to define who sees what.
2. Use <location> and group your pages into their own folders. This way you
will have less of <location> elements to declare.
3. You could do a IsInRole() on each page.

Options 1 and 2 are elegant... option 3 will work, but now you have to check
roles on each page.

--
Manohar Kamath
Editor, .netBooks
www.dotnetbooks.com
"dw" <co************ ***@uncw.edu> wrote in message
news:es******** ******@TK2MSFTN GP09.phx.gbl...
Hello. I've got my LDAP authentication working, and have authorization
working to a great extent as well: I'm limiting who can access the site by
using <allow users="smithj, harrisb, ...."> in the Web.config file.

Is it possible to use this file to also determine who can write to a
particular page and only read from another? The scenario I'm thinking of
is this:

User Page Permission
--------------------------------------------
smithj search.aspx Admin
smithj reports.aspx Read_Only
harrisb search.aspx None
harrisb reports.aspx Admin
.......

Can this be accomplished using the User.IsInRole technique or will it
require custom role-management against a SQL database?
Is it possible to make it even more fine-grained, so that a person may
have permission to only view/edit a part of a page? Thanks.

Nov 19 '05 #2
dw
Thanks, Manohar. Great idea. Can you point me to some examples of how to do
this? I've been finding results on Google, but wondered if you know of a
good one. Thanks.

"Manohar Kamath" <mk*****@REMOVE THISkamath.com> wrote in message
news:%2******** ********@TK2MSF TNGP14.phx.gbl. ..
You can do it one of several ways:

1. Use <location> in your web.config to define who sees what.
2. Use <location> and group your pages into their own folders. This way
you will have less of <location> elements to declare.
3. You could do a IsInRole() on each page.

Options 1 and 2 are elegant... option 3 will work, but now you have to
check roles on each page.

--
Manohar Kamath
Editor, .netBooks
www.dotnetbooks.com
"dw" <co************ ***@uncw.edu> wrote in message
news:es******** ******@TK2MSFTN GP09.phx.gbl...
Hello. I've got my LDAP authentication working, and have authorization
working to a great extent as well: I'm limiting who can access the site
by using <allow users="smithj, harrisb, ...."> in the Web.config file.

Is it possible to use this file to also determine who can write to a
particular page and only read from another? The scenario I'm thinking of
is this:

User Page Permission
--------------------------------------------
smithj search.aspx Admin
smithj reports.aspx Read_Only
harrisb search.aspx None
harrisb reports.aspx Admin
.......

Can this be accomplished using the User.IsInRole technique or will it
require custom role-management against a SQL database?
Is it possible to make it even more fine-grained, so that a person may
have permission to only view/edit a part of a page? Thanks.


Nov 19 '05 #3

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

3
2037
by: jerrygarciuh | last post by:
Hello everyone, Wondering if anyone else has had problems with gifs created by php or if anyone sees a problem with this code. Symptom: created jpegs work fine and created gifs work fine in Netscape and
2
2982
by: Eric Woudenberg | last post by:
I just installed a Python 2.3.4 Windows binary on a friend's WinXP machine (because the latest Cygwin-provided Python 2.3 build leaves out the winsound module for some reason). When I try and run this newly installed Python from bash it just hangs (no version message, no prompt, CPU is idle). When I run it from IDLE, or the DOS CMD prompt, it runs fine. Also, Python scripts using the new version run fine, even invoked on the bash command...
9
3328
by: Larry Woods | last post by:
I have a site that works fine for days, then suddenly, I start getting ASP 0115 errors with an indication that session variables IN SEPARATE SESSIONS have disappeared! First, for background information, I have a customized 500-100 page that sends the value of various session variables via email to my support site. The situation: On the home page of the site, the FIRST THING that is done is a Session
8
2347
by: Rick Hawkes | last post by:
Has anyone seen these symptoms? Running IIS 4.0 on NT 4.0. Service packed and updated to the max. Reboot system and everything works fine. After some undetermined period of time (between 10 and 36 hours) asp pages stop working and just hang. Normal HTML pages work just fine.
1
2334
by: Adrian Manic | last post by:
H We have a strange problem which I can not get my head around The entry point of the application is a file called home.asp. First it includes some files that define constants, then is resets / creates a Cookie called PROCAT and then outputs a basic HTML page. The Body tag has an OnLoad event that gets called on the Client Side which does some processing and then loads the main page. The application uses COM components and SQL Server but...
56
3583
by: john bailo | last post by:
I just installed mono from ximian on my redHat 9 workstation and wrote a simple program from the interesting book ado.net in c# by Mahesh Chand. mono is fun ( is there ado for linux ? why/why not? )
3
1889
by: Larry R Harrison Jr | last post by:
I designed this webpage: http://www.dbases.net/photography_pages/new_style_frames_index.html It has horizontal hover/pop-down menus; it works fine on the given machine run off the hard drive, but NOT off the Internet. However, on another machine in my house, it runs fine on the Internet, period--no problems. One of those machines it runs flawlessly on is the computer I designed it on; it also ran fine on a 3rd machine which is was NOT
6
1343
by: shror | last post by:
I need your help please in an aspx webpage. I have 2 combo boxes in the page The first combo load and when i select item from it then the other combo should be loaded then and this cenario work fine in Fire Fox but on Internet Explorer when i select the item from the first combo it doesn't load the second combo but it gives the yellow error mark in the statusbar <error in page> and the says error:
0
1186
by: service0073 | last post by:
Designs For Fine Jewelry Pieces Fine jewelry is created from the finest precious metals and the gems that are set in these metals could be what makes the jewelry so fine. Jewelry lovers can wear precious gems like sapphire, emeralds, diamonds, rubies, and birthstone gems in a variety of ways, but no matter what the designs are, the wearer will know that quality of workmanship is what makes wearing the fine jewelry so special....
0
8680
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
8609
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can effortlessly switch the default language on Windows 10 without reinstalling. I'll walk you through it. First, let's disable language synchronization. With a Microsoft account, language settings sync across devices. To prevent any complications,...
1
8899
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows Update option using the Control Panel or Settings app; it automatically checks for updates and installs any it finds, whether you like it or not. For most users, this new feature is actually very convenient. If you want to control the update process,...
0
8871
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the choice of these technologies. I'm particularly interested in Zigbee because I've heard it does some...
0
7738
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then launch it, all on its own.... Now, this would greatly impact the work of software developers. The idea...
1
6528
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new presenter, Adolph Dupré who will be discussing some powerful techniques for using class modules. He will explain when you may want to use classes instead of User Defined Types (UDT). For example, to manage the data in unbound forms. Adolph will...
0
5861
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert into image. Globals.ThisAddIn.Application.ActiveDocument.Select();...
0
4622
by: adsilva | last post by:
A Windows Forms form does not have the event Unload, like VB6. What one acts like?
2
2335
muto222
by: muto222 | last post by:
How can i add a mobile payment intergratation into php mysql website.

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.