Design suggestions on Permission handling
We have a rather complicated system for permissions at hour company for ASP.NET Core system we are running. So there are multiple applications and user's permission needs to carry over from one application to another so we are not creating a different permission table for each application for the user.
I found this from 8 years ago but since many new improvements made in this field, I wanted to bring it up to the table again.
Patterns / design suggestions for permission handling
How is the best way to handle permissions through multiple apps that proves to have the least amount of extra data and efficient?
c# database design-patterns asp.net-core permissions
|
show 3 more comments
We have a rather complicated system for permissions at hour company for ASP.NET Core system we are running. So there are multiple applications and user's permission needs to carry over from one application to another so we are not creating a different permission table for each application for the user.
I found this from 8 years ago but since many new improvements made in this field, I wanted to bring it up to the table again.
Patterns / design suggestions for permission handling
How is the best way to handle permissions through multiple apps that proves to have the least amount of extra data and efficient?
c# database design-patterns asp.net-core permissions
too broad with too little information
– Steve
Nov 8 '18 at 15:48
What other information needed?
– Peace
Nov 8 '18 at 15:50
what kind of permission? how are the permission relate to each other? are permissions for different app completely isolated from each other? whats the problem of storing all of them in one table? how many kinds of permissions do you anticipate? things like those
– Steve
Nov 8 '18 at 15:54
List of permission from ability to view, edit, add, delete to perform certain actions.Yes each app has its own isolated functions. There are so many attributes that needs to be allowed or not for each user. The problem is also, if we create a template and say each time we create a user we select a template to apply permissions, then at some point later we want to modify every xyz type of users we cant...
– Peace
Nov 8 '18 at 15:57
can you give some concrete example? still not convinced that group based policy wouldnt do the job
– Steve
Nov 8 '18 at 16:00
|
show 3 more comments
We have a rather complicated system for permissions at hour company for ASP.NET Core system we are running. So there are multiple applications and user's permission needs to carry over from one application to another so we are not creating a different permission table for each application for the user.
I found this from 8 years ago but since many new improvements made in this field, I wanted to bring it up to the table again.
Patterns / design suggestions for permission handling
How is the best way to handle permissions through multiple apps that proves to have the least amount of extra data and efficient?
c# database design-patterns asp.net-core permissions
We have a rather complicated system for permissions at hour company for ASP.NET Core system we are running. So there are multiple applications and user's permission needs to carry over from one application to another so we are not creating a different permission table for each application for the user.
I found this from 8 years ago but since many new improvements made in this field, I wanted to bring it up to the table again.
Patterns / design suggestions for permission handling
How is the best way to handle permissions through multiple apps that proves to have the least amount of extra data and efficient?
c# database design-patterns asp.net-core permissions
c# database design-patterns asp.net-core permissions
asked Nov 8 '18 at 15:46
PeacePeace
567
567
too broad with too little information
– Steve
Nov 8 '18 at 15:48
What other information needed?
– Peace
Nov 8 '18 at 15:50
what kind of permission? how are the permission relate to each other? are permissions for different app completely isolated from each other? whats the problem of storing all of them in one table? how many kinds of permissions do you anticipate? things like those
– Steve
Nov 8 '18 at 15:54
List of permission from ability to view, edit, add, delete to perform certain actions.Yes each app has its own isolated functions. There are so many attributes that needs to be allowed or not for each user. The problem is also, if we create a template and say each time we create a user we select a template to apply permissions, then at some point later we want to modify every xyz type of users we cant...
– Peace
Nov 8 '18 at 15:57
can you give some concrete example? still not convinced that group based policy wouldnt do the job
– Steve
Nov 8 '18 at 16:00
|
show 3 more comments
too broad with too little information
– Steve
Nov 8 '18 at 15:48
What other information needed?
– Peace
Nov 8 '18 at 15:50
what kind of permission? how are the permission relate to each other? are permissions for different app completely isolated from each other? whats the problem of storing all of them in one table? how many kinds of permissions do you anticipate? things like those
– Steve
Nov 8 '18 at 15:54
List of permission from ability to view, edit, add, delete to perform certain actions.Yes each app has its own isolated functions. There are so many attributes that needs to be allowed or not for each user. The problem is also, if we create a template and say each time we create a user we select a template to apply permissions, then at some point later we want to modify every xyz type of users we cant...
– Peace
Nov 8 '18 at 15:57
can you give some concrete example? still not convinced that group based policy wouldnt do the job
– Steve
Nov 8 '18 at 16:00
too broad with too little information
– Steve
Nov 8 '18 at 15:48
too broad with too little information
– Steve
Nov 8 '18 at 15:48
What other information needed?
– Peace
Nov 8 '18 at 15:50
What other information needed?
– Peace
Nov 8 '18 at 15:50
what kind of permission? how are the permission relate to each other? are permissions for different app completely isolated from each other? whats the problem of storing all of them in one table? how many kinds of permissions do you anticipate? things like those
– Steve
Nov 8 '18 at 15:54
what kind of permission? how are the permission relate to each other? are permissions for different app completely isolated from each other? whats the problem of storing all of them in one table? how many kinds of permissions do you anticipate? things like those
– Steve
Nov 8 '18 at 15:54
List of permission from ability to view, edit, add, delete to perform certain actions.Yes each app has its own isolated functions. There are so many attributes that needs to be allowed or not for each user. The problem is also, if we create a template and say each time we create a user we select a template to apply permissions, then at some point later we want to modify every xyz type of users we cant...
– Peace
Nov 8 '18 at 15:57
List of permission from ability to view, edit, add, delete to perform certain actions.Yes each app has its own isolated functions. There are so many attributes that needs to be allowed or not for each user. The problem is also, if we create a template and say each time we create a user we select a template to apply permissions, then at some point later we want to modify every xyz type of users we cant...
– Peace
Nov 8 '18 at 15:57
can you give some concrete example? still not convinced that group based policy wouldnt do the job
– Steve
Nov 8 '18 at 16:00
can you give some concrete example? still not convinced that group based policy wouldnt do the job
– Steve
Nov 8 '18 at 16:00
|
show 3 more comments
0
active
oldest
votes
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53211281%2fdesign-suggestions-on-permission-handling%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53211281%2fdesign-suggestions-on-permission-handling%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
too broad with too little information
– Steve
Nov 8 '18 at 15:48
What other information needed?
– Peace
Nov 8 '18 at 15:50
what kind of permission? how are the permission relate to each other? are permissions for different app completely isolated from each other? whats the problem of storing all of them in one table? how many kinds of permissions do you anticipate? things like those
– Steve
Nov 8 '18 at 15:54
List of permission from ability to view, edit, add, delete to perform certain actions.Yes each app has its own isolated functions. There are so many attributes that needs to be allowed or not for each user. The problem is also, if we create a template and say each time we create a user we select a template to apply permissions, then at some point later we want to modify every xyz type of users we cant...
– Peace
Nov 8 '18 at 15:57
can you give some concrete example? still not convinced that group based policy wouldnt do the job
– Steve
Nov 8 '18 at 16:00