Rather than create a hierarchical structure of permissions, I only use
Active Directory group membership.  If you are in the appropriate AD
group, you have access.  I can pass in multiple groups if that applies
as well.

It works quite well for me since our organizational structure is not
very deep.  Well, not deep in the respect that my security method has
caused any issues.

Next, I am going to give department managers the ability to add/remove
members from groups.  That way, they can control the security
themselves.

M!ke 

-----Original Message-----
From: Rich Kroll [mailto:[EMAIL PROTECTED] 
Sent: Monday, November 14, 2005 8:23 AM
To: CF-Talk
Subject: Module Security

Hello all,
I am in the process of trying to develop a new security model for a
project I am working on.  I've developed the base model with a hierarchy
of permissions to access areas of the application.  My problem is that
now I need to extend this to control certain modules within a page.
These modules are not consistent to a specific page, or even a sequence
of pages.  My first thought is to have each specific module register
with the system and then authenticate against that.  Has anyone set up
something along these lines and have any gotcha's I may be overlooking?
One fear is, since this will be managed by end users, how to communicate
what each "module" actually is for them to know if they want their users
to have access. For example, within an existing workflow, on the third
page in the process is an graph meant for administrators.  Trying to
explain "Process 1 step 3 graph" might get cumbersome.

Any ideas?

Rich

Rich Kroll
Application Developer
 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Discover CFTicket - The leading ColdFusion Help Desk and Trouble 
Ticket application

http://www.houseoffusion.com/banners/view.cfm?bannerid=48

Message: http://www.houseoffusion.com/lists.cfm/link=i:4:224063
Archives: http://www.houseoffusion.com/cf_lists/threads.cfm/4
Subscription: http://www.houseoffusion.com/lists.cfm/link=s:4
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.4
Donations & Support: http://www.houseoffusion.com/tiny.cfm/54

Reply via email to