On Sunday, May 17, 2015 at 4:09:35 PM UTC-4, Encompass solutions wrote:
>
> Each role in the system is going to need different tables.  To improve 
> security it would be good to restrict the roles to only have access to 
> certain tables, rather than depend on only the controller to enforce this 
> kind of database access.
>

In that case, you might even consider conditionally defining models 
depending on role -- if the relevant table model doesn't exist, it won't be 
possible to use the DAL to access any records.

Anthony

-- 
Resources:
- http://web2py.com
- http://web2py.com/book (Documentation)
- http://github.com/web2py/web2py (Source code)
- https://code.google.com/p/web2py/issues/list (Report Issues)
--- 
You received this message because you are subscribed to the Google Groups 
"web2py-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to