Hi all,
Lets assume a site can have multiple users - buyer, seller, admin
And we'll assume all pages in folder "~/buyer" can be accessed by users in the role of buyer, "~/seller" for seller and "~/admin" for admin.
Users with the role of admin should be also able to view "~/buyer" and "~/seller" pages.
Is it better to have a user with multiple roles - i.e. user "manager" is assigned the roles of admin, buyer and seller
web.config for "~/buyer" when user can have multiple roles
<system.web><authorization><allow users="buyer"/><deny users="*" /></authorization></system.web>
Or is it better to restrict access with multiple role definitions
web.config for "~/buyer" when user is assigned to one role
<system.web><authorization><allow users="buyer, admin"/><deny users="*" /></authorization></system.web>