Quantcast
Channel: Security
Viewing all articles
Browse latest Browse all 4737

Which is better - a user with many roles or a page accessible by many roles?

$
0
0

Hi all,

Lets assume a site can have multiple users - buyer, seller, admin

And we'll assume all pages in folder "~/buyer" can be accessed by users in the role of buyer, "~/seller" for seller and "~/admin" for admin.

Users with the role of admin should be also able to view "~/buyer" and "~/seller" pages.

Is it better to have a user with multiple roles - i.e. user "manager" is assigned the roles of admin, buyer and seller

web.config for "~/buyer" when user can have multiple roles

<system.web><authorization><allow users="buyer"/><deny users="*" /></authorization></system.web>

Or is it better to restrict access with multiple role definitions

web.config for "~/buyer" when user is assigned to one role

<system.web><authorization><allow users="buyer, admin"/><deny users="*" /></authorization></system.web>


Viewing all articles
Browse latest Browse all 4737

Trending Articles