Professional Web Applications Themes

Require multiple role membership? - ASP.NET Security

Is there any way in the web.config "allow roles" authorization section, to AND the roles together? Eg. in my app, i have roles Customer, Employee, and Admininstrator. Now, there could be Admin employees, and Admin Customers, each with access to different sections. Is there a way to specifiy that you can only get into the folder "AppAdmin" if you are in role Employee AND role Administrator? As ive seen it before, the roles by default only OR together. Thanks in advance, - Arthur Dent...

  1. #1

    Default Require multiple role membership?

    Is there any way in the web.config "allow roles" authorization section, to
    AND the roles together?
    Eg. in my app, i have roles Customer, Employee, and Admininstrator. Now,
    there could be Admin employees, and Admin Customers, each with access to
    different sections.
    Is there a way to specifiy that you can only get into the folder "AppAdmin"
    if you are in role Employee AND role Administrator?
    As ive seen it before, the roles by default only OR together.

    Thanks in advance,
    - Arthur Dent


    Arthur Dent Guest

  2. #2

    Default Re: Require multiple role membership?

    I don't think you can do this via web.config. You could do this
    programmatically with IsInRole calls, but that is extra work.

    Another way around this might be to create "AND" roles when you do your role
    mapping, so that you have a special role like EmployeeANDAdminstrator that
    you could then use in web.config.

    HTH,

    Joe K.

    "Arthur Dent" <hitchhikersguideto-news> wrote in message
    news:%23NgJ4Ks3EHA.404TK2MSFTNGP10.phx.gbl...
    > Is there any way in the web.config "allow roles" authorization section, to
    > AND the roles together?
    > Eg. in my app, i have roles Customer, Employee, and Admininstrator. Now,
    > there could be Admin employees, and Admin Customers, each with access to
    > different sections.
    > Is there a way to specifiy that you can only get into the folder
    > "AppAdmin" if you are in role Employee AND role Administrator?
    > As ive seen it before, the roles by default only OR together.
    >
    > Thanks in advance,
    > - Arthur Dent
    >

    Joe Kaplan \(MVP - ADSI\) Guest

  3. #3

    Default Re: Require multiple role membership?

    Yeah, thats what im doing at the moment... i have my roles defined in an
    enum, and as additional members of the enum i have my combined roles, then i
    check those names (i use System.Enum.GetName() to define my role names). Eg.
    Enum UserRoles
    Employee = 2
    Administrator = 4
    AdminEmployee = Employee Or Administrator
    End Enum

    Then in my allow role i add AdminEmployee.

    I just thought maybe there was a way to do this without creating combinatory
    values like that.
    Thanks!


    "Joe Kaplan (MVP - ADSI)" <joseph.e.kaplanremovethis.accenture.com> wrote
    in message news:O9eOf%23s3EHA.2788TK2MSFTNGP15.phx.gbl...
    >I don't think you can do this via web.config. You could do this
    >programmatically with IsInRole calls, but that is extra work.
    >
    > Another way around this might be to create "AND" roles when you do your
    > role mapping, so that you have a special role like EmployeeANDAdminstrator
    > that you could then use in web.config.
    >
    > HTH,
    >
    > Joe K.
    >
    > "Arthur Dent" <hitchhikersguideto-news> wrote in message
    > news:%23NgJ4Ks3EHA.404TK2MSFTNGP10.phx.gbl...
    >> Is there any way in the web.config "allow roles" authorization section,
    >> to AND the roles together?
    >> Eg. in my app, i have roles Customer, Employee, and Admininstrator. Now,
    >> there could be Admin employees, and Admin Customers, each with access to
    >> different sections.
    >> Is there a way to specifiy that you can only get into the folder
    >> "AppAdmin" if you are in role Employee AND role Administrator?
    >> As ive seen it before, the roles by default only OR together.
    >>
    >> Thanks in advance,
    >> - Arthur Dent
    >>
    >
    >

    Arthur Dent Guest

Similar Threads

  1. #25782 [Opn->Bgs]: require( 'require.php' ) crashing Apache 1.3.28
    By sniper@php.net in forum PHP Development
    Replies: 0
    Last Post: October 13th, 02:33 AM
  2. #25782 [Fbk->Opn]: require( 'require.php' ) crashing Apache 1.3.28
    By akinder at technology-x dot com in forum PHP Development
    Replies: 0
    Last Post: October 8th, 09:01 PM
  3. #25782 [Opn->Fbk]: require( 'require.php' ) crashing Apache 1.3.28
    By sniper@php.net in forum PHP Development
    Replies: 0
    Last Post: October 8th, 12:56 AM
  4. #25782 [NEW]: require( 'require.php' ) crashing Apache 1.3.28
    By akinder at technology-x dot com in forum PHP Development
    Replies: 0
    Last Post: October 8th, 12:33 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139