Re: why is authorization in a separate layer from the model?

Remy Fannader <[email protected]>
Newsgroups gmane.comp.programming.domain-driven-design
Message-ID <CAMdXxPAxTAMajUUGQPWEspkxV4kJCjvSo+ugepy3OMk00O2kBA@mail.gmail.com>
So, roles and authorizations are set in their own domain, right ?
Here a suggestion:
http://caminao.wordpress.com/how-to-implement-symbolic-representations/patterns/functional-patterns/users/
Remy.

On 10 March 2013 11:41, Giacomo Tesio <[email protected]> wrote:

> **
>
>
> On Sat, Mar 9, 2013 at 8:19 PM, Caleb Cushing <[email protected]>wrote:
>
>>  Why am I wrong? where should this authorization check actually live?
>> and what does that code look like? (references to DDD or Implementing
>> fine)
>>
> You are right.
>
> Actually, authorization is related to the company organization.
> I usually model each role of the organization that is relevant for the
> application (see http://epic.tesio.it/doc/manual/bounded_roles.html ).
> This solution comes from a simple insight (that is quite evident in some
> corporate): different roles use slightly different languages, with
> different perspective on the same concepts and some times giving different
> meanings to the same term.
>
> This works very well. You can take a look to the Epic.Core module (
> http://epic.tesio.it/doc/manual/epic-core.html) to see how I have modeled
> authorization.
>
>
> Giacomo
>
>  
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.