Net SQL AzMan
Bill Bassler <[email protected]> Tue, 3 Mar 2009 08:50:31 -0500
| Newsgroups | gmane.comp.windows.devel.dotnet.advanced |
|---|---|
| Message-ID | <LISTSERV%[email protected]> |
Over the past several years I've evaluated the state/pro/cons of the various authorization frameworks available in .net in the area of authorization. The out-of-the-box asp.net 2.0 > role-based authorization has always seemed to be very limited in: - its lack of permissions granularity. Role-based only. - its lack of permissions inheritence. - its lack of the notion of user groups and assigning groups to role(s). - its lack of ability to easily configure and store authorizations in a database. - its lack of temporal delegation of permissions. - it defines only Allow permissions. No Deny. I've looked at NetSqlAzMan for the past couple of years. In general, it appears to support a lot of the concepts that are useful in application authorizations. The things concern me with Net Sql AzMan is that: - it doesn't appear to have gained wide-spread adoption. - I don't have a feel for it's performance under very high web application load. - future development/support/enhancements. Can anyone provide some insight on NetSqlAzMan or other authorization frameworks ... or tell me that missing the point on the weaknesses of the out-of-the-box asp.net 2.0 > role-based authorization =================================== View archives and manage your subscription(s) at http://peach.ease.lsoft.com/archives