Net SQL AzMan

Bill Bassler <[email protected]> Tue, 3 Mar 2009 08:50:31 -0500
Newsgroups gmane.comp.windows.devel.dotnet.advanced
Message-ID <LISTSERV%[email protected]>
Over the past several years I've evaluated the state/pro/cons of the various authorization frameworks available in .net in the area of authorization. 

The out-of-the-box asp.net 2.0 > role-based authorization has always seemed to be very limited in:

 -  its lack of permissions granularity. Role-based only.
 -  its lack of permissions inheritence.
 - its lack of the notion of user groups and assigning groups to role(s).
 - its lack of ability to easily configure and store authorizations in a  database.
 - its lack of temporal delegation of permissions.
 - it defines only Allow permissions. No Deny.

I've looked at NetSqlAzMan for the past couple of years. In general, it appears to support a lot of the concepts that are useful in application authorizations. The things concern me with Net Sql AzMan is that:

 - it doesn't appear to have gained wide-spread adoption. 
 - I don't have a feel for it's performance under very high web application load.
- future development/support/enhancements.

Can anyone provide some insight on NetSqlAzMan or other authorization frameworks ... or tell me that missing the point on the weaknesses of the out-of-the-box asp.net 2.0 > role-based authorization 

===================================
View archives and manage your subscription(s) at http://peach.ease.lsoft.com/archives