Subject | Roles (ex planning the use of blr codes) |
---|---|
Author | Marcelo Lopez Ruiz |
Post date | 2001-04-18T21:07:48Z |
> Yeah. Although the Interbase role model is a single roleI assume you mean with only one active role at a time, right? Changing roles
> identified at logon, a more useful model is multiple roles,
> each of which may be turned on or off during a session.
>
> Jim Starkey
without having to reconnect sounds quite useful. But when defining each role
correctly, I really don't think there should be any need to support the user
of multiple active roles. That would introduce the problem of conflicting
permissions and restrictions, and it would probably generate more headaches
than saving time.
For tricky stuff, implementing security in an outside layer is usually the
way to go (IMHO). The SQL security declarations have no notion of turning
permissions on/off in response to the current time, the connection IP,
permissions managed through other models, etc.
Marcelo Lopez Ruiz