In my MVC3 application I have ASP.NET Membership roles like - Manager, System Admin and EditorI am using Windows Authentication for the website and I am adding the users in the Network to the Membership just like in the following example -
But, my problem is there are people who require multiple permissions. For example
User-John is the Manager of Department-ABC and he can see all the Actions in Department-ABC.User-John is also Editor in Department-XYZ and he should be able to see all the Actions of an Editor in Department-XYZ; but NOT the Actions of Manager; because he is not the Manager of Department-XYZ.
User Mathew is the Manager of Department-XYZ and he is an Editor in Department-ABC.
If I use normal role privileges, it will allow User-John to be the Manager of both departments and it is not right.
My solution is to store the DepartmentID, UserID and RoleID in a seperate table in SQL database and allow according to this table.
How can I get the role ID from ASP.NET Membership in C# and also in SQL?
Is it safe to do? Is there a better solution?
Naveen BishtPosted Jun 18, 2013, 5:43 AM
if(user Role=="Manger")
{
all action.visible=true
}else if(userrole=="Editor")
{
you can hide some action and show only editor actions
}
this setting can be done when you do page or view load..:)
r pPosted Jun 18, 2013, 3:46 AM
If I give manager permission to User A, he will be able to access the department of User-B as well. I DON'T WANT user A to see the department of user B. So, just setting the role is not a good option.
thanks
Naveen BishtPosted Jun 18, 2013, 2:10 AM
Or you can get all roles for a user by