[Progress Communities] [Progress OpenEdge ABL] Forum Post: RE: PASOE - Programmatically access ACLs

Status
Not open for further replies.
S

ssouthwe

Guest
And that's the crux of my question: How can the UI know what groups can do what? Code is not the place to contain that. It has to somehow get the rules from the back end. The UI may know that it needs to protect a certain button or API for example, but the UI should not be hard-coded as to what roles can access it. It should call whatever the main source of truth is, and ask "can my current user run this button?" or "tell me what functions this user can run." I think the answer to my question was that no, PASOE provides no built-in means for the oeablSecurity.csv file to be used by anything other than Spring's protection or URLs, so it's pretty much "roll your own".

Continue reading...
 
Status
Not open for further replies.
Top