AlyceBrady / ramp

Record and Activity Management Program (temporarily combined with SMART: Software for Managing Academic Records and Transcripts)
BSD 2-Clause "Simplified" License
3 stars 11 forks source link

Field-based authorization #24

Open AlyceBrady opened 11 years ago

AlyceBrady commented 11 years ago

Authorization is currently based solely on a table-by-table basis; Restricting access to some fields in a table to different roles than the rest of the table is not currently supported.

AlyceBrady commented 11 years ago

Thoughts for the future: perhaps authorization should be based on table AND setting (or combination of setting and associated tables) to support allowing authorized viewing or modification of only some fields. Of course, the authorization based on setting part will only work if non-DBAs can't create or edit settings :(.