[jboss-user] [JBoss Seam] - Entity Authorization
shakenbrain
do-not-reply at jboss.com
Tue Oct 16 21:26:40 EDT 2007
Can someone tell me if the following is possible?
Application users (SiteUser) have a collection of authorizedOrganizations (Organization). Other (but not all) entities in the model belong to one particular organization. When those particular entities (perhaps identified by a custom annotation?) are loaded from the database, I'd like to verify that the entity's organization is contained within the authorizedOrganizations belonging to the connected user (a SiteUser in session scope). If that verification fails, I want to throw an AuthorizationException.
I don't think a hibernate filter will work, because the authorized organizations live in a collection...
I don't think there's a seam event I can work with...
I don't think the Hibernate event system will work either...
If anyone has a suggestion for an avenue to investigate, I'd appreciate it. I can always do the verification 'manually' (in each load entity method), but I'm hoping there's a better way...
View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4095847#4095847
Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=4095847
More information about the jboss-user
mailing list