Complex Righty System: ACL, RBAC and more what?
问题 We are currently developing a project management software. And we are having trouble deciding on the correct approach to implement security. We have looked at both ACL and RBAC and are already pretty certain that we need at least a combination of both for specific reasons. But there are a couple of problems that do not have a nice solution in either world. Let me explain: Let's say you have the following entities: Users , with different roles, i.e. Project Lead Worker Admin Projects Assigned