Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 4099448
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 20, 20262026-05-20T20:26:06+00:00 2026-05-20T20:26:06+00:00

RBAC is well understood, so this is beyond RBAC. Looking for an efficient/tested approach

  • 0

RBAC is well understood, so this is beyond RBAC.

Looking for an efficient/tested approach to deal with attribute, or domain, based security such that a principal may have N attributes (with N values) that will limit what they can or can not see. I understand acegi can handle this, but by replacing JAAS, and I would like to evaluate if there is a way to work with JAAS to deal with this security model.

Examples:

joe likes apples, oranges, pears.

john likes oranges and tomatoes.

jane likes apples but is allergic to tomatoes (explicitly denied from tomatoes).

You serve 100’s of vegetables and fruits, and you specialize in special varieties of each fruit and vegetable.

If someone has permission to see apples, they can see all the specialized apples like ‘granny smiths’ for example, but not allowed to see other specialized types if they do not have that ‘likes’ attribute/permission.

Technical, each principal has various attributes associated with them, that will limit what they are allowed to see from various data calls/updates and looking for a clean way to support having those attributes with the principal be used in a JavaEE setting (ejb/servlet).

thanks in advance!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-20T20:26:07+00:00Added an answer on May 20, 2026 at 8:26 pm

    JAAS does not specify how (or even if) a Java EE container should implement this. Therefore various contains have (or don’t have) their own support for this.

    Because of this, if you want it to work along with JAAS, then the solution will be container-specific, or will be an add-on library such as acegi.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

What is the best database schema to track role-based access controls for a web
Executing Oracle RAC cluster management commands such as $ORA_CRS_HOME/bin/crs_start requires root permissions. Using Solaris
I'm working on a Rails app using CanCan for RBAC and I only have
In my job we are trying to consolidate the Authentication of the application farm
I've begun doing some research on XACML and external authorization. Right now I have
I originally set up spring with xapool, but it turns out that's a dead
What does the following error message mean? Googling for MARKED_FOR_JOINED doesn't return any useful

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.