ofbiz-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Chinmay Patidar <chinmay.pati...@hotwaxsystems.com>
Subject [Proposal] Create separate Permission Service for security checks
Date Sat, 09 Sep 2017 11:36:05 GMT
Hello Devs,

Recently, I came across the CRUD operation services for ShoppingList and
ShoppingListItem entities. The security related checks are present inline
in these services which violate the best practice of keeping security
implementation different from the business logic.

I would like to propose creating security services for such operations and
to call them as a permission-service from the CRUD operation
services definition. This will also enable users to easily modify the
security checks for their custom implementation. ill then, I would like to
know your thoughts on this idea.

*Chinmay Patidar*

  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message