Skip to Content.
Sympa Menu

grouper-users - [grouper-users] question about Grouper permissions....

Subject: Grouper Users - Open Discussion List

List archive

[grouper-users] question about Grouper permissions....


Chronological Thread 
  • From: Steven Carmody <>
  • To: Grouper-Users <>
  • Subject: [grouper-users] question about Grouper permissions....
  • Date: Mon, 22 Aug 2011 09:06:14 -0400

Sorry for what is likely to be an inane question ;-)

I'm looking for a high level description of Grouper's support for permissions...

I've watched the video "Grouper permission assignment screen first pass ", and that's consistent with what I'd expect to see....

Here's my attempt at describing the model:

A "permission definition" is created, and then someone assigns that permission to a Role (and perhaps to just some entities while operating in that role).

"permission definition"s, tho, look like strings ?

So, how are these "pushed" into the target application ? Does ldappcng do that ? Is it expected that they will be pushed into ldap, and the target application looks at attribute values to see if someone has a specific permission?

We have applications that export APIs that allow a provisioning program to specify which group/role can do VERB on RESOURCE X -- is there some sort of plugin architecture in ldappcng -- where we provide the appropriate plugin and something like ldappcng will use our plugin ?

Once again, sorry for the Q -- I assume this has been discussed somewhere, and I just can't find it.



Archive powered by MHonArc 2.6.16.

Top of Page