On Wed, Aug 21, 2013 at 9:31 PM, Firas Al Khalil <[email protected]>wrote:

> Hi Christian,
>
> OrBAC and the extensions described in the references I mentioned are
> not OGC standards, I am aware of that. I am trying to implement OrBAC
> with the extensions. The initial goal was to make a prototype, a proof
> of concept.
>
> I have read this document
> [http://demo.geo-solutions.it/share/securing_geoserver.pdf] and I
> tried to understand the work done on the GeoXACML community module
> because what I'm trying to do is the same workflow. I failed for the
> reasons I mentioned earlier.
>
> I would like to know how to implement a custom access control model. I
> am struggling with the code.
>

Not sure how relevant it is, but you might also want to have a look at
GeoFence,
it plugs into the GeoServer authorization subsystem to apply security rules
that can limit attributes, filter features, cut rasters, based on the
current user,
request and layer, using an IPTables inspired approach (in terms of how the
security rules are evaluated):
https://github.com/geosolutions-it/geofence

Cheers
Andrea

-- 
==
Our support, Your Success! Visit http://opensdi.geo-solutions.it for more
information.
==

Ing. Andrea Aime
@geowolf
Technical Lead

GeoSolutions S.A.S.
Via Poggio alle Viti 1187
55054  Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39  339 8844549

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

-------------------------------------------------------
------------------------------------------------------------------------------
Introducing Performance Central, a new site from SourceForge and 
AppDynamics. Performance Central is your source for news, insights, 
analysis and resources for efficient Application Performance Management. 
Visit us today!
http://pubads.g.doubleclick.net/gampad/clk?id=48897511&iu=/4140/ostg.clktrk
_______________________________________________
Geoserver-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/geoserver-users

Reply via email to