计算机英语考虑是,计算机英语中单词privilege和permission的区别

涉及ER图和RBAC知识。

我们要考虑的是角色和认证的ER图(实体关系图)

an application has functions

functions may be performed by roles

identities are given roles

individuals are provisioned with identities

bringing that together a little bit, we can say: + an individual (who has an online identity), performing a role is given permission to perform functions in applications。

So:the permission is the ER link between the role, function and application, i.e. permissions are given to roles

the privilege is the ER link between an individual and the application, i.e. privileges are given to people.

HOWEVER, many designers don't bother separating individual and role or don't separate function and application and so the difference between privilege and permission is missed. In my experience, you often see this when someone says "use AD groups to store RBAC" - this is a serious anti-pattern.

In a world where there are requirements to report on toxic combinations and granular permissioning is more common place then it the data model for storing RBAC is very much more important.

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值