Every discussion or tutorial I've ever come across has related to authorization, related to simple binary authorization. Can I edit pages in a blogging application? Can the user approve the comments? Simple examples.
What I have not seen much are more complex permission-based "examples". Can the user edit this page? Can the user confirm this comment? ... where the user has permission to perform actions on certain records, but not all.
Are there common approaches to this problem? Any good examples? I can crack various simple solutions, but I donβt like the feeling that I am reinventing the wheel.
FWIW, the current application I'm dealing with, is built in Python Pylons.
source share