-
Book Overview & Buying
-
Table Of Contents
The Web Application Hacker's Handbook
By :
Access controls can be divided into three broad categories: vertical, horizontal, and context-dependent.
Vertical access controls allow different types of users to access different parts of the application's functionality. In the simplest case, this typically involves a division between ordinary users and administrators. In more complex cases, vertical access controls may involve fine-grained user roles granting access to specific functions, with each user being allocated to a single role, or a combination of different roles.
Horizontal access controls allow users to access a certain subset of a wider range of resources of the same type. For example, a web mail application may allow you to read your e-mail but no one else's, an online bank may let you transfer money out of your account only, and a workflow application may allow you to update tasks assigned to you but only read tasks assigned to other people.
Context-dependent access controls ensure that...
Change the font size
Change margin width
Change background colour