Alex Rivera | Logout

Authorization in social networking website

Asked 2011-06-13T09:18:35.747
12

I need to accomplish the following related to privileges:

I have 3 users:

- User A
- User B
- User C

Each of the users has the following documents with associated access settings:

- User A
    - Document A1, only allow contacts to view
    - Document A2, allow everyone to view
    - Document A3, allow no one to view except myself
    - Document A4, allow contacts, and contacts of contacts to view
- User B
    - Documents B1, B2, B3, B4 with similar privileges
- User C
    - Documents C1, C2, C3, C4 with similar privileges

User A has User B as a contact but is not a contact of User C (User B and User C are contacts).

Thus, User A would be able to view the following:

- Document B1 (contacts can view)
- Document B2 (everyone can view) 
- Document B4 (contacts of contacts)
- Document C2 (everyone can view)
- Document C4 (contacts of contacts)

I am interested to learn how these privileges would be handled. I am also seeking any documentation or articles that would help me hit the ground running.

Edit
Report

2 Answers

3

What you basically need is to Limit access to logged-in users that pass a test. But the part with "contacts of contacts" can lead to very complicated sql-queries. And I suggest you to rethink that requirement. (I have lots of good friends whom I like and trust. But they have all kinds of weird people as friends ...)

answered 2011-06-13T18:54:31.250
0

You could include a "friends of friends" field. It would be a very big table (say, 200*200*N = 40,000*N ... or really huge if you have no limit to friends, and someone is friends with a million people - that's 1 million people with 1 million FoF) but it would be easier than hitting the database 200 times per view.

answered 2011-06-19T01:22:57.727

Your Answer