Declarative Access Control for WebDSL

Declarative Access Control for WebDSL
复制标题

WebDSL 的声明式访问控制

DOI:
--
复制
发表时间:
2008
期刊:
影响因子:
--
通讯作者:
D. Groenewegen
D. Groenewegen
中科院分区:
--
文献类型:
--
作者:
D. Groenewegen

文献摘要

被引文献

相似文献

本文描述了WebDSL的扩展,WebDSL是一种用于web应用程序开发的领域特定语言,具有用于声明性访问控制的抽象。该扩展支持将广泛的访问控制策略定义为简洁透明的单独关注点。访问受WebDSL应用程序中各种资源(最重要的是页面和页面操作)的控制。除了直接规范访问控制之外,还推断出某些访问控制检查,例如控制应用程序中导航链接的可见性。这个扩展展示了一种设计特定于领域的语言的方法,以支持关注点分离,同时保留静态验证。此方法是通过转换语义实现的,该语义将单独定义的方面编织到集成实现中。
This thesis describes the extension of WebDSL, a domain-specific language for web application development, with abstractions for declarative access control. The extension supports the definition of a wide range of access control policies concisely and transparently as a separate concern. Access is governed to the various resources in a WebDSL application, most importantly the pages and page actions. Besides direct specification of access control, certain access control checks are inferred, for instance to control the visibility of navigation links within the application. This extension shows an approach for designing a domain-specific language to support separation of concerns while preserving static validation. This approach is realized by means of a transformational semantics that weaves separately defined aspects into an integrated implementation.