Build an alumni website with PHPRunner and ASPRunner.NET

Suppose you need to build an alumni website with several levels of access:

  • Visitors can see limited public information.
  • Registered users can view complete alumni information.
  • Class administrators can add, edit, and manage records only for their own graduation year.

This can be implemented in PHPRunner and ASPRunner.NET using user groups, record-level security, and a Custom View.

1. Create three access groups

Use three groups:

  • Guest - public read-only access without a password.
  • User - registered users who can view complete alumni information.
  • Admin - class administrators who can manage alumni records for their own graduation year.

2. Create the Users table

Create a Users table with fields such as:

  • Id
  • Name
  • Password
  • GraduationYear
  • AccessLevel

The GraduationYear field identifies the class that an administrator is allowed to manage. The AccessLevel field determines which user group the account belongs to.

3. Create a Custom View for administrators

On the Datasource tables screen, create a Custom View based on the alumni table.

This Custom View will be used by the Admin group so class administrators can edit only records that belong to their graduation year.

4. Configure database authentication

Open the Security screen and select database-based authentication.

Select the Users table and specify the fields used for the username and password.

5. Configure record-level permissions

Open Advanced security settings.

For the regular alumni table, configure the permissions required for registered users. If registered users should be able to view all alumni records but edit only their own record, select:

Users can see other users data, can edit their own data only

Use the appropriate user ID field as the OwnerID field.

For the administrator Custom View, select:

Users can see other users data, can edit their own data only

Use GraduationYear as the OwnerID field in both the Users table and the Custom View.

This makes the graduation year act as the ownership key. An administrator assigned to the class of 2005, for example, can edit records belonging to 2005 but cannot edit records from other years.

6. Enable guest access

Enable Login as guest and give the Guest group read-only permissions.

Use the Guest group to expose only the fields that should be publicly visible, such as:

  • Name
  • Graduation year

More detailed information can remain available only to registered users.

7. Configure user group permissions

Open User Group Permissions and use AccessLevel as the GroupID field.

Configure permissions for each group:

  • Guest - read-only access to public alumni information.
  • User - access to the full alumni information intended for registered users.
  • Admin - add, edit, view, and delete permissions on the administrator Custom View.

Result

With this setup:

  • Visitors can browse limited public alumni information.
  • Registered alumni can view additional information after logging in.
  • Class administrators can manage alumni records only for their assigned graduation year.

The same approach can be adapted to many other applications where administrators should manage records only for a specific department, office, region, school year, customer, or other group.

Applies to

  • PHPRunner
  • ASPRunner.NET