Suppose you need to build an alumni website with several levels of access:
This can be implemented in PHPRunner and ASPRunner.NET using user groups, record-level security, and a Custom View.
Use three groups:
Create a Users table with fields such as:
The GraduationYear field identifies the class that an administrator is allowed to manage. The AccessLevel field determines which user group the account belongs to.
On the Datasource tables screen, create a Custom View based on the alumni table.
This Custom View will be used by the Admin group so class administrators can edit only records that belong to their graduation year.
Open the Security screen and select database-based authentication.
Select the Users table and specify the fields used for the username and password.
Open Advanced security settings.
For the regular alumni table, configure the permissions required for registered users. If registered users should be able to view all alumni records but edit only their own record, select:
Users can see other users data, can edit their own data only
Use the appropriate user ID field as the OwnerID field.
For the administrator Custom View, select:
Users can see other users data, can edit their own data only
Use GraduationYear as the OwnerID field in both the Users table and the Custom View.
This makes the graduation year act as the ownership key. An administrator assigned to the class of 2005, for example, can edit records belonging to 2005 but cannot edit records from other years.
Enable Login as guest and give the Guest group read-only permissions.
Use the Guest group to expose only the fields that should be publicly visible, such as:
More detailed information can remain available only to registered users.
Open User Group Permissions and use AccessLevel as the GroupID field.
Configure permissions for each group:
With this setup:
The same approach can be adapted to many other applications where administrators should manage records only for a specific department, office, region, school year, customer, or other group.