求推荐.NET中类似Spring Security Domain Object ACLs的权限框架
Great question—since you're working with NHibernate and Castle Windsor and want to avoid polluting domain logic with security code, there are a few mature frameworks and patterns that align perfectly with your needs:
1. Spring.NET Security ACL
This is the closest direct equivalent to Spring Security's Domain Object ACLs in the .NET ecosystem. It provides a full-featured ACL system that:
- Supports fine-grained permission checks on domain objects (e.g., read, write, delete for specific entities)
- Integrates seamlessly with NHibernate for storing ACL metadata (you can map ACL entities directly with your existing NHibernate setup)
- Works well with Castle Windsor via interception: you can configure Windsor to inject ACL checks as cross-cutting concerns, keeping your domain logic clean
- Includes built-in support for permission inheritance and object hierarchies, just like Spring Security's ACLs
To use it, you'd define ACL permissions for your domain entities, then use Windsor interceptors to apply permission checks before methods that access or modify those entities—no need to add security attributes directly to your domain classes.
2. SharpArchitecture Security
SharpArch is a well-established framework for building layered .NET apps, and its security module is designed to work with NHibernate and Castle Windsor out of the box. Key features:
- Uses Castle Windsor interceptors to enforce method-level and object-level permissions
- Integrates with NHibernate to store permission data alongside your domain entities
- Supports attribute-based configuration (if you prefer) but keeps security logic decoupled from domain code
- Includes utilities for checking permissions on individual domain objects before they're accessed or modified
Since you've already experimented with interceptors and attributes, this framework will feel familiar but gives you a polished, production-ready implementation instead of rolling your own.
3. Optimized Custom Implementation (Leveraging Your Existing Work)
If you want to build on the interceptor/attribute approach you've already started, you can enhance it with NHibernate Filters to make it more robust:
- Use NHibernate's built-in filter functionality to automatically filter out domain objects the current user doesn't have access to at the query level—this reduces the need for post-query permission checks
- Combine this with Castle Windsor interceptors to enforce method-level permissions (e.g., preventing a user from calling
Delete()on an entity they don't own) - Store permission data in a dedicated ACL table mapped with NHibernate, and use a service layer to retrieve permissions instead of embedding logic in domain classes
This approach lets you keep full control while avoiding the pitfalls of a homegrown solution by leveraging NHibernate and Windsor's native features.
All of these options let you maintain a clean separation between domain logic and security, which is exactly what you're looking for.
内容的提问来源于stack exchange,提问作者terminal

