You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求推荐.NET中类似Spring Security Domain Object ACLs的权限框架

Great question—since you're working with NHibernate and Castle Windsor and want to avoid polluting domain logic with security code, there are a few mature frameworks and patterns that align perfectly with your needs:

1. Spring.NET Security ACL

This is the closest direct equivalent to Spring Security's Domain Object ACLs in the .NET ecosystem. It provides a full-featured ACL system that:

  • Supports fine-grained permission checks on domain objects (e.g., read, write, delete for specific entities)
  • Integrates seamlessly with NHibernate for storing ACL metadata (you can map ACL entities directly with your existing NHibernate setup)
  • Works well with Castle Windsor via interception: you can configure Windsor to inject ACL checks as cross-cutting concerns, keeping your domain logic clean
  • Includes built-in support for permission inheritance and object hierarchies, just like Spring Security's ACLs

To use it, you'd define ACL permissions for your domain entities, then use Windsor interceptors to apply permission checks before methods that access or modify those entities—no need to add security attributes directly to your domain classes.

2. SharpArchitecture Security

SharpArch is a well-established framework for building layered .NET apps, and its security module is designed to work with NHibernate and Castle Windsor out of the box. Key features:

  • Uses Castle Windsor interceptors to enforce method-level and object-level permissions
  • Integrates with NHibernate to store permission data alongside your domain entities
  • Supports attribute-based configuration (if you prefer) but keeps security logic decoupled from domain code
  • Includes utilities for checking permissions on individual domain objects before they're accessed or modified

Since you've already experimented with interceptors and attributes, this framework will feel familiar but gives you a polished, production-ready implementation instead of rolling your own.

3. Optimized Custom Implementation (Leveraging Your Existing Work)

If you want to build on the interceptor/attribute approach you've already started, you can enhance it with NHibernate Filters to make it more robust:

  • Use NHibernate's built-in filter functionality to automatically filter out domain objects the current user doesn't have access to at the query level—this reduces the need for post-query permission checks
  • Combine this with Castle Windsor interceptors to enforce method-level permissions (e.g., preventing a user from calling Delete() on an entity they don't own)
  • Store permission data in a dedicated ACL table mapped with NHibernate, and use a service layer to retrieve permissions instead of embedding logic in domain classes

This approach lets you keep full control while avoiding the pitfalls of a homegrown solution by leveraging NHibernate and Windsor's native features.

All of these options let you maintain a clean separation between domain logic and security, which is exactly what you're looking for.

内容的提问来源于stack exchange,提问作者terminal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:43:59