I want your help to build a security environment that a think quite complex, and I'm wondering if I can only use spring hierarchy role system or even spring ACL...
I need to build a security environment with lots of roles, for example:
- lvl 1 - (group 1, group 2...)
- lvl 2 - (company 1, company 2...)
- lvl 3 - (functionality 1, functionality 2...)
- lvl 4 - (method 1, method 2...)
- lvl N - (N)
The admin user will create users with dynamic roles for example:
user 1 has = group 1 > company 1 > func 1, func 2 > method 1
user 2 has = group 2 > company 1, company 2 > func 3 > method 1, method 2
This structure can easily grow to even particular details and I'm afraid of to manage all this things.
Any ideas of how to solve it with spring security?