Solr:文档和文档子文档级安全性
我有一个非常了解的 Solr 问题。该索引包含一组员工记录文档,其中包含一组公共访问字段和一组安全字段。根据用户的安全凭证(可以在文档中作为一个字段进行索引),如果文档匹配,则显示其所有公共字段以及他有权访问的一些安全字段。此安全字段列表会因同一索引中的文档而异。示例:一个部门(属于一个公司)的经理可以查看他手下的员工(文档)的所有安全字段,但不能查看不在他手下工作的人员(无论是否在同一家公司)。但他仍然可以看到所有员工的所有公共字段(匹配和过滤的文档)。
因此,作为经理,我可以看到在我手下工作的每个人的所有(公共+安全)字段,但我的助理只能看到他手下的一些安全字段。如何在 Solr 中实现这一点。谢谢。
I have a rather very know Solr issue. The index contain a group of docs of employee records that has a set of public access fields and a set of secure fields. Based on the user's security credentials (which may be indexed in the doc as one field), if a document matched, all its public fields and some of the secured fields which he has access. This list of secure fields varies document to document in the same index. Example: a manage of a department (belonging to one company) can view all secure fields of employees (doc) under him but not for those who do not work under him (whether in the same company or not). But he can still see ALL the public fields of ALL the of the employees (matched and filtered docs).
So being manager, I can see all (public + secure) fields of every one working under me but my asst can see only some of the secure fields who are under him. How to implement this in Solr. Thanks.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
文档指出 Solr 不关心文档级别的安全性。
Solr 被设计为数据的索引,而不是数据库的替代品(访问控制是一项重要的数据库功能,只会增加索引的复杂性)
我的建议:
The documentation states that Solr does not concern itself with security at the document level.
Solr is designed to be an index of your data, not a replacement for your database (Access control is an important DB feature, only adds complexity to an index)
My suggestions:
我建议采取以下步骤:
I would suggest to take the following steps: