OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Tahsin Alam (tahsinalamYAHOO.COM)
Date: Mon Sep 24 2001 - 10:10:57 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Hi all:

    I am trying to use the COM+ IsUserInRole(caller, rolename) method to determine whether the caller is in a particular role or not.

    When I used "IsCallerInRole", everything worked correctly. Then I used IsUserInRole, passing in the SID of the original caller (that I got from the security call context), and the method returned false for every role!

    I was mapping my COM+ Roles to AD Groups. When I changed the mapping, and mapped COM+ Roles to individual AD users instead, IsUserInRole started working!

    Aaargh - this seems like a bug to me! Seems like IsUserInRole does not work when COM+ roles are mapped to AD groups, but in a full AD environment, why would anyone map COM+ roles to individual AD users!

    Bug or design feature?

    tahsin

    ---------------------------------
    Do You Yahoo!?
    Get email alerts & NEW webcam video instant messaging with Yahoo! Messenger.

    ----------------------------------------------------------------
    Users Guide http://discuss.microsoft.com/archives/mailfaq.asp
    contains important info. Save time, search the archives at
    http://discuss.microsoft.com/archives/index.html .
    To unsubscribe, mailto:DCOM-signoff-requestDISCUSS.MICROSOFT.COM