< previous page page_301 next page >

Page 301
After some additional exchange between you and your client, you realize that the current requirements call for two workgroups:
Account Transactions
Account Administration
The Account Transactions workgroup is primarily responsible for processing deposit and withdrawal transactions. The roles in this workgroup include
Bank Teller
Regular Account Manager
The Account Administration workgroup is responsible for opening accounts, modifying customer and account characteristics, and closing accounts. Because the workers in this workgroup tend to be very experienced personnel, there are only two roles in this workgroup:
Regular Account Manager
Investment Account Manager
The Branch Manager, unlike managers in other banks, does not want the roles in one workgroup to perform the tasks of a role in the other. Also, she wants password protection.
Figure 13.2 shows the sequence of events that occurs in establishing a work session on behalf of a user.
The bank branch manager wants the password to be encrypted as it travels across the network. She also wants the password stored in the database to be encrypted as well.
Modeling the Workgroup and User Security Subsystem Classes
Modeling the classes in this type of subsystem is seldom easy. In fact, one of the more difficult tasks for the designer and developer is implementing a suitable login mechanism and tracking the various roles a user is likely to perform. To create a proper, truly secure login mechanism, your more sophisticated users expect you to encrypt the passwordnot just trust a text box's password character display alone. Your customers don't want the actual text of the password stored in the database; they want the encrypted text value. If you develop a login mechanism for an Internet application tasked with keeping parents' children from certain features on the Web, the parents would expect that the more curious children aren't able to peep into the database and get the passwords. They, too, would need encryption. The classes for an application's security policy have also been modeled and included in the sample code for this lesson.

 
< previous page page_301 next page >

If you like this book, buy it!