I have been finding some solution to put security on basis of entity.Like a user can only access to entity to which it has access.
Rather than putting check on each and every action method can i control in centralized way. I am here talking about access entity using ajax call also. For example a user has opened a orderId 10 for that i have an hidden field if by any means if he changes the value of orderId to 11 he can access or modify order with orderId 11 while he was allowed to see only orderId 10 .
There are the time we just send some values along with main entity id for example getOrderByUserId(int userId) as this action method is in OrderController accessing order based on userId.