Forums / Developer / 4.3 Roles and Policies: How to restrict object editing to only "Content" attributes?

4.3 Roles and Policies: How to restrict object editing to only "Content" attributes?

Author Message

Thiago Campos Viana

Monday 26 April 2010 7:19:12 am

Could someone help me with content attribute grouping in eZ Publish 4.3?

Is it possible to disable meta attributes editing for a group of users?

eZ Publish Certified Developer: http://auth.ez.no/certification/verify/376924

Twitter: http://twitter.com/tcv_br

tom stovall

Monday 26 April 2010 12:28:26 pm

Well, Not saying this is the way to do it, but what I would do is edit the associated role and add a policy that only allows the user read access to any user objects where they are the owner, e.g. their user object.

I think, however, that will disable their ability to change their own password.

You could also change the user/edit template so they can only change what you want them to change...???

-tom

Thiago Campos Viana

Monday 26 April 2010 4:39:10 pm

"

... but what I would do is edit the associated role and add a policy that only allows the user read access to any user objects where they are the owner, e.g. their user object....

...

You could also change the user/edit template so they can only change what you want them to change...???

-tom

"

I would block some attributes of the user own object, like hit counter, rating, and others... so, even he is the owner of the object, I wouldn't allow him to edit all the fields. If I modify the edit template it is not secure because the user could use firebug and add/modify fields... I had this problem some time ago, the user edited some hidden fields with firebug, then he used firebug to create the fields I removed from editing template and I got some problems. The best solution would be to control the user allowed editing attributes to some groups.

eZ Publish Certified Developer: http://auth.ez.no/certification/verify/376924

Twitter: http://twitter.com/tcv_br

Jérôme Vieilledent

Tuesday 27 April 2010 12:01:10 am

Hi Thiago

Unfortunately, it is not (yet) possible to apply security policies at the attribute level. A hack does exist, but maybe you should wait a little as this feature has been waited for a long time and is claimed for Fuji next release (see features requests and ideas).

Norman Leutner

Tuesday 27 April 2010 12:50:21 am

Currently policies at attribute level are not on the roadmap for the upcoming releases !

see: http://ez.no/ezpublish/roadmap

Mit freundlichen Grüßen
Best regards

Norman Leutner

____________________________________________________________
eZ Publish Platinum Partner - http://www.all2e.com
http://ez.no/partners/worldwide_partners/all2e_gmbh

André R.

Tuesday 27 April 2010 5:57:04 am

Correct, it is not on the roadmap.
Might make more sense to do it pr attribute category, but then the storage of it should improve some..

eZ Online Editor 5: http://projects.ez.no/ezoe || eZJSCore (Ajax): http://projects.ez.no/ezjscore || eZ Publish EE http://ez.no/eZPublish/eZ-Publish-Enterprise-Subscription
@: http://twitter.com/andrerom

Thiago Campos Viana

Tuesday 27 April 2010 7:12:28 am

ok, thank you all!

I'm looking forward to this feature.

eZ Publish Certified Developer: http://auth.ez.no/certification/verify/376924

Twitter: http://twitter.com/tcv_br

Jérôme Vieilledent

Tuesday 27 April 2010 8:05:59 am

"

Correct, it is not on the roadmap.
Might make more sense to do it pr attribute category, but then the storage of it should improve some..

"

This approach may be interesting :)

Thiago Campos Viana

Tuesday 27 April 2010 11:07:39 am

"
"

Correct, it is not on the roadmap.
Might make more sense to do it pr attribute category, but then the storage of it should improve some..

"

This approach may be interesting :)

"

Could someone please tell me how to do that?

eZ Publish Certified Developer: http://auth.ez.no/certification/verify/376924

Twitter: http://twitter.com/tcv_br

eZ debug

Timing: Jan 18 2025 02:54:10
Script start
Timing: Jan 18 2025 02:54:10
Module start 'content'
Timing: Jan 18 2025 02:54:10
Module end 'content'
Timing: Jan 18 2025 02:54:11
Script end

Main resources:

Total runtime0.7745 sec
Peak memory usage4,096.0000 KB
Database Queries219

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0049 588.0938180.7813
Module start 'content' 0.00490.6436 768.8750764.2344
Module end 'content' 0.64850.1259 1,533.1094344.3984
Script end 0.7744  1,877.5078 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00340.4448210.0002
Check MTime0.00130.1696210.0001
Mysql Total
Database connection0.00070.088310.0007
Mysqli_queries0.675387.18922190.0031
Looping result0.00210.26902170.0000
Template Total0.753897.320.3769
Template load0.00240.313420.0012
Template processing0.751397.007720.3757
Template load and register function0.00010.013310.0001
states
state_id_array0.00110.147710.0011
state_identifier_array0.00070.093920.0004
Override
Cache load0.00230.2948520.0000
Sytem overhead
Fetch class attribute can translate value0.00120.150860.0002
Fetch class attribute name0.00120.1524140.0001
XML
Image XML parsing0.00650.834260.0011
class_abstraction
Instantiating content class attribute0.00000.0042180.0000
General
dbfile0.01081.3983550.0002
String conversion0.00000.000630.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
9content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
9content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
14content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
4content/datatype/view/ezxmltags/quote.tpldatatype/ezxmltext/quote.tplextension/ezwebin/design/ezwebin/override/templates/datatype/ezxmltext/quote.tplEdit templateOverride template
1content/datatype/view/ezxmltags/link.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/link.tplEdit templateOverride template
3content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 42
 Number of unique templates used: 8

Time used to render debug report: 0.0001 secs