Forums / Install & configuration / restrict login to object/section/folder??

restrict login to object/section/folder??

Author Message

Gerhard Hoogterp

Wednesday 26 February 2003 12:07:36 am

As it seems the role model is limited OR I don't understand completely what's going on but..

I would like to limit the adminrights of editors to the folder (plus children) containing their site. How to go?

I can limit rights to a module, but all the sites/folders are handled by content and the rest of the modules named are uncharted territory. For me it would seem much more logical if I could restrict users to sections or classes. (No! You're not allowed to write in the news-folder!)

On a side note it also seems that the list of modules is just the list of subdirectories in the kernel directory linking the cms part to the physical environment. A CMS should,imnho, be self-contained in this matter and roles/security should deal with the CMS and not with "weird" things on disc. The system administrator can deal with those..

Anyhow, leaves the question "how to restrict users to a section/folder or other object?"

Volker Lenz

Thursday 27 February 2003 2:52:35 am

> As it seems the role model is limited OR I don't understand
> completely what's going on but..
>
> I would like to limit the adminrights of editors to the
> folder (plus children) containing their site. How to go?
>
> I can limit rights to a module, but all the sites/folders
> are handled by content and the rest of the modules named are
> uncharted territory. For me it would seem much more logical
> if I could restrict users to sections or classes. (No!
> You're not allowed to write in the news-folder!)
>
> On a side note it also seems that the list of modules is
> just the list of subdirectories in the kernel directory
> linking the cms part to the physical environment. A CMS
> should,imnho, be self-contained in this matter and
> roles/security should deal with the CMS and not with "weird"
> things on disc. The system administrator can deal with
> those..
>
> Anyhow, leaves the question "how to restrict users to a
> section/folder or other object?"

Your question first:
You can define policies to control a user's access to sections.
Take a look to this one: http://developer.ez.no/forum/message/14977

Your general comments on the current ezp authorisation model next:

Yes, you got things right! ezp3 is still quite limited in its ability to support fine-tuned authorisation regimes. I spent some time to study the diverse authorisation utilities shipped with ezp3 and finally wrote rather exhausting comments on this, e.g. this one:

http://developer.ez.no/forum/message/14601/

I have also issued a bunch of authorisation-related feature requests to the ezp3 bug reportings.

Hope that helps.

Gerhard Hoogterp

Thursday 27 February 2003 4:20:27 am

> Your question first:
> You can define policies to control a user's access to sections.
> Take a look to this one:
> http://developer.ez.no/forum/message/14977

I found that one, but what I wanted is

content * <section>

and that doesn't seem to be possible as such. So I would have to create a rule for every option within the content class. No prices here, but for now it would do I guess..

> http://developer.ez.no/forum/message/14601/

I have to reread thatone as by now I think I'm deep enough into the matter to appriciate the content.

Thanks,
Gerhard

eZ debug

Timing: Jan 18 2025 04:53:26
Script start
Timing: Jan 18 2025 04:53:26
Module start 'content'
Timing: Jan 18 2025 04:53:27
Module end 'content'
Timing: Jan 18 2025 04:53:27
Script end

Main resources:

Total runtime1.3932 sec
Peak memory usage4,096.0000 KB
Database Queries194

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0067 587.8516180.8203
Module start 'content' 0.00681.2453 768.6719519.2578
Module end 'content' 1.25210.1411 1,287.9297336.7344
Script end 1.3931  1,624.6641 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00460.3274210.0002
Check MTime0.00170.1241210.0001
Mysql Total
Database connection0.00080.056410.0008
Mysqli_queries1.301293.39711940.0067
Looping result0.00190.13431920.0000
Template Total1.356497.420.6782
Template load0.00280.199720.0014
Template processing1.353697.159720.6768
Template load and register function0.00020.017610.0002
states
state_id_array0.00380.274810.0038
state_identifier_array0.00170.120820.0008
Override
Cache load0.00230.1652530.0000
Sytem overhead
Fetch class attribute can translate value0.00130.091230.0004
Fetch class attribute name0.00090.066840.0002
XML
Image XML parsing0.00080.057430.0003
class_abstraction
Instantiating content class attribute0.00000.000740.0000
General
dbfile0.00920.6628270.0003
String conversion0.00000.000430.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
3content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
5content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
1content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
4content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 15
 Number of unique templates used: 6

Time used to render debug report: 0.0002 secs