Forums / Suggestions / Permissions...

Permissions...

Author Message

perrin aybara

Monday 11 October 2004 12:48:40 am

I've been working with eZ Publish for a short while now, but only with template design. So when I today attempted to set permissions for content objects, i was pretty suprised by the hopeless role-system... where on earth is the logic? you have to go through way too many steps to set permissions for a content object. Why not adopt a more "standard" file-system permission-system? Protect content-nodes directly by setting permissions for users/user groups?

Oh well. one can only wish...

Frederik Holljen

Monday 11 October 2004 2:26:56 am

We used a file system kind of permission systems in the 2.x series and quickly discovered that it is way to limited for web use. One of the main problems is that users don't understand the permission controls and sets incorrect permissions giving others to many or to few permissions. It is also very hard for site administrators to find out what content is actually available for the site user and what content is not.

The current system allows you more fine grained control over the possiblities for the different users/user groups based on the actions of the modules without giving to much power to the users themselves. That said, an additional, more file system like, permission system could come in handy in some (few) cases.

Paul Borgermans

Monday 11 October 2004 3:04:37 am

<i>That said, an additional, more file system like, permission system could come in handy in some (few) cases.</i>

You bet! I've implemented a small simple file sharing area in one of our portals, and per object permissions while possible aren' that feasible (to implement).

-paul

eZ Publish, eZ Find, Solr expert consulting and training
http://twitter.com/paulborgermans

Hans Melis

Tuesday 12 October 2004 2:45:07 am

The permission system indeed has room for improvement. Per object permissions would be nice to have, but it would also be nice to specify "deny" access rules.

All rules in the permission system are of the "allow" type. But if you have users who should be able to do a lot except a few things, you end up with a huge rule list in a role because you can't specify deny rules.

Hans
http://blog.hansmelis.be

Frederik Holljen

Tuesday 12 October 2004 4:56:16 am

Yes, both deny permissions and per object permissions would be really nice to have. It is not trivial to implement in a way that is not resource consuming however :/

Margon C.

Tuesday 26 October 2004 2:48:50 pm

That would be useful for me too.
I want to set user roles by folders, but the only way I could do this was by setting permission for section, but I need more specific role policies. I have n sections on my site, each one's administrated only by one user, I do not want the other users even to READ the other one's content... I can achieve the "create" and "edit" permissions but not "READ" permission, because I just don't get access to the content at all.

eZ debug

Timing: Jan 18 2025 11:13:36
Script start
Timing: Jan 18 2025 11:13:36
Module start 'content'
Timing: Jan 18 2025 11:13:36
Module end 'content'
Timing: Jan 18 2025 11:13:36
Script end

Main resources:

Total runtime0.6792 sec
Peak memory usage4,096.0000 KB
Database Queries209

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0064 587.5391180.8516
Module start 'content' 0.00640.4971 768.3906688.1875
Module end 'content' 0.50350.1757 1,456.5781338.8906
Script end 0.6792  1,795.4688 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00450.6599210.0002
Check MTime0.00150.2236210.0001
Mysql Total
Database connection0.00060.084210.0006
Mysqli_queries0.578585.17152090.0028
Looping result0.00300.44742070.0000
Template Total0.651695.920.3258
Template load0.00200.294620.0010
Template processing0.649595.631920.3248
Template load and register function0.00020.034310.0002
states
state_id_array0.00070.098810.0007
state_identifier_array0.00080.114020.0004
Override
Cache load0.00170.2479240.0001
Sytem overhead
Fetch class attribute can translate value0.00150.228160.0003
Fetch class attribute name0.00110.160390.0001
XML
Image XML parsing0.00270.404960.0005
class_abstraction
Instantiating content class attribute0.00000.0026100.0000
General
dbfile0.01472.1691390.0004
String conversion0.00000.001430.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
6content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
6content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
4content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
1content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 19
 Number of unique templates used: 6

Time used to render debug report: 0.0002 secs