4.3 Roles and Policies: How to restrict object editing to only "Content" attributes?

Author Message

Thiago Campos Viana

Monday 26 April 2010 7:19:12 am

Could someone help me with content attribute grouping in eZ Publish 4.3?

Is it possible to disable meta attributes editing for a group of users?

eZ Publish Certified Developer: http://auth.ez.no/certification/verify/376924

Twitter: http://twitter.com/tcv_br

tom stovall

Monday 26 April 2010 12:28:26 pm

Well, Not saying this is the way to do it, but what I would do is edit the associated role and add a policy that only allows the user read access to any user objects where they are the owner, e.g. their user object.

I think, however, that will disable their ability to change their own password.

You could also change the user/edit template so they can only change what you want them to change...???

-tom

Thiago Campos Viana

Monday 26 April 2010 4:39:10 pm

"

... but what I would do is edit the associated role and add a policy that only allows the user read access to any user objects where they are the owner, e.g. their user object....

...

You could also change the user/edit template so they can only change what you want them to change...???

-tom

"

I would block some attributes of the user own object, like hit counter, rating, and others... so, even he is the owner of the object, I wouldn't allow him to edit all the fields. If I modify the edit template it is not secure because the user could use firebug and add/modify fields... I had this problem some time ago, the user edited some hidden fields with firebug, then he used firebug to create the fields I removed from editing template and I got some problems. The best solution would be to control the user allowed editing attributes to some groups.

eZ Publish Certified Developer: http://auth.ez.no/certification/verify/376924

Twitter: http://twitter.com/tcv_br

Jérôme Vieilledent

Tuesday 27 April 2010 12:01:10 am

Hi Thiago

Unfortunately, it is not (yet) possible to apply security policies at the attribute level. A hack does exist, but maybe you should wait a little as this feature has been waited for a long time and is claimed for Fuji next release (see features requests and ideas).

Norman Leutner

Tuesday 27 April 2010 12:50:21 am

Currently policies at attribute level are not on the roadmap for the upcoming releases !

see: http://ez.no/ezpublish/roadmap

Mit freundlichen Grüßen
Best regards

Norman Leutner

____________________________________________________________
eZ Publish Platinum Partner - http://www.all2e.com
http://ez.no/partners/worldwide_partners/all2e_gmbh

André R.

Tuesday 27 April 2010 5:57:04 am

Correct, it is not on the roadmap.
Might make more sense to do it pr attribute category, but then the storage of it should improve some..

eZ Online Editor 5: http://projects.ez.no/ezoe || eZJSCore (Ajax): http://projects.ez.no/ezjscore || eZ Publish EE http://ez.no/eZPublish/eZ-Publish-Enterprise-Subscription
@: http://twitter.com/andrerom

Thiago Campos Viana

Tuesday 27 April 2010 7:12:28 am

ok, thank you all!

I'm looking forward to this feature.

eZ Publish Certified Developer: http://auth.ez.no/certification/verify/376924

Twitter: http://twitter.com/tcv_br

Jérôme Vieilledent

Tuesday 27 April 2010 8:05:59 am

"

Correct, it is not on the roadmap.
Might make more sense to do it pr attribute category, but then the storage of it should improve some..

"

This approach may be interesting :)

Thiago Campos Viana

Tuesday 27 April 2010 11:07:39 am

"
"

Correct, it is not on the roadmap.
Might make more sense to do it pr attribute category, but then the storage of it should improve some..

"

This approach may be interesting :)

"

Could someone please tell me how to do that?

eZ Publish Certified Developer: http://auth.ez.no/certification/verify/376924

Twitter: http://twitter.com/tcv_br

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 18 2025 05:21:35
Script start
Timing: Jan 18 2025 05:21:35
Module start 'layout'
Timing: Jan 18 2025 05:21:35
Module start 'content'
Timing: Jan 18 2025 05:21:35
Module end 'content'
Timing: Jan 18 2025 05:21:35
Script end

Main resources:

Total runtime0.8132 sec
Peak memory usage4,096.0000 KB
Database Queries82

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0053 588.4063152.6875
Module start 'layout' 0.00530.0039 741.093839.5234
Module start 'content' 0.00920.8024 780.6172759.1094
Module end 'content' 0.81160.0015 1,539.726624.0625
Script end 0.8131  1,563.7891 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00310.3804160.0002
Check MTime0.00130.1575160.0001
Mysql Total
Database connection0.00110.139210.0011
Mysqli_queries0.735590.4474820.0090
Looping result0.00070.0866800.0000
Template Total0.783596.320.3917
Template load0.00180.223220.0009
Template processing0.781696.121220.3908
Template load and register function0.00010.012810.0001
states
state_id_array0.00110.130810.0011
state_identifier_array0.00220.266220.0011
Override
Cache load0.00160.2024520.0000
Sytem overhead
Fetch class attribute can translate value0.00060.075950.0001
Fetch class attribute name0.00130.1643140.0001
XML
Image XML parsing0.00240.292050.0005
class_abstraction
Instantiating content class attribute0.00000.0039180.0000
General
dbfile0.00140.1681440.0000
String conversion0.00000.001040.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
9content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
9content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
14content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
4content/datatype/view/ezxmltags/quote.tpldatatype/ezxmltext/quote.tplextension/ezwebin/design/ezwebin/override/templates/datatype/ezxmltext/quote.tplEdit templateOverride template
1content/datatype/view/ezxmltags/link.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/link.tplEdit templateOverride template
3content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 42
 Number of unique templates used: 8

Time used to render debug report: 0.0001 secs