RE: [PEAR-DEV] Re: permissions managment
| From: | Lukas Smith | Date: | Tue, 13 Aug 2002 14:08:12 +0000 |
| Subject: | RE: [PEAR-DEV] Re: permissions managment | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-8366@lists.php.net to get a copy of this message | ||
I am now also +1 to put LiveUser into PEAR.
I have talked things over with Markus.
While he is working on his short-term ToDO list I will work on other
things.
Namely (in order of importance):
- admin types
Person/User/Admin*: only has the right specifically given to him
Moduladmin: all the right of an Administrator plus he can do
anything within the modules he is assigned to as Moduladmin
Superadmin: can do anything a Moduladmin can do for all Modules
Masteradmin: can do anything
- implied user rights
for example it makes few sense to be able to delete entries if I
dont have the right to view them. Therefore the right delete implies
view.
- on demand user check
instead of always checking the user rights at object creation,
the user right is only gathered once the first real checkRights() is
done
- non bulk right retrieval
instead of always getting all user rights, I want to give the
option of just getting all rights in a single AuthArea or even just for
a specific right. The result will be stored in the array just as before.
This might come in handy when you have a lot of AuthAreas (might be
faster but will defiantely save some RAM)
- right levels
You can have a user right on 3 levels
Level 1: right only applies to data records you own
Level 2: right only applies to data records your group (or
someone in your group owns)
Level 3: right applies to all data records
- rights can have a scope
This is more of a feature for interface:
Certain rights may only be gained by a Person/User/Admin*.
This should reduce the amount of choices of rights that people
can gain. So it should make the interface more compact.
* Person/User/Admin:
Person: anonymous
User: known Person that has logged in
Admin: known Person that has logged in and has Administrator status
I have a word document where I describe the concepts that I have come up
with and that fit quite perfectly what Markus is doing with LiveUser. It
is in german however:
www.dybnet.de/perm/WebBuilder RMS Konzept.doc
www.dybnet.de/perm/Glossar.doc
FYI: AuthArea pretty much fits what my Modules are.
regards,
Lukas Smith
smith@dybnet.de
_______________________________
DybNet Internet Solutions GbR
Reuchlinstr. 10-11
Gebäude 4 1.OG Raum 6 (4.1.6)
10553 Berlin
Germany
Tel. : +49 30 83 22 50 00
Fax : +49 30 83 22 50 07
www.dybnet.de info@dybnet.de