Mailing List Archive

[Bricolage-General] All Users
We found something interesting with the All Users group, and I'm wondering
if it's a bug, scope oversight, or a non-issue. I feel like it's been
discussed before but couldn't find the thread, so forgive me for rehashing
(if I am).

We created a user and put her in the "All User" group. When you log in, all
you see is Admin in the left-hand nav. When you click on Admin, you get
System, Publishing, and Distribution. Clicking on any of these items will
list the components in that section (Preferences, Users, etc for ADMIN, and
so on).

However, when you click on each of these components (Groups in Admin for
example), you can't view anything within the component. So an "All User"
can see Groups in Admin, however when she clicks on it, it appears there are
no Groups.

I re-logged in as a Global Admin (the power!) and looked in Groups for All
Users. Not there. So I ask:

-- Is All Users a "default" group that isn't configurable via the UI?
-- Seems if the user has no access to anything within the component, she
shouldn't be able to view the component. Should we make "All Users"
configurable via the UI, or make someone who's only in "All Users" see Admin
> Users > [their profile]?

Given the flexibility theme in Bric, seems like it should be configurable
via the UI with the read access to their own profile as the baseline, the
lowest that perms can be set.

Thoughts?


Thanks,
Jason
Re: [Bricolage-General] All Users [ In reply to ]
On Thursday, March 28, 2002, at 09:02 AM, Merrick, Jason wrote:

>  -- Is All Users a "default" group that isn't configurable via the UI?

Yes. All users are in the All Users group by default (makes sense, don't
it?). If you add users to no other groups, they'll have access to nothing
but their own user profile.

>  -- Seems if the user has no access to anything within the component, she
> shouldn't be able to view the component.  Should we make "All Users"
> configurable via the UI, or make someone who's only in "All Users" see
> Admin > Users > [their profile]?

The way that permissions work is to grant/limit access to groups of
objects in the system. The ADMIN menus aren't object -- they're just
convenience links to areas that display lists of objects. So there's
really no way to limit viewing the menus, even if, when you click on them,
you don't see anything.

> Given the flexibility theme in Bric, seems like it should be configurable
> via the UI with the read access to their own profile as the baseline, the
> lowest that perms can be set.

The user should be able to edit his/her own user profile.

HTH,

David


_______________________________________________
Bricolage-General mailing list
Bricolage-General@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/bricolage-general