You are viewing a plain text version of this content. The canonical link for it is here.
Posted to user@lenya.apache.org by Simon Dutil <s....@gmail.com> on 2004/09/14 20:42:19 UTC

AC Live

Hi list,

Im having problems with the access controler for the live section of the site.  

For the authoring section, the access right "world ( the world )" is
defined in the Ac live tab.  Right next to it, there is a delete
button but clicking on it have no effects!

With "The world" access right set at that level, at any time, even if
i add a group of user in the Ac live tab, anyone can get access to
every pages that are "live".

I have removed <ac:world>...</ac:world> directly from
subtree-policy.acml file located in
\\lenya\lenya\pubs\$myPub\config\ac\policies\live.  Now, when i add a
group of user in Ac live tab, only the members of the specified group
can read the page, Lenya ask for a login&password...

I was wondering why the default publication have the "world" set in Ac
live tab for the authoring section and why the delete button isnt
working ( you dont want user to remove it ? )

Thanks in advance!

Simon

---------------------------------------------------------------------
To unsubscribe, e-mail: lenya-user-unsubscribe@cocoon.apache.org
For additional commands, e-mail: lenya-user-help@cocoon.apache.org


Re: AC Live

Posted by Andreas Hartmann <an...@apache.org>.
Simon Dutil wrote:
> On Wed, 15 Sep 2004 09:20:58 +0200, Andreas Hartmann <an...@apache.org> wrote:
> 
> 
>>Simon Dutil wrote:
>>
>>>Hi list,
>>>
>>>Im having problems with the access controler for the live section of the site.
>>>
>>>For the authoring section, the access right "world ( the world )" is
>>>defined in the Ac live tab.  Right next to it, there is a delete
>>>button but clicking on it have no effects!
>>
>>This is a bug. The question is, what to do about it ...
>>We could remove the delete button or allow the deletion,
>>any suggestions?
>>
> 
> 
> I think that the access right "the world" should be removed from
> there...I mean that there is no need to have it defined at that level,
> we already have the inherited rights "the world" that is allowing, by
> default, every users to visit the live section.  Having it hardcoded
> seems more like desactivating the access controler feature for the
> live section...

Actually, the problem is that on the "authoring" node the
inherited world (grey) and defined world (black) is identical.

I think that's why you can't delete it.

I didn't yet have the time to dig deeper into this problem,
but I'll try on the weekend.

[...]

>>The idea behind this is that the live section is visible for everybody
>>by default, but can be restricted to certain users/groups/ip-ranges.
>>It seems to be buggy ATM, would you mind adding some bugzilla entries?
>>
> 
> 
> Yeah no problem! this will be done by the end of the day ( in -0400
> time zone ! )

OK, that's great.
Thanks!
-- Andreas


---------------------------------------------------------------------
To unsubscribe, e-mail: lenya-user-unsubscribe@cocoon.apache.org
For additional commands, e-mail: lenya-user-help@cocoon.apache.org


Re: AC Live

Posted by Simon Dutil <s....@gmail.com>.
On Wed, 15 Sep 2004 09:20:58 +0200, Andreas Hartmann <an...@apache.org> wrote:

> Simon Dutil wrote:
> > Hi list,
> >
> > Im having problems with the access controler for the live section of the site.
> >
> > For the authoring section, the access right "world ( the world )" is
> > defined in the Ac live tab.  Right next to it, there is a delete
> > button but clicking on it have no effects!
> 
> This is a bug. The question is, what to do about it ...
> We could remove the delete button or allow the deletion,
> any suggestions?
>

I think that the access right "the world" should be removed from
there...I mean that there is no need to have it defined at that level,
we already have the inherited rights "the world" that is allowing, by
default, every users to visit the live section.  Having it hardcoded
seems more like desactivating the access controler feature for the
live section...
 
> > With "The world" access right set at that level, at any time, even if
> > i add a group of user in the Ac live tab, anyone can get access to
> > every pages that are "live".
> 
> This seems to be a bug too. Actually, when you add a group
> to a subtree, the access on this subtree should be restricted
> to this group.
> 
> > I have removed <ac:world>...</ac:world> directly from
> > subtree-policy.acml file located in
> > \\lenya\lenya\pubs\$myPub\config\ac\policies\live.  Now, when i add a
> > group of user in Ac live tab, only the members of the specified group
> > can read the page, Lenya ask for a login&password...
> >
> > I was wondering why the default publication have the "world" set in Ac
> > live tab for the authoring section and why the delete button isnt
> > working ( you dont want user to remove it ? )
> 
> The idea behind this is that the live section is visible for everybody
> by default, but can be restricted to certain users/groups/ip-ranges.
> It seems to be buggy ATM, would you mind adding some bugzilla entries?
> 

Yeah no problem! this will be done by the end of the day ( in -0400
time zone ! )

> Thanks!
> -- Andreas
>

Regards,

Simon

---------------------------------------------------------------------
To unsubscribe, e-mail: lenya-user-unsubscribe@cocoon.apache.org
For additional commands, e-mail: lenya-user-help@cocoon.apache.org


Re: AC Live

Posted by Andreas Hartmann <an...@apache.org>.
Simon Dutil wrote:
> Hi list,
> 
> Im having problems with the access controler for the live section of the site.  
> 
> For the authoring section, the access right "world ( the world )" is
> defined in the Ac live tab.  Right next to it, there is a delete
> button but clicking on it have no effects!

This is a bug. The question is, what to do about it ...
We could remove the delete button or allow the deletion,
any suggestions?

> With "The world" access right set at that level, at any time, even if
> i add a group of user in the Ac live tab, anyone can get access to
> every pages that are "live".

This seems to be a bug too. Actually, when you add a group
to a subtree, the access on this subtree should be restricted
to this group.

> I have removed <ac:world>...</ac:world> directly from
> subtree-policy.acml file located in
> \\lenya\lenya\pubs\$myPub\config\ac\policies\live.  Now, when i add a
> group of user in Ac live tab, only the members of the specified group
> can read the page, Lenya ask for a login&password...
> 
> I was wondering why the default publication have the "world" set in Ac
> live tab for the authoring section and why the delete button isnt
> working ( you dont want user to remove it ? )

The idea behind this is that the live section is visible for everybody
by default, but can be restricted to certain users/groups/ip-ranges.
It seems to be buggy ATM, would you mind adding some bugzilla entries?

Thanks!
-- Andreas


---------------------------------------------------------------------
To unsubscribe, e-mail: lenya-user-unsubscribe@cocoon.apache.org
For additional commands, e-mail: lenya-user-help@cocoon.apache.org