Update:Remora Permissions: Difference between revisions

no edit summary
No edit summary
Line 60: Line 60:
'''Note''' that when you disable ACLs using this method, you may not manually check permissions because this method essentially disables the components.
'''Note''' that when you disable ACLs using this method, you may not manually check permissions because this method essentially disables the components.


== Public permissions ==
== ACL Concerns and Feedback ==
* We have overlap between ACL and the user login and user ownership checks.  Do we want to consolidate or just keep things the way they are?  What would we gain from the better consistency?
* If a user is editing their personal profile is it possible for them to forge a form and edit their own rules field even if they shouldn't have the permissions to do it?
 
== Controller Notepad ==
Controllers, actions and their permissions.
Controllers, actions and their permissions.


3,035

edits