On Tue, Oct 21, 2008 at 3:20 AM, blues <[EMAIL PROTECTED]> wrote: > > On Oct 20, 9:19 pm, "The Editor" <[EMAIL PROTECTED]> wrote: >> On Mon, Oct 20, 2008 at 8:37 AM, itay <[EMAIL PROTECTED]> wrote: >> > 1. What the meaning of the content of site.auth.upload? What does it >> > matter to the user from where can he upload if he can use it in all >> > the pages he can edit? (It's like to allow him to upload, but to do it >> > complicated for him) >> >> It can be used to control which users can upload from which pages. >> This way you can have people edit pages, but not be able to upload >> files. > > i think what itay means is that, from the moment that a user has > upload rights to ONE page, it's like it has upload rights to all pages > he can edit, since he then can use the uploaded file in any page. > the only thing is that the user is forced to use the upload action > only from the page where he has upload rights. > > as a result, upload rights are not page-centric, but user-centric. > that't the confusion in using pages to control uploads. maybe > site.auth.upload should be just the list of users that have upload > rights.
On site.auth.upload you would have entries like: site.upload: @members test*: @editor,bob etc. This should mean members can upload on site.upload page only (surely write protected), with editor's and bob also able to upload files from any test.* page. So it is a combination of pages and id's. The advantage is, you can create specially controlled upload forms which determines where the files are stored, their size, and even their file name, etc. according to whatever rules you desire. This allows you to setup criteria you can use elsewhere in using that information. On my site for example, members can load up profile pictures, there are all stored in a profile subdirectory and are named id.jpg. So on their profile page I can just refer to the graphic using their id as part of the file name. On the other hand (and I didn't catch this at first), it is true that once file is uploaded it is available on any page.a person has edit permissions and can add the appropriate markup. There is however, an optional site.auth.files page that can be created, which can allow you to control file by file who can see which graphics. For example, try creating the page and then adding: img1.gif: @members img2.gif: @editors,bob You will discover every file will be blocked unless specified. A bit of overkill perhaps, but it does give more fine tuned control. I'm open to suggestions for modifiying how this works, if someone can present a clear picture of what we would like to see happen. Easy syntax, etc. Cheers, Dan --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "BoltWire" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [EMAIL PROTECTED] For more options, visit this group at http://groups.google.com/group/boltwire?hl=en -~----------~----~----~----~------~----~------~--~---
