On Tue, Oct 21, 2008 at 3:20 AM, blues <[EMAIL PROTECTED]> wrote:
>
> On Oct 20, 9:19 pm, "The Editor" <[EMAIL PROTECTED]> wrote:
>> On Mon, Oct 20, 2008 at 8:37 AM, itay <[EMAIL PROTECTED]> wrote:
>> > 1. What the meaning of the content of site.auth.upload? What does it
>> > matter to the user from where can he upload if he can use it in all
>> > the pages he can edit? (It's like to allow him to upload, but to do it
>> > complicated for him)
>>
>> It can be used to control which users can upload from which pages.
>> This way you can have people edit pages, but not be able to upload
>> files.
>
> i think what itay means is that, from the moment that a user has
> upload rights to ONE page, it's like it has upload rights to all pages
> he can edit, since he then can use the uploaded file in any page.
> the only thing is that the user is forced to use the upload action
> only from the page where he has upload rights.
>
> as a result, upload rights are not page-centric, but user-centric.
> that't the confusion in using pages to control uploads. maybe
> site.auth.upload should be just the list of users that have upload
> rights.

On site.auth.upload you would have entries like:

site.upload: @members
test*: @editor,bob
etc.

This should mean members can upload on site.upload page only (surely
write protected), with editor's and bob also able to upload files from
any test.* page.  So it is a combination of pages and id's.

The advantage is, you can create specially controlled upload forms
which determines where the files are stored, their size, and even
their file name, etc. according to whatever rules you desire. This
allows you to setup criteria you can use elsewhere in using that
information. On my site for example, members can load up profile
pictures, there are all stored in a profile subdirectory and are named
id.jpg. So on their profile page I can just refer to the graphic using
their id as part of the file name.

On the other hand (and I didn't catch this at first), it is true that
once file is uploaded it is available on any page.a person has edit
permissions and can add the appropriate markup.

There is however, an optional site.auth.files page that can be
created, which can allow you to control file by file who can see which
graphics. For example, try creating the page and then adding:

img1.gif: @members
img2.gif: @editors,bob

You will discover every file will be blocked unless specified. A bit
of overkill perhaps, but it does give more fine tuned control.

I'm open to suggestions for modifiying how this works, if someone can
present a clear picture of what we would like to see happen. Easy
syntax, etc.

Cheers,
Dan

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"BoltWire" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/boltwire?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to