[ 
https://issues.apache.org/jira/browse/CLEREZZA-393?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12982583#action_12982583
 ] 

Tsuyoshi Ito commented on CLEREZZA-393:
---------------------------------------

I have implemented 2 Permissions:

PermissionManagerAccessPermission
UserManagerAccessPermission

Furthermore the GUI and the webservices checks the permissions of the current 
user. if the latter has not assigned the permissions which he wants to add a 
response 403 is returned. These checks are ontop of java permission and should 
prevent endusers form misusage of the usermanager.webinterface.

> Permission for Administration->Logging
> --------------------------------------
>
>                 Key: CLEREZZA-393
>                 URL: https://issues.apache.org/jira/browse/CLEREZZA-393
>             Project: Clerezza
>          Issue Type: Improvement
>            Reporter: franco fallica
>            Priority: Trivial
>
> There should be a permission to see/edit administration permission. 
> Now even if you don't have the right to thw graph it still shows up in the 
> menu. Doesn't make much sense to me and it's likely that you don't want users 
> to see it. 

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.

Reply via email to