you need to add the following security pattern (using the permissions module) for the 
forums.

Admins .*:.*: ADMIN
Users .*:.*: ????

if you want to allow moderators for specific categories, you'd do this (assuming you 
have a category named Foo)

Users Foo:.*: Level

if you wanted to allow moderators for a specific forum (assuming you have a forum 
named Bar), you'd do this:

Users .*:Bar: Level

you could also do a specific category and forum

Users Foo:Bar: Level 

----
i will work on a fix to allow individual users to edit their own posts as well. 

the issue stems from the fact that isIdentical method on the EJBObject uses the 
jndiName in it's comparison. 

what happens is the UserEJBLocal reference that is returned from the Api class has a 
different jndiName from the UserEJBLocal reference that is returned from the forums w/ 
information about the poster. 

given what we are doing, i think it will be safe to just use the user_id in the 
comparision to see if the person who posted message is the same one who is currently 
reading it. 
 



View the original post : 
http://www.jboss.org/index.html?module=bb&op=viewtopic&p=3840669#3840669

Reply to the post : 
http://www.jboss.org/index.html?module=bb&op=posting&mode=reply&p=3840669


-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - 
digital self defense, top technical experts, no vendor pitches, 
unmatched networking opportunities. Visit www.blackhat.com
_______________________________________________
JBoss-user mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/jboss-user

Reply via email to