oh oh ... within seconds I realize a severe flaw in my plan, and a
flaw in the current Jetspeed role-based model: The whole /point/ of
role-based access is because people change whereas roles remain the
same, but in the current role-merging model, once a person is granted
the structure of some role's portlets, if they are re-assigned to some
other role, although the security model can prevent them from /seeing/
particular portlets, the only way to actually remove them is to do it
manually.

Here's my exact problem, and maybe this will give someone a better
idea for how I could accomplish this:  

     I have public members, paid members and internal staff members.

     Everyone is anonymous until they register, at which point they
     become a public member.

     Paid members are promoted from the public members, and are
     demoted if their subscription lapses.  

     Ideally, one supervisory role among the staff has exclusive
     access to do this promotion, and that suggests an Action
     within a VelocityPortlet instead of the normal user editor.

     Members could go straight from public membership to staff;
     staff is not a superset of paid, it is only partially 
     overlapping.

Are there any magic bullets for doing what I need to do here?

-- 
Gary Lawrence Murphy - [EMAIL PROTECTED] - TeleDynamics Communications
   - blog: http://www.teledyn.com/mt/ - biz: http://teledyn.com/ -
  "Computers are useless. They can only give you answers." (Picasso)

--
To unsubscribe, e-mail:   <mailto:[EMAIL PROTECTED]>
For additional commands, e-mail: <mailto:[EMAIL PROTECTED]>

Reply via email to