PDA

View Full Version : Permissions - allow vs deny


hazy
13-12-06, 12:40 AM
Hallo

I have just figured out that I can set up for example for the module 'Links'
Access 'Deny' and access 'Allow' at the same time!!!

Is that ok?

shouldn't be like this that if I set the access to allow for 'Access' and 'View' than access for 'Add' 'Edit' and 'Delete' is deny automatically?

thnx

PS I couldn't find the similiar topic at the forum but if i am wrong i will approciate the linke to the proper thread

oniTony
13-12-06, 01:59 AM
Permissions should probably be discussed in the Permissions forum... just a thought.

Everything is denied by default, unless it is allowed. Though you could allow a group, but then make exceptions by overwriting with deny on a personal level. (or the other way around)

hazy
13-12-06, 03:18 AM
but how to explain the fact that I can allow and deny at the same time the same option?

oniTony
13-12-06, 04:34 AM
possibly has to do with the way those settings are stored..

additionally I would just expect you to know what you are doing if you have access to change permissions :D

hazy
13-12-06, 09:28 PM
possibly has to do with the way those settings are stored..

additionally I would just expect you to know what you are doing if you have access to change permissions :D

I don't get what you mean by ' the way those settings are stored..' but still i think there should pop up an error message when im trying to set up 'allow' and 'deny' to the same option.

Does anybody have the same problem? or am i the only one? if so than do you know how can i solve it?

hazy
15-12-06, 10:49 PM
Is there anybody who can help me?
Is there any site i can read about it?
Is there anybody out there? ;)

c u

caseydk
29-12-06, 02:45 PM
I *believe* it applies all the Deny permissions first and then all the allows. This would allow a scenario where you can't see all the details for a Company but you could see the details for a specific Project for that Company.

Therefore, if you give both Deny/Allow, I *believe* it will first filter out that item and then filter it back in.

Yes, at some point there should be some logic to only allow one or the other for a specific item.