Security Advice needed, re: Group vs Category
Posted: Fri Nov 06, 2009 7:24 pm
Hi.
Now that I've done a clean install from your download files, I'm finding your blog software really cool, easy to use, and easy to configure. Thank you for a great product.
Advice I can offer so far to other newbies. Using that easy-peezy-lemon-squeezy control-panel install from your hosting provider will probably make your life harder, not easier.
Ok, now, one thing I'm having trouble with is the security strategy that pulls categories in with groups.
It may be that I'm trying to make blog software serve in a roll of document-management and that I'm trying to turn a screw with a hammer.
Groups are great, let's say:
Visitors
Acquaintances
Friends
Good Friends
Best Friends
I want the same set of content-categories to show for each of these groups (even if there are only one or two people in there... ahem...
). Depending on what category, or set of categories they choose to view, I want them to see all the messages to which their group has been given access.
As a newbie, and un-initiated, I want to think this would require View and Comment attributes to be specifiable for each message. It would be fine with me if these attributes each held only a single security group. I don't mind making people members of multiple groups depending on where they are in the hierarchy (e.g. Friends are members of "Friends", "Acquaintances", and "Visitors" groups).
I've messed with the category hierarchy, but that either spreads a single content-category over multiple security branches of the tree, or it spreads a given security-group over a multiple content-categories of a tree. Either way (I think), the visitor will have to click into multiple combined security/content categories to see all the message in a given content-only category.
I suppose you could place a given message in multiple security-categories for the same content-category but this would seem even more tedious than just saying what group gets to read, and what group gets to comment. Also, since content-categories are listed on each entry, this would certainly clutter up the display. And what a mess if your entry fits into multiple content-categories.
Also, having a tree of security-over-content, or content-over-security would multiply the categories listing on the side of the blog listing-screen. In essence, no matter how you do it, you'd have a list of security- multiplied by content-category categories in the listing.
I notices that the category plug in lets you limit your blog to a single root-level branch (or a single ANY level branch), but I haven't been able to figure out how to make that work to resolve the issues alluded to above...
That's why I'm here, hat in hand, asking for your advice....
Thanks if you can help.
-djr
Now that I've done a clean install from your download files, I'm finding your blog software really cool, easy to use, and easy to configure. Thank you for a great product.
Advice I can offer so far to other newbies. Using that easy-peezy-lemon-squeezy control-panel install from your hosting provider will probably make your life harder, not easier.
Ok, now, one thing I'm having trouble with is the security strategy that pulls categories in with groups.
It may be that I'm trying to make blog software serve in a roll of document-management and that I'm trying to turn a screw with a hammer.
Groups are great, let's say:
Visitors
Acquaintances
Friends
Good Friends
Best Friends
I want the same set of content-categories to show for each of these groups (even if there are only one or two people in there... ahem...
As a newbie, and un-initiated, I want to think this would require View and Comment attributes to be specifiable for each message. It would be fine with me if these attributes each held only a single security group. I don't mind making people members of multiple groups depending on where they are in the hierarchy (e.g. Friends are members of "Friends", "Acquaintances", and "Visitors" groups).
I've messed with the category hierarchy, but that either spreads a single content-category over multiple security branches of the tree, or it spreads a given security-group over a multiple content-categories of a tree. Either way (I think), the visitor will have to click into multiple combined security/content categories to see all the message in a given content-only category.
I suppose you could place a given message in multiple security-categories for the same content-category but this would seem even more tedious than just saying what group gets to read, and what group gets to comment. Also, since content-categories are listed on each entry, this would certainly clutter up the display. And what a mess if your entry fits into multiple content-categories.
Also, having a tree of security-over-content, or content-over-security would multiply the categories listing on the side of the blog listing-screen. In essence, no matter how you do it, you'd have a list of security- multiplied by content-category categories in the listing.
I notices that the category plug in lets you limit your blog to a single root-level branch (or a single ANY level branch), but I haven't been able to figure out how to make that work to resolve the issues alluded to above...
That's why I'm here, hat in hand, asking for your advice....
Thanks if you can help.
-djr