Wednesday 14 November 2007 3:23:34 am
Hi Rémy Limouzin <b>First read more about Role</b> http://ez.no/doc/ez_publish/technical_manual/3_9/concepts_and_basics/access_control
I have seen in you site that url http://www.ambeli.com/role/view/1 allows anonymouse user to do everything.
That is because of the following string: "content * * " Éditer le rôle : Anonymous
content read Section( Standard )
content pdf Section( Standard )
rss feed *
user login SiteAccess( ambeli )
<b>user login SiteAccess( ) </b>
content read Class( Flash , Image , Quicktime , Windows media , Real video , Banner ) , Section( Media )
content create Class( Atelier )
content create Class( Atelier )
content edit Class( Atelier )
<b>content * * </b>
infocollector * * <b>* * *</b> <b>Then I changed it to</b>
Affichage du rôle
Rôle
Nom
Anonymous
Règles d'action du rôleModule Fonction Limite
content read Section( Standard )
content pdf Section( Standard )
rss feed *
user login SiteAccess( ambeli )
content read Class( Flash , Image , Quicktime , Windows media , Real video , Banner ) , Section( Media )
content create Class( Atelier )
content create Class( Atelier )
content edit Class( Atelier )
infocollector * *
Utilisateurs et groupes assignés à ce rôleUtilisateur Limite
<b>And dont forget about "ParentClass, Section( Standard)" where Anonymous will create "Atelier" "content create Class( Atelier )"</b> Don't forget to remove user which was created by me for testing purposes. Good Luck!
|