Re: Permission issue

Chuck Cunningham <[email protected]>
Newsgroups gmane.comp.bug-tracking.roundup.user
Message-ID <CAH-41398c40N-y_hjr_02+J1X+4X+Dm181T0S8_vAOOV4BZ24A@mail.gmail.com>
Thanks very much, this did indeed fix the problem.  I will take a more
careful look at the Provisional User example.  I think adding two lines for
the issue Search permission to the other example I was trying would be a
good improvement to the docs.

By the way, I'll just take this opportunity to say how much I like Roundup,
it rocks.  Thank you to everyone who works on this.

Charles

On Tue, Nov 23, 2021 at 8:30 PM John P. Rouillard <[email protected]> wrote:

> Hello Chuck:
>
> Welcome to Roundup I'm sorry your are having problems, but I may have
> a solution.
>
> In message
> <CAH-41388SWAGShnEKUuEuZs727f2yCkd4=-nVejkFcCoHhQ3uA@mail.gmail.com> ,
> Chuck Cunningham writes:
> >I've been trying to implement this customization below, from
> >https://www.roundup-tracker.org/docs/customizing.html#examples
> >
> >It works nicely except for one thing - the dropdowns for "Sort on" and
> >'Group on" on the webpage become empty when I put this into schema.py, and
> >I can't sort or group when logged in (although anonymous still has the
> >dropdowns)...
>
> My guess is Anonymous has View access on the issues as well. Is this
> correct? If you run 'roundup-admin -i <tracker dir> security'
>
> >It seems like a permission issue, but I can't figure out what
> >permission controls those dropdowns...any advice would be appreciated!
>
> I'll bet it's the Search permission that was added after that example
> was created.
>
> >All users may only view and edit issues, files and messages they create
> ><https://www.roundup-tracker.org/docs/customizing.html#id126>
> >
> >Replace the standard “classic” tracker View and Edit Permission
> assignments
> >for the “issue”, “file” and “msg” classes with the following:
>
> Please change the code by ading description parameter (optional)
> and the two last lines:
>
>
> def checker(klass):
>     def check(db, userid, itemid, klass=klass):
>         return db.getclass(klass).get(itemid, 'creator') == userid
>     return checkfor cl in 'issue', 'file', 'msg':
>     p = db.security.addPermission(name='View', klass=cl,
>         check=checker(cl), description='User can view only if creator.')
>     db.security.addPermissionToRole('User', p)
>     p = db.security.addPermission(name='Edit', klass=cl,
>         check=checker(cl), description='User can edit only if creator.')
>     db.security.addPermissionToRole('User', p)
>     db.security.addPermissionToRole('User', 'Create', cl)
> # add the two lines below
> p = db.security.addPermission(name='Search', klass='issue')
> db.security.addPermissionToRole('User', p)
>
> This adds the Search permission to the user role. By default the
> search permission is implied by the View permission. If the view
> permission denies access to the class in general (which this check
> command does), the Search permission is added to allow viewing of the
> properties of the class. The description lines are displayed when you
> run the security command for roundup-admin. Makes it a little clearer
> that it's not normal view/edit permissions.
>
> The 'Users may only edit their issues' example with the Provisional
> User demonstrates adding the Search permission. That example includes:
>
>     # This allows the interface to get the names of the properties
>     # in the issue. Used for selecting sorting and grouping
>     # on the index page.
>     p = db.security.addPermission(name='Search', klass='issue')
>     db.security.addPermissionToRole ('Provisional User', p)
>
> This example also uses the description parameter.
>
> If this change solves your issue, I'll update the example to include
> Search perms.
>
> Hope this helps. Have a great day and stay safe.
>
> --
>                                 -- rouilj
> John Rouillard
> ===========================================================================
> My employers don't acknowledge my existence much less my opinions.
>

_______________________________________________
Roundup-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/roundup-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.