Re: Replacing local roles on users with local roles on groups
Encolpe Degoute <[email protected]>
| Newsgroups | gmane.comp.web.zope.plone.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello, All this sounds really interresting to me. I'm thinking about 3 questions: You do you manage the Owner role and rights? Zope and Plone still have some specific behavior for that role. I'm not saying that we should keep them, I just want to know how you manage them. Anonymous and Authenticated, Members groups are very importants when you connect the large organizations' directories. Do you will modify them? CMFPlacefulWorkflow was developed for Plone 2.1 and 2.5 and need some refreshing^Wrecoding. Are you working on this too ? Best regards Le 21/11/2013 16:00, Matt Hamilton a écrit : > Hi All, > I'm currently sprinting on a suite of functionality for intranets in > Plone. This effort came about from an open space on intranets in > Brasilia. > > The aspect we are currently working on and brainstorming is the concept > of 'workspaces'. We are basing our work on David Glick's > collective.workspace package he is working on (taking ideas from the > other dozen 'workspace' implementations around). > > As anyone who has run a large Plone site knows, that assigning local > roles to users on containers can be expensive as it involves calling > reindexObjectSecurity on all children of the folder. > > The way we've always worked around this (and what c.workspace does, > and what many other people seem to do) is to create a group for the > 'workspace' and then assign the local roles to this group. Then manage > 'membership' of the workspace by adding/removing users from the group. > > I'm now wondering if this could be generalised to be a generic add-on > to Plone that entirely (mostly transparently) replaces local roles > added to users with local roles added to groups. > > >From the (existing) Sharing Tab if you assigned a local role to a > user, then it would behind the scenes create a group (maybe with a > custom PAS groups plugin, like c.workspaces) add the user to that > group and then assign the local role to that group. This first time > this happens for a particular content item / role combo then the > children would have to be re-indexed, but subsequent times you assign > a user that role on this container it would simply add the user to the > already-existing group. > > If maybe we can use a separate PAS plugin that would handle the > generation of the groups (which may not 'appear' as groups as we know > them) can anyone see why this idea would be insane? Anyone know of any > other products / PLIPs addressing this? > > Done this way, then we shouldn't need to change any of the behaviour > of the allowedRolesAndUsers index and all that stuff (which is a mess > too, but a far bigger problem to solve). > > -Matt > -- Encolpe DEGOUTE http://encolpe.degoute.free.fr/ Logiciels libres, hockey sur glace et autres activités cérébrales ------------------------------------------------------------------------------ Shape the Mobile Experience: Free Subscription Software experts and developers: Be at the forefront of tech innovation. Intel(R) Software Adrenaline delivers strategic insight and game-changing conversations that shape the rapidly evolving mobile landscape. Sign up now. http://pubads.g.doubleclick.net/gampad/clk?id=63431311&iu=/4140/ostg.clktrk