Announcement

#1 2014-01-11 00:08:37

Todd Gee
Guest

New Security Model

Hey Folks ->

I'm migrating to Piwigo from Gallery2 and am excited as Piwigo seems much more efficient.

However, I'm confused by the separate permissions model in use for albums and for photos.

Albums allow privacy per user groups.  Users in specified groups can access the albums that are private to the group.  (I'm still learning, so I'm not exactly sure of what privileges are granted by being part of the affiliated group -- whether it's read only or allows writing -- doesn't make a difference here tho.)

Photos use the hard coded admin/family/friends/contacts/everybody security levels.  A photo requires a specified permission level or above to view..  (Again, possibly other permissions are granted by having a sufficient security level -- not salient here.)

I'm wondering why the continued use of these dual security models.  I do think the role/permission model used for albums is ultimately the more flexible of the two -- one group could give access to one set of things, another group could give access to another set of things.  Groups (roles) can be assigned to users at will.

Migration away from the permission level model for photos would be simple -- each permission level could be made a group with the specified permissions added to the group.

I think having a single security model for albums and photos would make things simpler overall and would be more powerful to boot!

 

#2 2014-01-11 07:01:24

rvelices
Former Piwigo Team
2005-12-29
1960

Re: New Security Model

Simple usage: trip photos in a single album. Friends can see photos of me. Guests see sunsets and animals...

Offline

 

#3 2014-01-11 15:16:51

flop25
Piwigo Team
2006-07-06
7037

Re: New Security Model

Hello
Since Piwigo allow only administrators to uplaod, the permissions are for viewing.
the security level per photos would be a lot more resource consuming, if it was integrated with groups etc.
The admin/family/friends/contacts/everybody security levels are not hard coded and can be changed using the local configuration and then translated using also the local translations.


To get a better help : Politeness like Hello-A link-Your past actions precisely described
Check my extensions : more than 30 available
who I am and what I do : http://fr.gravatar.com/flop25
My gallery : an illustration of how to integrate Piwigo in your website

Offline

 

#4 2014-02-06 07:58:11

samwilson
Member
Fremantle, Western Australia
2014-02-06
42

Re: New Security Model

This makes lots of sense. I don't use Groups at all and just rely on the Privacy Levels.

Offline

 

Board footer

Powered by FluxBB

github twitter newsletter Donate Piwigo.org © 2002-2024 · Contact