Hi Sam:

On Wed, 21 Jul 2010, Samuele Kaplun wrote:
> The question is, shall we impose that authors are always authorized to
> access any file attached to a record?

Probably not fully globally, because the access may be problematic in
setups where we have pre-published record merged with published record
and this one has various `interesting' files attached to it that are
normally hidden from public's eyes.  Some of these are OK, especially
for read-only access to the author; but some may want to be kept in a
closet.  I guess these use cases can be filtered easily by status flag
or somesuch.  So I'd say generally yes, but not fully globally, let's
have a configurable set of flags that aren't touched by this.  More IRL.

Best regards
-- 
Tibor Simko

Reply via email to