On 28/10/2014 13:43, "Richard Purdie" <[email protected]>
wrote:
>
>I think this is fine, however there is a "but" coming. I believe there
>will be some "site" configuration which people will desire, for example
>whether users can or cannot invite other users to projects or can create
>new users. Some of these operations will need to be restricted to some
>set of users.

Indeed. I spoke about the permissions system in my reply to Mihail. For
1.8, permissions will be very simple:
 
* Access to a project

* Creating projects

* Administering Toaster


>
>So whilst I like the idea, there will be a pressure towards elements of
>the other model and there are some reasons for that which we should try
>and consider if we can.

In this 'distributed' approach, you can grant permissions that match your
own permissions, so:

* Users who can only access projects cannot create users, and cannot grant
permissions of any kind

* Users that can create projects can grant access to other users and can
grant rights to create projects.

* Toaster administrators can grant access, grant rights to create projects
and create other Toaster administrators.

So as I mentioned before, we don't only distribute the workload: we also
distribute the responsibility. If you give someone the rights to
administer Toaster, we hope you know what you are doing.

I hope this makes sense.

Cheers

Belén


>
>I feel I'm explaining that badly, I hope this is understandable...
>
>Cheers,
>
>Richard
>
>
>

-- 
_______________________________________________
toaster mailing list
[email protected]
https://lists.yoctoproject.org/listinfo/toaster

Reply via email to