Doing without form-builder-permissions.xml

classic Classic list List threaded Threaded
6 messages Options
Reply | Threaded
Open this post in threaded view
|

Doing without form-builder-permissions.xml

christinab
Hi,

I'm trying to take out the form-builder-permissions.xml file and find a
different way to map the roles. Maybe have them in a database. Is there a
way to do this? The reason we need to get rid of
form-builder-permissions.xml is that there will be too many roles to list.
The goal is for everything regarding roles to be in a database as opposed to
being hard-coded. Any direction would be great.

Thanks
Christina

--
Sent from: http://discuss.orbeon.com/

--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/orbeon/1565039467472-0.post%40n4.nabble.com.
Reply | Threaded
Open this post in threaded view
|

Re: Doing without form-builder-permissions.xml

Alessandro  Vernet
Administrator
Hi Christina,

At this point there isn't a way to have those permissions defined in a place
other than `form-builder-permissions.xml`. This is to say that this would
need to be implemented as a new feature. But I am curious: how many roles do
you expect to have, roughly? And could you tell me more about the use case
that calls for that many roles to be defined?

‑Alex

-----
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet
--
Sent from: http://discuss.orbeon.com/

--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/orbeon/1565041224172-0.post%40n4.nabble.com.
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet
Reply | Threaded
Open this post in threaded view
|

Re: Doing without form-builder-permissions.xml

christinab
Alessandro,

Thank you for your insight. We would have thousands of roles - we are using
Orbeon Forms for several different agencies to have several of roles within
them. The plan now is to block access to restricted resources within our
program so that we don't actually need Orbeon to have roles. We're just
starting on that now! So hopefully that comes together well.

Thanks again!
Christina

--
Sent from: http://discuss.orbeon.com/

--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/orbeon/1565099414480-0.post%40n4.nabble.com.
Reply | Threaded
Open this post in threaded view
|

Re: Doing without form-builder-permissions.xml

Alessandro  Vernet
Administrator
Hi Christina,

I can see the approach you describe work for cases where you want to prevent
form authors from accessing certain existing forms.

A minor downside is that when users try to access a page, say
`/fr/orbeon/builder/edit/123`, you'll need to call the Orbeon Forms API to
know what the app/form for `123` is before you can know whether to let the
user through or not.

More importantly, the following might be showstoppers:

1. You can't use the Form Builder summary page.
2. You can't really use the new page, since you can't restrict the app/form
name users enter.

Does this make sense, or am I missing something?

‑Alex

-----
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet
--
Sent from: http://discuss.orbeon.com/

--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/orbeon/1565215841568-0.post%40n4.nabble.com.
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet
Reply | Threaded
Open this post in threaded view
|

Re: Doing without form-builder-permissions.xml

christinab
Hey Alessandro!

So our plan involves a lot of URI parsing to work around the two things you
mentioned there. Since for every new form created, the URI will start with
"/fr/orbeon/builder/new", we have that as an acceptable URI.

As far as the new form summaries go, since the URI for a summary is
"/fr/app/form/summary", we are only going to have a few apps that we allow
to pass through, and from there we are going to let our program that we are
connecting Orbeon Forms to block everything that isn't a form saved in our
database to that app. With this part I don't know if I'm explaining it as
well as it was explained to me, just because I don't fully understand how we
are going to keep all of our users from viewing whatever form they want just
by writing in a different URL.

Blocking the overall summary page "/fr/" from end users is something we
absolutely want to do.

Our workaround seems like it's fine for like broke-stroke blocking, but I
don't know how tricky it will be within our program to track who can see
what.

I will definitely post back when we work this out!

Thanks!
Christina

--
Sent from: http://discuss.orbeon.com/

--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/orbeon/1565628035431-0.post%40n4.nabble.com.
Reply | Threaded
Open this post in threaded view
|

Re: Doing without form-builder-permissions.xml

Alessandro  Vernet
Administrator
Hi Christina,

Got it, and you'll just let us know if you find that the workaround you have
in mind turns out have some limitations you need to overcome.

‑Alex

-----
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet
--
Sent from: http://discuss.orbeon.com/

--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [hidden email].
To view this discussion on the web visit https://groups.google.com/d/msgid/orbeon/1565814901109-0.post%40n4.nabble.com.
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet