Opened 12 years ago

Last modified 11 years ago

#10421 closed enhancement

Do we really to implement permissions for this plugin? — at Initial Version

Reported by: Ryan J Ollos Owned by: yosiyuki
Priority: high Component: BookmarkPlugin
Severity: normal Keywords: permissions
Cc: Jun Omae Trac Release: 0.12

Description

I've been thinking lately about whether the permissions for this plugin offer any value. The plugin should be disabled for anonymous users, but for other users, what is the value of being able to grant the feature to some users, and not other users?

What use cases do people have that make use of the permissions? Would it be a problem to just drop the permissions? The feature seems to be pretty benign; I can't see the harm in providing it to everyone. Can anyone think of security holes that would be opened by dropping the permission? Dropping the permission would certainly simplify installation.

The BOOKMARK_MODIFY is not currently used, and I can't understand how it could be applicable even as features are added. Is there a use case for allowing users to view bookmarks, but not add them?

An alternative to permissions would be to have a user preference, so that users not wanting the feature could disable it.

What brought this to mind, was the possibility of including the feature in the Bloodhound project, and simplifying the installation in order to make that a more realistic possibility.

Change History (0)

Note: See TracTickets for help on using tickets.