[TYPO3-dev] hide be_user options by default?

georg kuehnberger georg at georg.org
Fri Feb 1 00:49:38 CET 2008


Martin Kutschker wrote:
> Hi!
> 
> I'm a strong believer in rights-belong-to-groups setups. 

me, too.

So the fact
> that you can set things up in user accounts is 

IMHO to be removed completely; (hiding is at least a starter);

sometmes nice, but mostly
> a threat to a good rights management.

It's not only a thread, but unfortunately an invitation to do BAD 
rights-management;


> So I'd like to see a "show access lists" settings for users as well. 

NOPE;
IMHO
default TCA should disallow any User-Based Rights, thus requiring lazy 
admins to manage user-rights through group-config and inheritance;

> Unless this is check nearly all options would be hidden.
> Masi
> PS: The default access to live and draft should be removed as well.

YUP, including all other default rights ! - I'm not kidding here;
IMHO ALL rights of editors, should exclusively
- be handled via configurable BE-group-permissions (with maybe one 
default group + user including minimal rights), and
- no rights (except login) should be allowed by default;

This might seem to be a bit radical, however, that's IMHO the only way 
to "educate" "Admins" to do a decent setup.

TOTH to Masi for the kick-off;
regards georg




More information about the TYPO3-dev mailing list