I am developing a site that needs an access permission scheme. I'm not sure how I want to structure the scheme, and it's hard for me to find good resources to determine not only how to implement the permission scheme, but also how to plan what the scheme should be capable of.
I have a lot of questions, not a lot of solid information. And I can not formulate the pros and cons of the answers available.
- Should it be role based and if users have roles?
- Should it be based on a group?
- If groups can be members of groups, as in AD?
- Or can only users be members of groups?
- How do I handle default permissions?
- Should it be installed based on the tool that creates the page?
- Should the creating user set permissions when creating the page?
- Should users create their own groups?
What is your experience in developing permission schemes? I am pretty green at that, and any good resources, books, blogs, etc. Will be really helpful.
source
share