Skip to content
  • There are no suggestions because the search field is empty.

Roles and permissions rules

This document outlines the patterns and principles for implementing permissions within GO 4 Schools MIS.

Fundamental permission types

  • can-view
    • can-view-simple
    • can-view-detailed
  • can-manage

Rules for granting and revoking

  • when a user is granted "can-manage" they are also granted "can-view"
  • when "can-manage" is revoked, "can-view" is unaffected and must be revoked separately
  • when "can-view" is revoked" the associated "can-manage" is also revoked

Can-view vs can-view-simple and can-view-detailed

Some areas include sensitive data that require a tiered approach to visibility, e.g. medical. In these cases "view" is further subdivided into "view-simple" and "view-detailed".

For a given entity type one of two "view" permission patterns will be followed

  • single tier: can-view
  • two tier:
    • can-view-simple
    • can-view-detailed

Granting and revoking can-view-simple and can-view-detailed

  • when a user is granted "can-view-detailed" they are also granted "can-view-simple"
  • when "can-view-detailed" is revoked, "can-view-simple" is unaffected and must be revoked separately
  • when "can-view-simple" is revoked" the associated "can-view-detailed" is also revoked

Resolution of permissions granted or revoked through roles

The rules above are applied when granting permissions through the assignment of one or more roles. E.g.:

  • [using a role] if you deny a view permission, the manage permission is also denied.

Precedence

  • when resolving granted and denied permissions, regardless of the method by which a permission is awarded (via a role or as an additional permission), a deny rule ALWAYS has precedence.