Roles and permissions rules
This document outlines the patterns and principles for implementing permissions within GO 4 Schools MIS.
- can-view
- can-view-simple
- can-view-detailed
- can-manage
Rules for granting and revoking
- when a user is granted "can-manage" they are also granted "can-view"
- when "can-manage" is revoked, "can-view" is unaffected and must be revoked separately
- when "can-view" is revoked" the associated "can-manage" is also revoked
Can-view vs can-view-simple and can-view-detailed
Some areas include sensitive data that require a tiered approach to visibility, e.g. medical. In these cases "view" is further subdivided into "view-simple" and "view-detailed".
For a given entity type one of two "view" permission patterns will be followed
- single tier: can-view
- two tier:
- can-view-simple
- can-view-detailed
Granting and revoking can-view-simple and can-view-detailed
- when a user is granted "can-view-detailed" they are also granted "can-view-simple"
- when "can-view-detailed" is revoked, "can-view-simple" is unaffected and must be revoked separately
- when "can-view-simple" is revoked" the associated "can-view-detailed" is also revoked
Resolution of permissions granted or revoked through roles
The rules above are applied when granting permissions through the assignment of one or more roles. E.g.:
- [using a role] if you deny a view permission, the manage permission is also denied.
Precedence
- when resolving granted and denied permissions, regardless of the method by which a permission is awarded (via a role or as an additional permission), a deny rule ALWAYS has precedence.