PPL

Comment 8 for bug 688355

Revision history for this message
Christopher Adams (christopheradams) wrote :

Do forms have concept of permissions?

Here is the output of two different users visiting the /story/add/((id)) page.

This is the output from an Owner:

<div id="form_container"><form action="http://pple.aikilab.com/index.php?pretty=story/add/6238" method="post" enctype="multipart/form-data" id="new_record_form" name="new_record_form">
  <div class='ppl_stories'></div><div class='id'></div><div class='updated_at'></div><div class='story_title'><h2>Title</h2><input type="text" id="story_title" name="story_title" dir="" value=""></div><div class='story_body'><h2>Story</h2><div id="story_body_container"><textarea rows="7" dir="" cols="50" id="story_body" name="story_body"></textarea></div></div><div class='owner'></div><div class='userid'></div><div class='created_at'></div><p class="form-buttons"><input type="hidden" value="25" name="form_id"><input type="submit" class="submit_button" value="Submit" name="add_to_form"></p></form></div>

Here is the output from a user with People permissions

<div id="form_container"><form action="http://pple.aikilab.com/index.php?pretty=story/add/6306" method="post" enctype="multipart/form-data" id="new_record_form" name="new_record_form">
  <div class='ppl_stories'></div><div class='id'></div><div class='updated_at'></div><div class='story_title'></div><div class='story_body'></div><div class='owner'></div><div class='userid'></div><div class='created_at'></div><p class="form-buttons"><input type="hidden" value="25" name="form_id"><input type="submit" class="submit_button" value="Submit" name="add_to_form"></p></form></div>

Note that the later is missing the input form.