dsp-api
dsp-api copied to clipboard
In the context of permissions think in Roles instead of UserGroups
The current behavior should not change.
knora-base:Usercan be part of aknora-base:UserGroupknora-admin:Rolerepresents a role giving the holder certain permissions (knora-admin:Permission), which need to be defined separatelyknora-admin:Rolecan be attached toknora-base:Userandknora-base:UserGroup
The user's final permission is the sum of all roles and the permissions attached to each role.
The permission string knora-base:hasPermissions "M knora-base:ProjectMember" on a resource would thus have the meaning: award the permission M to the ProjectMember role.
Related issues:
- #679