We are allowing our authenticated users the ability to create content that is registration-enabled. Ideally, we would like for the content author to be able to manage those registrations, mostly for the purposes of contacting registrants via email. However, this does not seem to be possible without assigning the ability to manage *all* registrations. Is this by design, or are we implementing the module incorrectly? Shouldn't there be a way for the content author to be limited to managing registration information for just the content he/she "owns"?

Comments

modctek’s picture

Any comments here? Is this something that is within planned scope of this module?

modctek’s picture

Anyone able to answer whether this will be something that this module will do?

dpi’s picture

Version: 7.x-1.0-beta2 » 7.x-1.x-dev
Category: support » feature

Sounds like a good feature to add.

Add permission: "administer own $type registration"

levelos’s picture

Status: Active » Fixed

Take a look at 87ab659.

dpi’s picture

Status: Fixed » Needs work

I fail to see how this was resolved in 87ab6594.

From my understanding fixing the issue would involve allowing the author of a host entity to edit the registration settings of the host entity. If the user has been granted "administer own $type registration".

Obviously there is no standard way to check who is the author of an entity, however you can assume that if the user has permission to 'edit' the entity, then access to the 'own' permission should be granted.

dpi’s picture

Status: Needs work » Needs review
StatusFileSize
new1.8 KB
levelos’s picture

Status: Needs review » Fixed

Sounds reasonable, thanks @dpi. Committed.

modctek’s picture

Looks great. I'll give this a try tonight!

modctek’s picture

This is working very well for us, thanks!

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.

  • levelos committed ac0fe45 on 7.x-1.x, panels, any-entity, slots, integrations, hold_state authored by dpi
    Corrections to #1616944 by dpi: Per entity permissions to manage...
  • levelos committed 87ab659 on 7.x-1.x, panels, any-entity, slots, integrations, hold_state
    #1616944: Add permission to manage own registration type settings.
    
semei’s picture

Issue summary: View changes

It seems to me that the permission to manage applications doesn't include the permission to view the actual registration, does it? When I try to access the absolute URL of the registration I have received (in order to view the values of its attached fields), I get set back to my own user profile.