Keep permission checks at the boundary

Use the request context when checking access to data and actions. A hidden button is not an authorization check: callers can invoke a model or endpoint directly.

Check the resource, action, and module permission that the operation requires. Return a clear error when access is denied. Test as an anonymous visitor, an editor with limited rights, and an administrator.

Avoid replacing the caller's context with a privileged shell context in application code. If a background task needs elevated access, constrain the operation and authorize its initiation explicitly.

Test with different users

Choose roles that exercise the operation's permission boundary: anonymous visitor, limited editor, and administrator. Use separate browser sessions or an explicit test context for each role.

Test the direct model or endpoint as well as the visible interface. Confirm that denied writes leave the data unchanged and do not reveal private fields in the error response.

Include unpublished resources and resources outside the user's content group where relevant. Record the role and resource used in the test so someone else can reproduce the result.

Also in: Developer guide

Referred by

Controllers

controller_file

Serve an uploaded-, resized- or library file.

Modules

mod_authentication

This module contains the main Zotonic authentication mechanism. It contains the logon and logoff controllers, and implements the various hooks as described in…

Reference

ACL options

Authorization checks to perform, in addition to the acl_action dispatch option, can be given in the acl dispatch option, and accepts the following options:

Modules

mod_facebook

The mod_facebook module plugs into the authentication system to enable Facebook login on your site.

Modules

mod_admin_predicate

Add support for editing predicates in the admin, by presenting a list of all defined predicates on http://yoursite.com/admin/predicate .

Modules

mod_linkedin

The mod_linkedin module plugs into the authentication system to enable LinkedIn login on your site.