[Building Sakai] permisions in forums

José Mariano Luján González jmariano at um.es
Thu Nov 4 01:48:20 PDT 2010


Hi,
This is Mariano, from the University of Murcia (Spain), we are currently 
running sakai 2.7.1 and we are experiencing something really weird with 
the use of the forums tool. We have set up custom types of sites and 
roles but following the same templates as the type of site course and 
the roles instructor, TA and student. So in forums, as you might know, 
there are a set of permissions that the owner of the forum can customize 
for each role of the site. For example, the instructor (owner of the 
forum) can customize, by cliking in /"Forum settings",/ the student role 
and set their permissions so that they act like owner too. In our case, 
by default, for the role student, they act like a contributor, not an 
owner. So a student can only post new threads but not create forums, 
topics and of course, not customize forums. So a student should never 
see the menu option "Forum settings" and not either the opction 
"Delete". That initial configuration seems to come because sakai is 
mapping the section.role.student permission to the contributor role in 
forums, so a student would be a contributor and the instructor who has 
section.role.instructor permission is the owner. Until here, everything 
seems to work fine but we have found out that in some random cases, some 
students can customize the permissions in forums because they see the 
menu options "/Forum settings/" and "/Delete/". This students have a 
site role which is the same as the default student role from sakai and 
of course, they don´t have site.upd permission. The weird thing about it 
is that a student with for example 6 courses (6 different sites but with 
same permissions and roles), would only see this in one site. But if we 
take a look at the permissions, we see that he has the student role in 
the site and that student role has the contributor role in forums with 
the option "Change settings" uncheked so it doesn´t make any sense at 
all...
Since we are piloting right now, to do some research about this weird 
thing, we have used the tool "Become user" in production with real 
students in order to check with 7 different students but with the same 
courses (6 courses from the same degree). It only happened twice but 2 
different students in two different courses. Its weird, right?? We have 
tried to find a pattern with those users but nothing makes them unique 
from the other 5 users, it seems very random... If anyone have 
experienced something similar or have an idea of what the problem could 
be, please let us know!
Thanks in advance!
Mariano
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://collab.sakaiproject.org/pipermail/sakai-dev/attachments/20101104/5ed7575d/attachment.html 


More information about the sakai-dev mailing list