[Zope3-dev] a note on groups and roles

Steve Alexander steve at z3u.com
Thu Nov 20 05:17:37 EST 2003


Martijn Faassen wrote:
> Steve Alexander wrote:
> 
>>>I'm not sure what you mean here. Roles should be assigned to groups just 
>>>like
>>>to any other principal like a user,
>>
>>A group is a kind of principal? I find that odd.
> 
> 
>>Can a group be responsible for some actions?
>>
>>Can a group be responsible for some request?
> 
> 
> I thought the whole point of calling them 'principals' instead of 'users'
> was to enable concepts like groups to fit under the same banner as 
> users. You seem to be associating quite a different set of ideas with them.
>
> To me a principal is anything which can get a role assigned to them. :)

Let's say I choose to make roles able to imply other roles. That doesn't 
make a 'role' a principal, does it?


I thought the whole point of calling them 'principals' instead of 
'users' was to support concepts such as several users being jointly 
responsible for some action or request, and to represent agents that are 
responsible for actions that are not actually 'users', such as certificates.

--
Steve Alexander




More information about the Zope3-dev mailing list