forked from trheyi/Ghost
-
Notifications
You must be signed in to change notification settings - Fork 0
User Roles & Permissions
Hannah Wolfe edited this page Jul 9, 2014
·
17 revisions
| Name | Description |
|---|---|
| Owner | Automatically has all permissions. There can only ever be one owner, the owner cannot be deleted |
| Admin | Has all permissions, except being able to transfer ownership of the blog |
| Editor | Has permissions to manage their posts, and the posts of authors. Also has permissions to add and edit author users. |
| Author | Has permissions to create and edit their own posts, and their own user details |
| No-Auth | User who is not authenticated - i.e. a reader on the blog |
| API Method | Admin | Editor | Author | NoAuth |
|---|---|---|---|---|
| browse | y | y | y (status == published or created_by == self) | y (status == published) |
| read | y | y | y (status == published or created_by == self) | y (status == published) |
| edit | y | y | y (created_by == self) | |
| add | y | y | y | |
| destroy | y | y | y (created_by == self) | |
| getSlug | y | y | y |
| JSON API | Admin | Editor | Author | NoAuth |
|---|---|---|---|---|
| users.browse | y | y | y | |
| users.read | y | y | y | y |
| users.edit | y | y | y (user == self) | |
| users.add | y | y |
| API Method | Admin | Editor | Author | NoAuth |
|---|---|---|---|---|
| db.exportContent | y | |||
| db.importContent | y | |||
| db.deleteAllContent | y |
| API Method | Admin | Editor | Author | NoAuth |
|---|---|---|---|---|
| settings.browse |
- core | | | |
- blog | y | y | y | y
- app | y | y | y |
- theme | y | y | y | settings.read | | | |
- core | | | |
- blog | y | y | y | y
- app | y | y | y |
- theme | y | y | y | settings.edit | | | |
- core | | | |
- blog | y | | |
- app | y | | |
- theme | y | | |