About security
19
You can specify the following permissions on a SCO:
Because a group is a principal, you can set these permissions on a SCO for a custom group as well
as for an individual user; if a group has a particular permission, all members of the group have
that permission. Use the
group-membership-update
API to add a member to a group. Use the
permissions-update
API to set a group’s permissions for a particular SCO.
For more information about groups and permissions, see Chapter 19, “Working with Users and
Groups,” in
Breeze Manager User Guide
.
About security and launching content
When you launch a SCO, you must provide authentication. You can do so using any of the
following approaches:
•
When you open the URL of the content, add a query parameter named
session
with a value
equal to the value of the
BREEZESESSION
login cookie, as the following example shows:
http://breeze.example.com/p12345678/?session=breez3238uf298
This approach is a potential security problem because anyone who obtains the specified URL
can act as the logged-in user. If you take this approach, use the cookie for an ordinary user
rather than the cookie for an administrative user.
Also, if users give the URL to someone else (for example, by copying it and pasting it into an
e-mail message), they are giving access to their account, which presents a security risk.
Permission
Description
Denied
The principal cannot view, access, or manage the SCO. You cannot specify this
permission on meetings or courses.
Host
(For meetings only) The host of a meeting. This permission lets the principal
create or present the meeting, even if the principal doesn’t have View permission
on the parent folder of the meeting.
The Presenter permission is now an alias for Host. A presenter in Breeze 4
presenter is a host in Breeze 5.
Manage
The principal can view, delete, move, and edit the SCO. This permission also lets
the principal set permissions for the SCO. For a folder, the Manage permission
lets the principal view reports for files in the folder and create new folders. You
cannot specify this permission on meetings or courses.
Publish
The principal can publish the SCO to the server and can update the SCO. This
permission includes the View permission. It also lets the principal view reports
related to the SCO. For a folder, the Publish permission doesn’t let the principal
create new folders within the folder or set permissions for the folder. You cannot
specify this permission on meetings or courses.
View
The principal can view the SCO but not modify it. For a course, the View
permission lets the principal enroll in the course. For a meeting, the View
permission lets the principal attend the meeting. For a folder, this permission lets
the principal view the contents of the folder.
Содержание BREEZE 5
Страница 1: ...Breeze Integration Guide ...
Страница 40: ...40 Chapter 3 Common Tasks ...