Granular group-based permissions for anonymous and logged in users

wait just seen this.

so some people were confused by everyone meaning just logged in users?

who?!

everyone is everyone surely - very clear.

everyone is everyone who is hitting the site, logged in or no, surely that’s simple?

so now a Category that is fully public has to have a minimum of two groups now instead of one - logged in and anon? that’s silly and not an upgrade?

and if not, and you only have to put “anon” because that’s a synonym for “everyone” - that’s no longer correct as logged in users are not anon.


where there was some “learning” around discourse was TL0 in some cases meaning “all those who have an account and logged in” but could also mean “those who have not yet reached TL1 but have an account and are logged in”

the key here is that it didn’t represent a single group of people, it represented a threshold and that was key.

by changing just TL0 to “logged in users” you now break the consistency of each security level being a threshold. TL1 is also a threshold and not really a “single group”. so does that mean we need a group called “logged in users who are at least trust level 1”?!

I’m not at all convinced any of this needed changing - change for change sake?

Very confusing and access control is a very sensitive part of the app!

This is messing with some really long term staple Discourse norms which have stood the test of time because they were correct in the first place (imho)

3 Likes