Modifications of the Wikispiral website
09/01/2014 : Opening the wiki for registered
[+]Testing before on preproduction site
- No visible security flaw
- Not possible to affect database (tested to create a trackerfilteredit plugin with Mons account : not able to change Charleroi data)
- Testing wikipages discussion in forums : works well (thread created only if there is some actual discussion, not on wikipage creation)
- Need for Jean-Marc to code us something that puts in value the discussion (currently a single button amidst other samelike buttons) !
Done on production site
Securing
- Secured menu wiki pages (deletion, editing, renaming, rollback for admins only) applying AdminVIezOnly category to the structure wikispiral
- Secured Unified pages and other tools:
- CG Facilitators - Dashboard, CG Facilitators - Homogeneous Groups, CG Facilitators - Criteria entry, CG Facilitators - Edit Criteria, CG Facilitators - Attributions of Components and Categories, CG Facilitators - Elaborate Attributions, CG Facilitators - Pilot Actions,
- Synthesis graphical, Synthesis print,
- CG management: Filter Indicators for hints, CG management: Filter Propositions for hints, CG management: Search Indicators for hints, CG management: Search Propositions for hints, template_CG_creation_facilitators_infopage, template_CG_creation_facilitators_statspage, template Edit Action, template_CG_creation,
- Spiral Registration Form,
- Secured Responding together
- Created RTAdminEditOnly to secure menu elements and other pages
- Menu, via respondingtogether structure secured
- Secured special pages not in the menu : Admin - Complete template challenges, Admin - Complete template, Admin - Template Challenges, Admin - Template RT Action, New_city_template, Answer with a contribution,
- Securing editable pages against renaming with category AdminRenameOnly (methodology pages, CG infopages)
Opening the Wiki
- Lowered wiki edition rights to registered users
- Corrected rights for Categories AdminEditOnly and RTAdminEditOnly to remove rights for registered user appearing due to the former step
- Checked security : pages are protected
- Checking categories availability when creating / modifying a page : rNOT POSSIBLE TO REMOVE VISIBILITY OF SOME ADMIN CATEGORIES
Adding new functionalities
- Show the buttons at the bottom of the pages
- Add a wikipage discussions forum
- Implement the possibility to discuss pages in forums
- Reduced or not showing to registered some dispendable functionalities (-similar, -view source, etc.) to have less buttons on bottom