I'm creating a website in which there are projects, users, and permissions for each user or groups of users. What this is is a community collaboration tool, and I have 4 different permissions:
- Creator - make changes, accept changes, change permissions
- Accept changes
- Make changes
- View
How could I implement, in a database, this kind of permission system, for groups of users?
Edit: Groups/permissions are defined by reputation, like on StackOverflow.
Edit 2 - more in detail: Each file needs to have a permission, projects need default permissions for newly created files, and I also need to set up MySQL database permissions.
I would create two tables; users and ranks.
Then just create the various ranks that you want in the Ranks table and set the rankID of the users to match the corresponding one that you want. Make sure to set in the Ranks table each field to a value of 0 or 1; with 0 being not having that ability and 1 having that option.
Edit If you were going to do this without a database then you could give do it with the classes or even instances in PHP5. For instance, let's say that you had set a name for each of the things that you had in your original post:
Then you could do something like below. (The database way would obviously be a much better way, but this is just an example.)
with this structure, each user could have several permission types associated with their account, one for each set of features they could have access to. you would never need to change the table structure in order to add new types of permissions.
to take this a step further, you could make each type of permission a binary number. this way you could make a set of permissions be represented by one integer by using bitwise operators.
for instance if you had the constants
you could combine these values into one integer using a bitwise operator "|"
then to check if they have a specific permission, use the bitwise operator "&"
if you did that, you would only need one db record for each set of permissions.
I have used Zend_Acl in the past for this. I can recommend it. A tried and tested library that is quite easy to implement and can be used stand-alone. This option will scale well if you have different permission schemes to add afterwards.