1 of 33

2 of 33

HOW BRYN MAWR USES GROUP FOR ACCESS MANAGEMENT

Michael Harris

Web Applications Developer

mharris1@brynmawr.edu

3 of 33

ABOUT BRYN MAWR

  • Historic residential women’s college in Bryn Mawr, PA established in 1885
  • Mostly undergraduate, 3 graduate programs
  • 1,780 students

4 of 33

5 of 33

ABOUT THE WEBSITE

  • Drupal 9 (Feb 2022, migrated from D7)
  • Vendor: iFactory
  • Marketing, Academic Information, General Information, Admissions, Human Resources, Everything
  • ~11,000 Nodes
  • ~400 Very Enthusiastic Authenticated Users
  • 16 Content Types
  • ~50 Paragraph types

6 of 33

KINDS OF PERMISSIONS PROBLEMS WE HAVE TO SOLVE

  • How do restrict users to be able to edit just their department’s nodes, and no one else’s

  • Within a department, how do we give some users different permissions than others?

7 of 33

D7 SOLUTIONS

  • Organic Groups

Node

Term

Reference

8 of 33

WHY MOVE AWAY FROM OG?

  • Change in IA Approach
  • Security and reliability
  • OG is still in alpha for D8/9
  • OG support modules are still in alpha/beta

9 of 33

D9 SOLUTION

  • Group

Node

References

Group

Group Content Entity

References

10 of 33

CONFIGURING GROUP

  • Create different “group types” (like content types)

  • For each group type, select which node types are “groupable”

  • For each group type, create roles and permissions

11 of 33

HOW GROUP ROLES WORK

  • Anonymous: no Drupal account
  • Outsider: Drupal account, but not a member of the group
  • Member: Drupal account, and member of the group (like global “Authenticated” role)
  • Custom Roles: Members may also get custom roles, each with their own permissions

12 of 33

HOW GROUP PERMISSIONS WORK

  • If a node is in a group, the user must meet the group permissions to perform an action on the node (view, edit, delete, etc)

  • If a node is not in a group, global permissions apply

13 of 33

14 of 33

SITE WIDE ROLES AND PERMISSIONS

  • Avoid giving global roles create/edit/delete node permissions. Give them at the group level.

  • Give super roles (e.g., site admin) the Bypass group access control global permission

15 of 33

16 of 33

HOW BRYN MAWR CONFIGURES GROUP

  • 1 Group Type

  • Not all node types are groupable

  • Nodes may belong to at most one group

  • Group roles restrict create and edit permissions to particular content types

17 of 33

PAIN POINTS AND CUSTOMIZATIONS

  • Group Entity Pages

  • Assigning Nodes to Groups

  • Reporting

18 of 33

PAIN POINTS AND CUSTOMIZATIONS

  • Group Entity Pages

  • Assigning Nodes to Groups

  • Reporting

19 of 33

DEFAULT GROUP ENTITY PAGE

20 of 33

BRYN MAWR GROUP PAGE

21 of 33

BRYN MAWR GROUP PAGE

22 of 33

PAIN POINTS AND CUSTOMIZATIONS

  • Group Entity Pages

  • Assigning Nodes to Groups

  • Reporting

23 of 33

DEFAULT GROUP CONTENT ASSIGNMENT FORM

24 of 33

BRYN MAWR CUSTOM VBO ACTION

25 of 33

26 of 33

BRYN MAWR NODE EDIT FORM ALTER

27 of 33

PAIN POINTS AND CUSTOMIZATIONS

  • Group Entity Pages

  • Assigning Nodes to Groups

  • Reporting

28 of 33

DEFAULT GROUP LISTING

29 of 33

BRYN MAWR CUSTOM GROUP LISTING

30 of 33

BRYN MAWR CUSTOM USER ASSIGNMENT VIEW

31 of 33

BRYN MAWR NODES NOT IN GROUP REPORT

32 of 33

FINAL THOUGHTS

  • Group works for us pretty well

  • Our use case is fairly straightforward

  • There is a learning curve for roles and permissions

  • Expect to do some custom quality-of-life work

33 of 33

LINKS

  • Bryn Mawr Website:
    • https://www.brynmawr.edu
  • Drupal Group Module: