Apture is currently secured with "access administration pages" permission. That's falls a little short. The thing is, in publishing world (which Apture is mostly used in, of course), editor or author will need "access administration pages" permission to access editorial control panel, but that does not necessarily mean s/he should be allowed to view/update Apture settings like API key.

I think we should introduce a specific permission: "Manage Apture" or something.

Comments

hamburger’s picture

Version: 6.x-1.x-dev » 6.x-1.7

Subscribing

oerpli’s picture

i have a version of apture with this features (and another hook_perm for enabling apture-editing). i will look where i've saved it.

oerpli’s picture