Kontrola pristupa¶
Weblate sadrži sustav privilegija za dodjeljivanje korisničkih dozvola za cijelu instancu s unaprijed definiranim ulogama ili dodjeljivanjem jedne ili više grupa dozvola korisnicima za sve ili pojedinačne projekte, komponente, glosare i tako dalje.
Kontrola pristupa projektu¶
Napomena
Projekti koji koriste besplatni Libre plan na Hosted Weblateu su uvijek Javni. Možeš se prebaciti na plaćenu tarifu ako želiš ograničiti pristup svom projektu.
Ograniči korisnički pristup pojedinačnim projektima odabirom drugačije Kontrola pristupa postavke. Dostupne opcije su:
- Javno
Svima vidljivo.
Bilo koji autorizirani korisnik može doprinijeti.
VCS Repozitorij sustava za kontrolu verzija smiju vidjeti svi korisnici.
Choose this for open-source projects, or when your Weblate instance is private or locked-down.
- Zaštićeno
Svima vidljivo.
Doprinijeti mogu samo odabrani korisnici.
Repozitoriju sustava za kontrolu verzija mogu pristupiti samo odabrani korisnici.
Choose this to gain visibility, but still have control over who can contribute.
- Privatno
Vidljivo samo odabranim korisnicima.
Doprinijeti mogu samo odabrani korisnici.
Repozitoriju sustava za kontrolu verzija mogu pristupiti samo odabrani korisnici.
Choose this for projects that should not be exposed publicly at all.
- Prilagođeno
Vidljivo samo odabranim korisnicima.
Doprinijeti mogu samo odabrani korisnici.
Repozitoriju sustava za kontrolu verzija mogu pristupiti samo odabrani korisnici.
Nije dostupno na Hosted Weblate.
You will have to set up all the permissions using Globalna kontrola pristupa.
Choose this on your own Weblate instance if you want to define access in a specific, finely customizable way.
Access control can be changed in the Access tab of the configuration (Operations ↓ Settings) of each respective project.
Standardna dozvola se može promijeniti pomoću DEFAULT_ACCESS_CONTROL.
Napomena
Aggregate statistics include Private projects and restricted components, including in site-wide, language, and workspace summaries. Object listings, names, and actions remain permission-filtered, so these aggregates do not grant access to the underlying projects or components.
Napomena
Instance administrators can modify the default permission sets available to users in Public, Protected, and Private projects by using custom settings.
Više informacija
Workspace access control¶
Workspace-scoped teams are documented in Workspace access control.
Upravljanje kontrole pristupa projektima¶
Za Javne, Zastićene i Privatne projekte:
Granting users Manage project access (see Popis dozvola) allows them to assign other users in Public, Protected and Private (but not Custom) projects via adding them to teams.
These are the default teams provided with Weblate; teams can be added or modified by users with sufficient privileges:
- Adminitracija
Sve dostupne dozvole za projekt.
- Pregledaj
Odobri prijevode koji se pregledavaju.
Dostupno je samo ako je review workflow uključeno.
Samo za „zaštićene” i „privatne” projekte:
- Prevedi
Prevodi projekt i prenesi lokalno prevedene datoteke.
- Izvori
Uredi izvorne izraze (ako je dozvoljeno u project settings) i podatke izvornog izraza.
- Jezici
Upravljaj prevedenim jezicima (dodaj ili ukloni prijevode).
- ` Glosar`
Upravljaj glosarom (dodaj ili ukloni unose i prenesi glosar).
- Memorija
Upravljaj prevodilačkom memorijom.
- Snimke ekrana
Upravljaj snimkana ekrana (dodaj, ukloni i poveži ih s izvornim izrazima).
- Automatski prijevod
Može koristiti automatsko prevođenje.
- Sustav za kontrolu verzija
Upravljaj sustavom za kontrolu verzija i pristupi izvezenom repozitoriju.
- Naplata
Pristupi podatcima naplate (pogledaj Naplata).
Ove su funkcije dostupne na stranici Kontrola pristupa u izborniku projekta Operacije ↓ Korisnici.
Savjet
Timove može ograničiti na jezike ili komponente i dodijeliti im određene uloge pristupa (pogledaj Popis dozvola).
Administratori tima¶
Added in version 4.15.
Each team can have team administrators, who can add and remove users within the team.
This is useful in case you want to build self-governed teams.
Pozivanje novog korisnika¶
Adding existing users will send them invitation to confirm. With
REGISTRATION_OPEN the administrator can also invite new users using
e-mail. Invited users have to complete the registration process to get access
to the project.
It is not required to have any site-wide privileges in order to do so, access management permission on the project’s scope (e.g. a membership in the Administration team) would be sufficient.
Savjet
If the invited user missed the validity of the invitation, a new invitation has to be created.
The same kind of invitations are available site-wide from the management interface on the Users tab. Both project administrators and site administrators can also invite multiple users at once by pasting whitespace-separated e-mail addresses. All invitations created in one bulk action use the selected team, and site-wide bulk invites also apply the selected superuser flag.
Site-wide user management is controlled by the global user.edit
permission. Unlike project access management, this is a trusted administrative
permission which allows editing user accounts across the whole instance,
including assigning site-wide teams and granting superuser status to the
managed account, even the caller’s own account.
Site administrators can also disable password authentication for a user. The Regenerate API key option is enabled by default so that the current personal API key stops working. Clear it only when the current API key should remain active.
Bulk invitations are processed individually. Invalid addresses and addresses with an already pending invitation are skipped while valid invitations are still created and sent.
Promijenjeno u verziji 5.0: Weblate now does not automatically create accounts or add users to the teams. This is only done after confirmation from the user.
Blokiranje korisnika¶
Added in version 4.7.
If users misbehave in your project, you can block them from contributing. With the relevant permissions blocked, users can still see the project, but won’t be able to contribute.
Cleaning up user contributions¶
When blocking spam or abusive accounts, project administrators can also clean up the user’s existing contributions in that project. Use Operations ↓ Users, block the user, and select the cleanup actions in the block form. For users who are already blocked, use Clean up user contributions in the blocked users list.
The available cleanup actions are:
Revert user edits reverts the latest editable translations by the user.
Reject user suggestions rejects pending suggestions by the user.
Delete user comments deletes comments by the user.
Site administrators with the site-wide user.edit permission can perform
the same bulk cleanup across all projects from the
management interface on the Users
tab. Open the user’s profile, select the Edit tab, and use
Contribution cleanup.
Individualno upravljanje dozvolama za projekte¶
You can set your projects to Protected or Private (see Kontrola pristupa projektu), and manage users access per-project.
By default this prevents Weblate from granting access provided by Users and Viewers default teams due to these teams’ own configuration. This doesn’t prevent you from granting permissions to those projects site-wide by altering default teams, creating a new one, or creating additional custom settings for individual component as described in Globalna kontrola pristupa below.
One of the main benefits of managing permissions through the Weblate user interface is that you can delegate it to other users without giving them the superuser privilege. In order to do so, add them to the Administration team of the project.
This project-scoped delegation is separate from the site-wide user.edit
permission. Membership in a project Administration team allows managing
access only for that project, while user.edit grants site-wide user
management in the Weblate UI and API and should be assigned only to fully
trusted site administrators.
Tokeni za pristup projektima¶
Added in version 4.10.
You can define project-scoped access tokens in API access tab. The API tokens can have expiry date set, and their permissions can be customized by team memberships same as with users.
Više informacija
Globalna kontrola pristupa¶
Napomena
Ova funkcija nije dostupna na Hosted Weblateu.
The permission system is based on roles defining a set of permissions, and teams linking roles to users and translations, read Korisnici, uloge, timovi i dozvole for more details.
The most powerful features of the Weblate’s access control system can be configured in the Management interface. You can use it to manage permissions of any project. You don’t necessarily have to switch it to Custom access control to utilize it. However you must have superuser privileges in order to use it.
If you are not interested in details of implementation, and just want to create a simple-enough configuration based on the defaults, or don’t have a site-wide access to the whole Weblate installation (like on Hosted Weblate), please refer to the Upravljanje kontrole pristupa projektima section.
Globalno upravljanje dozvolama¶
To manage permissions for a whole instance at once, add users to appropriate default teams:
Users (this is done by default by the automatic team assignment).
Reviewers (if you are using review workflow with dedicated reviewers).
Managers (if you want to delegate most of the management operations to somebody else).
You should keep all projects configured as Public (see Kontrola pristupa projektu), otherwise the site-wide permissions provided by membership in the Users and Reviewers teams won’t have any effect.
You may also grant some additional permissions of your choice to the default teams. For example, you may want to give a permission to manage screenshots to all the Users.
You can define some new custom teams as well. If you want to keep managing your permissions site-wide for these teams, choose an appropriate value for the Project selection (e.g. All projects or All public projects).
Prilagođene dozvole za jezike, komponente ili projekte¶
You can create your own dedicated teams to manage permissions for distinct objects such as languages, components, and projects. Although these teams can only grant additional privileges, you can’t revoke any permission granted by site-wide or per-project teams by adding another custom team.
Primjer:
Restricting translation to Czech to a selected set of translators, (while keeping translations to other languages public):
Ukloni dozvole za češki prijevod svim korisnicima. U standardnoj konfiguraciji se to može učiniti mijenjanjem Korisnici default team.
Grupa Korisnici¶ Odabir jezika
Kao što je definirano
Jezici
Svi osim`češki`
Dodaj tim za češke prevodioce.
Grupa češki prevodioci¶ Uloge
Napredni korisnici
Odabir projekta
Svi javni projekti
Odabir jezika
Kao što je definirano
Jezici
Češki
Dodaj korisnike u ovaj tim kojima želiš dati dozvole.
Management permissions this way is powerful, but can be quite a tedious job. You can only delegate it to other users by granting them Superuser status.
Korisnici, uloge, timovi i dozvole¶
Modeli autenitifikacije sastoje se od nekoliko objekata:
- Dozvola
Individual permission defined by Weblate. Permissions cannot be assigned to users, only through assignment of roles.
- Uloga
Uloga definira skup dozvola i može se ponovo koristiti na više mjesta).
- Korisnik
Korisnik može pripadati nekolicini timova.
- Grupa
Groups connect roles and users with authentication objects (projects, languages, components, and component lists).
Napomena
Timu se mogu dodijeliti nikoje uloge. U tom se slučaju pretpostavlja da bilo tko može pregledavati projekt (pogledaj niže dolje).
Project-browsing access¶
A user has to be a member of a team linked to the project, or any component inside that project. Having membership is enough, no specific permissions are needed to browse the project (this is used in the default Viewers team, see Popis timova).
Component-browsing access¶
Granting browsing access to a user in one project gives it access to any component with derived browsing permissions. With Ograničen pristup on, access to components (or component lists) are granted explicitly.
Opseg timova¶
The scope of the permission assigned by the roles in the teams are applied by the following rules:
If the team specifies any Component list, all the permissions given to members of that team are granted for all the components in the component lists attached to the team, and an access with no additional permissions is granted for all the projects these components are in. Components and Projects are ignored.
Using huge component lists might have a performance impact, please consider giving access via projects instead.
If the team specifies any Components, all the permissions given to the members of that team are granted for all the components attached to the team, and an access with no additional permissions is granted for all the projects these components are in. Projects are ignored.
Otherwise, if the team specifies any Projects, either by directly listing them or by having Projects selection set to a value like All public projects, all those permissions are applied to all the projects, which effectively grants the same permissions to access all projects unrestricted components.
The restrictions imposed by a team’s Languages are applied separately, when it’s verified if a user has access to perform certain actions. Namely, it’s applied only to actions directly related to the translation process itself like reviewing, saving translations, adding suggestions, etc.
Individual team memberships can further limit these permissions to selected languages. Leaving the per-member language limit empty applies no additional limit beyond the team language selection. The same language limit can be set when inviting new users to a project team. When a per-member language limit is set, the membership grants only permissions that can be evaluated for one of those languages. Project-wide, component-wide and global permissions from that team are not granted for that member.
Savjet
Use Language selection or Project selection to automate inclusion of all languages or projects.
Primjer:
A project
foowith the components:foo/barandfoo/baz, with reviewing and management rights, in the following team:
Group Spanish Admin-Reviewers¶ Uloge
Review strings, Manage repository
Komponente
foo/bar
Jezici
Španjolski
Members of that team will have these permissions (assuming the default role settings):
General (browsing) access to the whole project
fooincluding both components in it:foo/barandfoo/baz.Review strings in
foo/barSpanish translation (not elsewhere).Manage VCS for the whole
foo/barrepository e.g. commit pending changes made by translators for all languages.
Automatska dodjeljivanja timu¶
While editing the Team, you can specify Automatic assignments, which is a list of regular expressions used to automatically assign newly created users to a team based on their e-mail addresses. This assignment only happens upon account creation.
The most common use-case for the feature is to assign all new users to some
default team. This behavior is used for the default Users and Guest teams
(see Popis timova). Use regular expression ^.*$ to match all users.
Another use-case for this option might be to
give some additional privileges to employees of your company by default.
Assuming all of them use corporate e-mail addresses on your domain, this can
be accomplished with an expression like ^.*@mycompany.com.
Napomena
Automatic team assignment to Users and Viewers is always recreated
when upgrading from one Weblate version to another. If you want to turn it off, set the regular expression to
^$ (which won’t match anything).
Napomena
Bulk inviting through the user interface creates invitations. Existing users still have to confirm the invitation before they become team members.
Standardni timovi i uloge¶
Nakon instalacije se izrađuju zadani skupovi timova (vidi Popis timova).
Ove se uloge i timovi stvaraju prilikom instalacije. Ugrađene uloge se uvijek altualiziraju migracijom baze podataka prilikom nadogradnje. Ne mogu se zapravo promijeniti Definiraj novu ulogu ako želiš definirati vlastiti skup dozvola.
Popis dozvola¶
Opseg |
Dozvola |
Ugrađene uloge |
|---|---|---|
Promjene |
Preuzmi promjene |
Adminitracija |
Komentari |
Pošalji komentar |
Adminitracija |
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Izbriši komentar |
Adminitracija |
|
Riješi komentar |
Adminitracija |
|
Koordinator prijevoda |
||
Pregledaj izraze |
||
Komponenta |
Uredi postavke komponente |
Adminitracija |
Zaključaj komponentu, onemogućuje prevođenje |
Adminitracija |
|
Upravljaj repozitorijem |
||
Glosar |
Dodaj unos u glosar |
Adminitracija |
Upravljaj glosarom |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Dodaj terminologiju glosara |
Adminitracija |
|
Upravljaj glosarom |
||
Koordinator prijevoda |
||
Uredi unos u glosaru |
Adminitracija |
|
Upravljaj glosarom |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Izbriši unos iz glosara |
Adminitracija |
|
Upravljaj glosarom |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Prenesi unose u glosaru |
Adminitracija |
|
Upravljaj glosarom |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Automatski prijedlozi |
Koristi automatske prijedloge |
Adminitracija |
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Prevodilačka memorija |
Uredi prevodilačku memoriju |
Adminitracija |
Upravljaj prevodilačkom memorijom |
||
Izbriši prevodilačku memoriju |
Adminitracija |
|
Upravljaj prevodilačkom memorijom |
||
Projekti |
Uredi postavke projekta |
Adminitracija |
Upravljaj pristupima projektu |
Adminitracija |
|
Izvještaji |
Preuzmi izvještaje |
Adminitracija |
Workspace administration |
||
Snimke ekrana |
Dodaj snimku ekrana |
Adminitracija |
Koordinator prijevoda |
||
Manage screenshots |
||
Uredi snimku ekrana |
Adminitracija |
|
Koordinator prijevoda |
||
Manage screenshots |
||
Izbriši snimku ekrana |
Adminitracija |
|
Koordinator prijevoda |
||
Manage screenshots |
||
Izvorni izrazi |
Uredi dodatne informacije o izrazu |
Adminitracija |
Uredi izvor |
||
Izrazi |
Dodaj novi izraz |
Adminitracija |
Ukloni izraz |
Adminitracija |
|
Odbaci neuspjelu provjeru |
Adminitracija |
|
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Uredi izraze |
Adminitracija |
|
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Pregledaj izraze |
Adminitracija |
|
Koordinator prijevoda |
||
Pregledaj izraze |
||
Izrazi skupnog uređivanja |
Adminitracija |
|
Bulk editing |
||
Uredi izraz kad se prijedlozi primjenjuju |
Adminitracija |
|
Koordinator prijevoda |
||
Pregledaj izraze |
||
Uredi izvorne izraze |
Adminitracija |
|
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Prijedlozi |
Prihvati prijedlog |
Adminitracija |
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Dodaj prijedlog |
Adminitracija |
|
Uredi izvor |
||
Dodaj prijedlog |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Izbriši prijedlog |
Adminitracija |
|
Napredni korisnik |
||
Koordinator prijevoda |
||
Glasaj za prijedlog |
Adminitracija |
|
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Prijevodi |
Dodaj jezik za prijevod |
Adminitracija |
Napredni korisnik |
||
Koordinator prijevoda |
||
Upravljaj jezicima |
||
Izvrši automatsko prevođenje |
Adminitracija |
|
Automatski prijevod |
||
Izbriši postojeći prijevod |
Adminitracija |
|
Upravljaj jezicima |
||
Preuzmi prevodilačku datoteku |
Adminitracija |
|
Uredi izvor |
||
Pristupi repozitoriju |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Upravljaj jezicima |
||
Dodaj nekoliko jezika za prijevod |
Adminitracija |
|
Upravljaj jezicima |
||
Prijenosi |
Odredi autora prenesenog prijevoda |
Adminitracija |
Prepiši postojeće izraze s prenesenim podatcima |
Adminitracija |
|
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Prenesi prijevode |
Adminitracija |
|
Uredi izvor |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Pregledaj izraze |
||
Prevedi |
||
Sustav za kontrolu verzija |
Pristupi internom repozitoriju |
Adminitracija |
Pristupi repozitoriju |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Upravljaj repozitorijem |
||
Spremi promjene u interni repozitorij |
Adminitracija |
|
Upravljaj repozitorijem |
||
Prenesi promjenu iz internog repozitorija |
Adminitracija |
|
Upravljaj repozitorijem |
||
Resetiraj promjene u internom repozitoriju |
Adminitracija |
|
Upravljaj repozitorijem |
||
Prikaži mjesto izvornog repozitorija |
Adminitracija |
|
Pristupi repozitoriju |
||
Napredni korisnik |
||
Koordinator prijevoda |
||
Upravljaj repozitorijem |
||
Aktualiziraj interni repozitorij |
Adminitracija |
|
Upravljaj repozitorijem |
||
Objave |
Objavi objave |
Adminitracija |
Koordinator prijevoda |
||
Izbriši objave |
Adminitracija |
|
Koordinator prijevoda |
||
Workspaces |
Edit workspace settings |
Workspace administration |
Add projects to workspace |
Workspace administration |
|
Add workspace projects |
||
Manage workspace access |
Workspace administration |
|
Globalne dozvole |
Koristi upravljačko sučelje |
|
Manage site configuration |
||
Dodaj nove projekte |
Dodaj nove projekte |
|
Add new workspaces |
Dodaj nove projekte |
|
Dodaj definicije jezika |
||
Upravljaj definicijama jezika |
||
Upravljaj timovima |
||
Pogledaj podatke tima |
||
Upravljaj korisnicima |
||
Pogledaj podatke korisnika |
||
Upravljaj ulogama |
||
Pogledaj podatke uloge |
||
Upravljaj objavama |
||
Upravljaj prevodilačkom memorijom |
||
Upravljaj strojnim prevođenjem |
||
Upravljaj popisima komponenti |
||
Upravljaj naplatama |
||
Upravljaj dodacima web-stranica |
Napomena
Globalne dozvole nisu dodijeljene nijednoj standardnoj ulozi. One su moćne i vrlo slične stanju super-korisnika. Većina njih utječe na sve projekte u tvojoj Weblate instalaciji.
Popis ugrađenih uloga¶
Adminitracija |
|
Uredi izvor |
|
Dodaj prijedlog |
|
Pristupi repozitoriju |
|
Upravljaj glosarom |
|
Napredni korisnik |
|
Koordinator prijevoda |
|
Pregledaj izraze |
|
Prevedi |
|
Upravljaj jezicima |
|
Bulk editing |
|
Automatski prijevod |
|
Upravljaj prevodilačkom memorijom |
|
Upravljaj snimkama ekrana |
|
Upravljaj repozitorijem |
|
Workspace administration |
|
Add workspace projects |
|
Dodaj nove projekte |
|
Popis timova¶
Sljedeći timovi će se stvoriti nakon instalacije (ili nakon izvođenja setupgroups) i možeš ih promijeniti ako želiš. Migracija će ih međutim ponovo stvoriti ako ih izbrišeš ili preimenuješ.
- Gosti
Definira dozvloe za neautentificirane korisnike.
Ovaj tim sadrži samo anonimne korisnike (pogledaj
ANONYMOUS_USER_NAME).Ukloni uloge iz ovog tima za ograničavanje dozvola za neautentificirane korisnike.
Standarne uloge: Dodaj prijedlog, Pristupi repozitoriju
- Gledatelji
Ova uloga osigurava vidljivost javnih projekata za sve korisnike. Standardno su svi korisnici članovi ovog tima.
Opcija automatic team assignment pretvara sve nove račune korisnika članovima ovog tima kad se pridruže.
Standardne uloge: neodređeno
- Korisnici
Standardni tim za sve korisnike.
Opcija automatic team assignment pretvara sve nove račune korisnika članovima ovog tima kad se pridruže.
Standardne uloge: Napredni korisnik
- Pregledatelji
Grupa za pregledatelje (pogledaj Radni tokovi za prevođenje).
Standardne uloge: Pregledaj izraze
- Administratori
Grupa za administratore.
Standardne uloge: Administrator
- Osnivači projekta
Added in version 5.1.
Korisnici koji mogu stvarati nove projekte.
Standardne uloge: Dodaj nove projekte
Upozorenje
Nikada nemoj uklanjajti unaprijed definirane Weblate timove i korisnike, jer to može dovesti do neočekivanih problema! Ako ih ne trebaš, jednostavno ukloni sve njihove dozvole.
Dodatna ograničenja pristupa¶
If you want to use your Weblate installation in a less public manner, i.e. allow
new users on an invitational basis only, it can be done by configuring Weblate
in such a way that only known users have an access to it. In order to do so, you can set
REGISTRATION_OPEN to False to prevent registrations of any new
users, and set REQUIRE_LOGIN to True to require signing in to access
all the site pages. This is basically the way to lock your Weblate installation.
Additionally, changing DEFAULT_ACCESS_CONTROL to 100 will make
all newly created projects private, requiring explicit access to be granted.
Savjet
You can use built-in Pozivanje novog korisnika to add new users.
Expiration of user accounts¶
Each account can have an expiry set. After the expiration, the account will be automatically disabled. This is used for Tokeni za pristup projektima, but can be utilized for regular users as well.