<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Permissions on TinyChen's Blog</title><link>https://tinychen.com/tags/permissions/</link><description>Recent content in Permissions on TinyChen's Blog</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Thu, 23 Jul 2026 12:00:00 +0800</lastBuildDate><atom:link href="https://tinychen.com/tags/permissions/index.xml" rel="self" type="application/rss+xml"/><item><title>Octans-媒体库用户角色与权限分层</title><link>https://tinychen.com/20260412-octans-user-role-iam-principles/</link><pubDate>Sun, 12 Apr 2026 12:00:00 +0800</pubDate><guid>https://tinychen.com/20260412-octans-user-role-iam-principles/</guid><description>&lt;p&gt;本文主要说明一类自托管媒体库（以 Octans 为例）在**身份与访问管理（IAM）**上应先固定哪些原则：全局角色只管系统级能力，媒体库访问另用 &lt;code&gt;R/W&lt;/code&gt; 表达；再通过三类库集合与资源范围解析，把列表过滤、详情隐藏、写操作拒绝和播放 / 图片等边角资源收进同一套语义。重点是分层与边界，不是登录配置、迁移步骤或排障命令。&lt;/p&gt;</description></item></channel></rss>