<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://mwiki.costasano.club/index.php?action=history&amp;feed=atom&amp;title=ICT%3ANamespaces_and_Lockdown_Policy_v4.1</id>
	<title>ICT:Namespaces and Lockdown Policy v4.1 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://mwiki.costasano.club/index.php?action=history&amp;feed=atom&amp;title=ICT%3ANamespaces_and_Lockdown_Policy_v4.1"/>
	<link rel="alternate" type="text/html" href="https://mwiki.costasano.club/index.php?title=ICT:Namespaces_and_Lockdown_Policy_v4.1&amp;action=history"/>
	<updated>2026-07-22T23:27:33Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://mwiki.costasano.club/index.php?title=ICT:Namespaces_and_Lockdown_Policy_v4.1&amp;diff=288&amp;oldid=prev</id>
		<title>Mngr: Created page with &quot;= Namespaces and Lockdown Policy = == Costa Sano MediaWiki Platform == === Version 4.1 ===  == Purpose ==  This document describes the namespace architecture and access control configuration of the Costa Sano MediaWiki installation.  It complements:  * Data model version 4.1 * Identifier and numbering policy * Cargo + Page Forms implementation  This page is intended for:  * ICT successors * system maintainers * administrators  It explains:  * why namespaces exist * which...&quot;</title>
		<link rel="alternate" type="text/html" href="https://mwiki.costasano.club/index.php?title=ICT:Namespaces_and_Lockdown_Policy_v4.1&amp;diff=288&amp;oldid=prev"/>
		<updated>2026-02-03T13:53:29Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;= Namespaces and Lockdown Policy = == Costa Sano MediaWiki Platform == === Version 4.1 ===  == Purpose ==  This document describes the namespace architecture and access control configuration of the Costa Sano MediaWiki installation.  It complements:  * Data model version 4.1 * Identifier and numbering policy * Cargo + Page Forms implementation  This page is intended for:  * ICT successors * system maintainers * administrators  It explains:  * why namespaces exist * which...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= Namespaces and Lockdown Policy =&lt;br /&gt;
== Costa Sano MediaWiki Platform ==&lt;br /&gt;
=== Version 4.1 ===&lt;br /&gt;
&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
This document describes the namespace architecture and access control configuration of the Costa Sano MediaWiki installation.&lt;br /&gt;
&lt;br /&gt;
It complements:&lt;br /&gt;
&lt;br /&gt;
* Data model version 4.1&lt;br /&gt;
* Identifier and numbering policy&lt;br /&gt;
* Cargo + Page Forms implementation&lt;br /&gt;
&lt;br /&gt;
This page is intended for:&lt;br /&gt;
&lt;br /&gt;
* ICT successors&lt;br /&gt;
* system maintainers&lt;br /&gt;
* administrators&lt;br /&gt;
&lt;br /&gt;
It explains:&lt;br /&gt;
&lt;br /&gt;
* why namespaces exist&lt;br /&gt;
* which namespace is used for what&lt;br /&gt;
* which user groups may access each namespace&lt;br /&gt;
* how Lockdown protects content&lt;br /&gt;
* how this is configured in &amp;#039;&amp;#039;LocalSettings.php&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Design principles ==&lt;br /&gt;
&lt;br /&gt;
The namespace design follows these rules:&lt;br /&gt;
&lt;br /&gt;
# One namespace per real-world entity type&lt;br /&gt;
# Plain English names (no technical abbreviations)&lt;br /&gt;
# Separation between documentation and research data&lt;br /&gt;
# Sensitive technical content must never be transcludable&lt;br /&gt;
# Simple, boring, maintainable configuration&lt;br /&gt;
&lt;br /&gt;
Goals:&lt;br /&gt;
&lt;br /&gt;
* clarity for non-technical users&lt;br /&gt;
* predictable URLs&lt;br /&gt;
* easy export and backup&lt;br /&gt;
* easy onboarding of successors&lt;br /&gt;
* minimal configuration complexity&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Namespace overview ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Namespace !! Purpose !! Typical pages !! Access group&lt;br /&gt;
|-&lt;br /&gt;
| Research:&lt;br /&gt;
| User documentation&lt;br /&gt;
| manuals, procedures&lt;br /&gt;
| research&lt;br /&gt;
|-&lt;br /&gt;
| ICT:&lt;br /&gt;
| Technical/system documentation&lt;br /&gt;
| server setup, backups, passwords, maintenance notes&lt;br /&gt;
| ict&lt;br /&gt;
|-&lt;br /&gt;
| Chapter:&lt;br /&gt;
| Research chapters (narrative structure)&lt;br /&gt;
| CH01, CH02, CH03&lt;br /&gt;
| club&lt;br /&gt;
|-&lt;br /&gt;
| Place:&lt;br /&gt;
| Geographic entities&lt;br /&gt;
| Oostende, Rome, Floréal&lt;br /&gt;
| club&lt;br /&gt;
|-&lt;br /&gt;
| Organisation:&lt;br /&gt;
| Institutions / organisations&lt;br /&gt;
| ARCH, CONG, etc.&lt;br /&gt;
| club&lt;br /&gt;
|-&lt;br /&gt;
| Person:&lt;br /&gt;
| People&lt;br /&gt;
| researchers, historical actors&lt;br /&gt;
| club&lt;br /&gt;
|-&lt;br /&gt;
| Heritage:&lt;br /&gt;
| Heritage objects&lt;br /&gt;
| buildings, sanatoria, artefacts&lt;br /&gt;
| club&lt;br /&gt;
|-&lt;br /&gt;
| Asset:&lt;br /&gt;
| DigitalAssets (numbered research sources)&lt;br /&gt;
| CH03-ROM-0007&lt;br /&gt;
| club&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Naming rationale ==&lt;br /&gt;
&lt;br /&gt;
Namespaces use full words instead of abbreviations.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;Asset:&amp;#039;&amp;#039; instead of &amp;#039;&amp;#039;DA:&amp;#039;&amp;#039;&lt;br /&gt;
* &amp;#039;&amp;#039;Heritage:&amp;#039;&amp;#039; instead of &amp;#039;&amp;#039;HO:&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
Reasons:&lt;br /&gt;
&lt;br /&gt;
* self-explanatory&lt;br /&gt;
* easier for new users&lt;br /&gt;
* easier for successors&lt;br /&gt;
* avoids documentation overhead&lt;br /&gt;
* improves long-term maintainability&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Relationship to the data model ==&lt;br /&gt;
&lt;br /&gt;
Namespaces map 1:1 to Cargo tables:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Namespace !! Cargo table&lt;br /&gt;
|-&lt;br /&gt;
| Chapter:&lt;br /&gt;
| ResearchChapters&lt;br /&gt;
|-&lt;br /&gt;
| Place:&lt;br /&gt;
| Places&lt;br /&gt;
|-&lt;br /&gt;
| Organisation:&lt;br /&gt;
| Organisations&lt;br /&gt;
|-&lt;br /&gt;
| Person:&lt;br /&gt;
| Persons&lt;br /&gt;
|-&lt;br /&gt;
| Heritage:&lt;br /&gt;
| HeritageObjects&lt;br /&gt;
|-&lt;br /&gt;
| Asset:&lt;br /&gt;
| DigitalAssets&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Each page in these namespaces represents exactly one database entity.&lt;br /&gt;
&lt;br /&gt;
The page name normally equals the entity identifier.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 Asset:CH03-ROM-0007  → DigitalAssets.identifier&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Lockdown security model ==&lt;br /&gt;
&lt;br /&gt;
The Lockdown extension restricts read/edit access per namespace.&lt;br /&gt;
&lt;br /&gt;
Groups:&lt;br /&gt;
&lt;br /&gt;
* research  → user documentation only&lt;br /&gt;
* ict       → system documentation only&lt;br /&gt;
* club      → all research data&lt;br /&gt;
* sysop     → full access&lt;br /&gt;
&lt;br /&gt;
Policy:&lt;br /&gt;
&lt;br /&gt;
* Research namespace → research group&lt;br /&gt;
* ICT namespace → ict group&lt;br /&gt;
* all research data namespaces → club group only&lt;br /&gt;
&lt;br /&gt;
This ensures:&lt;br /&gt;
&lt;br /&gt;
* technical information remains protected&lt;br /&gt;
* research data visible only to club members&lt;br /&gt;
* clear separation of responsibilities&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Transclusion protection ==&lt;br /&gt;
&lt;br /&gt;
MediaWiki allows pages to be embedded (transcluded) into other pages.&lt;br /&gt;
&lt;br /&gt;
This can bypass read restrictions.&lt;br /&gt;
&lt;br /&gt;
To prevent leakage of sensitive system information:&lt;br /&gt;
&lt;br /&gt;
 ICT: is marked non-includable&lt;br /&gt;
&lt;br /&gt;
Configuration:&lt;br /&gt;
&lt;br /&gt;
 $wgNonincludableNamespaces[] = NS_ICT;&lt;br /&gt;
&lt;br /&gt;
Other namespaces are intentionally includable because:&lt;br /&gt;
&lt;br /&gt;
* research content may be reused&lt;br /&gt;
* templates and summaries are useful&lt;br /&gt;
* no sensitive information is stored there&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Upload policy ==&lt;br /&gt;
&lt;br /&gt;
Uploads are restricted globally.&lt;br /&gt;
&lt;br /&gt;
Rules:&lt;br /&gt;
&lt;br /&gt;
* normal users → cannot upload&lt;br /&gt;
* club members → upload allowed&lt;br /&gt;
* sysops → full rights&lt;br /&gt;
&lt;br /&gt;
Rationale:&lt;br /&gt;
&lt;br /&gt;
Digital files belong to DigitalAssets and must follow the identifier naming policy.&lt;br /&gt;
Uploads are therefore limited to trained members.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== LocalSettings.php configuration ==&lt;br /&gt;
&lt;br /&gt;
The following block defines the namespaces and protection rules.&lt;br /&gt;
&lt;br /&gt;
(Reference implementation – keep synchronized with this document.)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;php&amp;quot;&amp;gt;&lt;br /&gt;
wfLoadExtension( &amp;#039;Lockdown&amp;#039; );&lt;br /&gt;
&lt;br /&gt;
# namespaces&lt;br /&gt;
define(&amp;quot;NS_RESEARCH&amp;quot;, 3000);&lt;br /&gt;
define(&amp;quot;NS_ICT&amp;quot;, 3002);&lt;br /&gt;
define(&amp;quot;NS_CHAPTER&amp;quot;, 3004);&lt;br /&gt;
define(&amp;quot;NS_PLACE&amp;quot;, 3006);&lt;br /&gt;
define(&amp;quot;NS_ORGANISATION&amp;quot;, 3008);&lt;br /&gt;
define(&amp;quot;NS_PERSON&amp;quot;, 3010);&lt;br /&gt;
define(&amp;quot;NS_HERITAGE&amp;quot;, 3012);&lt;br /&gt;
define(&amp;quot;NS_ASSET&amp;quot;, 3014);&lt;br /&gt;
&lt;br /&gt;
# permissions and lockdown configured accordingly&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
See &amp;#039;&amp;#039;LocalSettings.php&amp;#039;&amp;#039; for the complete current configuration.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Maintenance notes ==&lt;br /&gt;
&lt;br /&gt;
When changing namespaces:&lt;br /&gt;
&lt;br /&gt;
# update constants&lt;br /&gt;
# update Lockdown rules&lt;br /&gt;
# update VisualEditor namespace list&lt;br /&gt;
# search for old namespace names&lt;br /&gt;
# test with non-admin users&lt;br /&gt;
&lt;br /&gt;
Never reuse old namespace IDs.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Version history ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Version !! Date !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| 2026&lt;br /&gt;
| Introduced full namespace separation, replaced HO/DA by Heritage/Asset, added Lockdown rules&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Mngr</name></author>
	</entry>
</feed>