<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Permission Questions - Enterprise Network in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/permission-questions-enterprise-network/m-p/31494#M16265</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a few permission questions I was hoping to have answered:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) It is my understanding that permissionDefinitions.xml is where you would essentially define an â€œACLâ€&amp;#157; that is associated with a type or aspect. Then that definition could be assigned to a user or group. Is this correct?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2) Currently out-of-the-box the following roles exist: Contributor, Coordinator, Editor, Guest. Is it possible to define a custom role, and assign custom permissions to this role, perhapse specific to a type or aspect? If so, could an example of how to do this be provided? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3) Could permissions be configured in such a way that a type and/or aspect would be available to one group, but not any others? Again, if possible, an example would be great.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;4) Does security extend beyond types and aspects? For example, could you limit which actions a user can choose when defining content rules for their space?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;5) Would it be possible with security, to have multiple conceptual â€œcompany homesâ€&amp;#157; within the same Store? For example with the following space structure:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;Company Home (root of the store)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; |&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; |— Home 1&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |— Projects&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |— project 1&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |— etcâ€¦&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; |&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; |— Home 2&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |— Projects&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Then assume there were two groups Group1 and Group2.&amp;nbsp;&amp;nbsp; Group1â€™s â€œcompany homeâ€&amp;#157; should be Home 1, and for all intents and purposes appear to be the root for all users in Group1. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Similarly Group2â€™s â€œcompany homeâ€&amp;#157; should be Home 2, and users in Group2 should not be allowed to go up any higher. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Would this be possible? Or would it be better to just set up a separate Store for each Group?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-Ryan&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jan 2006 17:18:44 GMT</pubDate>
    <dc:creator>rberg</dc:creator>
    <dc:date>2006-01-12T17:18:44Z</dc:date>
    <item>
      <title>Permission Questions - Enterprise Network</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/permission-questions-enterprise-network/m-p/31494#M16265</link>
      <description>Hi,I have a few permission questions I was hoping to have answered:1) It is my understanding that permissionDefinitions.xml is where you would essentially define an â€œACLâ€&amp;#157; that is associated with a type or aspect. Then that definition could be assigned to a user or group. Is this correct?2) Curre</description>
      <pubDate>Thu, 12 Jan 2006 17:18:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/permission-questions-enterprise-network/m-p/31494#M16265</guid>
      <dc:creator>rberg</dc:creator>
      <dc:date>2006-01-12T17:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Permission Questions - Enterprise Network</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/permission-questions-enterprise-network/m-p/31495#M16266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The first point of call is:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://www.alfresco.org/mediawiki/index.php/Security_and_Authentication" rel="nofollow noopener noreferrer"&gt;http://www.alfresco.org/mediawiki/index.php/Security_and_Authentication&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;1) It is my understanding that permissionDefinitions.xml is where you would essentially define an â€œACLâ€&amp;#157; that is associated with a type or aspect. Then that definition could be assigned to a user or group. Is this correct?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;You are correct, and this file is a good example of what to do.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ACL is really (node, authority, permission, ALLOW|DENY)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;You are defining permissions and convenient groups of permissions (which you may call roles if you want …)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;2) Currently out-of-the-box the following roles exist: Contributor, Coordinator, Editor, Guest. Is it possible to define a custom role, and assign custom permissions to this role, perhapse specific to a type or aspect? If so, could an example of how to do this be provided?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;It is possible to define your own role. Just create another permissoin group. All are specific to a type or aspect. The ownable aspect is a good example.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;3) Could permissions be configured in such a way that a type and/or aspect would be available to one group, but not any others? Again, if possible, an example would be great.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;This is not available at the moment. It requires some thought as you want to add a new "AddAspect/CreateType" permission bound to a type (as opposed to make a permission per type). I will add this to the list of things.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;4) Does security extend beyond types and aspects? For example, could you limit which actions a user can choose when defining content rules for their space?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;You can check if a user has any permission when building the UI so in principle, yes. You would have to assign global ACLs for some new permissions. Global ACLs are only in XML at the moment. You would have to change how these lists are built to reflect permissions. It is not supported out of the box. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;5) Would it be possible with security, to have multiple conceptual â€œcompany homesâ€&amp;#157; within the same Store? For example with the following space structure:&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;We do not have pseudo roots. You could define the structure as described. If Home 1 and Home 2 have access restricted to each group then people will only see what they are allowed when they move up a folder. Home 1 will be Hidden from group 2 and the reverse.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I do not see why you can not have &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;|- Company Home &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;|- Group 1 Home&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;|- Group 2 Home&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't recall any reason why a user's home space has to be below the company home. It may not be so easy to create it from the UI, I have not tried!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Company home is expected to be a unique location.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2006 08:28:56 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/permission-questions-enterprise-network/m-p/31495#M16266</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2006-01-13T08:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Permission Questions - Enterprise Network</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/permission-questions-enterprise-network/m-p/31496#M16267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Andy,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you for your quick reply, this really helps.&amp;nbsp; I completely understand the security/permission model conceptually, but for some reason I am struggleing to get my mind around how to actually implement (in permissionDefinitions.xml) what I would like to do.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you please provide me with a simple example of the xml definition for this situation: &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Let's say we have type &lt;/SPAN&gt;&lt;EM&gt;cm:mytype&lt;/EM&gt;&lt;SPAN&gt;, and a role called &lt;/SPAN&gt;&lt;EM&gt;myrole&lt;/EM&gt;&lt;SPAN&gt; (maybe it should actually be ROLE_myrole).&amp;nbsp; I would like to only provide READ access to all content of type &lt;/SPAN&gt;&lt;EM&gt;mytype&lt;/EM&gt;&lt;SPAN&gt; to users and groups who have the role &lt;/SPAN&gt;&lt;EM&gt;myrole&lt;/EM&gt;&lt;SPAN&gt;, all other users should have no access.&amp;nbsp; If you have time perhaps you could extend the example to demonstrate how to add READ and WRITE priveledges to content of type &lt;/SPAN&gt;&lt;EM&gt;mytype&lt;/EM&gt;&lt;SPAN&gt; to users and groups who have a role named &lt;/SPAN&gt;&lt;EM&gt;authorrole&lt;/EM&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks again.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-Ryan&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2006 14:58:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/permission-questions-enterprise-network/m-p/31496#M16267</guid>
      <dc:creator>rberg</dc:creator>
      <dc:date>2006-01-13T14:58:44Z</dc:date>
    </item>
  </channel>
</rss>

