<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alfresco Security Model in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-security-model/m-p/35675#M18753</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have a quick question for you guys:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In the web app all of the security assignment is at the space level.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Users are assigned to spaces then assigned roles.&amp;nbsp; This seems very ganular but a little bit wierd to me.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I was kinda expecting there to be something like:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;we add roles to the system&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;we add users to the system&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;we assign roles to users&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;we assign roles to spaces &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;we assign a user to a space as a corner case&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In the current system we have to add a user to a space then assign a role at each space.&amp;nbsp; Seems a little bit like a management nightmere.&amp;nbsp; If tomrrow i decide Joe is no longer an editor I have to run around to all of the possible spaces that he may be assigned to and assigned the editor role and remove it. (as apposed to going to the user manager and removing his editor role)&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Nov 2005 22:52:34 GMT</pubDate>
    <dc:creator>rdanner</dc:creator>
    <dc:date>2005-11-30T22:52:34Z</dc:date>
    <item>
      <title>Alfresco Security Model</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-security-model/m-p/35675#M18753</link>
      <description>I have a quick question for you guys:In the web app all of the security assignment is at the space level.Users are assigned to spaces then assigned roles.&amp;nbsp; This seems very ganular but a little bit wierd to me.I was kinda expecting there to be something like:we add roles to the systemwe add users to</description>
      <pubDate>Wed, 30 Nov 2005 22:52:34 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-security-model/m-p/35675#M18753</guid>
      <dc:creator>rdanner</dc:creator>
      <dc:date>2005-11-30T22:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Security Model</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-security-model/m-p/35676#M18754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The permissions model can be summarised as:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;Authority&amp;nbsp; -&amp;nbsp; assigned&amp;nbsp; -&amp;nbsp;&amp;nbsp; Permission&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp; on a node&amp;nbsp;&amp;nbsp; - deny/allow&lt;BR /&gt;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;User&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Permission&lt;BR /&gt;Group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set of permisoins&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Permissions are inherited by child nodes by default.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Any allow allows (as opposed to any deny denies)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In the UI, we refer to roles, they are really sets of permissions.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We only expose "allow" and "clearing" permissions.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;An editor needs the lower level read/write/… permission sets.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The read permission set has the read-children and read-properties permissions. These low level permissions are used to control service level access.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So you can define what the set of permissions given to an editor are and change these. May be you want them to be able to undo check out….or not….&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Group support is not present in the open version. In the next release of the open version you can assign permissions and permission sets to users. In the next pro/enterprise release you also get groups and group management.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So you can assign permission sets (or roles) to groups for maximum flexibility. If you want to define editors globally then you can create a group and assign the appropriate editor permission globally regardless of which node. Global permissions are currently defined in config.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2005 09:57:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-security-model/m-p/35676#M18754</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2005-12-01T09:57:00Z</dc:date>
    </item>
  </channel>
</rss>

