<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using security features in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41141#M22024</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The open 1.1 release has a permission service implementation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It includes inheritance and persists to hibernate.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You need to create your own authentiation component and DAO and wire these up to manage users yourself.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://www.alfresco.org/mediawiki/index.php/Security_and_Authentication" rel="nofollow noopener noreferrer"&gt;http://www.alfresco.org/mediawiki/index.php/Security_and_Authentication&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Out of curiosity, how are you intending to manage users?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Dec 2005 09:16:14 GMT</pubDate>
    <dc:creator>andy</dc:creator>
    <dc:date>2005-12-08T09:16:14Z</dc:date>
    <item>
      <title>Using security features</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41140#M22023</link>
      <description>Hi,I wasn't sure which forum to post this message in… just trying it here.I was thinking of using the infrastructure provided in Alfresco code to implement my security stuff.&amp;nbsp; The plan was that I'll have my own means of creating and managing users, and I will only need to give the PermissionService</description>
      <pubDate>Thu, 08 Dec 2005 03:51:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41140#M22023</guid>
      <dc:creator>hsjawanda</dc:creator>
      <dc:date>2005-12-08T03:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Using security features</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41141#M22024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The open 1.1 release has a permission service implementation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It includes inheritance and persists to hibernate.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You need to create your own authentiation component and DAO and wire these up to manage users yourself.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://www.alfresco.org/mediawiki/index.php/Security_and_Authentication" rel="nofollow noopener noreferrer"&gt;http://www.alfresco.org/mediawiki/index.php/Security_and_Authentication&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Out of curiosity, how are you intending to manage users?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2005 09:16:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41141#M22024</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2005-12-08T09:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Using security features</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41142#M22025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Out of curiosity, how are you intending to manage users?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;Well, we already have a means of creating users in a database.&amp;nbsp; I was thinking that I would only need the username to wire my stuff into Alfresco's PermissionService.&amp;nbsp; Also, we are already doing authentication (only) using this database.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Dec 2005 03:26:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41142#M22025</guid>
      <dc:creator>hsjawanda</dc:creator>
      <dc:date>2005-12-10T03:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Using security features</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41143#M22026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sounds good to me.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Dec 2005 08:45:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41143#M22026</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2005-12-12T08:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Using security features</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41144#M22027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Andy,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'd read that wiki earlier, and I've been reading it since.&amp;nbsp; I still have some questions (or issues I want to get confirmed) :-)…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;From the wiki (&lt;/SPAN&gt;&lt;A href="http://www.alfresco.org/mediawiki/index.php/Security_and_Authentication" rel="nofollow noopener noreferrer"&gt;Security_and_Authentication&lt;/A&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;'Deny takes precidence. If "bob" is a member of the group "rats" and "bob" is allowed "read" and "rats" is denied "read" then "bob" will be allowed read. Any allow allows access, as opposed to a single deny denies all as used by the microsoft file systems.'&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;Shouldn't the part '"bob" will be allowed read' actually say that he will &lt;/SPAN&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;SPAN&gt; be allowed to read (since deny takes precedence).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Also:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;'Each permission or grouping of permissions applies only in the context of a type or aspect or to all types.'&lt;/BLOCKQUOTE&gt;&lt;SPAN&gt;Does this mean that I can define permissions perm1 and perm2 such that perm1 is only applicable to folders and perm2 is only applicable to assets?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Some clarifications:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Usernames, role names and group names are different types of authorities, correct?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If a (type of) permission is not explicitly defined on a node, and it either doesn't inherit permissions or none of its parents defines that particular permission, then the permission is assumed to be denied, correct?&amp;nbsp; For example, if there's an asset node that doesn't have READ permission defined for any user, and it doesn't inherit permissions – then that means that everybody is denied READ permission on that node.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What does PermissionService.ALL_AUTHORITIES mean (or would it be more correct to ask when is it used)?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;PermissionService#getOwnerAuthority() seems to imply that roles and groups can also be owners.&amp;nbsp; Is that so?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The implementation of the PermissionService seems tied closely to the authentication component (all of the methods that require an authority get it from the authentication component, instead of getting it as a method parameter), so does this mean that I can't use PermissionServiceImpl stand-alone, that I will have to use the whole shebang or none at all?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I had been hoping that I could just pass in the username (or group- or role-name), NodeRef and permission type to the PermissionService, and&amp;nbsp; get a decision on whether the user has permissions on the node in question.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for all your help and patience.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Dec 2005 01:55:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41144#M22027</guid>
      <dc:creator>hsjawanda</dc:creator>
      <dc:date>2005-12-16T01:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using security features</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41145#M22028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;Shouldn't the part '"bob" will be allowed read' actually say that he will not be allowed to read (since deny takes precedence). &lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;The example is correct &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Bob is in group Rats.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Rats is denied read on a folder&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Bob is allowed read on a folder….&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Bob has access as ANY ALLOW ALLOWS….&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If Rats is given read access to the parent folder (the folder inherits) then Rats will not have access as a result of the deny. Deny takes precedence. Bob will still have access.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Rats will have access to the parent folder.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You can have permissions linked to type, if that makes sense to you.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;As an example, we have ownership permissions that relate to the Ownable aspect and service.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;UserNames and Groups are authorities&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Permissions and PermissionGroups are Permissions&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Roles are confused generally. In the Alfresco UI we mean convenient groups of permissions, and is therefore a permission. In other systems it is an authority. You can do the latter if you want but I would not recommend it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ALL_AUTHORITIES is there for when you want to assign permissions to everyone( except guest - which will be coming soon ….)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Owner is a dynamic authority. The permission service will give you the reserved name. When evaluating permissions, for read for example, if any of the authorities you are granted have read you are in. That is your user name authority , group authorities , and maybe the owner authority - if you are dynamically evaluated to be the owner of the object.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Authentication means putting the valid user in a thread local security context. It is also used by auditing etc. You should set this up correctly and there is a method on AbstractAuthenticationComponent to help.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The same class supports reading this thread local information when required. The permissions are evaluated for the "current user" for this security context. You coud always force a context switch. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2005 10:59:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/using-security-features/m-p/41145#M22028</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2005-12-19T10:59:14Z</dc:date>
    </item>
  </channel>
</rss>

