<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Complex Permission Management Question in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/complex-permission-management-question/m-p/92120#M27295</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not aware of any addon that covers this specific constellation. Since permission schemes are typically extremely specific to the use cases of individual customers / users, I don't expect any addons to exist that automate such behaviour (granting read access up the folder tree to "reach" a specific folder where a permission has been granted), primarily because such automatisms would risk accidentally exposing critical information, and no developer would accept the risk of warranty / indemnity issues that could come with providing such a security-related addon. Neither does Alfresco really provide the tooling / framework to develop such automatisms. Only since Alfresco 5.2.x does a policy interface actually exist that could support that kind of logic, but it is neither marked as part of the public API nor are its invocations correctly implemented (it's an internal hack by an Alfresco engineer, really).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, to keep things short: If you allow access on a specific folder for a specific user, you yourself must ensure that the user can actually navigate to that folder. This would mean&amp;nbsp;ensuring that user is a member of the site, and potentially granting read permissions on ancestor folders, as well as disabling / fixing any inherited read permissions on other folders the user should NOT be able to access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Aug 2019 22:40:01 GMT</pubDate>
    <dc:creator>afaust</dc:creator>
    <dc:date>2019-08-01T22:40:01Z</dc:date>
    <item>
      <title>Complex Permission Management Question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/complex-permission-management-question/m-p/92119#M27294</link>
      <description>Hi AllWe have an Alfresco 5.2 Community implementation, where there is a complex hierarchy of folders under sites. Something like the below&lt;IMG id="smileyfrustrated" class="emoticon emoticon-smileyfrustrated" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-frustrated.png" alt="Smiley Frustrated" title="Smiley Frustrated" /&gt;ite A--&amp;gt; Folder 1&amp;nbsp; ---&amp;gt; Subfolder 1, 2, 3 etc.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Folder 2 ---&amp;gt; Subfolder 4, 5, 7 etc.It gets fairly complex, but the above is an over s</description>
      <pubDate>Wed, 31 Jul 2019 16:30:59 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/complex-permission-management-question/m-p/92119#M27294</guid>
      <dc:creator>villdre</dc:creator>
      <dc:date>2019-07-31T16:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Complex Permission Management Question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/complex-permission-management-question/m-p/92120#M27295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not aware of any addon that covers this specific constellation. Since permission schemes are typically extremely specific to the use cases of individual customers / users, I don't expect any addons to exist that automate such behaviour (granting read access up the folder tree to "reach" a specific folder where a permission has been granted), primarily because such automatisms would risk accidentally exposing critical information, and no developer would accept the risk of warranty / indemnity issues that could come with providing such a security-related addon. Neither does Alfresco really provide the tooling / framework to develop such automatisms. Only since Alfresco 5.2.x does a policy interface actually exist that could support that kind of logic, but it is neither marked as part of the public API nor are its invocations correctly implemented (it's an internal hack by an Alfresco engineer, really).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, to keep things short: If you allow access on a specific folder for a specific user, you yourself must ensure that the user can actually navigate to that folder. This would mean&amp;nbsp;ensuring that user is a member of the site, and potentially granting read permissions on ancestor folders, as well as disabling / fixing any inherited read permissions on other folders the user should NOT be able to access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2019 22:40:01 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/complex-permission-management-question/m-p/92120#M27295</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2019-08-01T22:40:01Z</dc:date>
    </item>
  </channel>
</rss>

