<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to enable non-admin user to modify ACLs to docs in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15380#M6805</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The order of the permissions does not matter. If there is a DENIED set on a level in addition to an inherited ALLOWED, the DENIED has precedence.&lt;/P&gt;&lt;P&gt;The only way to remove inherited ALLOWED is to disable the inheritance on that folder alltogether.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Nov 2017 10:32:04 GMT</pubDate>
    <dc:creator>afaust</dc:creator>
    <dc:date>2017-11-10T10:32:04Z</dc:date>
    <item>
      <title>How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15373#M6798</link>
      <description>Hello AllHow do we enable user to modify ACLs (add new, remove existing) ?Me as an admin can make a call to folder.addAcl() and assign new permissions for principals. But how can i enable other selected user to achieve the same thing? Would i need to put a user into a group and then assign it some c</description>
      <pubDate>Fri, 03 Nov 2017 16:12:22 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15373#M6798</guid>
      <dc:creator>longinus</dc:creator>
      <dc:date>2017-11-03T16:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15374#M6799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A user needs to have the ChangePermissions privilege / permission on the document (or inherited from the parent folder) to be able to manage the ACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Nov 2017 18:50:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15374#M6799</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-11-03T18:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15375#M6800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way to set it outside of&amp;nbsp;Share?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Nov 2017 12:59:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15375#M6800</guid>
      <dc:creator>longinus</dc:creator>
      <dc:date>2017-11-04T12:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15376#M6801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean out-of-the-box? There isn't even a way to&amp;nbsp;set this privilege in Share without some minor customisation. But as long as you have a tool / client that can call a ReST API, you could use either ReST v1 API or custom web scripts to set this privilege.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Nov 2017 13:00:43 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15376#M6801</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-11-05T13:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15377#M6802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mind telling me which rest public so i I can use to set permissions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Nov 2017 19:16:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15377#M6802</guid>
      <dc:creator>longinus</dc:creator>
      <dc:date>2017-11-05T19:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15378#M6803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A pu to the &lt;A href="https://github.com/Alfresco/rest-api-explorer/blob/master/src/main/webapp/definitions/alfresco-core.yaml#L895" rel="nofollow noopener noreferrer"&gt;/nodes/{nodeId} v1 ReST endpoint&lt;/A&gt; allows to set permissions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Nov 2017 09:39:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15378#M6803</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-11-06T09:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15379#M6804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for pointing me to this endpoint. I am able to add new permissions with it now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, overwriting the existing inherited permissions doesn't work. Inherited permissions are: GROUP_EVERYONE, Consumer, ALLOWED. I would like to remove it or overwrite it with GROUP_EVERYONE, Consumer, DENIED.&lt;/P&gt;&lt;P&gt;I end up having them both set, and since ALLOWED is first on the list, it is applied first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to remove ALLOWED or overwrite it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Nov 2017 17:34:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15379#M6804</guid>
      <dc:creator>longinus</dc:creator>
      <dc:date>2017-11-09T17:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15380#M6805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The order of the permissions does not matter. If there is a DENIED set on a level in addition to an inherited ALLOWED, the DENIED has precedence.&lt;/P&gt;&lt;P&gt;The only way to remove inherited ALLOWED is to disable the inheritance on that folder alltogether.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 10:32:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15380#M6805</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-11-10T10:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15381#M6806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the precedence in reverse situation? I.e. when DENIED is inherited and you want to enable a group to documents in child folder only?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 14:05:35 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15381#M6806</guid>
      <dc:creator>longinus</dc:creator>
      <dc:date>2017-11-10T14:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15382#M6807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And what happens when user is in GROUP_EVERYONE with DENIED and also in another group with "Write" ALLOWED?&lt;/P&gt;&lt;P&gt;Would the GROUP_EVERYONE rule overwrite the 2nd group's write access? Can user be in two different groups, one of which allows him access and the other denying him access?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 18:01:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15382#M6807</guid>
      <dc:creator>longinus</dc:creator>
      <dc:date>2017-11-14T18:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable non-admin user to modify ACLs to docs</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15383#M6808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically it is safe to assume that permission set at a lower level take precedence over a higher level, and&amp;nbsp;more specific permissions take precedence over less specific ones. I.e. if user A has been DENIED Consumer permission but has been ALLOWED Read permission, that user will be able to read content items. If user has competing permissions set on the same level (directly or via membership in multiple groups), then the DENIED will take precedence, though the "more specific" rule still kicks in, i.e. a permission set to user specifically will have precedence over a permission set to the group.&lt;/P&gt;&lt;P&gt;It's all quite logical...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 19:33:07 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/how-to-enable-non-admin-user-to-modify-acls-to-docs/m-p/15383#M6808</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-11-14T19:33:07Z</dc:date>
    </item>
  </channel>
</rss>

