<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deny Remove permission but Delete button still enabled in Nuxeo Forum</title>
    <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313332#M333</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This is due to the access rights priorization, as explained on this page: &lt;A href="http://doc.nuxeo.com/x/UYEk" target="test_blank"&gt;http://doc.nuxeo.com/x/UYEk&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;In this case, the user still has the right to remove documents because at the same level (in the same workspace) he's denied the right to delete documents, but he's also granted the Write permission. Since Write includes the Remove permission and granted rights win over denied rights, in the end the user is granted the right to remove.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2012 15:03:09 GMT</pubDate>
    <dc:creator>Solen_Guitter</dc:creator>
    <dc:date>2012-02-16T15:03:09Z</dc:date>
    <item>
      <title>Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313331#M332</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have just dowloaded and installed Nuxeo Document Management 5.5 and I tried what is described at
&lt;A href="http://doc.nuxeo.com/display/DMDOC/Managing+access+rights" target="test_blank"&gt;http://doc.nuxeo.com/display/DMDOC/Managing+access+rights&lt;/A&gt;
about access rights management.&lt;/P&gt;
&lt;P&gt;So I did the following steps:&lt;/P&gt;
&lt;P&gt;As Administrator&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;login&lt;/LI&gt;
&lt;LI&gt;create a John Do user&lt;/LI&gt;
&lt;LI&gt;create a workspace&lt;/LI&gt;
&lt;LI&gt;On the Manage tab, add two permissions: John Do - Grant - Write + John Do - Deny - Remove&lt;/LI&gt;
&lt;LI&gt;create a note in the workspace&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;as John Do user&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;login&lt;/LI&gt;
&lt;LI&gt;go to the workspace created above as Administrator&lt;/LI&gt;
&lt;LI&gt;check the box in front of the Note created above as Administrator
=&amp;gt; the Delete button is enabled so the user John Do can remove the document&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Question:
Is it normal that the Delete button is enabled even if there is a Deny - Remove permission on the workspace for the user ?&lt;/P&gt;
&lt;P&gt;I would have expected that the user won't be able to delete any document.&lt;/P&gt;
&lt;P&gt;Thanks in advance for your answer&lt;/P&gt;
&lt;P&gt;Best regards,
Christophe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2012 21:03:16 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313331#M332</guid>
      <dc:creator>ChristopheL_</dc:creator>
      <dc:date>2012-02-15T21:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313332#M333</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This is due to the access rights priorization, as explained on this page: &lt;A href="http://doc.nuxeo.com/x/UYEk" target="test_blank"&gt;http://doc.nuxeo.com/x/UYEk&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;In this case, the user still has the right to remove documents because at the same level (in the same workspace) he's denied the right to delete documents, but he's also granted the Write permission. Since Write includes the Remove permission and granted rights win over denied rights, in the end the user is granted the right to remove.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2012 15:03:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313332#M333</guid>
      <dc:creator>Solen_Guitter</dc:creator>
      <dc:date>2012-02-16T15:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313333#M334</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2012 15:48:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313333#M334</guid>
      <dc:creator>ChristopheL_</dc:creator>
      <dc:date>2012-02-16T15:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313334#M335</link>
      <description>&lt;P&gt;If you want to override the default rights hierarchy then you can create a custom security policy by extending SecurityPolicy. See &lt;A href="http://doc.nuxeo.com/display/NXDOC/Security+Policy+Service"&gt;http://doc.nuxeo.com/display/NXDOC/Security+Policy+Service&lt;/A&gt; for more details.&lt;/P&gt;
&lt;P&gt;Be careful with this because there can be negative performance side-effects if the custom policy is too complex!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2012 16:48:03 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313334#M335</guid>
      <dc:creator>bruce_Grant</dc:creator>
      <dc:date>2012-02-21T16:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313335#M336</link>
      <description>&lt;P&gt;I'm wondering why the Write permission needs to include Remove, it could be a good test to check if this is a problem for other features. I think it could be considered a bug, maybe to handle at the same time than https&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2012 14:32:46 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313335#M336</guid>
      <dc:creator>Anahide_Tchertc</dc:creator>
      <dc:date>2012-02-23T14:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313336#M337</link>
      <description>&lt;P&gt;I think the original question is an important one: how to grant permission to create new objects but not remove old ones.&lt;/P&gt;
&lt;P&gt;The comments above (directing to the doc) seem to be in conflict with the doc, which states:&lt;/P&gt;
&lt;P&gt;The "Remove" permission is intended to be denied, so as to restrict the actions available to users with "Write" permission.&lt;/P&gt;
&lt;P&gt;If  "Remove" permission is intended to be denied, but granting Write takes precedence, how is it possible to ever deny remove? To me this smells like a defect.&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2012 02:50:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313336#M337</guid>
      <dc:creator>tomi1123_</dc:creator>
      <dc:date>2012-09-27T02:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313337#M338</link>
      <description>&lt;P&gt;The answer is to redefine the aggregate permission Write to work the way you want it to. Or create a new permission (e.g., Write Only) which maps to a subset of the existing Write permission.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2012 03:04:12 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313337#M338</guid>
      <dc:creator>bruce_Grant</dc:creator>
      <dc:date>2012-09-27T03:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313338#M339</link>
      <description>&lt;P&gt;Is &amp;lt;require&amp;gt; tag needed for override to take effect and if so what does need to refer to?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 00:23:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313338#M339</guid>
      <dc:creator>tomi1123_</dc:creator>
      <dc:date>2012-10-01T00:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313339#M340</link>
      <description>&lt;P&gt;I got it to work. You will need a standard component wrapper around this but otherwise it works. Nuxeo is wonderful but does not make a good first date...&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;&amp;lt;require&amp;gt;org.nuxeo.ecm.core.security.SecurityService&amp;lt;/require&amp;gt;
&amp;lt;require&amp;gt;org.nuxeo.ecm.core.security.defaultPermissions&amp;lt;/require&amp;gt;
 
&amp;lt;extension target="org.nuxeo.ecm.core.security.SecurityService" point="permissions"&amp;gt;
&amp;lt;!-- Removed 'Remove' from Write permission --&amp;gt;
    &amp;lt;permission name="Write"&amp;gt;
        &amp;lt;remove&amp;gt;Remove&amp;lt;/remove&amp;gt;
    &amp;lt;/permission&amp;gt;
&amp;lt;/extension&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Oct 2012 04:49:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313339#M340</guid>
      <dc:creator>tomi1123_</dc:creator>
      <dc:date>2012-10-01T04:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Deny Remove permission but Delete button still enabled</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313340#M341</link>
      <description>&lt;P&gt;Is there some way to apply this extension to specific document types?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 23:12:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/deny-remove-permission-but-delete-button-still-enabled/m-p/313340#M341</guid>
      <dc:creator>a_c</dc:creator>
      <dc:date>2019-11-04T23:12:41Z</dc:date>
    </item>
  </channel>
</rss>

