<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do authentication and permissions work when using the CMIS API? in Nuxeo Forum</title>
    <link>https://connect.hyland.com/t5/nuxeo-forum/how-do-authentication-and-permissions-work-when-using-the-cmis/m-p/319860#M6861</link>
    <description>&lt;P&gt;Authentication is done through the CMIS API using Web Service Security user token. If the user used for that purpose is correctly configured and as the righ ACL in the Nuxeo server, only the document accessible to him will be accessible from the CMIS client using his user token.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jul 2011 21:42:18 GMT</pubDate>
    <dc:creator>Roland_Benedett</dc:creator>
    <dc:date>2011-07-28T21:42:18Z</dc:date>
    <item>
      <title>How do authentication and permissions work when using the CMIS API?</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/how-do-authentication-and-permissions-work-when-using-the-cmis/m-p/319859#M6860</link>
      <description>&lt;P&gt;Can I restrict the documents available through CMIS requests based on user permissions? How does authentication work when using CMIS?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2011 21:31:07 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/how-do-authentication-and-permissions-work-when-using-the-cmis/m-p/319859#M6860</guid>
      <dc:creator>Roland_Benedett</dc:creator>
      <dc:date>2011-07-28T21:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do authentication and permissions work when using the CMIS API?</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/how-do-authentication-and-permissions-work-when-using-the-cmis/m-p/319860#M6861</link>
      <description>&lt;P&gt;Authentication is done through the CMIS API using Web Service Security user token. If the user used for that purpose is correctly configured and as the righ ACL in the Nuxeo server, only the document accessible to him will be accessible from the CMIS client using his user token.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2011 21:42:18 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/how-do-authentication-and-permissions-work-when-using-the-cmis/m-p/319860#M6861</guid>
      <dc:creator>Roland_Benedett</dc:creator>
      <dc:date>2011-07-28T21:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do authentication and permissions work when using the CMIS API?</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/how-do-authentication-and-permissions-work-when-using-the-cmis/m-p/319861#M6862</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Permissions&lt;/STRONG&gt;: with CMIS like with all other Nuxeo APIs, the access to documents obeys the user's permissions. This means that you will not be able to see or search documents to which you don't have &lt;EM&gt;Read&lt;/EM&gt; access granted, and won't be able to create, modify or delete documents to which you don't have &lt;EM&gt;Write&lt;/EM&gt; access.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Authentication&lt;/STRONG&gt;: this is the process through which you state and prove which user you actually are. Authentication depends on the protocol employed by your CMIS connection. Nuxeo 5.4.2 supports the standard AtomPub (REST) and SOAP (Web Services) bindings and the authentication methods standardized by CMIS for them:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;For AtomPub, you authenticate through HTTP Basic Auth.&lt;/LI&gt;
&lt;LI&gt;For SOAP, you authenticate through the Web Services Security (WSS) UsernameToken.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In both cases, using HTTPS is recommended as otherwise the credentials could be eavesdropped.&lt;/P&gt;
&lt;P&gt;You can read more about CMIS in Nuxeo &lt;A href="https://doc.nuxeo.com/x/JIAO"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2011 11:52:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/how-do-authentication-and-permissions-work-when-using-the-cmis/m-p/319861#M6862</guid>
      <dc:creator>Florent_Guillau</dc:creator>
      <dc:date>2011-07-29T11:52:53Z</dc:date>
    </item>
  </channel>
</rss>

