cancel
Showing results for 
Search instead for 
Did you mean: 

Seeking clarification on access controls

ddougan
Champ in-the-making
Champ in-the-making
I've installed Community - v3.3.0 (2765) on my test system. I have it up and running OK (on SME Server 7.4) with OOo, etc. all accessible.

I'm trying to get my head around the access control model - specifically, I would like to set a default such that when a user is created, only she has access to her home directory. Right now, out of the box, User Homes seem to be open to all. When I go to "Manage Space Users" for the User Homes folder, I see that the access rights are inherited (with Guest and EVERYONE having read access); if I set them to Local, there are no user rights displayed - and no menu option for me to customize the access.

I realize I can go to each user folder and remove the EVERYONE setting; however, I would like to set global access. Having searched the available resources, I can't see what needs to be done. It seems unusual for other users' home folders to be accessible by default - can anyone comment why this might be?

Thanks,

Des Dougan
3 REPLIES 3

dkenned
Champ in-the-making
Champ in-the-making
I've noticed the same thing and have the same desire to eliminate EVERYONE from automatically being granted access to a user's home space.  There must be an easy solution?

mrogers
Star Contributor
Star Contributor
Home folder creation is "pluggable" so you can do whatever you want.

The interface to look at is HomeFolderProvider so either plug one of your own into the Person Service or it may be possible to configure one of the existing ones.

andy
Champ on-the-rise
Champ on-the-rise
Hi

The permissions to set can indeed be part of the default home folder provider - you just need over-ride the bean and tweak the config.
See config/alfresco/authentication-services-context.xml.
This will apply for LDAP sync for example and auto created users.

However if you create users via the UI it does its own thing (rather than allowing you to select a home folder provider - or even configure define a default provider).
In this case you need to have …  https://issues.alfresco.com/jira/browse/ENH-161


Andy
Getting started

Tags


Find what you came for

We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.