User account with guest only role?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-22-2005 03:57 AM
Hi,
Objective
We want to use Alfresco to distribute the project deliverables (reports, discussion notes, working docs) to our customers. The customer are not entitled to submit documents to the store (at least not for now - security issues).
Problem
An account in Alfresco comes with a home space where the account owner has full administrator rights. He can upload documents, create subspaces, invite other users, etc… After creating a test account "test01", I tried to reclaim the "All" roles from her to award her the "Guest" role only. Alfresco did not object to this operation. When I logged on as test01, however, I could still create content and spaces in my home space. Is that a bug?
Regards
Ludo
Objective
We want to use Alfresco to distribute the project deliverables (reports, discussion notes, working docs) to our customers. The customer are not entitled to submit documents to the store (at least not for now - security issues).
Problem
An account in Alfresco comes with a home space where the account owner has full administrator rights. He can upload documents, create subspaces, invite other users, etc… After creating a test account "test01", I tried to reclaim the "All" roles from her to award her the "Guest" role only. Alfresco did not object to this operation. When I logged on as test01, however, I could still create content and spaces in my home space. Is that a bug?
Regards
Ludo
Labels:
- Labels:
-
Archive
2 REPLIES 2

Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-22-2005 05:15 AM
It is not a bug, as Alfresco has the concept of "ownership" as part of the permissions and security framework. If you are the Owner of a folder/document, then it overrides any specific permissions applied for that item. So if you remove any other permissions for a user who is the owner (which is the case for the homespace or any documents created by the user) then it won't stop the Owner from having full access to the item.
A user with the appropriate permissions can "Take Ownership" of a document through the details page, so an Admin can take control of a document and will become the Owner for it. However we have not yet exposed Take Ownership for space - which you would need to stop the user from still having rights in the space.
There is a way around this for now, if you set the "test01" user homespace to be a space that was created by Admin (e.g. which the test01 does not own) and then delete the other homespace you created for them, then they will no longer have any spaces that they own, and will not be able to create/edit docs etc. unless you specifically give them rights to the space you have now set.
We are adding proper Guest access to the system for a release early next year.
Hope this is useful,
Kevin
A user with the appropriate permissions can "Take Ownership" of a document through the details page, so an Admin can take control of a document and will become the Owner for it. However we have not yet exposed Take Ownership for space - which you would need to stop the user from still having rights in the space.
There is a way around this for now, if you set the "test01" user homespace to be a space that was created by Admin (e.g. which the test01 does not own) and then delete the other homespace you created for them, then they will no longer have any spaces that they own, and will not be able to create/edit docs etc. unless you specifically give them rights to the space you have now set.
We are adding proper Guest access to the system for a release early next year.
Hope this is useful,
Kevin
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-12-2006 09:44 AM
Hope this is useful
Yes it was.
Thanks again
Ludo
