cancel
Showing results for 
Search instead for 
Did you mean: 

User account with guest only role?

omegerard
Champ in-the-making
Champ in-the-making
Hi,

Objective

We want to use Alfresco to distribute the project deliverables (reports, discussion notes, working docs) to our customers. The customer are not entitled to submit documents to the store (at least not for now - security issues).

Problem

An account in Alfresco comes with a home space where the account owner has full administrator rights. He can upload documents, create subspaces, invite other users, etc…  After creating a test account "test01", I tried to reclaim the "All" roles from her to award her the "Guest" role only. Alfresco did not object to this operation. When I logged on as test01, however, I could still create content and spaces in my home space. Is that a bug?

Regards

Ludo
2 REPLIES 2

kevinr
Star Contributor
Star Contributor
It is not a bug, as Alfresco has the concept of "ownership" as part of the permissions and security framework. If you are the Owner of a folder/document, then it overrides any specific permissions applied for that item. So if you remove any other permissions for a user who is the owner (which is the case for the homespace or any documents created by the user) then it won't stop the Owner from having full access to the item.

A user with the appropriate permissions can "Take Ownership" of a document through the details page, so an Admin can take control of a document and will become the Owner for it. However we have not yet exposed Take Ownership for space - which you would need to stop the user from still having rights in the space.

There is a way around this for now, if you set the "test01" user homespace to be a space that was created by Admin (e.g. which the test01 does not own) and then delete the other homespace you created for them, then they will no longer have any spaces that they own, and will not be able to create/edit docs etc. unless you specifically give them rights to the space you have now set.

We are adding proper Guest access to the system for a release early next year.

Hope this is useful,

Kevin

omegerard
Champ in-the-making
Champ in-the-making
Hope this is useful

Yes it was.

Thanks again

Ludo