12-26-2013 11:24 AM
I see that if a user is granted with Read permission for a workspace, he can view and EXPORT everything in that workspace to a file, and if he install a new instance of nuxeo (quite easy due to the excelent work from Nuxeo team) he can then import every thing to it and have that workspace at hand with full access rights.
I'm quite embarrassed, or even terrified, with the fact that a user with lowest access right (Read permission) can easily download EVERYTHING from workspace structure to content, files... inside and bring home, upload (import) to new instance of Nuxeo and then become the owner of the full data. It's just like employee at a company: they are provided with everything at the office to work: computer, office machine and other properties. They have access to that in order to work at the office but absolutely they cannot take them home and become the owner of those properties.
If this is the case, in my opinion it would be a terrible thing regarding access right permission. I think that in the access right management, there should be setting to whether allow user to export workspace or not, just some very high-level users can export and users with low-level right such as Read right cannot export. I think the Export right should be even higher than Manage right (and of course much higher than Read, Write, Remove rights)
Could anyone please help me to clarify this point?
Thanks alot.
12-26-2013 06:04 PM
Hi,
If you access a web page you can do (almost) everything you want, in Nuxeo or other, with an export feature or withtout. Because you can receive the source of the page, and you can hit each resources.
For example, if your user can read a folder from :
then he can create a folder with the same name in :
and he can download all files and upload them. He doesn't need an export feature. NB: manually it could be a pain, but with a simple web parser it's easy
If you can't trust the user, don't allow him to access your data. Have you never seen an employee going to home with its professional laptop ? or getting data on an usb key ? Depending on the security requirements needed by the company, you have to implement some rules ... and educate your employees.
12-26-2013 08:57 PM
Thank you for your prompt reply.
12-27-2013 04:20 AM
As sdenef said, when you have read access, then you can read all the docs.
12-27-2013 05:36 AM
> I agree with you that Google Drive or
Find what you came for
We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.