Hmm. I was hoping to not have to create a separate space just for secured
pages.
I'm confused about how "deny" rights can be stronger than "allow"
rights.
If my wiki-level permissions allow View, but have blocked edit and delete,
then how can I go into the space-level rights and grant edit and delete
rights there? Wouldn't the wiki-level permissions override the
space-level? If not, then why wouldn't the page-level permissions override
the space-level? What am I missing?
On Mon, Sep 24, 2012 at 1:42 AM, Sergiu Dumitriu <sergiu(a)xwiki.com> wrote:
On 09/24/2012 12:53 AM, Matt Lamoureux wrote:
Can someone please confirm that I understand user
rights properly?
I have a wiki in which I have loaded all of our custom pages into a space
called "1". We use LDAP, so every user is automatically added to the
XWikiAllGroup. We have a small team that wants to utilize secured pages,
so I created a group called GroupA. I then went through and added team
members to GroupA (without removing them from XWikiAllGroup).
At the wiki level, I have granted both groups "view" access, but blocked
everything else.
At the "1" space level, I have granted both groups "edit" and
"delete"
rights
Now, in that space, there are some pages that we only want GroupA to see.
I thought it was simple - I could just go into each page, block
XWikiAllGroup from view/edit/delete, and grant view/edit/delete access to
GroupA. Apparently that is not true - the fact that they are still in
XWikiAllGroup prevents them from viewing those pages, since that group is
blocked? I expected the fact that they are part of GroupA and GroupA is
authorized, they would be authorized.
If that is true, what is the solution to this? What is the simplest way
to
secure a page from everyone except the members of GroupA? If I remove
GroupA members from XWikiAllGroup, that seems to cause other issues with
skins and such.
Any suggestions?
From
http://markmail.org/message/**32zfathwmj3pzjre<http://markmail.org/messa…
"Deny rights are always stronger than allow rights. There is no group
ordering, no notion of a "more specific" group."
From
http://markmail.org/message/**jzxb2mtzn6kcx6yi<http://markmail.org/messa…
"Specifying an access right for a group automatically denies that right
for those that are not in that group."
So you should just "allow" GroupA, without any "deny".
--
Sergiu Dumitriu
http://purl.org/net/sergiu/
______________________________**_________________
users mailing list
users(a)xwiki.org
http://lists.xwiki.org/**mailman/listinfo/users<http://lists.xwiki.org/m…