Will do.
Am I correct (or even close) in saying that when creating/updating a user group:
1. Policies on the Context Access tab should be based on the Administrator policy.
2. Policies on the Resource Group Access tab should be based on the Resource policy.
??
Quote from: OpenGeek at Dec 18, 2009, 10:46 AM
Quote from: BobRay at Dec 17, 2009, 01:37 PM
Am I correct (or even close) in saying that when creating/updating a user group:
1. Policies on the Context Access tab should be based on the Administrator policy.
2. Policies on the Resource Group Access tab should be based on the Resource policy.
That’s exactly correct.
I guess there’s a first time for everything.
Ok, a few more questions:
1. When a situation is covered by more than one permission setting (e.g. doc in more than one resource group, user in more than one user group), does the most restrictive case apply or the most permissive one?
2. What exactly does ACL refer to in the Manager? I’m assuming it’s the Context Access tab in Update User Group and the Resource Group Access tab. It’s confusing when the docs focus on ACLs and there’s no reference to an ACL anywhere in the Manager.
3. When we say that a role inherits roles/policies with higher authority numbers, that means just in that particular ACL, right, not all roles/policies with higher authority numbers anywhere on the site?
Quote from: OpenGeek at Dec 21, 2009, 12:46 PM
Quote from: BobRay at Dec 21, 2009, 11:59 AM
Quote from: BobRay at Dec 21, 2009, 11:59 AM
2. What exactly does ACL refer to in the Manager? I’m assuming it’s the Context Access tab in Update User Group and the Resource Group Access tab. It’s confusing when the docs focus on ACLs and there’s no reference to an ACL anywhere in the Manager.
An access control list generically refers to any set of access control entries, i.e. User Group -> Policy -> Context or User Group -> Policy -> Resource Group -> Context. In the future there may be other ACL’s that set permissions on Elements directly, Menus, or any other object that extends the modAccessibleObject base class.
There is no User Group -> Policy in the current SVN (It’s User Group -> Context Access and User Group -> Resource Group Access), but I get what you mean. Thanks.
One more question:
If two roles have equal authority numbers, are the policies/permissions inherited from one to the other on an ACL, or does the authority # have to be greater to be inherited?
So is it correct to say that it’s possible to create different roles with the same authority number, but it shouldn’t be done?