Quote from: onepack at Oct 23, 2010, 03:42 AM
Hi Bobray,
Thanks for your reply.. but... I still don’t understand the logic... I’m really sorry.
I see that there are some standard access policy sets like admin, resource, "load only" etc.
You also get the option to add/create a new policy set. Lets call that one Custom.
Why can’t the "custom" set ever give a user enough permissions to show the files so they can work with pictures in the file system?
If I understand your explanation it doesn’t matter what I do. Even though I assign all permissions to "custom" it won’t ever show the files.
Only the "admin" example, the standard permission set admin can do this.
But what if the admin set gives too many rights? I can remove some rights but this will alter the standard Admin permission set.
If an other user is allowed to have more rights I cannot create a new admin set because you just explained that will never give enough rights to see the files.
Anyway, what I did was follow your advice and assign the admin permission set as well to the user and flushed all sessions, log in again with the standard user.
The result was the same.. no files could be seen for the other user. The same as my previous screenprint.
Sorry for the long story, I just try to make it clear.
Thanks again for the help!
Sorry if I wasn’t clear. The easy way to do thing is to "duplicate" that correct kind of policy and remove unwanted permission rather than creating a new one from scratch. Creating a new one and adding permissions risks misspelling a permission or two or forgetting to add a key permisson and spending a long time wondering why it doesn’t work.
The end result is the same if you get everything right.
Anyway, what I did was follow your advice and assign the admin permission set as well to the user and flushed all sessions, log in again with the standard user.
This makes it hard to help you, because it’s not clear what you actually did. It sounds like you created an ACL entry, but what kind, with what minimum role, and what policy?
I would say to try this:
Delete the domain admin group.
Delete any user settings you created for the user related to the file tree.
Follow these steps exactly:
Duplicate the standard Administrator policy -- call it domainAdmin.
Create a role of DomainAdmin with a level of 5.
Add the user to the Administrators User Group with a role of DomainAdmin.
Create a Context Access ACL for the mgr context with a minimum role of DomainAdmin and a policy of domainAdmin.
See what that gets you.
The user will be an admin Super User, but we’ll change that after it gets the Files tree back.