Hi,
I've been through and setup a user with access policies and resource groups to limit which files they can view. As far as I can tell everything is working as it should although the process of setting this up has been a bit of trial and error. In Access Policies I've left "create a Resource at the root level" unchecked. This appears to work except the user is still able to duplicate and resource in the root.
edit: I have context access and resource access setup, do I need both?
Any ideas? I'll provide more info on the permissions if required.
Revolution 2.1.5-pl
Many thanks
[ed. note: bobwal last edited this post 14 years, 10 months ago.]
Just a little hopeful bump
If the user has another policy that applies in that situation with a different setting for that permission, the more permissive permission will apply.
If that's not the case, it sounds like a bug.
Thanks for the reply Bob, much appreciated. This was my initial thought too, that the permission was being negated by another.
For my resource group I have an EditorResource policy and for contexts I have an EditorAdmin policy (web & mgr) nothing in the permissions jumps out at me though.
Should I file a bug?
Thanks
Is duplicate_resource turned off in the EditorAdmin policy applied for Context Access to both web and mgr contexts?
Are the Editors also members of the Administrator group?
Hi Bob, I can't find duplicate_resource anywhere. I also double checked the groups and the editors aren't in the administrator group.
Sorry. I think it used to be called that. Look for the 'copy' permission in the Resource Group Access policy.
If new_document_in_root is not enabled in the Context Access policy, that *should* stop them as well, but looking at the code, I'm not sure it does.
There doesn't seem to be any easy way to let users create new documents but not duplicate them. If you uncheck the new_document permission, they won't be able to duplicate anything, but they also won't be able to create new docs.
Thanks for looking Bob, I think I can live with this for now.