When wanting to restrict a user's acces in Revolution, i stumbled upon all bells and whistles it has to offer, wich is offcourse great, but for my comprehension a little too much to take at once.
I just wanted to restrict a user to editing documents in the web tree and give acces to one custom CMP. Is there some easy setup or do i really need to create a complete configuration for just one user?
You probably do need to create a new user access role, but fortunately you can export the configuration to an xml file so next time you have something to work from.
-
☆ A M B ☆
- 24,524 Posts
Thanks Susan, that first sentence about nailed it:)
This whole permission thing feels a bit like having to take flying lessons while i am just a passenger.
-
☆ A M B ☆
- 24,524 Posts
I don't think you will find anyone who disagrees with you about that.
It's been 6 months but i still can't figure this out properly. Normally i manage websites, so i don't need all this. But now i have 1 user that i want to restrict to editing documents in the web context and to access and use a CMP. (would then also need acces to a mediasource).
How to go about that in the most simple way?
1. Don't put the user in the administrator group.
2. Create a Context Access ACL entry connecting the Web context and the Administrator group (you probably have one already)
3. Make sure the user's group doesn't have an ACL entry like #2.
That should hide any non-web resources in the tree.
For the CMP, it's trickier, basically you want to hide almost all the *other* menu choices in the Top Menu. You can do that by adding a permission to them in Manager->Actions. Right-click on the menu options in the right-hand tree and select "Update Menu". Then, add the new permission in the last field. If there's already one there, add a comma and your permission (no spaces).
Important! Make sure *you* have the permission before you start messing with them.
As long as the user doesn't have the permission and you do, they won't see those menu items. I use the access_permissions permission for this since in almost all cases no user other than the admin Super User should have that permission in the Policy used by their Context Access ACL entry for the 'mgr' context.
If the ACL entry for the user's user group that gives access to the Media Source has a context of 'mgr' I think it should work. It if doesn't it might be a bug. I'm not really an expert on Media Source permissions, though.