Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Folder Security (User Right to Import Doc)
bfelknor
Greetings...
I know this seems basic.... I want to import a document to a WorkSite Folder, but first I want to establish that the user has the authority to import a document to that folder. Duh.
What the proper method to do this ? Of course, if one already has instantiated a document it is easy to check rights. I see how to check for authority to import a document to a database...but what about the folder right ?
Thanks.
Bruce
Find more posts tagged with
Comments
bfelknor
I should have indicated this is for VB 6, Server 7.x...the NRT Folder object. For this object there is no "EffectiveAccess" property on the folder.
jny
It will not be a straightforward implementation to check whether or not a user can add the imported document to the specified folder in using NRTFolder Object. You would need to check the folder security against the currently logged-on user: 1) default security, 2) Owner, and 3) ACL's -- to see if the current user has a minimum of readwrite access.
Please keep in mind that the user should still be able to import a document to the database, but by design, a reference to this document should not be added to the specified folder if the folder security limits the current user from doing so.
bfelknor
Thanks for the reply. Yeah, I figured it would be combersome. I think the user acl is pretty clear...I can see if the current user is in the list, then check the rights. But the group acl, do I actually have to A) read each group, get its members and compare to current user, or
get all the current user's groups and compare to the folder group acl ?
Thanks.
Bruce
jny
You could do either for group checking but you would need to check group members (if the GroupACLs is populated).
I think as a result of this painful approach, the New Interface has the new implemented EffectiveAccess Property to alleviate the problem. But, if you must use the older interfaces, you would need to unfortunately embark the aforementioned implementation approach.
bfelknor
Well, if someone is on Server 7.x and DeskSite 6.x, I can't use the new interface...right ?
jny
No.
DaleN
Hi folks!
The old api (NRT interface) does have a similar method available for checking whether operations could be performed. Here's an extract from the old COM Object manual:
'The following example checks whether the user has the right to add a document to a folder. This will return false is the user does not have read-write
'access to the folder, if the folder contains search parameters, or if the folder is the root folder for a database.
‘aFolder is a NRTFolder object
‘aDoc is a NRTDocument object
If aFolder.IsOperationAllowed(nrAddDocumentFolderOp) = True Then
aFolder.Documents.Add aDoc
Else
MsgBox "Operation not allowed."
End If
Regards,
Dale
bfelknor
I believe this pertains to adding a "document folder" i.e., subfolder, to another folder, and not adding a document to a given folder. Isn't that right ?
jny
That's correct: The INRTFolder.IsOperationAllowed Method is used to determine if an operation on a folder is allowed -- which does not include the operations on the documents collection belonging to a folder.
DaleN
I just had another read of the 3.1 SDK manuals and ran a bit of code up to test the scenario. The IsOperationAllowed(nrAddDocumentFolderOp) method does return a correct boolean value that lets me know whether I can add a document to a folder or not. There is another test < IsOperationAllowed(nrCreateSubFolderFolderOp) > that determines whether you have the rights to create a sub folder. Here's the sample code:
Private Sub Command1_Click()
Dim myDMS As New IManage.NRTDMS
Dim mySession As IManage.NRTSession
Dim myDB As IManage.NRTDatabase
Dim myFolder As IManage.NRTFolder
Dim myDoc As IManage.NRTDocument
Set mySession = myDMS.Sessions.Add("server")
mySession.Login "userid", "password"
If mySession.Connected Then
Set myDB = mySession.Databases(1)
Set myDoc = myDB.GetDocument(2590, 1)
For Each myFolder In myDB.Root.Folders
If myFolder.Name = "Project X" Then
Exit For
End If
Next
If Not myFolder Is Nothing Then
If myFolder.IsOperationAllowed(nrAddDocumentFolderOp) Then
'this works
myFolder.AddDocument myDoc
Else
'this results in an error
myFolder.AddDocument myDoc
End If
If myFolder.IsOperationAllowed(nrCreateSubFolderFolderOp) Then
'this works
myFolder.CreateSubFolder "Test X", "Testing adding subfolder", nrInherit
Else
'this results in an error
myFolder.CreateSubFolder "Test X", "Testing adding subfolder", nrInherit
End If
End If
mySession.Logout
End If
myDMS.CloseApplication
End Sub
The difference is that the above code is working directly off the folder object instead of retrieving the NRTDocuments collection and trying to work with that.
Regards,
Dale
Edited by DaleN on 02/02/05 07:29 PM (server time).
jny
Yep, you're absolutely correct. I checked the source and it indeeds makes an internal call to check whether or not the current user may add contents to the contents collection of the folder.
May be the operation Enum should be "nrAddDocumentToFolder" instead of "nrAddDocumentFolder" to maker it clearer and more concise.
Thanks for the redirection.
Ben: I hope you're seeing this and that you'll be using this method instead of doing that painful security check. Sorry for misguiding you.
bfelknor
I haven't been here in a while, however, nice work !