Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Workarea Permissions in 6.5
Santy05
I have installed Teamsite 6.5 on windows. I created a user and assign a workarea to that user. However,
I am unable to restrict users from viewing other workareas when logged in as ContentCenter professional.
Any help would be of great help!!!
Find more posts tagged with
Comments
Michael
Have you turned workarea security on?
from the doco:
Branch and Workarea Security
--------------------------------------------------------------------------------
Branch and workarea security determines whether or not users can see the names of branches and workareas they do not have access to. By default, the branch_security and workarea_security lines in the [iwserver] section of iw.cfg are set to off. This means that all branch and workarea names are displayed to users even if they do not have permission to access them (they see the name of the branch or workarea, but it is not linked and [N/A] displays next to it).
You can configure TeamSite to not display the names of branches and workareas in the TeamSite GUIs if the user does not have read permissions by editing the branch_security and workarea_security lines in the section of iw.cfg as follows:
[iwserver]
branch_security=on
workarea_security=on
Santy05
Hi Michael,
Thanks for the reply...
I have turned on the branch security and the workarea security... still doesn't work :-((((
When I log in to ContentCenter Professional as an author, I am able to traverse through all the branches, workareas and also able to view the files logging as an author. However, I am unable to edit or Import any files to other workareas.... but on the contrary I am able to delete and rename the files in other workareas.
One more thing.. when I log in using ContentCenter Standard with the same userid and the role, I am unable to view other workareas or branches that does not belong to that user.
is there any way that I can restrict users from not accessing the ContentCenter Professional????
Regards,
Santosh
Michael
Hi Santosh
After you updated the config did you do a reset? - presumably something like iwreset -ui would do the trick, but seeing as you are on Windows why not just restart the whole box
The problem you describe with being able to delete and rename but not modify or create in a certain workarea seems very odd. Especially when rename is generally a delete and create operation (on a versioned file). Perhaps you could test out some more and give some more details?
CCS will generally only show you the workareas you have access to -- I don't think that is dependent on the workarea security stuff.
There are seperate threads around about 'turning off' the interface -- generally stopping users logging in to CCS. It isn't supported but I recall you can change the JSP or some such... I don't think there is currently anyway to do it on a per user basis -- would be a great feature request though if it isn't already logged.
Cheers
Michael
Adam Stoller
It's been a while since I've had to do any significant amount of work on Windows [thankfully], but I seem to recall that, by default, "Everyone" has access throughout the backingstore and that you need to go through some [minor?] contortions after setting up TeamSite and before really using it (or [major?] contortions afterwards) to get it so that "Everyone" does not have access.
Check the permissions of your branches and workareas through Windows (possibly through TeamSite's properties) - and see if 'Everyone' is listed with permissions on all your workareas. If so - that's the problem.
--fish
Senior Consultant, Quotient Inc.
http://www.quotient-inc.com
Michael
Hi
I am not 100% sure about this -- and I don't have a box I can check it on but I don't think Everyone has default permissions anymore. I think there is a user (or is it a group?) called TeamSite Web Preview (or something quite like that) that has permissions everywhere so that the web server can serve up content for preview, etc.
I also recall having a half-failed install with 6.0 or 6.1 where this user or group wasn't created and I think it reverted to Everyone instead... not sure if that helps though.
Anyhoo definitely worth checking out either way.
Cheers
Michael
NathansDIS
The default is still for everyone to have access. However there is now the option to override this default. See the following from the TS 6.1 Win Admin guide. hth, -n
Default Permissions
You can now control branch permissions on Windows by adding the branch_default_perm
parameter to the [iwserver] section of the iw.cfg file as follows:
[iwserver]
branch_default_perm=0
The default behavior—which has not changed— still creates all branches with read access
for the group Everyone. If you add branch_default_perm=0 as shown, the group
Everyone is not added to the ACL for new branches created after this configuration setting
is added.
Santy05
I guess it should solve the problem. but, I am unable to remove "Everyone" from Y drive.
Santy05
I am getting the following error while I try to remove Everyone
I get the following error dialog when I try to remove the group Everyone from the security tab...
********************************************************
Unable to save permission change on IFS volume (y
the system cannot find the specified
********************************************************
The same group also exist in iw-home... I cannot remove that also... I get the following error message
***************************************************************************************************************
You cannot remove "Everyone" because this object is inheriting permissions from its parent
***************************************************************************************************************
Any help would be appreciated...
Thanks !!!
Bowker
I don't see from a quick scan on the thread if you are running Unix or Windows.
If you are running Windows you can issue a command line tool (windows command) of CACLS
That will allow you to modify the permissions on files. You will get "help" if you just enter cacls and press enter.
*** WARNING ***
Make sure you specify the \E option or you will not be happy
Dan Bowker
Northern Trust
Web Publishing Technology
John742
You should be able to remove inherited permissions from the folder and then remove Everyone. I believe there is some sort of check box to remove inherited permissions on the permissions gui if not, there may be an advanced option that has this option. Another gotcha is that I belive you must have at least one group or user listed, even if you give them no access. In other words your permissions list cannot be blank.
J Dagenhardt