Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Disabling Branch for a user
heredite
Hi All!
Is it possible to remove(only from viewing it) a branch for a specific User or group of Users?
I'm in a Solaris server with teamsite 6.5.0.0 installed.
Thanks!
Find more posts tagged with
Comments
iwovGraduate
If you use CCStd you'll only see the areas that you have access to.
If you use CCPro, you can use branch_security setting in iw.cfg. However, this is a global setting - not per user. You might want to look at he documentation for this to see if you can use that for your situation.
Migrateduser
For CCPro or std? If I understand your question correctly, you want to restrict a group from being able to see the contents of a branch? You could make the branch readable only to a certain group or groups, thus restricting other folks from seeing it. For some reason, I think I'm not understanding you well, though.
Dave
Current Environment(s):
(1) TS 6.1 SP1 on W2K3
(2) TS 6.1 SP2 on W2K
(3) TS 6.1 on W2K
artor
As per your situation don't apply the changes on iw.cfg because it effects globally and Dave suggestion is quite help you.
Regards,
A
gzevin
Dave,
I am discussing a similar thing in a different topic. My requiremnt is - to restrict access to branch/workarea (even for READ acces) to user that do not belong to that particular group. your suggestions? Believe me, we are trying a lots of things to do it.. no much success so far. setting 770 on the workarea breaks the preview.
Greg Zevin, Ph.D. Comp. Sc.
Independent Interwoven Consultant/Architect
Sydney, AU
Migrateduser
Let me do some homework on this in the environment marked as #3 in my signature file, there are many, many branches but I can only "see" a few of them and I even have Administrator access. That is, I can drill down as far as the Workarea level, but cannot go any further. I don't think you'd want to set 770, but tonight/tomorrow, I can do a Remote Desktop on the machine and see specifically how they're restricting access for me.
Dave
Current Environment(s):
(1) TS 6.1 SP1 on W2K3
(2) TS 6.1 SP2 on W2K
(3) TS 6.1 on W2K
gzevin
well, you are on Windows.. Solaris could be a bit different
Greg Zevin, Ph.D. Comp. Sc.
Independent Interwoven Consultant/Architect
Sydney, AU
Migrateduser
Maybe, but I'd be willing to bet that this particular solution would be more similar on both platforms than different.
Dave
Current Environment(s):
(1) TS 6.1 SP1 on W2K3
(2) TS 6.1 SP2 on W2K
(3) TS 6.1 on W2K
gzevin
Ok.. eagerly awaiting
Greg Zevin, Ph.D. Comp. Sc.
Independent Interwoven Consultant/Architect
Sydney, AU
heredite
Hi all!
Thanks for answering but not really sure that all answer there can really help me for the moment.
I gave you more details:
I have 2 groups of user. One is using a branch on my system and the other one is using another branch. I want that each group cannot see the branch of the other one. Is there a way to do it?
If I use iw.cfg, it's probably based on role(author, editor...). But on each of my groups I have authors, editor... So that can't help me.
Someone have an Idea?
Pascal
Interwoven Consultant for Aeroplan
LooseCannon
Greg -
Our shop (running TeamSite 6.1 on Solaris 8) accomplishes this by setting the branch and workarea to 771.
LooseCannon
Unix's permission model handles this fairly easy...
1) Assign groupA to branchA
2) Assign groupB to branchB
3) Set the permissions on both branches to 771
Migrateduser
Okay, I just checked on their configuration and, although it's Windows, LooseCanon (previous post to this one) hit the nail right on the head as far as how you'd do this in Unix:
In this environment, I am a member of a privileged group that can see and write to all branches. A former teammate of mine is not in the privileged group but she can see the branches/workareas that she needs to. I've logged in under her ID a few times and I can verify that she can't browse down to the workarea level in most cases. Simply put, the workareas to which she should not have access are defined as having group ownership of another group. I'm in the admin group, so I can pretty much come and go as I please.
On Unix, this seems to be accomplished easily by chmoding the workarea to 711.
HTH,
Dave
Current Environment(s):
(1) TS 6.1 SP1 on W2K3
(2) TS 6.1 SP2 on W2K
(3) TS 6.1 on W2K
gzevin
thanks.
I gotta check... however - that '1' is what I am not comfortable with. Can all the users see the content?
Greg Zevin, Ph.D. Comp. Sc.
Independent Interwoven Consultant/Architect
Sydney, AU
Migrateduser
Sorry, meant 771 on the permissions. Tried to edit my post but the time expired.
Current Environment(s):
(1) TS 6.1 SP1 on W2K3
(2) TS 6.1 SP2 on W2K
(3) TS 6.1 on W2K
gzevin
can you still previw the content and are guaranteed that the other users cannot view anything in that workarea?
we are very concerned about ANY possibility to view unathorised content
Greg Zevin, Ph.D. Comp. Sc.
Independent Interwoven Consultant/Architect
Sydney, AU
LooseCannon
This model will only allow the workarea owner, group or any user logged in as Master to view content.
Setting the world execute bit allows for processes to be ran by those not in the group, i.e. iwui, etc...
LooseCannon
Anyone in the group can view, edit, preview, etc...
I can think of one potential loophole… Depending on the perms you use for the dirs and files inside the workarea a user could view a dir / file by pasting the full path to the dir / file in the GUI. Note : they still couldn’t edit or preview a file
gzevin
Ok, thanks. will this a try...
Greg Zevin, Ph.D. Comp. Sc.
Independent Interwoven Consultant/Architect
Sydney, AU