Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Setting Group Security with NRS Script
sleclerc
I have a database where a specific group should always have "Full Access" to all documents, but not necesarily should have "Full Access" to the folders they are placing documents into. So I am trying to set the Group's Rights in the NewProf.nrs script file and I receive an "access is denied" error when I reach the line in the script that reassigns the security. Does anyone have a suggestion how I can update the group security on the imported document. Here's the code I'm using. BTW it fails on the line that reads "secDlg.GroupNameArray = newGroups" :
Const imPublic = 80
Const imPrivate = 88
Const imView = 86
Const imRightNone = 0
Const imRightRead = 1
Const imRightReadWrite = 2
Const imRightAll = 3
Const strAllUsersGroupName = "ALLUSERS"
Sub NewProfileDlg_OnOK(dlg)
Dim k
Dim arGroups
Dim arRights
Dim newGroups
Dim newRights
Dim secDlg
Dim blnSecChanged
Set secDlg = dlg.UsrGrpSecurityDlg
blnSecChanged = False
Stop
' Check if the document's security is not set to Private
If Context("ImportedDocument").Security.DefaultSecurity = imPublic Then
arGroups = secDlg.GroupNameVariantArray
arRights = secDlg.GroupAccessRightsVariantArray
' Resize the new arrays
ReDim newGroups(UBound(arGroups))
ReDim newRights(UBound(arRights))
' Check If the AllUsers group was added to the document's security
For k = 0 To UBound(arGroups)
' Add the group name to the new Array
newGroups(k) = arGroups(k)
'If StrComp(oGroup.Group.Name, strAllUsersGroupName, 1) = 0 Then
If StrComp(arGroups(k), strAllUsersGroupName, 1) = 0 Then
' Make sure the group Is Not Set To no access
If arRights(k) <> imRightNone Then
' The group does not have no access, make sure it gets it
' has full access
newRights(k) = imRightAll
blnSecChanged = True
Else
' The rights do not need to change, so somply exit everything
Exit For
End If
Else
' This is not the group we are looking for, so simply copy it's security Right
newRights(k) = arRights(k)
End If
Next
End If
If blnSecChanged Then
secDlg.GroupNameArray = newGroups
secDlg.GroupAccessRightsArray = newRights
End If
Set secDlg = Nothing
End Sub
Find more posts tagged with
Comments
jny
I don't think you can modify the acl's in the OnOK event as the dialog is already done with committing its profile/security info to the server. Why not just change the security through the document object, which is returned by the ImportedDocument ContextItem? The fact that you can get a handle to the imported document object is because the document is already checked into the database.
The NRTDocument.Security.GroupACLs collection object can be used instead.
sleclerc
The NRTDocument and ImportedDocument are not available in the Office or FileSite products, it's only available in the DeskSite integration in the PostOnOK event handler. Any other ideas?
jny
I have 8.0SP1 and I was able to get a handle to the imported document object.
[newprof.nrs]
Sub NewProfileCmd_PostOnOK(obj)
on error resume next
dim doc
set doc = Context("ImportedDocument")
if doc is nothing then
msgbox "PostOnOK: doc is null."
else
msgbox doc.Number & "_" & doc.Version
end if
End Sub
In Office, however, this contextitem does seem to be missing. I don't see any other contextitem you may use to get the imported document object. What you could do is use FileSave.nrs to accomplish the same -- but you would need to be in EAI mode to fire this script:
[filesave.nrs]
Sub IManFileSaveCmd_PostOnOK(dlg)
dim doc
set doc = Context("ImportedDocument")
msgbox doc.Number
End Sub
Migrateduser
Can anyone confirm or otherwise whether it is programatically possible to set the document security via the NRS script??
Thanks
jny
Yes, it can.
Migrateduser
Thanks for the confirmation, do you have an example script I could take a look at?
jny
This depends on at which event you intend to set the default security. If it's at an event prior to closing the profile, you would use the NewProfileDlg.SetAttributeValueByID method, like so:
Const imProfileDefaultSecurity = 17
Const imPrivate = 88
dlg.SetAttributeValueByID imProfileDefaultSecurity, imPrivate, True
If it's after the profile is closed, in PostOnOK, then you can get the imported document object back to set the default security off of the WorkSite document object:
Dim oWSDoc
' Get a handle to the checked-in document object
Set oWSDoc = Context("ImportedDocument")
oWSDoc.Security.DefaultVisibility = imPrivate
oWSDoc.Update
Migrateduser
Thanks for the example, that's really useful.
Following on from that, is it possible to add a security group to the existing doc security via NRS script?
Migrateduser
Guys, can anyone help me out with this question.
Is it possible to add a security group to the acl via the NRS script?
Thanks
jny
I don't have adding group acl's readily available, but I do have the script below to show examples on how to add user acl's, which is very similar to adding groupacl's.
If you're still stuck, let me know exactly when you want to add the group acls from with newprof.nrs. I'll try to get something out to you as soon as I can.
Option Explicit
' AttributeID
Const nrAuthor = 5
' Access rights
Const nrRightAll = 3
Const nrRightReadWrite = 2
Const nrRightRead = 1
Sub NewProfileDlg_OnChange(obj, id)
dim secDlg
dim arrUserNames(2) ' Assuming array count is 3
dim arrUserRights(2) ' Assuming array count is 3
dim strOwner, str1, str2
dim lngOwner, lng1, lng2
If id = nrAuthor Then
' Usernames
strOwner = obj.GetAttributeByID(nrAuthor)
If "" = strOwner Then Exit Sub
str1 = "user1"
str2 = "user2"
' User access rights
lngOwner = nrRightAll
lng1 = nrRightReadWrite
lng2 = nrRightRead
' Put ACLs in a safe array
arrUserNames(0) = strOwner
arrUserNames(1) = str1
arrUserNames(2) = str2
arrUserRights(0) = lngOwner
arrUserRights(1) = lng1
arrUserRights(2) = lng2
' Get UsrGrpSecurityDlg object
set secDlg = obj.UsrGrpSecurityDlg
' Put UserACLs
secDlg.UserNameArray = arrUserNames
secDlg.UserAccessRightsArray = arrUserRights
End If
End Sub
Sub NewProfileCmd_PostOnOK(obj)
dim secDlg
dim arrUserNames
dim arrUserRights
dim lngNames, lngRights, i
dim strRet
' Get UsrGrpSecurityDlg object
set secDlg = obj.UsrGrpSecurityDlg
' Get UserACLs
arrUserNames = secDlg.UserNameVariantArray
arrUserRights = secDlg.UserAccessRightsVariantArray
If Not IsEmpty(arrUserNames) Then
' Obtain a count of the usernames and userrights.
lngNames = UBound(arrUserNames) - _
(LBound(arrUserNames) - 1)
' Determine if there are usernames.
If lngNames > 0 Then
for i = 0 to (lngNames-1)
strRet = strRet & arrUserNames(i) & "=" & _
arrUserRights(i) & "," & VBCRLF
next
msgbox strRet
End If
End IF
End Sub
Migrateduser
The code I'm working with is as follows :
if strCustomSecurity = "HR_PERS" then
NewProfDialog.SetAttributeValueByID imProfileDefaultSecurity, "88", False
dim secDlg
Const nrRightAll = 3
'Get UsrGrpSecurityDlg object
set secDlg = NewProfDialog.UsrGrpSecurityDlg
'Put GroupACL permissions
Dim strGroupName
strGroupName = "TEST"
secDlg.GroupNameArray = strGroupName
secDlg.GroupAccessRightsArray = nrRightAll
End if
This code is executing, but not applying the group to the ACL. Its worth noting that if I set strGroupName = "" and open a copy of a document that has groups on the acl, if strCustomSecurity = "HR_PERS" then the groups are removed.
In short, I can remove security groups via NRS script, but I cannot add them.
jny
You would need to put your group input in an array as demonstrated in the script for adding user acls.
Migrateduser
Thanks for the reply. I've added the code, but I'm now getting the following :
IManExt: The document could not be imported.
IManExt
Invalid index.
Any ideas?
Thanks
jny
Would you show your current code?
MMTest20.rptdesign