Another permissions question - Roles / TS 6.7.1
I was wondering if anyone could shed light on the value of these custom groups in TeamSite 6.7.1. This is a little long winded, but want to demonstrate what I'm going after and what I've tried.
I am on Microsoft Windows, and we have users that use the GUI to import/edit/upload, and we also have users that use the virtual drive (\\server-name\iw-server\default) to do all of their file editing. I was under the impression that we "no longer" had to use Active Directory domain groups, and could switch everything to custom groups with roles, but now I'm wondering - it doesn't seem to work as I would expect.
So here's what I want to accomplish: In short, all users from the same custom group should be able to share files - if one Author in a custom group adds a file, the other Author in that custom group should be able to edit, preview, and submit that file, as well as import and create files of their own.
Let's use a branch called 'sales' as the example: default/main/sales.
In our old TeamSite system (6.1) we had used an A/D group called "DN\Sales Users". We had user Sally_Author and Peggy_Author in the Authors.uid file, and we had Suzy_Admin in the Admins.uid file, and all 3 were members in the "DN\Sales Users" group.
I create 2 custom groups through the TS GUI - "Sales Admins" and "Sales Authors". I now go to the default/main/sales branch, click "Users and Roles" and add "Sales Authors" as an Author role, and "Sales Admins" as an Admin role. I've assigned the correct users in the correct groups.
I have an existing workarea, and as a MASTER create a new file in it. I can't even preview the file I just created. I can Edit it but when I go to preview it, it gives me the windows authentication dialog box.
I log in as Sally_Author, and I can't even see the workarea. So I log back in as Master - lo and behold the properties on my workarea say that it is (1) Restrict access to this workarea; and (2) the owner sharing group is "DN\Sales Users" which Sally_Author is not a member of. So out of curiosity, I change my owner group to "Sales Authors". Ah-ha, Sally_Author sees the workarea.
Sally_Author logs in, and navigates in to the work area. Now her Edit and Import buttons are grayed out, and she can't preview the file that the master created. Nor can she create a new file. As a master, I can't even get in through the windows file system to \\server-name\iw-server\default\main\sales\WORKAREA\sales-workarea. It says access is denied.
==================================================
So at this point it's becoming obvious through further fiddling that the owner on the Workarea is what's giving the Windows file and folder permissions, and you need those permissions before you can edit, preview, etc. in the GUI, even if you have correct permissions in the GUI.
The problem is, is if I add the Custom Group as the owner, that does no good; if I add the domain group "DN\Sales Users" as the shared owner, then everyone in that group can do everything - authors now have full control.
So I guess my questions are - most importantly, is there any way to accomplish what I'm looking to do without domain groups; and if not, what is the value or usage of having roles assigned to the branches?
Thanks for any light that anyone can shed on this.