Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Permissions in Teamsite New Form Entry / (Best Practices)
abiondo
I am trying to setup the permissions in Teamsite before getting the business involved. I setup a test user to see what the user would experience. When they go to the branch and WorkArea they can click around to files, but can not do a New Form Entry.
Teamsite Version 6.7.2
OS: Windows 2003
User: Local User on Server
Structure
main
- internet
-- sitename
---- WorkArea
------- content
Branch: main
- Administrator - web services - administrators
- Administrator - Administrator
- Author - web services - authors
Branch: internet
- No additional permissions here
Branch: sitename
- Author: sitename - authors
- Reviewer: sitename - reviewers
WorkArea
- web services - administrators (Full Control)
- sitename - authors (Change)
Desired Outcome
I want Authors to be able to add new content in additional to administrators.
I don't think users should see the iwadmin branch
I would like to hide other branches the user does not have access to if possible
I would like to understand the best practices for permissions or get an idea of what other people are doing here.
What I did so far
Edited iw.cfg
- branch_security=on
- workarea_security=on
Adjusted permissions as above.
Behavior
I notice that the items like New Form Entry are disabled if at the branch level the group is anything other than Administrator.
I notice that the user in the group can browse other branches it does not have permissions to, but they can not view or edit items and they appear disabled.
Any help you can provide would be much appreciated.
thanks,
Anthony
Find more posts tagged with
Comments
Adam Stoller
You have to consider a combination of both roles (TS) and access lists (OS/TS).
If a user has a particular role (e.g.: Author) associated with a particular branch, but does not have write access to the directories within the workarea - they will not be able create content there.
Generally, what I like to do is use TS Groups for both role-assignment
and
access lists within TeamSite - it makes administration generally easier (IMO).
So - for example - create a TS Group called
sitename
_Authors - add your test user to the group. Then associate this group with the workarea on the
sitename
branch giving them at least Modify, if not Full, rights
and
associate the role Author with the group at the branch level.
abiondo
Hi Ghoti:
Thanks for your message. I agree with you about using the TS Groups. That is what I am doing. What I neglected to do is make sure I created a group called
- work area and assign this group the the Group under the Work Area properties. Once I did this everything started working correctly.
I was wondering what you do from a permissions perspective on the templatedata directory. This is what I was thinking.
templatedata (Read Only)
-- internet (Read Only)
------ common (Read Only)
---------- data (Change)
---------- presentation (Read Only)
---------- components (Read Only)
Thanks for all of your help.
Anthony