Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
SitePUblisher Sites - Security
interDev
I have 2 questions about Site Publisher branching structure:
1. I have site "A" living in a Teamsite branch and in this site, 2 folders folder "FA" and folder "FB" are present (These folders are actually my navigation nodes for the site) and .page files are present in these folders as this site has been created using SitePublisher.
Is it possible to apply security at folder level of the site? So User "UA" should be able to see content from folder "FA" only and user "UB" should be able to see content in folder "FB" only.
2. Similarly if i configure 2 sites site "A" and site "B" within a branch, is it possible to apply security in such a way that users having access to site A do not have access to site B?
Is it possible in version 7.x?
Find more posts tagged with
Comments
vpatel
Yes it is possible. Look at the "Managing TeamSite Access" chapter in the TS Admin guide.
Migrateduser
If the question was whether it is possible to secure the files in TeamSite, vpatel's answer gives you good direction. However, it seems like your question might be about securing the runtime - so that one visitor logging in to your site might have access to FB and its children, but not FA. If that was what you are asking, I suspect that you will have to write a site controller that would interact with your userprofile system to enforce those permissions (or have a front end security solution like SiteMinder that would enforce the security before the request ever gets to LiveSite).
interDev
Yes it is possible. Look at the "Managing TeamSite Access" chapter in the TS Admin guide.
I dont think it actually fullfills my requirement. Reason Being:
I shared the workarea with User Group "GpAll" and users "A" and "B" are member of this Group. i have 2 sites "SiteA" and "SiteB" in the same workarea and I created two additional groups "GpA" and "GpB" which are specific to SiteA and SiteB in same Workarea (as i want to restrict the access on sites). User "A" is also a member of "GpA" and User "B" is also a member of "GpB".
Now i reset the permissions on "SiteA" folder and make "GpAll" permissions as "readonly". Add "GpA" for "SiteA" and give full control. Repeat same steps for "SiteB" folder.
With this setup, Yes users who are member of Group GpA, are not allowed to change content in SiteB and Users in Group GpB are not able to change content in SiteA.
BUT Users from Group GpA are able to submit the files to Staging from SiteB folder, can do "Get Latest" for SiteB and are even able to initiate a Workflow through "New Job" from SiteB folder. Same behavoir happens for SiteA as well where Group GpB can submit,can do Get Latest and can initiate workFlows.
How this problem can be overcome?
Mr_Cruise
You need to use a set of TeamSite groups to manage file level edit access and apply these through the configuration file 'submit.cfg'. You then need to look at TeamSite roles and appply those through TeamSite groups to manage menu access. Then through formAPI in the workflow intiation screen you can further check who started the workflow, what groups they are in and then close the workflow screen if required. To be honest there are plenty of options available to control access.
For exmaple you could remove the menu item 'get latest' and create a workflow to implement this method. When this workflow starts it could check what groups you are in and dislay what sites you can sync(Get latest). You need to look at the different options and most importantly be consistent.
Hope this helps.
Lee