Publish permissions

We have a project being migrated from CQ4 to CQ5.  We are trying to understand how people manage their permissions on the publisher.
In CQ4, the permissions were associated with the user/group and replicated easily from author, so we could define the rules in author and just activate them.
In CQ5, the permissions are associated with the content, but when you activate the page, the permissions are not replicated.
Adobe says the reason for this is :
"Page permissions are not replicated because they are stored under the nodes to which access is granted, not with the user.
In general page permissions should not be replicated from the author to publish and are not by default. This is because access rights should be different in those two environments. Therefore it is recommended to configure ACLs on publish separately from author."
See http://helpx.adobe.com/cq/kb/PagePermissionsNotReplicatedWithUser.html
However, they don't say how exactly one should "configure ACLs on publish separately from author"
So what to do ?
1) One way would seem to be to create a package of just the permissions and then manually install this package on each publish instance.
Just activating the package would appear not to work
This has the disadvantage that the sys admin has to log in directly to each publisher to install the packages, and it becomes a "deployment" task to change permissions
2) Login to the publishers and apply the access rights directly on each publisher.
This has similar problems to the one above, and might have timing issues, e.g. when a page is activated by a user
3) we could use Closed User groups.
Whilst this would seem to work for a limited extent, it seems the limitations might be too much for us.
E.g. If we have a Closed User Group for the intranet, and then within the intranet we have a section for HR only, we would want 2 groups, one
for "intranet-users" which would have access to
/content/intranet/en
and one for "intranet-hr-users". which would have access to
/content/intranet/en/hr
From what I can tell a member of "intranet-users" automatically gets access to everything underneath /content/intranet/en so would have access to all the HR content too
Also with Closed User Groups, how do I get an overview of what permission a particular user or group has ? 
4) There is a utility package to create packages based on an XPATH which might help with 1) but still has the same issue of direct deployment to publish.
TBH, I am not sure really why the permissions cannot be replicated.
Normally we would just assign users to groups and assign groups permission to read the pages, on publish users would not be members of the "authoring" groups so there wouldn't be a problem.
Is there a workaround or hotfix ?
Dev.

Hi Dev,
For 1 See alternative [1] works for you. AFAIK there is no hotfix & as a alternative need to develop a custom component implementing EventListener, EventHandler and set acl accordingly based on properties.
[1]   
https://helpx.adobe.com/crx/kb/HowToInstallPackagesUsingRepositoryInstall.html
Thanks,
Sham
@adobe_sham

Similar Messages

  • Publisher permissions and BI integration

    I have switched to Oracle BI Server Security Model in publisher so I can log in with users stored in an external Database. The presentation works just fine, but when I try to use Publisher I cannot access the Catalog and also get the following issues/errors.
    1. "No input xdo file path is specified" When creating a new Data Model.
    2. If I ignore this error and create a new Data Set - Oracle BI Analysis, I can only see the folders in the catalog initially (Shared Folders, Users), and all sub folders, but no reports.
    3. If close out, or click back on the breadcrump the folders no longer show up (from issue 2).
    I've already tried this: Error integrating publisher and BI but no luck.
    Could I be missing another security policy?
    The user I am testing with has the BIAdministrator Role with all the publisher permissions I can find.
    Edited by: 844667 on Aug 4, 2012 5:08 PM

    I added the default Oracle BI EE datasource awhile ago. All this did was allow me to click refresh when creating a new data model and it shows up in the Default Data Source list (not sure why I have to click refresh Data Source List but if I do not it is empty)
    The only other error in the logs I can find is this
    [2012-08-06T14:49:44.000-04:00] [OBIPS] [WARNING:16] [] [saw.securitysubsystem.authenticationutils.addauthenticatedusertocatalog] [ecid: 7eee1bf15b0dff8d:-4dbe3b88:138fcdc54a4:-8000-0000000000001aa4,0:1:1] [tid: 8792] Empty ROLE or ROLEGUID session variable received for the user admin. User may not have
    access to many features in Oracle Business Intelligence[[
    File:authenticationutils.cpp
    Line:191
    Location:
         saw.securitysubsystem.authenticationutils.addauthenticatedusertocatalog
         saw.securitysubsystem.checkauthentication.runimpl
         saw.threadpool.asynclogon
         saw.threads
    ecid: 7eee1bf15b0dff8d:-4dbe3b88:138fcdc54a4:-8000-0000000000001aa4,0:1:1
    ThreadID: 8792
    Still looking into this but not finding much.

  • Publisher Permissions on the CMC in XI 3.1 SP2

    We have a Developers group (with a Developers custom access list) within the CMC.  Aside from universe and report development, we would also like to have the developers create publications.  The permissions have been set so a developer can create a publication, however, they cannot see any users or groups in the Enterprise Recipients list.  I've tried updating the settings through the CMC to allow for this, but haven't been able to find the right combination.  The Administrator, of course, has no issue seeing the Enterprise Recipients list.  Does anybody know what settings should be used to bring this list back?
    We are using XI 3.1 with SP2 on a Windows 2008 server.  The 3.1 Publisher Guide hasn't been all that helpful.  It gives the generic "View right on users and groups intended as recipients" rights that are required.  I have tried updating settings in Users and Groups, Publications, Profiles, General, etc.
    Any help would be much appreciated!

    The client would like to send content (PDF mostly) to users outside of the BusinessObjects environment.  As an FYI, we are using Active Directory authentication.
    I tried a couple of things.  The first was including the Enterprise Recipients and then adding additional users in the Destinations section by appending additional email addresses after the %SI_EMAIL_ADDRESS% parameter in the To: text field.  This resulted in the non BusinessObjects users receiving emails multiple times (the number of Enterprise Recipients).  As a workaround, we added these two additional users to the Active Directory group so we could include them in Enterprise Recipients.
    My test with the Dynamic Recipients included creating a WebI report that included a Project ID, Full Name, and Email and using that report as my source for Dynamic Recipients.  I continued getting the following error, which I sent to SAP Support:
    ERROR [PublishingService:HandlerPool-96] BusinessObjects_PublicationAdminErrorLog_Instance_27585 - [Publication ID # 27585] - Scheduling document job "Materialized View Freshness Report" (ID: 27,592) failed: An internal error occured while calling 'submitReport' API. (Error: ERR_WIS_30270) (FBE60502) [3 recipients processed.]
    Both WebI reports refresh correctly through InfoView - the dynamic recipient source document and the source document specified for refresh.

  • Report Service And Report Builder Issue

    SQL SERVE 2012
    In our web site project we use ReportingService2010 Methods to show and operate folder and report which stored in Report Service, in our project configuration file, we use windows authentication mode for Report Service.
    In requirement
    User can show and operate folder “A” and folder “B” (we can create and delete report or folder) in web site.
    User can’t use “Report Builder” to save reports which created by Report Builder to folder “B”, Reports which created by Report Builder only can be saved in folder “A”.
    [User click “Report Builder” button in our web page to start Report Builder, use
     “Report Builder” to create report, if user want to save report, we need to hidden folder “B” in “Report Builder” or we need to remove some operate right from folder “B”.]
    We have no solution for this requirement, could you help us?

    Thank you for your replay, but I don't understand it very clearly.
    Please check the first requirement:
    User can show and operate folder “A” and folder “B” (we can create and delete report or folder) in web site.
    For example, I login my PC with account "lfang", in report server, we grand "Browse" permission on both folder and grand only "Publish" permissions for folder "A", report builder can't save report into folder "B",
    it's correct.
    But our web site has create report function, that means in our web site we want to create report for both folder "A" and "B", that is the issue, if we don't give "Publish" permissions to folder
    "B", we can't create report in our web site.
    Is there any method to run "report builder" use specified account? then we can only give folder "A" "Publish" permissions with specified account.

  • Unable to add aspx file to document library using REST and JSOM in SharePoint Hosted App

    Hi,
    I am unable to add an aspx file to document library.  I was actually trying to create a WIKI page and upload to Pages library but that wasn't working so I tried simple document library.  It keeps failing with Access Denied error.  I have checked
    the blocked types and aspx is not included.  I can upload it directly from the browser so that shouldn't be the case.  I have read that it can be achieved with CSOM but I need this to work with a SharePoint Hosted App.  Here is my JSOM:
    factory = new SP.ProxyWebRequestExecutorFactory(appweburl);
        context.set_webRequestExecutorFactory(factory);
        appContextSite = new SP.AppContextSite(context, hostweburl);
        oWeb = appContextSite.get_web();
        oList = oWeb.get_lists().getByTitle('Documents');
        fileCreateInfo = new SP.FileCreationInformation();
        fileCreateInfo.set_url("mywiki.aspx");
        fileCreateInfo.set_content(new SP.Base64EncodedByteArray());
        fileContent = "<%@ Page Inherits=\"Microsoft.SharePoint.Publishing.TemplateRedirectionPage,Microsoft.SharePoint.Publishing,Version=15.0.0.0,Culture=neutral,PublicKeyToken=71e9bce111e9429c\" %> <%@ Reference VirtualPath=\"~TemplatePageUrl\"
    %> <%@ Reference VirtualPath=\"~masterurl/custom.master\" %>";
        for (var i = 0; i < fileContent.length; i++) {
            fileCreateInfo.get_content().append(fileContent.charCodeAt(i));
        newFile = oList.get_rootFolder().get_files().add(fileCreateInfo);
        context.load(newFile);
        context.executeQueryAsync(function () {
            alert('yo');
        }, function (sender, args) {
            alert(args.get_message() + '\n' + args.get_stackTrace());
    If I change the file extension to "txt", it works.  Same with REST implementation, it works with "txt" but fails with "aspx".  Maybe what I am trying to do will not work using JSOM or REST.  Any suggestions?  Your
    help is always appreciated.
    Regards,
    kashif

    Your code works fine in both my on-premises and SharePoint Online. I have given the app full control, so I suspect this is a permissions issue. I would check your permissions on your appmanifest. Must be something to do with publishing permissions. Try
    giving full control and work the permissions down.
    Blog | SharePoint Field Notes Dev Tools |
    SPFastDeploy | SPRemoteAPIExplorer

  • Client loses ability to edit pages in CS3

    Hi folks,  although the permissions I had for client in CS3 were pretty broad, she is now only able to edit text   on SOME pages whereas she was able to edit text on all before. When I log in using CS5 I do not see any draft pages, but she said she cannot even create a draft for those pages.  She can only edit one page now...
    Any ideas what might be the problem here?     I am now using CS 5 but had NOT opened up the website for months until she emailed me today about the problem.

    Okay, I reloaded the site, made sure it is compatible and transitional, sent a new key. Client is able to log in and edit   one page but not others they have created, I think, even though  she has publisher permissions. She says she has no drafts on her system.  I used the same key in CS3 and was able to edit all pages.  We are stumped... She is one Windows and I'm on a Mac, so my guess there is something messed up in her Win preferences or whatever they're called, like plist on the mac...   or something else.
    All pages are checked in and she has Enabled the connection.
    can anyone give me a clue as to what to tell her to do to restore her ability to edit pages?

  • CS3 author 'preview in browser'

    My company recently upgrade all authors to Contribute CS3,
    from Contribute 3. In the previous version I, as system admin, gave
    everyone a new ccmenus.xml file that allowed authors (i.e. roles
    without Publishing permissions) to use F12 to 'Preview in browser'.
    However, now that we have CS3 (i.e. v4.1), this no longer works.
    I need my authors to be able to preview their work BEFORE
    they send for review, especially as the templates I created for
    them to use rely heavily on scripted sections, meaning that what
    they see in 'edit mode' is nothing like the end result once
    published.
    How can I re-enable the F12 functionality for authors?

    I found the ccmenus.xml file in C:\Program Files\Adobe\Adobe
    Contribute CS3\Configuration\Menus\.
    This is the xml:
    <menuitem name="P_review in Browser" platform="win"
    key="F12" enabled="dw.getDocumentDOM() &&
    dw.doesWorkflowAllowPublish() &&
    CCWorkspaceManager.getManager(dw.getDocumentDOM()) &&
    CCWorkspaceManager.getManager(dw.getDocumentDOM()).canProcessEvent('browserPreview')"
    command="CCWorkspaceManager.getManager(dw.getDocumentDOM()).processEvent('browserPreview' )"
    id="DWMenu_File_BrowserPreview"/>
    Maybe you can change this to:
    <menuitem name="P_review in Browser" platform="win"
    key="F12" enabled="dw.getDocumentDOM() &&
    CCWorkspaceManager.getManager(dw.getDocumentDOM()) &&
    CCWorkspaceManager.getManager(dw.getDocumentDOM()).canProcessEvent('browserPreview')"
    command="CCWorkspaceManager.getManager(dw.getDocumentDOM()).processEvent('browserPreview' )"
    id="DWMenu_File_BrowserPreview"/>
    I tested this as a writer and I can preview the page in the
    browser pressing F12 or going to File, Preview in browser.

  • Unable to Add .wmv file to KD

    Hi,
    I'm trying to add a .wmv file to KD. But it fails. Is there any setting that i have to do?
    Will plumtree support .wmv types in KD?
    Thanks,
    Bharat

    Your code works fine in both my on-premises and SharePoint Online. I have given the app full control, so I suspect this is a permissions issue. I would check your permissions on your appmanifest. Must be something to do with publishing permissions. Try
    giving full control and work the permissions down.
    Blog | SharePoint Field Notes Dev Tools |
    SPFastDeploy | SPRemoteAPIExplorer

  • Pdf uploads

    By what technique may my client (with administrator or
    publisher permissions) upload .pdf or other .doc files to her
    website? Image upload does not permit non-image files. She will
    link to these files from existing pages.

    Hello Zabeth69,
    While editing your page with InContext Editing:
    1. Select the text or element on the page that you want to
    turn into a link.
    2. Click the Link button on the left side of the Editing
    toolbar. This action activates the Link toolbar.
    3. To link to a document in the site you're working on (such
    as a word document or a PDF file), choose Document From My Website
    from the Link To pop-up menu.
    4. In the Which Documents dialog box, click the Upload New
    File button in the lower left corner.
    5. Navigate to the file on your local hard disk you want to
    upload, select it, then click Open (Win) or Select (Mac).
    6. After the file has been successfully uploaded, click OK in
    the File Upload dialog box.
    7. Select the file you just uploaded in the Which Documents
    dialog box, and click Insert.
    InContext Editing supports links to documents with the
    following file extensions: doc, docx, xls, xlsx, ppt, pptx, pps,
    ppsx, pdf, txt, rtf, odt, ods, odp, jpg, jpe, jpeg, gif, png, bmp,
    and tif. Please note, there is a 2MB limit on file uploads with
    InContext Editing.
    Please let me know if you need further assistance.
    Best regards,
    Corey

  • Permissions for creating a folder in Bi Publisher

    Hi All,
    I am unable to create a folder in Bi Publisher Shared Folder.
    Regards,
    Vishwanath

    hi vishwam,
    do u have permissions that for u r login user? please check the permissions
    Bi Publisher-->Admin>Roles and Permissions>Add Folders: ( Login User name)
    Thanks,
    Saichand.v

  • Permissions greyed out in BI Publisher 11g for every object

    Hi ,
    My BI Publisher's security model is of Oracle Fusion Middleware ie it is using the same weblogic user as an Admin.
    However Permission is always greyed out in BI Publisher. Is there something wrong at my side or is this the intended behaviour when the security is coupled with Fusion Middleware.
    Thanks
    Ashish

    Ashish,
    This is intended behaviour, nothing wrong in that. As in OBIEE11g the BIP is integrated with analytics presentation catalog you can manage the permissions from the analytics URL itself. If you create a new folder or report in BIP or in Presentation catalog it will get reflected in both and you can manage the permissions from analytics url for the presentation catalog folder.
    Hope it helps.
    Thanks,
    RM

  • How to publish a SWF with local access permissions

    Hi all,
    We have been purchased a training course made with Flash. When we received the course (a SWF file with external files inside a "data" directory, images, videos, etc), we realized that it was necessary to explicity give permissions to Flash Player to access the content in the CD drive. We think that is not a good idea to distribute a CD where the user have to do "extrange things" to make it work.
    So, we talked with the developer and he sent us an .EXE file with the course, that obiously works fine (al the content in the CD is readed without user interaction), but it only works in Windows machines.
    The question is: is it possible to publish an SWF that can access to the CD content without user interaction? We are almost sure that the answer is "yes" because we have a lot of "magazines" cds with SWF files that load the contents from CD (text and images) and they work perfectly "as is".
    Thank you very much!

    Look into creating your own projector file from the .fla:
    http://www.ehow.com/how_5942407_create-projector-files-adobe-flash.html
    or Google "Flash projector files"
    You can create both the .exe version for Windows as well as a Mac version
    But to burn both versions (so will work on either) on a CD at the same time, you'll need to create a Hybrid CD:
    http://76design.ca/shiftcontrol/2005/10/19/how-to-make-a-pcmac-hybrid-cd-if-you-dont-know- jack-about-macs/
    or Google "create hybrid CD"
    Once you get the cd burned, then you can use an autorun.inf file to get the auto start... works well with Windows... Mac... not so much. But perhaps this will get you started:
    http://www.phdcc.com/shellrun/autorun.htm
    Best wishes,
    Adninjastrator

  • What are the minimum permissions to publish a report to users' inbox?

    We want to be able to publish or send WebI documents to users' InfoView Inboxes.  So far the only way I found I can do this is:
    >> The document publisher/scheduler ( sender ) needs to have View permissions of each user's Inbox.  This causes a problem.  Either the admin gives sender view permissions to all Inboxes in CMC or the admin has to give view permissions on each individual user's Inbox...this option can be painful if there are many users.
    So, as I currently see it, either sender can see all users' Inboxes in the CMC or the admin has to go into each user's Inbox and give sender view permissions.
    Is there an easier/simpler way around this?

    MHO Only....  this subject on sending / publishing rights is horrible, sending to a users inbox ishould be a default and we should only have to either allow or deny users or groups,    not have go through steps 1-7 for part1 and 1-9 for part 2.!
    that being said,
    For XI31,
    Getting the users to see the user list when sending documents to the inbox.
    Resolution:
    1. Login to CMC using administrator account.
    2. Navigate to Users and Groups page in CMC.
    3. Select the user list and click on the Manage .
    4. From the Drop down menu for Manage tab , select Top Level Security -> All Users -> Everyone -> Assign Security -> Access levels -> Assign View access level -> Apply -> Ok.
    5. Now Users can view the users list when sending the reports to other users# inbox.
    Second issue was that the users could send documents, but they would never show up in their recipient's inbox:
    At the Inbox "View Objects" should be set under "System ->Inbox", not "General->General"
    Resolution
    1. In the Central Management Console (CMC), go to "Inboxes"
    2. Go to "Manage -> Top Level Security -> All Inboxes"
    3. Select "Everyone" and choose "Assign Security"
    4. Click the "Advanced" tab then "Add\Remove Rights"
    5. On the left hand side, "General" is selected. The only thing that should be specified here is:
    Grant: "Add objects to folder"
    Deny: "Delete Objects" (default)
    Deny: "Edit Objects" (default)
    6. Make sure you set "View Objects" to "Not specified" if selected at this level.
    7. On the Left pane, Expand "System" and choose "Inbox"
    8. In the right side, set the following:
    Check "Override General Global"
    Grant: "View Objects"
    Deselect "Apply to object"
    9. Click "OK", then "OK" again.
    there is also also a KB 1363269:
    Hope this helps!

  • When I try to work with the publish window of lightroom cc, I am told that I do not have permissions to perform operations (remove picture, etc.)

    When I try to work with thhe publish window of lightroom cc, I am told that I do not have permissions to perform operations (remove picture, etc.). I also notice that when the particular picture is selected, another show in its place, and I cannot change the collection.

    To diagnose problems with Thunderbird, try the following:
    *Restart the operating system in '''[http://en.wikipedia.org/wiki/Safe_mode safe mode with Networking]'''. This loads only the very basics needed to start your computer while enabling an Internet connection. Click on your operating system for instructions on how to start in safe mode: [http://windows.microsoft.com/en-us/windows-8/windows-startup-settings-including-safe-mode Windows 8], [http://windows.microsoft.com/en-us/windows/start-computer-safe-mode#start-computer-safe-mode=windows-7 Windows 7], [http://windows.microsoft.com/en-us/windows/start-computer-safe-mode#start-computer-safe-mode=windows-vista Windows Vista], [http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx?mfr=true" Windows XP], [http://support.apple.com/kb/ht1564 OSX]
    ; If safe mode for the operating system fixes the issue, there's other software in your computer that's causing problems. Possibilities include but not limited to: AV scanning, virus/malware, background downloads such as program updates.

  • Pages published with permissions 600

    Sun OS machine using Apache and contribute version CS3 when
    ever the users publish their changes or create new pages the
    changes are uploaded but the permissions for the file are reset to
    600 (rw- --- ---) meaning that the page cannot be viewed in the
    browser anymore, and more importantly is not visible in contribute,
    the only way I have found of fixing this is to ftp into the site
    and set the permissions to 644, this is not a realistic solution
    when we give contribute out to more users.
    Is there an admin setting that can be changed to change the
    default permission to 644?

    Currently investigating umask settings in .profile file on
    server. This may be the cause as I cannot find any setting in
    contribute and other forums seem to point to this.

Maybe you are looking for

  • Works on emulators but not on mobile devices

    Hello, My project works on emulators but not on mobile devices (no image and on Samsung it says "unsupported file"). Please help, I don't know what to do. My configurations: MIDP 2.1, CLDC 1.1. Thanks in advance. Edited by: Vitali.pom on Oct 27, 2011

  • Dynamic list of pages / site map of pages

    Hi, I've figured out how to add a Page Query to the Navigation. Now I want to have something similar on a page for a kind of site map. How do I display a dynamic list of pages on a page? cheers, Matthias Edited by: mprove on Jan 5, 2012 12:15 PM

  • Is this compatible with any modem?

    My router is going out and I was going to replace it with the Airport Express but was wondering if it works with all modems.  I have DSL.

  • Getting error in Delivery Creation

    Hi SAP Guru 1. When I save sales order i am getting error that financial documents: NO financial document assigned. To retifi this error, In header Billing - create financial doc no in risk management and save. Afer save the sales order still i am ge

  • Re:Query CFL

    Hi All, How to set multiple conditions in a query CFL. This is my Code : oRs.DoQuery("Select * from [@PSSIT_CMSAMHDR] where U_CardCode = '" & oVenCodeTxt.Value & "'")             oCFL = oForm.ChooseFromLists.Item("SRLst")             oCFL.SetConditio