Why is Admin Approval Needed to Share Folders Between 2 Standard Accounts?

Dear OS X users,
Please give this question due consideration because it's a fundamental question about the underpinnings of OS X which I've asked many people but no one seems to have a good answer. I have 3 accounts on my Mac. They are as follows:
- pete (standard account)
- wanda (standard account)
- mac admin (admin account)
It's logical that if Mac Admin creates a file/folder, he needs to set the permissions for it so that others can read/write to it. But imagine Pete and Wanda collaborate together on a project. Imagine Mac Admin creates a folder called /Swap with read-write permissions for all. Pete then creates a sub-folder without setting any particular permissions and then logs out. Then imagine Wanda logs in and wants to access the Pete's newly created folder. When doing so, an authentication prompt appears asking Wanda to enter an administrator's login details.
*Why doesn't it ask for Pete's authentication details? Why does it need an administrator's login details? Mac Admin has nothing to do with it.*
Now if you extrapolate this scenario to include a business enterprise where you may have lots of groups/teams with members all collaborating. It's ridiculous to involve an administrator for every trivial request of this kind e.g. a file permission change.
Please don't simply recommend sharing via USB or upgrading to Leopard. (I hated Leopard and 'upgraded' back to Tiger). I'm looking more for explanations than workarounds.
Thank you in advance.
MrLinguaFranca.

The short answer, of course, is that admin privileges are not needed (so long as you are the owner).
The long answer is that administrator privileges are required to change the owner of a file or folder, or to change the group of a file or folder (if you are not the owner or aren't a member of that group). To change the permissions on a file, one must be an administrator or the owner of the file.
In your scenario, Pete creates a folder, but forgets to make the folder read-write for others. Wanda is prompted for the administrator password because she doesn't have permission to access the folder until Pete says so. The default behavior on the Mac is to secure the folder.
The reason it doesn't ask for Pete's authentication details is the same as if it were Windows, Linux, Solaris, etc. Wanda is asking permission to override Pete's settings. If Pete wanted Wanda to access the file, he would have done so. So, logically, Wanda requires administrative privilege to supersede Pete's wishes. Wanda should NEVER have to be party to Pete's credentials because doing so compromises Pete's account entirely (nor the administrator's credentials -- if the folder has permissions that deny her access, she needs someone to grant the access, not someone else's credentials so that she can grant access to herself by assuming the role of the other party).
This is different from the case when you are accessing a network share. In that scenario, the connection to the remote machine does not know who's accessing the share and must require authentication to determine who it is dealing with. The correct way to implement network shares would be to have Wanda always authenticate as her self and never use the credentials of another. Once she's logged in as herself, the remote server can determine what she's permitted to access on the basis of her identity and the permissions on the files.
This is how file security works (not just OS X).

Similar Messages

  • How can I share folders between 2 User Accounts?

    I have 2 accounts. One for work and one for home. The home account is the main one as I keep my work one (DJ use) very limited concerning activities running. I still need to access some folders that are on the home account (pics, music..etc.) but I see a little red negative sign (protected). I know its a simple little thing im over looking but cannot think of it.
    Also, when I use fast user switching is the other account still running and using resources?
    Thanks!

    Log in from the home account, select the folders you're trying to access in the Finder, and change all three of the permission settings to Read & Write; if both accounts are admin accounts, you can optionally change the first two to Read & Write and the group to admin. A new group can be created in the NetInfo Manager in the /Applications/Utilities/ folder if you want another set of accounts to access the folder; to do this, duplicate an existing group, pick an unique name for the new group, and change its gid to 400 or another unique number in the 400-499 range.
    The processes and applications opened under another user account continue to run when Fast User Switching is used to switch out of it.
    (21795)

  • Why do two iPods need to share the same library? Is there any way I can change it?

    I owe one iPod and brought another today, and I just set up the other one. They're both the same model - iPod touch 8GB - and I've set the second one up. I've had the first one for some time, about an year, and I only bought another for a family member. I was wondering why do we need to share the same library and how can we change it. Help would be welcomed since we really like different kind of genres and we disagree on them, so we really really want to change this. I can't even say how much we need to change the setting. Thank you!

    Sherlocked, There are a few ways you can solve that problem.
    If you do want to share the same library, use the capabililty to "Sync Selected Playlists," so that each iPod will only get the music that its owner wants.
    Alternatively, you can set up two separate libraries.  This is easiest if you use two different Windows user IDs on the computer.  Then each iPod owner can sync to his own library.

  • Can i share music between two iTunes accounts on the same computer

    I know you can share the library with 'home share', but can you copy the titles to the account sothey can be loaded on to an ipod / iphone?
    Or have i got to load any required music on to the computer a second time?

    This should help:
    iTunes: How to share music between different accounts on a single computer
    Note that when it says "publicly accessible location", it needs to be a place where everyone has read and write access. The most common such place is the Shared folder in the Users folder, but you can place the music elsewhere if you change the access permissions manually (don't start tinkering with permissions unless you're confident you know what you're doing and can reverse things if they get messed up). 
    Regards.

  • Share folders between accounts

    I'd like someone with an account on my computer to be able to share my itunes music folders ( or some of them, if possible). How would I give a new account access to folders created on my admin account?

    Hi William,
    The easiest way is to go to iTunes>Preferences>Sharing tab, there you can share your whole Library or just certain Playlists.

  • I need to share files between to macs and I cannot seem to find an answer

    Hi All
    My biggest issue is that I have two macs and want to share files should as my Rapidweaver websites, my dosh (accounts package) master files, etc
    I had tried Mobileme for a time and could seem to get it to do what I wanted.
    I would like to be able to have my imac as the master, but be able to work from my macbook, eg if I want to work outside of the office in the house be able to just use the most up to date file of my website in rapid weaver (as I have 3 licenses)
    Can this be done?
    I had tried th network sharing to access the desktop, but my partner complains that his web viewing slows down too much

    Of course it can be done but you need to have a few things in place.
    * a fixed address so you can reach your computer at home (or a way to dynamically adjust for changes)
    * your computer needs to have a public address, or you need to set up your home network so it maps the ports you need to the right inside address.
    * You need to enable file sharing on the target Mac, share the appropriate folders, and set up an account with access.
    * You won't have proper file locking, so sharing files that may be open on another machine can cause corruption. If you're sharing files from your website while the website is active, that could cause trouble.

  • Why has TB started creating INBOX/Trash folders on all my accounts and how can I prevent it?

    For some reason, Thunderbird has started creating the folder INBOX with a subfolder Trash in it on all my IMAP email accounts whenever it starts. INBOX is grayed out, Trash is not. The INBOX folders are subfolders to the Inbox folder of the account and there is already a Trash folder as a subfolder to the Inbox account. How can I stop this from happening?
    This is on Windows machines, latest version of TB.

    I have the exact same problem. It seems to have started up recently. Looking at your post date of 3/1/2015, mine might have started a little bit later, but nonetheless around the same timeframe. I have tried deleting this 'shadow' folder, and it goes in the trash, and I empty the trash, and I think everything is great. Until the next time I start up TB, and it shows up as a Subdirectory of "Inbox". I use IMAP, and I check on the server side and see it there. And when I delete it from TB. It disappears from the server side. I empty the trash. I keep outlook closed for many hours, check the server side and it's "clean", as soon as I start up Thunderbird, within seconds, the 'shadow' (Inbox->"Inbox->Trash") pair of directories show up. And then it shows up on the server side as well. I have quite a number of email accounts/profiles, and it seems this happens to all but 'one' of them. Not sure what's magical about this one other profile. Otherwise, the other 10+ accounts ALL have this problem now. Some were created years and years ago, and some were created within the last year. I'm on a Mac.
    At first (and still suspect) I thought it might have had to do with the 'Server Settings-> When I delete a message: -> Move it to this folder" setting, but I checked and all the old accounts and the new account has the same setting. It sets it to "Move it to this folder: "Trash on [email protected]" of the corresponding account.
    And on the 'new' account, it is set to "Choose Folder". I've left it alone. For fear that if I 'choose' the folder to be like I've set up all the others, that this will start creating the 'Shadow' "INBOX->Trash" folder under the 'Inbox' of all my accounts.
    I wish there was a way for me to 'reset' the selection on one of my other accounts to "Choose Folder" and see if it helps 'fix' the problem. Nonetheless, it seems to be a weird bug.
    Screen shots attached:
    1) shot of problem situation,
    2 what it should look like (aka when I delete the Shadow INBOX->Trash before it reappears),
    3) settings on problem accounts/profiles,
    4) setting on newly created no-problem account/profile)
    Hopefully, this provides a bit more color to my version of what seems to be the same problem.
    Thanks.

  • How do I share folders between 2 MacBook Pro?

    I'm trying to connect two MacBook Pro by creating a share folder. Don't know how. I try airdrop but this is only to send files from one to another

    Do you want to share the files locally (on the same network) or in the cloud?
    Your best option for cloud sharing is probablly a third party app like Google Drive, Dropbox, Box or Copy. These all have an OSX app that will keep a deisgnated folder/s synced across devices (if you install and set up the app on each device).

  • Can u/how do u  share playlists between different apple accounts on the same computer?

    My other half has own iphone    how do I share i tunes with 2 different phones and 2 itunes ids

    First thing you need to do is disable auto syncing in iTunes. This is from Edit>Preferences>Devices>Prevent iPods, etc.
    Unfortunately, the only thing you can do is set up separate log in accounts for the laptop. This will allow you to have iTunes in each log in and they can have different content. iTunes cannot have separate content with the same log in and different Apple ID, but you can manage two phones with the same iTunes account. See if any of the information in this support document will help you http://support.apple.com/kb/ht1495 but the best solution is separate computer log in.

  • How do you share music between two user accounts for multimedia purposes???

    I am working with iDVD and am running into a slight snafu. My girlfriend has most of the pictures in her iPhoto account, while I have most of the music in my iTunes account. (she works on maintaining our over flowing pictures, while I handle paying for all our music... works out nice. <wink>)
    Anyways, we were both working on a new photo DVD for family using iDVD and were frustrated that we could not pull in music from my iTunes account to use with her pictures in iDVD. I am uncertain if we are doing anything wrong and just do not know how to do it, or if it is not possible. We also have a few pictures on my iPhoto account we wanted to add to the DVD, but cannot access those either from her account while in iDVD.
    Is it possible to share this data back and forth without making two copies of all of it?
    Thanks for all your help!!
    - jonathan

    Follow the steps after the section that says "If you have an earlier version of Mac OS X", Quintalis. It explains how to do it without the Fast User Switching/iTunes Sharing which is indeed limited only to playback.
    Note that when it says "publicly accessible location", it needs to be a place where everyone has read and write access. The most common such place is the Shared folder in the Users folder.

  • How do you share music between two iTunes accounts on one computer?

    My wife and I share a Windows 7 laptop computer.  We have separate Windows logins and separate iTunes accounts.  When we had separate computers we were able to use Home Sharing to share our music but this doesn't work when you have two accounts on the same computer.
    Is there a way to share our music libraries without wiping out what is already stored in our individual iTunes music libraries?

    Click here and follow the instructions.
    (109972)

  • How do I share music between two iTunes accounts?

    My friend recently purchased an iPod touch, and I have an iPad two. Instead of her spending so much money on music we thought I could share some of my music with her.... But how?! She does not have a computer but she does have Internet connection. I have both
    We would be grateful if someone could give a simple answer to this question.
    Thanks from lovingapple
    XxX

    You don't.

  • How do I share applications between different user accounts?

    Word is stored on my user account but when my girlfriend logs in she cannot get to Word or all Itunes music is not availiable....HELP

    Move the Word (or Office) folder from your user/Applications folder to the Macintosh HD/Applications folder. There it can be accessed by all users.
    iTunes Music is slightly different as that's user-oriented, but you should be able to allow other accounts to use it by opening iTunes and selecting iTunes/Preferences in the menu bar. Select the Sharing option and choose what to share;
    If the other account holder then checks the 'look for shared libraries' option, she should be able to access whatever music you choose to share.

  • Share calendars between 2 iCloud accounts

    I currently have multiple macs and IOS devices my wife and I have separate iCloud accounts. What would be the best way to share share our calendars?

    Log into iCloud.com with a computer browser, go to the calendar page and click the calendar button. There you can designate any existing calendar as "shareable".

  • Sharing Folders Between Accounts - Advice Needed

    Looking for advice. I am running 10.5.2 on a MacPro and have several people on my network logging in to a Standard User Account.
    These users need to read and write files in the Documents folder but I do not want them to have the ability to delete or move to the trash.
    If I create the Files and Folders in the Admin Account and then share them to the Standard Account, would this accomplish what I need to do?
    I know that in any User Account you can not prohibit people from deleting (both in Admin and Standard).
    Any ideas here or would we need 10.5 Server to prohibit deletion?
    Thanks

    You can do this by adding an ACE to your Documents folder as follows.
    run this in terminal:
    *chmod +a "username deny delete_child" ~/Documents*
    This command will prohibit user username from deleteing anything in your Documents folder. You can use group name instead of the user name.
    For example
    *chmod +a "admin deny delete_child" ~/Documents*
    or simply say
    *chmod +a "everyone deny delete_child" ~/Documents*
    which will require an admin password to delete anything from ~/Documents for everyone (including yourself).
    You can make this command recursive by adding -R option:
    *chmod +a -R "username deny delete_child" ~/Documents*
    However, if afterwards someone creates a new directory in ~/Documents, files from that directory will be deletable unless you run the command again.
    There might be an ACE which will protect all future subdirectories but I can't figure it out.

Maybe you are looking for