Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The These are default permissions set up in Magnolia. You can manage them in the Security app demonstrate how to assign roles, ACLs and web access . The default permissions are just an example how to grant permissions in a typical scenario. These permissions are complemented by configured app access

The Security app allows you to view a comprehensive list of permissions assigned to any user or group at any point in time. If you need to revert to the default permissions for any reason, you can access them online in the demo site in the Tools tab of the Security app.

The tables below show default permissions, role and group assignments, and configured access permissions. 

website. You should adapt the permissions to match your own organization. App access is configured separately in the app launcher configuration.


Table of Contents

Roles

anonymous (role, author instance)

...

Applies toNamePath
AppActivation/modules/activation/apps/activation/permissions/roles

 Configuration/modules/ui-admincentral/apps/configuration/permissions/roles

 Security/modules/security-app/apps/security/permissions/roles

 Security/modules/security-app/dialogs/role/form/tabs/role/fields/jcrName 

Mail tools/modules/mail/apps/mail/permissions/roles 

Dev tools/modules/tools/apps/tools/permissions/roles 

Backup/modules/backup/apps/backup/permissions/roles
App launcherDev group/modules/ui-admincentral/config/appLauncherLayout/groups/dev/permissions/roles 

Tools group/modules/ui-admincentral/config/appLauncherLayout/groups/tools/permissions/roles
PulseAbort action
/modules/workflow/messageViews/publish/actions/abort/availability/access/roles
 

Archive action/modules/workflow/messageViews/publish/actions/archive/availability/access/roles

...

Applies toAppNamePath
AppAssets 
/modules/dam-app/apps/assets/permissions/roles
ActionAssetsActivate/modules/dam-app/apps/assets/subApps/browser/actions/activate/availability/access/roles
ActionPagesActivate/modules/pages/apps/pages/subApps/browser/actions/activate/availability/access/roles

...

Applies toAppNamePath
AppAssets 
/modules/dam-app/apps/assets/permissions/roles
ActionAssetsActivate/modules/dam-app/apps/assets/subApps/browser/actions/activate/availability/access/roles
ActionPagesActivate/modules/pages/apps/pages/subApps/browser/actions/activate/availability/access/roles

...

Base role allowing users to use the workflow workspace (EE).

Access control lists

WorkspacePermissionScopePath
WorkflowRead/WriteSub nodes/
UserrolesRead onlySelected/workflow-base

contact-base

Access control lists

WorkspacePermissionScopePath
ContactRead onlySub nodes/
UserrolesRead onlySelected/contact-base

imaging-base

Access control lists

WorkspacePermissionScopePath
ImagingRead onlySub nodes/
UserrolesRead onlySelected/imaging-base

resources-base

Access control lists

WorkspacePermissionScopePath
Config

Read only

Selected and sub nodes

/modules/resources

ResourcesRead/WriteSub nodes/

...

UserrolesRead onlySelected/resources-base
Multiexcerpt
MultiExcerptNamerest-role-permissions

rest-admin

Web access

Permission

Path

Get & Post

/.rest/*

Configured access


Applies to

Name

Path

Commands

Delete

/modules/rest-services/rest-endpoints/commands/enabledCommands/markAsDeleted/access/roles


Activate

/modules/rest-services/rest-endpoints/commands/enabledCommands/activate/access/roles

rest-editor

Web access

Permission

Path

Deny

/.rest*

Get/.rest/delivery/*

Deny

/.rest/commands*

Deny

/.rest/nodes*

Get & Post

/.rest/nodes/v1/website*

Deny

/.rest/properties*

Get & Post

/.rest/properties/v1/website*

Get & Post

/.rest/cache/v1*

rest-anonymous

Web access

Permission

Path

Deny

/.rest*

Get

Get & Post

/.rest/delivery/

api-docs*

Configured access

*

rest-backup

Web access

Permission

Path

Get & Post

/.rest/commands/v2/backup/backup

Configured access

Applies to

Name

Path

Command

Backup

Applies toNamePath
CommandsDelete/modules/rest-services/rest-endpoints/commands/enabledCommands/markAsDeleted/access/roles
 Activate

/modules/rest-services/rest-endpoints/commands/enabledCommands/

activate

backup/access/roles

rss-aggregator-base

Access control lists

WorkspacePermissionScopePath
RssRead-onlySub nodes/
UserrolesRead onlySelected/rss-aggregator-base

scripter

Access control lists

WorkspacePermissionScopePath
ScriptsRead/WriteSub nodes/
UserrolesRead onlySelected/scripter

Web access

PermissionPath
Get & Post*

...

security-base

Web access

/.magnolia/pages/jcrUtils*
PermissionPathDeny
Deny/.magnolia/log4j
Deny/.magnolia/pages/configuration*
Deny/.magnolia/pages/logViewer*
Deny/.magnolia/pages/users*
Deny/.magnolia/pages/import*
Deny/.magnolia/pages/export*
Deny/.magnolia/pages/permission*
Deny/.magnolia/pages/developmentUtils*
Deny/.rest*

templater-base

...

WorkspacePermissionScopePath
ConfigRead-onlySelected and sub nodes/modules/inplace-templating
TemplatesRead/WriteSub nodes/
UserrolesRead onlySelected/templater-base

Configured access

Applies toAppPath
AppTemplates/modules/inplace-templating/apps/inplace-templating/permissions/roles

forum_ALL-user

Role that allows posting in all forums.

Access control lists

...

Web access

...

forum_ALL-admin

Role which gives administration permissions on ALL forums

Access control lists

...

Web access

...

Configured access

...

/modules/forum/apps/forum/permissions/roles

...

Groups

Group permissions are the same on author and public instances.

editors

Assigned groupsAssigned roles
(none)editor

workflow-base

publishers

Assigned groupsAssigned roles
(none)publisher

workflow-base

travel-demo-pur

The travel-demo-pur group is used to organize the editors of the sample websites.

Assigned groupsAssigned roles
 (none) categorization-base

contact-base

forum-pagecomments-user

imaging-base

travel-demo-base

travel-demo-pur

forum_ALL-moderator

Role which gives moderation permissions on ALL forums

Access control lists

...

Web access

...

Configured access

...

/modules/forum/apps/forum/permissions/roles

forum-pagecomments-user

Role which gives commenting permissions.

...

Groups

Group permissions are the same on author and public instances.

travel-demo-editors

The travel-demo-editors group is used to organize the editors of the sample websites.

   
Assigned groupsAssigned roles
(none)travel-demo-admincentral

travel-demo-editor

travel-demo-tour-editor

imaging-base 

security-base

 resources-base 

workflow-base

travel-demo-publishers

...

 
Assigned groupsAssigned roles
(none)travel-demo-admincentral 

travel-demo-publisher 

travel-demo-tour-editor

 security-base

workflow-base

travel-demo-tour-editors

...

Assigned groupsAssigned roles
(none)travel-demo-admincentral

 travel-demo-base 

travel-demo-tour-editor 

security-base  workflow-base

editors

Assigned groupsAssigned roles
(none)editor
 

workflow-base

publishers

Assigned groups
Assigned roles
(none)publisher
 workflow-base

Users

eric

User eric is an example editor.

...

Assigned groupsAssigned roles
travel-demo-editors
(none)

peter

User peter is an example publisher.

Assigned groupsAssigned roles
travel-demo-publisher
(none)

tina

User tina is an example tour editor.

...

   
Assigned groupsAssigned roles
(none)anonymous

categorization-base

 contact-base

forum-pagecomments-user

imaging-base

 rest-anonymous

travel-demo-base

superuser (system user)

...

Assigned groupsAssigned roles
publishers (EE)superuser 

rest -admin

forum_ALL_admin