About objects permissions

Build 1501 on 14/Nov/2017  This topic last edited on: 21/Mar/2016, at 18:34

Object permissions – i.e. what a user can do on a specific object, e.g. an article, a page, an edition etc. – are shown in a matrix of permissions (Read, Write, Place, Send, RefR(ead), RefW(rite), Delete, Ref Delete) and access classes (Normal, Protected, Special, Content).

See also System permissions that specify what users can do system-wide.

An example of the object permissions matrix

object_permissions2

Every item can be granted (green icon with +), denied (red icon with -) or undefined (gray icon).

object_permissions3

Permissions groups

The permissions are split in the following groups:

Access to objects as a whole (‘Delete’ and ‘RefDelete’)

Access to object attributes (ReadXXXX, WriteXXXX);

Access to referencing objects attributes (RefReadXXX, RefWriteXXX);

Permission on referenced objects (PlaceInXXXX and SendFromXXXX).

Note that the fact that ‘read’ and ‘write’ permissions for each access class allow to grant or deny access to different attributes of an object – e.g. allow a certain user to modify the meta-data (caption, source etc.) of a image, but not the image itself.

hmtoggle_plus1Explanation of object permissions
hmtoggle_plus1More on the use of the PlaceInXXXX/SendFromXXXX group of permissions
hmtoggle_plus1How the objects access permissions are computed?
Click to toggle expandAbout explicit denial

See also

Granting objects permissions (links)