Friday, October 3, 2008

CMS 6: Allow on User Overrides Deny on Role

OK, I suppose it could be fair to accuse me of being, perhaps, a tad bit on the quiet side with respect to my blog recently. Oh, all right, for the last year or so.

My apologizes.

I can give loads of excuses, but really, I just haven't had much to say. There are many excellent Sitecore bloggers who've done a much better job than I could at bringing forth interesting information.

Perhaps I could have mentioned that we have passed the 2000 certified developers mark (which happened a little while ago), but given that my last post mentioned that we had passed the 1000 mark, I was afraid that doing so would make my blog seem repetitive.

In any case, I do have a little tidbit today that I thought might interest some of you.

In Sitecore CMS 5, our security model had a simple rule:

Deny always overrides Allow

It was one of those simple, clean rules that's easy to explain, but that generally caught people off guard during training, when we asked new developers, "If Audrey is explicitly ALLOWED Write access to item X, but is also a member of the Author role, which is explicitly DENIED Write access to item X, do you think Audrey will be able to change the item or not?"

When you know the rule, the answer is simple, deny always overrides allow, therefore Audrey does not have Write access.

Alas, many people, perhaps even a majority of people, found this confusing. They thought that explicitly allowing Audrey Write access should override the denied access applied to a role.

Well, in Sitecore CMS 6, we've listened to these people and changed the rule. Sadly, this makes the rule a little more complex, but we think people will like it anyway. The rule is now:

Allow set on a User overrides Deny set on a Role, but Deny set on one Role will override Allow set on another Role.

It's still pretty simple, if you ask me.



Anonymous said...

[url=][img][/img][img][/img][img][/img][/url] Играть игровые автоматы бесплатно без регистрации и смс онлайн Samp 4 дракона казино эмуляторы игровых автоматы скачать бесплатно fairy land3 [url=]Играть онлайн в игровые автоматы вулкан[/url] Голикова и казино Интернет рулетка рулетка для андроид [url=]Пивная рулетка[/url] Какой налог с выигрыша в казино Tdu 2 казино без покупки dlc Казино рояль смотреть [url=]Казино онлайн бесплатно играть на виртуальные деньги[/url] цена эмулятор игрового автомата colfire 2 Онлайн казино без регистрации i pad2 В омске продажа лазерной рулетки [url=]Кавасаки вулкан 1500[/url]
[url=] Играть бесплатно без регистрации в игровые автоматы онлайн[/url] [url=]Мотель вулкан дер афанасово[/url] Пичинча вулкан


[url=http:/]Как загрузить шаблоны казино в игре казино империя в компании[/url][url=http:/]Crazy fruits игровой автомат играть бесплатно онлайн[/url]
[url=http:/]Казино в германии[/url]

Anonymous said...

Mail order golf equipment, golf club sets, golf club set popular, [url=]タイトリスト712 MBアイアン[/url]deep-discount Golf Club "
The evil shop mail order site of the latest golf equipment![url=]ミズノMP-68[/url]

amala amala said...

Thank you for taking the time to provide us with your valuable information. We strive to provide our candidates with excellent care and we take your comments to heart.As always, we appreciate your confidence and trust in us
Jobs in Bangalore
Jobs in Chennai

oracle fusion hcm online coaching institutes said...

This list is in fact very useful. in assessment to top notch net internet web sites i have visited, you furthermore would possibly likely blanket the little through the manual to test in in this internet web sites.
This list is without a doubt very useful.
oracle fusion training in Hyderabad