Inheriting Sitecore Roles
up vote
1
down vote
favorite
I have a role "Editor" which is having certain permissions and don't have read access to Sitecore/Social item.
Now i need to create a new role "Approver" which is having same access as Editor but with additional Read and Write access to Sitecore/Social Item.
I tried by making Approver as member of Editor and then gave additional access to Approver. But this is not working.

security role-management
add a comment |
up vote
1
down vote
favorite
I have a role "Editor" which is having certain permissions and don't have read access to Sitecore/Social item.
Now i need to create a new role "Approver" which is having same access as Editor but with additional Read and Write access to Sitecore/Social Item.
I tried by making Approver as member of Editor and then gave additional access to Approver. But this is not working.

security role-management
add a comment |
up vote
1
down vote
favorite
up vote
1
down vote
favorite
I have a role "Editor" which is having certain permissions and don't have read access to Sitecore/Social item.
Now i need to create a new role "Approver" which is having same access as Editor but with additional Read and Write access to Sitecore/Social Item.
I tried by making Approver as member of Editor and then gave additional access to Approver. But this is not working.

security role-management
I have a role "Editor" which is having certain permissions and don't have read access to Sitecore/Social item.
Now i need to create a new role "Approver" which is having same access as Editor but with additional Read and Write access to Sitecore/Social Item.
I tried by making Approver as member of Editor and then gave additional access to Approver. But this is not working.

security role-management
security role-management
asked Nov 20 at 6:20
Dheeraj p
17710
17710
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
up vote
5
down vote
accepted
Deny access right cannot be overwritten by any allow rule.
What you need to do is to:
- remove that
Denyread access forEditorrole - make your
Approverrole a member ofEditorrole - disable inheritance of access rights for that item for your
Editorrole - and for your
Approverrole you need to assignReadandWriteback
More information can be found in https://doc.sitecore.net/sitecore_experience_platform/setting_up_and_maintaining/security_and_administration/access_rights/the_inheritance_access_right
add a comment |
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
up vote
5
down vote
accepted
Deny access right cannot be overwritten by any allow rule.
What you need to do is to:
- remove that
Denyread access forEditorrole - make your
Approverrole a member ofEditorrole - disable inheritance of access rights for that item for your
Editorrole - and for your
Approverrole you need to assignReadandWriteback
More information can be found in https://doc.sitecore.net/sitecore_experience_platform/setting_up_and_maintaining/security_and_administration/access_rights/the_inheritance_access_right
add a comment |
up vote
5
down vote
accepted
Deny access right cannot be overwritten by any allow rule.
What you need to do is to:
- remove that
Denyread access forEditorrole - make your
Approverrole a member ofEditorrole - disable inheritance of access rights for that item for your
Editorrole - and for your
Approverrole you need to assignReadandWriteback
More information can be found in https://doc.sitecore.net/sitecore_experience_platform/setting_up_and_maintaining/security_and_administration/access_rights/the_inheritance_access_right
add a comment |
up vote
5
down vote
accepted
up vote
5
down vote
accepted
Deny access right cannot be overwritten by any allow rule.
What you need to do is to:
- remove that
Denyread access forEditorrole - make your
Approverrole a member ofEditorrole - disable inheritance of access rights for that item for your
Editorrole - and for your
Approverrole you need to assignReadandWriteback
More information can be found in https://doc.sitecore.net/sitecore_experience_platform/setting_up_and_maintaining/security_and_administration/access_rights/the_inheritance_access_right
Deny access right cannot be overwritten by any allow rule.
What you need to do is to:
- remove that
Denyread access forEditorrole - make your
Approverrole a member ofEditorrole - disable inheritance of access rights for that item for your
Editorrole - and for your
Approverrole you need to assignReadandWriteback
More information can be found in https://doc.sitecore.net/sitecore_experience_platform/setting_up_and_maintaining/security_and_administration/access_rights/the_inheritance_access_right
edited Nov 20 at 6:53
answered Nov 20 at 6:37
Marek Musielak
9,25011034
9,25011034
add a comment |
add a comment |
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsitecore.stackexchange.com%2fquestions%2f15030%2finheriting-sitecore-roles%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown