Repository navigation
Replies: 1 comment
|
Sync-in currently treats spaces as security boundaries, while folders are used to organize content within those boundaries. Adding per-user or per-group deny rules on arbitrary subfolders would introduce a second authorization model overlapping with spaces. It would also require permission inheritance and conflict resolution across file browsing, direct API access, search, recent files, WebDAV, synchronization, moves, copies, and caches. Could you clarify what cannot be achieved with separate spaces or shares, apart from preserving the existing TEST/... folder hierarchy? If the main requirement is visual grouping, grouping multiple spaces under a common category may be a more appropriate feature than nested folder ACLs. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
What type of request is this?
Enhancement of an existing feature
Clear and concise description of the feature you are proposing
Problem
When a user or group is granted access to a parent folder, that access currently applies to every subfolder.
For example, a shared folder named
TESTcontains five subfolders:AllowedFinanceHRLegalManagementA member should be able to access
TESTandTEST/Allowed, while the other four subfolders should remain inaccessible.Currently, this cannot be configured without reorganizing the folder structure or creating separate shares.
Proposed feature
Add support for inherited subfolder permissions with path-scoped overrides.
For each user or group, an administrator or space manager should be able to configure a folder with one of the following states:
An explicit deny rule should override access inherited from a parent folder.
Example
TEST: AllowedAllowed: Inherited / AllowedFinance: DeniedHR: DeniedLegal: DeniedManagement: DeniedThe member should still be able to browse
TEST, but should only see and access the authorized subfolder.Expected behavior
A denied folder and its contents should:
Permission enforcement must happen server-side and not only in the web interface.
Inheritance and precedence
Suggested behavior:
The behavior should also be defined when a user receives conflicting permissions through direct membership and group membership.
User interface suggestion
In the sharing or member-permission dialog, add a section named Subfolder permission exceptions.
This section could display the folder tree and allow an administrator to select:
Additional considerations
The implementation should account for:
Using a stable folder identifier instead of only a mutable path could help preserve rules when folders are renamed or moved.
Validations
All reactions