Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

821

April 13th, 2009 09:00

storagescope user premission

so I created a new user that's intended for everyone in my group to view the sts reports. The new user is not in any group, all I did was add it to the authorization rule type storagescope user, which I thought would only have permissions to view the reports. When I logged into storagescope using this account, I was all to delete/modify reports. any ideas?

Thanks

4 Operator

 • 

2.1K Posts

April 13th, 2009 10:00

The default permissions of the StorageScope Users authorization rule appears to be "StorageScope All". If you modify the permissions of this group to remove "Storagescope All" and add "StorageScope User" it should do what you want.

Or leave this group alone and create a new one that you assign only the "StorageScope User" permission to and move the account to that group.

Your choice.

BTW - I have no idea why the default permissions assigned to an authorization rule called "StorageScope Users" wouldn't match the name, but it seems like someone missed something with the defaults on this one.

1 Rookie

 • 

82 Posts

April 13th, 2009 10:00

thanks for the reply,
I'm still a little confused, when I created my sts user account I right-clicked it and
created a new authorization rule, I named it storagescope user and under choose objects I selected type->storagescope reports->storagescope user
so in my selected action it says type storagescope reports, name-all, permission- storagescope user. so I'm not sure where I can remove Storagescope All

4 Operator

 • 

2.1K Posts

April 13th, 2009 11:00

Hmmm... I guess you already went about this by manually creating a new authorization rule. And the rule sounds like it is configured correctly.

According to the documentation what you have configured should work the way you intended. The only other place I would check would be in the "Any User Rule" authorization rule. This applies to all users whether a role is applied to them or not. By default this will already give a user StorageScope User permissions (which I didn't know about until I went digging today). If someone changed the permissions assigned by default in this rule it could be overriding the authorization rule you created.

But you might want to try resetting the "Any User Rule" to the default permissions and removing the "StorageScope User" rule you created yourself. According to the docs this will achieve what you want without your manually created rule/group.

1 Rookie

 • 

82 Posts

April 13th, 2009 12:00

yup you're right Allen, I found that the any user rule already had the StorageScope User permission, so I removed the StorageScope User rule I created and was able to successfully log into sts with that account. But I'm able still able to fully modify/delete reports? I'm really stumped...
No Events found!

Top