Edit permissions for a specific role

Edit permissions for a specific role

avatar

Hello,

I have created several security groups and roles to better organize access to credentials on our team. One of those security groups "locks" access to a certain folder of credentials to avoid non authorized staff to login on certain hosts.

I wanted to give permissions to edit the credentials to the manager of that folder and no one else, but when I try to do this using the Permissions menu on Role Management they can't edit anything:



The user type is set as User.

When I login with that user and try to edit the option is greyed out:



Am I missing something here? Can someone help me figure this out?

EDIT: I forgot to mention I also tested going to the specific folder and edit the Permissions to Custom and choose the specific role for it as mentioned on the RDM manual, this also failed.

Thank you in advance

BR
Diogo

(5)

avatar

hello Diogo,

Is the user trying to edit the folder has the basic access to edit in the datasource?

You can find this by editing the user in the General area > User type



Could you confirm that this is not the issue ?

If this is not the case it might be permission that could be inherited from a parent folder.

Best regards,

Alexandre Roy

Edit.jpg

avatar

Hello Alexandre,

I set the user type as User so on that regard it should have those rights mentioned from what I read on the RDM documentation. Nonetheless I tested changing to restricted user and give the edit right and it's still not working..

I created a security group for this specific folder, an inherited permission could be blocking the edit feature on this folder? Even when it was a specific security group / role applied to it?

EDIT: I only fully understood what you meant by "If this is not the case it might be permission that could be inherited from a parent folder.", I removed every inherited permission and on that folder I only have the Security Group I wanted and it's working.

Thank you very much for the help

BR
Diogo

avatar

Hi diogo,

Could you post a screenshot of the folder showing the permission section ?

Also, could you make sure that the user you are connecting with to the datasource is the exactly the same than the one on the database.

We have a known issue with domain account that the permission doesn't apply when using only eg: "aroy" as login instead of "aroy@westeros.loc.

Best regards,

Alexandre Roy

avatar

@diogo,

Hello, I just want to mention real quick that we are not encouraging people to work with security group at this time as this method is our old way of attributing rights and will eventually reach a status of deprecated.

Since RDM 12, we have introduced "Permissions" rights which is much faster and simpler working with, role based permissions might be more apealing for you :).

Give it a try see if you like it.

Happy Holidays.

Best regards,

Alexandre Roy

avatar

Hello again :)

@ur 1st post,

I already have this working, thank you for the help, the problem was with inherited permission from parent folders.

@ur 2nd post,

I would be very much interested on working on a role based permission system mostly because our company bought rdm and we have a devolutions server ready to be shared between all subsidiaries and the plan is to start using AD groups.

I will check if it works for us, thanks for the tip.

Happy holidays!

BR
Diogo