jackrabbit-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Ian Boston <...@tfd.co.uk>
Subject Groups Deny, DefaultAccessManager
Date Fri, 24 Apr 2009 07:26:17 GMT
This is a question initiated by looking at Sling, but relates to the  
Jackrabbit DefaultAccessControlManager.

I notice the Access Control Elements with a deny statement don't get  
added to a ACE relating to a Group Principal.

Does any one know the reason for this ? Is it part of the Spec ?

We have use cases where we want to grant part of a tree to a group and  
then deny a subtree to the main group and grant to a smaller group. At  
the moment, it looks like DACM wont do this for us, we could write our  
own (in fact we did for JR 14), but I dont really want to drift too  
far from anything in the spec.


View raw message