Hopefully to answer your questions (a) I would think that the ability to assign group (not role) permissions to an object that is contained within a deployable application should not be allowed. I would think that this would defeat one of the main advantages of deployable applications.
(b) I've never tried testing the group permissions, but I would expect that after you export and re-import the application, that the group permissions would be removed. Terry -----Original Message----- From: Action Request System discussion list(ARSList) [mailto:[EMAIL PROTECTED] Behalf Of L. J. Head Sent: Friday, January 19, 2007 4:24 PM To: [email protected] Subject: Re: Group Permissions to Deployable Application Objects Oh I fully understand that....my question lies more along the lines of Why is remedy allowing me to still assign group permissions And How do those group permissions affect a users ability to access the application -----Original Message----- From: Action Request System discussion list(ARSList) [mailto:[EMAIL PROTECTED] On Behalf Of Terry Bootsma Sent: Friday, January 19, 2007 2:20 PM To: [email protected] Subject: Re: Group Permissions to Deployable Application Objects Best Practice.... When working with Deployable Applications, you should always assign permissions based on ROLE, not group name, independent on how you have mapped groups to roles in the ROLE form. Hope that helps.. Terry -----Original Message----- From: Action Request System discussion list(ARSList) [mailto:[EMAIL PROTECTED] Behalf Of L. J. Head Sent: Friday, January 19, 2007 4:10 PM To: [email protected] Subject: Group Permissions to Deployable Application Objects Ok...here is my understanding...please feel free to correct if I am mistaken at any point during this Create Deployable Application 'A' Create Form 'F' Make Form F part of Deployable Application A Create Group 'G' Create Role 'R' Map Roll R to Group G Now...when I'm in Form F I can grant permissions to the Role I created...but not the Group If in the application and I go to groups/roles I can manage any dynamic group...and all of my roles...but not my regular groups (as it should be) If I am simply connected to the server however...and I go into Groups from there...I noticed something weird, I have the ability to grant my Group form and field permissions. Now...I get an error stating that group permissions have been removed because the object is in a deployable app....but the field stays on the right side of the column....even if I leave and come back.... Now to the question. Does that group have access? If I were to re-map my role to another group...would members of group G still have access?...according to the groups dialog it does...but even after I grant that...I can't see it by going into the form and looking at those fields... If my group doesn't have access...why does it's permissions still get saved with the object? Why do objects that are in deployable applications still show up for me to assign group permissions to? ____________________________________________________________________________ ___ UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the Answers Are" ____________________________________________________________________________ ___ UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the Answers Are" ____________________________________________________________________________ ___ UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the Answers Are" _______________________________________________________________________________ UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the Answers Are"

