Hopefully to answer your questions

(a) I would think that the ability to assign group (not role) permissions to
an object that is contained within a deployable application should not be
allowed.  I would think that this would defeat one of the main advantages of
deployable applications.

(b) I've never tried testing the group permissions, but I would expect that
after you export and re-import the application, that the group permissions
would be removed.

Terry


-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] Behalf Of L. J. Head
Sent: Friday, January 19, 2007 4:24 PM
To: [email protected]
Subject: Re: Group Permissions to Deployable Application Objects


Oh I fully understand that....my question lies more along the lines of

Why is remedy allowing me to still assign group permissions
And
How do those group permissions affect a users ability to access the
application

-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] On Behalf Of Terry Bootsma
Sent: Friday, January 19, 2007 2:20 PM
To: [email protected]
Subject: Re: Group Permissions to Deployable Application Objects

Best Practice....

When working with Deployable Applications, you should always assign
permissions based on ROLE, not group name, independent on how you have
mapped groups to roles in the ROLE form.

Hope that helps..

Terry


-----Original Message-----
From: Action Request System discussion list(ARSList)
[mailto:[EMAIL PROTECTED] Behalf Of L. J. Head
Sent: Friday, January 19, 2007 4:10 PM
To: [email protected]
Subject: Group Permissions to Deployable Application Objects


Ok...here is my understanding...please feel free to correct if I am mistaken
at any point during this

Create Deployable Application 'A'
Create Form 'F'
Make Form F part of Deployable Application A Create Group 'G'
Create Role 'R'
Map Roll R to Group G

Now...when I'm in Form F I can grant permissions to the Role I created...but
not the Group If in the application and I go to groups/roles I can manage
any dynamic group...and all of my roles...but not my regular groups (as it
should be) If I am simply connected to the server however...and I go into
Groups from there...I noticed something weird, I have the ability to grant
my Group form and field permissions.  Now...I get an error stating that
group permissions have been removed because the object is in a deployable
app....but the field stays on the right side of the column....even if I
leave and come back....

Now to the question.  Does that group have access?  If I were to re-map my
role to another group...would members of group G still have
access?...according to the groups dialog it does...but even after I grant
that...I can't see it by going into the form and looking at those fields...

If my group doesn't have access...why does it's permissions still get saved
with the object?
Why do objects that are in deployable applications still show up for me to
assign group permissions to?

____________________________________________________________________________
___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the
Answers Are"

____________________________________________________________________________
___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the
Answers Are"

____________________________________________________________________________
___
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the
Answers Are"

_______________________________________________________________________________
UNSUBSCRIBE or access ARSlist Archives at www.arslist.org ARSlist:"Where the 
Answers Are"

Reply via email to