security - Limit read access to a subtree to a certain role in Sitecore -
i've been struggling off , on months, , may non-trivial answer.
what easiest way limit public access item , subitems members of single role? (editors still need able edit item.)
e.g. there's role, extranet/clubmember, , items,
- clubhouse | - items | - inside | - clubhouse and want extranet/clubmember members able read items , subitems, sitecore/* members (or, say, sitecore/editor) have edit access, , else (in default , extranet domains) denied.
second, solution still work custom role , membership providers extranet? why or why not, or methods need implement? recall earlier experiments custom role provider seems affect inheritance permissions in particular.
have tried following:
- uncheck inherit (the global one) clubhouse root
- explicitly allow read extranet\clubmember clubhouse root
- explicitly allow read/write sitecore\everyone clubhouse root
explicit assignments win. so, scheme should have effect expect.
Comments
Post a Comment