TITLE
    AppleShare IP: Setting Privileges for Multiple Groups
Article ID:
Created:
Modified:
30961
4/22/99
6/4/99

TOPIC

    How do I add privileges to more than one user/group when sharing a folder? I want one group to have read and write access to a folder, but I want another group to have just read access.


DISCUSSION

    Except where noted below, information in this article applies to both an AppleShare FIle Server and to Personal File Sharing.

    The server administrator can define three different levels of access: Owner, User/Group, and Everyone. The Owner and User/Group fields can each define privileges for one user or for one group. While there is no way to add privileges for more than these three classes of users, it is still possible to achieve the desired results.

    Example: You have a folder named "Documents" on your server. You want the "CopyWriters" group to have full read and write access to that folder, but you want the "ProofReaders" group to have read-only access to the folder.

    Solution 1
    Set the privileges for the shared folder as follows:

    OWNER: CopyWriters: Read/Write
    USER/GROUP: ProofReaders: Read Only
    EVERYONE: None

    For Personal File Sharing, this is located under "Sharing" in the "Get Info" window. For AppleShare, this is located in the Web & File Admin under "Show Disks & SharePoints".

    The drawback to this scheme is that if a user in the CopyWriters group creates a new folder, that folder will be owned by that individual user (not the CopyWriters group). This means that user must manually change the privileges to allow other members of the CopyWriters group to access the folder. Until that happens, members of the CopyWriters group will see a locked folder.

    Note: AppleShare 6.2 comes with the AppleShare IP Advanced Setup utility. This contains an option to "Make New Folders Inherit Their Privileges." By checking this box, the owner of a newly created folder will be the same as the enclosing folder. (In this example, the CopyWriters group is the owner of the new folder.)

    Another thing to be aware of when assigning ownership to a group is that any member of the group will be able to change privileges to the folders which that group owns. This includes changing ownership so that nobody else can access the folder.

    For a concrete example of how this principle is applied to a complex sharing setup, see the following Tech Info Library article:

    Article 12476: " AppleShare 3.0.x: Set Up For Large Group Possibilities "

    Solution 2
    OWNER: Administrator: Read/Write
    USER/GROUP: CopyWriters: Read/Write
    EVERYONE: Read Only

    This solves the problem above of new folders locking out members of the CopyWriters group. The drawback is that everyone will be able to at least read files in this folder. Any user that can see this folder (including guests, if they are allowed) will have read-only access to the Documents folder.

    You can address this by putting the Documents folder inside another folder that only members of CopyWriters and ProofReaders can access. That way, you can be sure that privileges granted to EVERYONE will only apply to members of the ProofReaders group.

Document Information
Product Area: Apple Software; Communications-Networking
Category: AppleShare
Sub Category: AppleShare for Mac OS

Copyright © 2000 Apple Computer, Inc. All rights reserved.