Previous Topic

Next Topic

Book Contents

Book Index

Access Rights

About

Access rights allow defining access levels for individual users, groups, domains, etc. These levels are:

Access Right

Description

Lookup

basic right just to see GroupWare folders (not to see items); this allows users to open subfolders they can be granted access to

Read

right only to read the GroupWare items and entries

Keep Seen Flag

right to mark a message as read

Write

right to set or clear flags other than seen and deleted

Insert

right to insert a new item

Post

right to send an email via SMTP

Create

right to create a new folder

Delete

rights to delete items from the public or shared folder

Expunge

mails can be removed from a folder (Inbox, Sent, ...) and sent to Trash for example versus deleted at all; this right allows final deleting of mails

Delete Mailbox

right to delete a mailbox

Administer

full rights

Permissions

It is a list of permissions attached to the object. This list specifies who or what is allowed to access the object and what operations are allowed to be performed on the object.

This dialog is used in the User, Group and Public Folders dialogs. It allows to define access rights to any folder (both GroupWare and IMAP) directly from the GUI and you can see the whole shared/public folder structure in a combined view.

For the Permissions dialog, refer to the Public Folder – General chapter – Permissions Tab section.

Permissions can be defined on each folder level and is automatically inherited from the parent if not defined. New "everyone" right has been introduced.

note_small

NOTE: Group members can edit their own contact information even if they have access rights to the group Contact folder set to Read only. (They still can not edit contact information of the other group members.)

Permissions Inheritance

Permissions inheritance is a mechanism that lets container objects (e.g. mail type folders, file ones, etc.) pass access control information to their child objects. A container's child objects can be non-container objects (e.g. messages, contacts, files, etc.) as well as other container objects.

From administrator point of view, permissions inheritance simplifies access control management. An administrator can set the permissions on a parent object and does not need to set permissions on each child object.

Permissions Notification

IceWarp GroupWare Server sends notifications to users (after any permissions change) stating that they have been granted access rights.

These emails include information about:

access_notification

Similar type of notification is sent to resource managers and organizers when they are granted any roles related to these resources.

Folder Permissions Inheritance in IceWarp WebClient

When sharing folders in WebClient, any created child folder inherits access rights from its parent. These access rights can be changed (both increased and decreased) by the owner. In the case, you want to set access rights of this folder back to parent's ones, you can use the Inherit button of the Folder Access Rights dialog (see the IMAP – Sharing Folders section). This eliminates necessity to set them back manually.

Setting Permissions

Examples of setting permissions are shown in the IMAP chapter:

See Also

Sharing Concepts

User Groups

Shared Items

Scheduling and Resource Management

Time Zones

SmartAttach

WebFolders

SmartDiscover

Global Address List (GAL)

Miscellaneous

Sharing Examples