accesscontroltool
accesscontroltool copied to clipboard
More restrictive service user rights
Currently the (single) service user is used for almost all operations and grants full access to the repository.
set principal ACL for actool-service
allow jcr:all on /
allow jcr:all on :repository
end
The permissions should be limited to what is actually necessary.
The necessary permissions differ by functionality:
- Dumping Authorizables/ACLs
jcr:readon/home/usersand/home/groupsjcr:readACLon/
- Installing ACTool configurations
jcr:readACLandjcr:modifyACLon/jcr:readandjcr:writeon/home/users/and/home/groups- potentially
jcr:writeanywhere due toinitialContent jcr:readinsideconfigurationRootPath
- Writing/Reading ACTool history
jcr:read/writeon/var/statistics/actooland/apps/netcentric/achistory