The groupware part of Open-Xchange Server 5 uses several aspects of rights management: On one hand, the administrator can set specific access rights for individual users for every section; on the other hand, for each object within a section specific read and write permissions can be assigned to particular users. Rights are assigned hierarchically. If a user does not have rights for a given section, he automatically has no way of accessing objects within this section.
The intranet administrator can set up a profile for every user which states for which sections he is generally authorized. If you have not received rights for a section, you will not see the respective icon in the main navigation bar. If you need authorization for a section, you can always ask the administrator to grant you the relevant rights.
![]() | Note:Changing single section rightsNewly granted rights only become effective after a new login to the groupware! |
Every time you add or change an object in the sections for bookmarks, knowledge entries, documents, or pin board you can determine who has the right to access this object. If someone does not have the right for specific objects, he will not see them in search results or other listings. Authorization is usually granted via the tabs read access and write access which are available when you create a new object or edit an existing one in the individual program categories. Alternatively, it is also possible to define settings via the list field templates, which allows you to set up defaults for read and write permissions.
Generating new templates is done analogously to setting read and write permissions. Under read access you can list the users who should only have permission to read the object data. Under write access you can list all users who should be able to access the object for reading as well as writing. In the groupware, write access also includes the right to delete an object. Under groups of users you can select whole groups as well as single users who should have access to the object. Finally, you can save the settings as a new template under the templates tab. Analogously to single objects you can assign read and write permissions to folders and subfolders in the mentioned modules.
Open-Xchange Server 5 knows two types of folders: Private and public folders. Only you can see private folders, while public folders can be used also by other users. In addition, you can grant access to individual folders to individual users or user groups. All folders that are visible for you are listed in the side frame (on the left or on the right) of the groupware portal. You can find detailed information about granting rights and configuring folders in the chapter on "folder management." The folders in the modules bookmarks, knowledge and documents belong to a special type of folder. Here you have folders for which you can directly assign read/write permissions. The approach corresponds to that already discussed under Defining Object Specific Rights
Via the list field "templates" you can utilize existing templates for the creation/editing of an object. Templates contain information about read and write permissions. Then, you do not have to add the relevant settings by hand any more. If you want to generate a new template yourself, simply add the desired settings via the read access and write access tabs. Once you have defined read and write permissions, you can save these settings as a template. You do this via the edit pages of the templates tabs. These allow you to save the entered settings as a template. Under title you give the template a suitable name. Under description you can enter a short description for the new template. If the new template should become the default template for new objects, check the flag default template. You can then save the new template by clicking on the button save template. Existing templates are shown in the list field at the end of the page. Templates are managed separately for the individual module sections, such as documents, knowledge, bookmarks, forum and pin board.
![]() | Read and write permissionsYou can find detailed information regarding read and write permissions in the individual chapters. For example, when you create an object there are default settings which allow for quick and easy work. |
You can add a group of users by selecting the group directly in the top left select field and then pressing the Add button. The selected group is then added to the right-hand select field showing the participating groups. You can also directly search for a group by entering its name. For this you enter the group's name - if necessary with wildcards - into the text field above the left select list and then start the search by pressing the GO button.
In the "groups of users" section you see only the groups whose member you are. In order to remove a group of users from the selection list, select this group in the right-hand select list and click the button remove. All select lists allow for multiple selections by holding the Ctrl button.
In order to add users, you must first select a group in the left-hand select field under groups of users in which the user is a member. Then click on the button Show users. Now you see a list of all members of the selected group of users in the left-hand select list in the users section. Users without access to the active section are grayed out and cannot be selected. In order to assign the desired user to the object, select this user in the left-hand select field and click the Add button. Alternatively, you can also use the input field above the user select list to pick a certain user directly from the list.
Users without access to the active section are shown in gray and cannot be selected for rights management.
It is possible to search for the user using first name, last name or user name. Here, wildcards are also accepted. You find a detailed description on the following pages or under the respective tab in the online help; more about the search function can be found in the subchapter Globale Suche in this manual.
In order to remove a participant from the object assignment, select this participant in the right-hand select list and click the button remove.
Using the list field Delete permission you can specify who should have the right to delete the object in the future. If you select the entry Like write access from the list field, all groupware users with write permission may also delete the object or folder. If you select one of the displayed users at this point, this particular user is granted the relevant permission for the object. Only this user may delete the object in the future or pass on the delete permission to another user. In the history of the object the user with delete permission is shown as an owner.
In addition to the normal selection of participants for an object you can also perform the selection in an extended view. Simply select the button More in the upper right-hand corner underneath the status line.
On the left-hand side of the extended view you see a tree view of all existing groups. If you click on the plus sign in front of a group, the view increases to include the members of this group of users. In order to add participants or groups to the object, select them by clicking on the box before the respective name. Now select the button add to associate the users and groups with the object. Groups appear in the upper participant selection field, users in the lower one. You remove a participant or a group of users from the object, make your selection in the respective select field and press the button remove below this select field.
![]() | Note:Rights ManagementThe respective chapters on individual modules detail the differences between the modules that arise from the fact that these options are treated differently from module to module. The following is generally true: If you first give write permissions to a user, he will automatically get read access. The opposite is not true! If you first give read access to a user, this does mean that he also automatically receives write access. |
In the Calendar, Tasks and Contacts modules, the access rights are defined via the choice of folders. When an object is created or edited in one of these modules, you select in which folder this object should be placed. Then the access rights correspond to those of the selected containing folder. You will find more information about this in the individual chapters on the modules Calendar, Contacts and Tasks as well as in chapter 15, which explains in detail the everyday handling of the folder system.
Once you have defined read and write permissions for an object (participant), you can save these settings as a template. You do this via the edit pages of the Templates tabs. These allow you to save the entered settings as a template. Under Title you give the template a suitable name. Under Description you can enter a short description for the new template. If the new template should become the default template for newly created objects within the same module, then check the flag Default template. You can then save the new template by clicking on the button Save Template. Existing templates are shown in the list field at the end of the page. To assign an already established template to a document, simply select the desired entry from the list field templates in the main dialog page of an object. It is also possible to choose directly from the list field under the Templates tab. Templates are managed separately for the individual module sections, such as Documents, Knowledge and Bookmarks. If you would like to set up several templates at once, you have to keep in mind that you have to go back to the start dialog for the object each time after you add a new template. There you have to set the list field Templates back to None. If you do not do this, you just keep changing the active template over and over again instead of defining new templates. You can see a list of all templates for a module section under Templates.