| Stefan [MSFT] 2004-11-28, 5:48 pm |
| Hi Chan,
that is by design.
You will see all items the current user has access to. This means items the
current user is assigned to or items that are allowed to be seen by
everybody - means items the guest account has rights to.
Cheers,
Stefan.
"Chan" <chandimak@synergy.co.nz> wrote in message
news:OAUmHqY1EHA.3820@TK2MSFTNGP11.phx.gbl...
> Has anyone come across this issue?
>
> Enabling Guest Access results in authors seeing resource galleries and
> template galleries that they have no access to.
>
> MCMS Configuration.
>
> Content Authoring (Read/Write) CMS01
> 1 Content editing web server with two client web site channels.
> Windows Server 2003
> MCMS SP1a
> MCMS Hotfix 824597
> IIS 6.0
> Channels:
> www.cleint1.com
> www.cleint2.com
> Authentication mode : Windows
>
> The above URL's are re-written using ISAPI rewrite as
www.cms-stgclient1.com
> and www.cms-stgclient2.com
>
> Each site has two separate user groups and roles setup.
> There are separate accounts for each Author. (UserAccountA, UserAccountB)
>
> Role Groups:
> Client1Authors
> Client2Authors
>
> UserAccountA belongs to Client1Authors group only
> Client1Authors group has access to only www.cleint1.com channel and sub
> channels plus template/resource galleries for that client. IE. Each cleint
> has their own template gallery.
>
> UserAccountB belongs to Client2Authors group only and has access only to
> www.cleint2.com sun channels and template/resource galleries specific to
> their channels.
>
>
> Database CMSDB
> 1 Database server for the above installation (both sites share the same
> database)
> SQL 2000 SP3
>
> Production (Read Only) CMS02
>
> Windows Server 2003
> MCMS SP1a
>
> Two web site's configured for read only MCMS site access.
> Uses the same content production DB (CMSDB). (Content is Live once the
> workflow is finished and published on the CMS01 box)
>
> ISSUE
>
> The above scenario works fine until a subscriber group is created and
guest
> user access is enabled for the IUSR account.
> Once the IUSR account is enabled the subscriber group has to be given
acess
> to all channels and templates/resources for guest access.
>
> To enable guest access the following was suggested
> http://support.microsoft.com/defaul...kb;en-us;810308
>
> Once this is applied Client1Authors and Client2Authors are able to see the
> template/resource galleries in edit mode.
>
> Once the IUSR account is removed they are not able to see eachothers
sites.
> Have tried the following but has had no results.
>
> Cleint1SubscriberGroup
> Cleint2SubscriberGroup
> Granted rights only to Cleint1Channels templates and resource gallery
access
> to IUSERCleint1 in Cleint1SubscriberGroup
>
> Granted rights only to Cleint2Channels templates and resource gallery
access
> to IUSERCleint2 in Cleint2SubscriberGroup
>
> This failed as you can specify only a single account as a guest account
in
> SCA. (IUSR)
>
> Thanks
>
> Chan
>
>
|