Rights

Intrexx's comprehensive permissions model covers the visibility of navigation elements, access to entire applications, access to individual pages and data groups within applications, and a distinction based on actions (view, create, edit, delete). In addition to the fixed assignment of permissions within the application, permission assignments can also be made accessible via the browser if necessary. For example, in Intrexx Share—Intrexx's collaboration application—it is possible to restrict access to posts and discussion groups to specific user groups.

Portal Administrator

Once you have created a portal, the portal will have a portal administrator. This role is responsible for key tasks related to the administration of a portal. For more information "Administrators" User Group see the section, among others

After logging in to the portal, you can create and manage additional portal administrators in the Intrexx Portal Manager. For more information, see the User section, among others.

Grant Permissions

In Intrexx, permissions for user objects—such as individual users, user groups, roles, etc.—are granted in various locations via a dialog box that essentially always follows the same structure.

First column

Displays an image that symbolizes the type of rights holder.

"Name" column

Displays the name of the copyright holder.

"Path" column

Displays the path to the user object in the "Users" module.

"Add" button

Opens a dialog box in which a user object can be selected.

"Remove" button

Removes the user object from the list. This does not mean that all rights are automatically revoked. The rights holder can still obtain the rights through membership in other objects, such as a user's membership in a user group.

"Law" Column

If you select a rights holder from the list at the top of the dialog box, the individual rights are displayed in this column.

Allow

Select the appropriate checkbox to grant a permission to the currently selected user object.

Portal Rights

You can find the portal permissions in the main menu under "Portal > Portal Permissions...".

This menu item is only accessible after logging in to a portal. All rights listed here apply to the current portal.

After you select the menu item, the "Set Portal Permissions" dialog box will appear.

Click on a user or user role to view the list of permissions.

Below is an overview of the portal permissions.

Name

Description

Change Portal PropertiesThis permission allows you to configure portal properties and create portal exports or imports via the main menu under "Portal / Export Portal" or "Portal / Import Portal," respectively.
Set up portal pages in your browserRights holders are authorized to administer the portal pages in default mode.
Access to the Design Module

In Portal Manager, rights holders have access to the Design module (Design).

The "Access to Design Module" permission or the "Access to Applications Module" permission is required to edit the portal's menu structure (Edit the Portal's Menu Structure).

Access to Module Applications

Rights holders have access to the Applications module (Applications) in Portal Manager.

The "Access to Module Applications" permission or the "Access to Module Design" permission is required to edit the portal's menu structure (Edit the Portal's Menu Structure).

Access to the Processes ModuleIn Portal Manager, rights holders have access to the Processes module (Processes).
Access to the Users ModuleIn Portal Manager, rights holders have access to the Users module (User).
Use ChatCopyright holders can use Chat.

Publish Velocity and Groovy Scripts

This permission allows Velocity and Groovy scripts to be published on the server.

Manage Global Language Constants

Rights holders can edit language constants in Portal Properties / Country Settings / Global Texts and in applications.

Starting with Intrexx version 12.0.1

Manage Security Settings

Rights holders can manage connection data in the "Integration" module and have access to the login information store.

Access to Integration Modules

Automatically checks the "Allow" checkbox for all applicable portal permissions, so that they do not need to be selected individually.

Perform Data Transfer

In Portal Manager, rights holders have the right to perform data transfers (Data Transfer).

Manage FileWalker Connections

In Portal Manager, rights holders have the right to manage FileWalker connections (FileWalker).

Manage API Keys

In Portal Manager, rights holders have the ability to manage API keys for the Intrexx Application API (Intrexx Application API).

Register OData Services

In Portal Manager, rights holders have the right to register OData services (OData Connector - Consuming Data).

Provide OData Services

In Portal Manager, rights holders have the right to offer OData services (OData Connector - Publish Data).

Register Web Services

In Portal Manager, rights holders have the right to register web services ( Register a Web Service).

Offer Web Services

In Portal Manager, rights holders have the right to offer web services (Web Service).

Configure WebDAV

Authorized users can access "WebDAV" in the "Tools" module (Configure WebDAV).

Document Integration

In Portal Manager, rights holders have the right to set up document integration (Collaboration - Documents).

Register SAP Gateway Sources

In Portal Manager, authorized users have the right to register SAP Gateway sources (Connector for SAP Gateway).

Register Lotus Notes Sources

In Portal Manager, authorized users have the right to register Lotus Notes sources (Connector for IBM Lotus Notes).

Manage Microsoft Exchange Sources

In Portal Manager, users with the appropriate permissions can manage Microsoft Exchange sources (Connector for Microsoft Exchange).

Manage SAP Business Suite Sources

In Portal Manager, authorized users have the right to manage SAP Business Suite sources (Connector for SAP Business Suite - Create a Connection).

Register M-Files Services

In Portal Manager, rights holders have the right to register M-Files services (Connector for M-Files 2.0).

Register for dg hyparchive Services

Rights holders have the right to register dg hyparchive services in Portal Manager (Connector for dg archive).

Access to ToolsWith this setting, the following permissions are granted for functions in the "Tools" module:
Use System Monitor

In Portal Manager, rights holders have the right to use the System Monitor (System Monitor).

Search Index Management

Authorized users have access to the Lucene index management (Search) feature.

Manage Task Scheduling

In Portal Manager, authorized users have the right to manage task scheduling (Task Planning).

Manage Request Variables

In Portal Manager, rights holders have the right to manage request variables (Form and Request Value Validation).

Access to Email Service

Rights holders can access the email service in Portal Manager (Email Service).

Special Considerations for Users Who Are Not Members of the "Administrators" User Group

  1. Users with the "Change Portal Properties" permission can make changes in the "Documents" section of the portal properties without having the "Access to Applications Module" permission.
  2. Users with the "Change Portal Properties" permission can make changes in the "Country Settings" section of the portal properties without needing the "Access to Design Module" permission. The "Access to Module Design" permission has no effect on this section in the portal properties. To edit global language constants, you need the "Manage Global Language Constants" permission.
  3. The "Manage Security Settings" permission is also required for the settings under "Security" and "Certificates" in the portal properties. Users without this permission cannot view these pages.

User

In the "Users" module, permissions are managed at two different levels: global permissions and individual permissions.

Global Rights

Global user permissions are managed through the "Users / Permissions" main menu. Authorized users can, for example, edit object classes and object instances, access the Schema Manager, and add, edit, or delete classes or attributes there, or modify the organizational chart.

Administration

The "Write Configuration" permission allows you to edit existing object classes in the Schema Manager.

Object Classes

Administer Class

This permission allows you to edit the currently selected class in the Schema Manager.

Create a New Object

Allows you to create new objects within the class in the Schema Manager.

Object Instances

Administer

This right applies to instances derived from the base classes Container, Set, and User. It allows you to edit all instances derived from the respective base class, including instances of subclasses.

Please note that when global permissions are assigned, they override individual permissions.

Individual Rights

Individual permissions are managed through the "Edit / Permissions" main menu. This main menu is accessible when a user object is selected.

Add User Objects

You can find all the information about selecting authorized users in the upper part of this dialog box here.

"Administer" Permission

With this individual right to edit the properties of individual object instances, you allow values to be changed that are physically stored in the database for each instance—such as the instance’s name, or address and contact information for an instance of the "User" object.

Apply setting to child nodes

With this setting, the "Administer" permission is applied to—or revoked from—all objects subordinate to the current user object if you have disabled the permission in the parent object that is currently selected.

Standard Users and User Groups

Newly created portals already include the user groups "Administrators" and "Users." You'll also find the users "Administrator" and "Anonymous" there. You can find information about the rights of these users and user groups here.

Application Permissions

The "Applications" module is used to define access rights to applications.

In addition, administrative rights that allow for technical modifications to the application can be granted. You can edit application permissions via the "Application / Permissions" main menu or the "Edit / Properties" main menu when the application node is selected.

On the left side of the dialog, you'll see tabs that represent the areas in which access rights to an application are managed:

  • Application

    Access to the application link and the home page in the browser; administrative privileges

  • Pages

    Access to Other Individual Pages

  • Data Groups

    Read and write access to the application data

  • File Fields

    Read and Write Permissions on File Fields

  • Search Configurations

    Rights to Search Configurations

  • Topics

    Rights to Topics

  • API Endpoints

    The right to use the Intrexx Application API.

Click here to learn how to add rights holders and assign individual rights in the right-hand section of the dialog box.

New or modified permissions are transferred to the server when the application is published.

Application

Full Access

This setting automatically selects all other permissions.

Manage Application

Rights holders are authorized to manage the application in the "Applications" module.

Use the application

Authorized users can access the application link and the application's home page in their browser.

The "Administrators" user group has full access to all pages and data groups in the application, as well as to the application itself. This setting cannot be changed in the application permissions. Remove the rights holder from the Administrators user group if you do not want to grant them the right to administer applications. The application's author always has the right to manage the application. This right is automatically entered when the application is created.

Pages

Allows access to the individual pages of the application. If you select one or more pages in the left pane, you can configure the permissions for those pages in the right pane. The browser automatically hides all unauthorized pages. Buttons that link to an unauthorized page will not be displayed in the browser.

Data Groups

Here, you specify in which data groups data may be read, added, modified, or deleted.

Data group permissions for Intrexx Share are controlled internally via Java classes and cannot be modified here.

Full Access

Selects all other rights.

Read a record

The rights holder may access the application's data.

Read Data Set (Custom)

Data subjects may access the existing data records that they themselves have stored.

Add a record

Copyright holders may add new data.

Edit Record

Rights holders may modify existing data records.

Edit Record (Custom)

Data subjects may modify existing data records that they have stored themselves.

Delete Record

Rights holders may delete existing data records.

Delete Record (Your Own)

Data subjects may delete existing data records that they have stored themselves.

File Data Fields

If file data fields have been created in a data group, you can set the permissions here

  • Full Access (selects all other permissions)

  • Read File

  • Read File (Custom)

  • Add File

  • Edit File

  • Edit File (Your Own)

  • Delete File

  • Delete File (Your Own)

be granted. To do this, select the corresponding file field in the application structure in the left pane of the dialog box.

Apply the permissions for the data group

With this setting, all permissions configured for the data group are applied to all file fields it contains. Permissions for individual data fields can only be set if this setting is not enabled.

If separate permissions are assigned to a single file field, a conflict check is performed. In the permissions table, permissions for which a conflict has been detected are highlighted in red. A conflict occurs when permissions have been granted for a file field that are not permitted according to the data group. If, for example, a user has only read access to a data group but is granted delete permissions for a file field in that data group, a conflict occurs. The "Delete" option will then be highlighted in red.

Search Configurations

In the left pane of the dialog box, select the search configuration for which you want to manage permissions.

Apply Permissions to the Data Group

With this setting, the permissions for the data group you selected in the search configuration settings will be applied.

Topics

"Topics" are related to WebSockets. They represent the object that delivers or provides WebSocket messages. A "consumer" can subscribe to a topic. A topic can be compared to a news feed that you can subscribe to.

You can set up the following rights for topics:

Full Access

If you select this option, the user in question will have the "Read Topic" and "Post in Topic" permissions.

Read this topic

This setting allows you to control which users see WebSocket messages in their browser.

Post in this thread

This right applies to the user of a process that contains a WebSocket action or a Groovy action with WebSocket functionality. You can have processes run in a user context. In that case, the rights of the relevant user are relevant. If the user does not have the "Post to Topic" permission, the process will not send a WebSocket message to the topic, nor will it be displayed in the browser.

For more information on WebSockets, see the following sections:

API Endpoints

This section displays the API endpoints you have created within the application. You can select one or more API endpoints and then assign a user or user group to them.

For more information on assigning permissions to API endpoints, see the section " Assign a user to an API endpoint."

For more information about the Intrexx Application API, see the " Intrexx Application API" section.

Permissions can be assigned for each individual menu item in the portal. These rights can be managed via the main menu under "Portal / Edit Menu Structure. " Menu items that a user is not allowed to select are automatically hidden in the browser.

The "Manage Menu Item (CMS)" permission allows articles from the CMS application to be published under this menu item. Articles are published directly in the CMS. For menu items that originate from the CMS, permissions cannot be managed using the Menu Designer. Deleting a CMS menu item is also only possible through the CMS. Menu items that link to CMS content can only be managed through the CMS.

The "Select Menu Item" permission allows authorized users to select the menu item in the browser.

When you select the "Full Access" permission, all permissions are automatically marked as "Allowed" and are therefore granted when you click "OK."

You can find more information on "Editing the Menu Structure" here.

FileWalker

Access to files on the network is controlled in two places: in the connection settings in the "Integration" module and in the properties of the FileWalker element in the "Applications" module.

Grant Permissions in the "Integration" Module

Click here to learn how to add users to the list of authorized users.

Full Access

This setting automatically selects all other permissions.

Administration

This permission allows you to manage the connection settings.

Use in Applications

Rights holders are authorized to select the connection in the "Applications" module and assign it to a FileWalker element.

Please note that the permissions for the FileWalker connection are subject to the directory permissions of individual users.

Grant Permissions in the "Applications" Module

For the "FileWalker" application element, permissions are granted on the "Permissions" tab in the Properties dialog box.

Click here to learn how to add users to the list of authorized users.

Full Access

Automatically selects all other permissions.

Direct Access

Direct access to the files; changes are made to the original files.

Download

Downloading files.

Create a file

Creating new files.

Copy File

Create copies of a file.

Overwrite File

Overwriting files is allowed.

Rename File

File names can be changed.

Delete File

Files can be deleted.

Create a directory

Additional directories can be created.

Rename Directory

Directory names can be changed.

Delete Directory

Directories can be deleted.

Enable the desired permissions by checking the corresponding checkbox in the "Allow" column. FileWalker users also need permissions for the application and for the page that contains the FileWalker element.

Web Service

To configure web services, you must have the portal permissions "Register Web Services" and access to the "Tools" module.

Implementation of a Login Module

You can find all the information on this topic here.

Generic Rights Management

Requirements

To access Generic Rights Management, the "Enable expert options" checkbox must be selected under "Tools > Options > Portals."

Target Audience

Generic Rights Management is designed for experts who want to manage additional rights beyond those assigned through the dialog-based interface. To use this feature, it helps if you are familiar with "Java Permission Classes."

Function Description

Generic Rights Management allows you to assign the rights classes provided by Intrexx—as well as your own rights classes—to specific objects. You can then assign the objects to rights holders. You can specify which actions should be performed in each case. Later, at runtime, you can use Groovy, for example, to check whether a specific rights holder is allowed to perform a specific action on a specific object and respond accordingly.

The following section provides an example of how to add (another) permission holder to an Intrexx permission class and how to add an additional permission.

Using Intrexx Permission Classes - Adding Permission Holders

Step-by-Step

To add an (additional) permission holder to an Intrexx permission class, follow these steps:

  1. In the main menu, click "Portal > Expert Area > Generic Rights."

    To access this menu item, the "Enable expert options" checkbox must be selected under "Tools > Options > Portals."

    The "Generic Rights Management" dialog box appears.

  2. Open the "Permission Class" drop-down list.

    The rights classes provided or used by Intrexx are displayed.

    For information on Intrexx permission classes, see the following links:

  3. Select the desired permission class ().

    In the screenshot shown below, the permission class `de.uplanet.lucy.security.permission.ApplicationPermission` has been selected.

    The "Object" section () displays all objects (applications) that use this permission class. In this case, the identifier is the GUID of the respective application.

    As soon as you select an identifier, the rights holders are displayed in the "Rights Holders" section ().

    As soon as you select a rights holder, the available actions will be displayed in the "Actions" field (). The "Actions" field is an input field. Here you can add or remove actions (separated by commas).

  4. Click the " " icon.

    The "Add Rights Holder" dialog box appears.

  5. Select the desired rights holder.

    The copyright holder is displayed.

  6. Enter the desired permissions in the "Actions" field.

    The screenshot shown below shows the " administration,access" permissions.

  7. Click "Finish."

More Information

Application Permissions

Add Your Own Rights Classes

Step-by-Step

To add a custom or new rights class, follow these steps:

  1. Click the " " icon.

    The "Rights Class" dialog box appears.

  2. Enter the rights class.

    In the screenshot below, this is `java.io.FilePermission`.

  3. Click "OK."

    You will return to the "Generic Rights Management" dialog box.

    The recorded rights class is displayed.

  4. Click the " " icon.

    A new row appears in the "Object" section.

  5. Click in the new row and enter the identifier.

    In the screenshot shown below, this is a path to a file.

    (For more information, see the FilePermission class at .)

  6. Click the " " icon in the "Rights Holder" section.

  7. The "Add Rights Holder" dialog box appears.

  8. Select the desired rights holder.

    You will return to the "Generic Rights Management" dialog box.

    The copyright holder is displayed.

  9. Enter the desired permissions in the "Actions" field.

    The screenshot below shows the read and write permissions.

  10. Click "Finish."

More Information