Rights
Intrexx's comprehensive permissions model covers the visibility of navigation elements, access to entire applications, access to individual pages and data groups within applications, and a distinction based on actions (view, create, edit, delete). In addition to the fixed assignment of permissions within the application, permission assignments can also be made accessible via the browser if necessary. For example, in Intrexx Share—Intrexx's collaboration application—it is possible to restrict access to posts and discussion groups to specific user groups.
Portal Administrator
Once you have created a portal, the portal will have a portal administrator. This role is responsible for key tasks related to the administration of a portal. For more information "Administrators" User Group see the section, among others
After logging in to the portal, you can create and manage additional portal administrators in the Intrexx Portal Manager. For more information, see the User section, among others.
Grant Permissions
In Intrexx, permissions for user objects—such as individual users, user groups, roles, etc.—are granted in various locations via a dialog box that essentially always follows the same structure.
First column
Displays an image that symbolizes the type of rights holder.
"Name" column
Displays the name of the copyright holder.
"Path" column
Displays the path to the user object in the "Users" module.
"Add" button
Opens a dialog box in which a user object can be selected.
"Remove" button
Removes the user object from the list. This does not mean that all rights are automatically revoked. The rights holder can still obtain the rights through membership in other objects, such as a user's membership in a user group.
"Law" Column
If you select a rights holder from the list at the top of the dialog box, the individual rights are displayed in this column.
Allow
Select the appropriate checkbox to grant a permission to the currently selected user object.
Portal Rights
You can find the portal permissions in the main menu under "Portal > Portal Permissions...".
This menu item is only accessible after logging in to a portal. All rights listed here apply to the current portal.
After you select the menu item, the "Set Portal Permissions" dialog box will appear.
Click on a user or user role to view the list of permissions.
Below is an overview of the portal permissions.
Name
| Description |
|---|---|
| Change Portal Properties | This permission allows you to configure portal properties and create portal exports or imports via the main menu under "Portal / Export Portal" or "Portal / Import Portal," respectively. |
| Set up portal pages in your browser | Rights holders are authorized to administer the portal pages in default mode. |
| Access to the Design Module | In Portal Manager, rights holders have access to the Design module (Design). The "Access to Design Module" permission or the "Access to Applications Module" permission is required to edit the portal's menu structure (Edit the Portal's Menu Structure). |
| Access to Module Applications | Rights holders have access to the Applications module (Applications) in Portal Manager. The "Access to Module Applications" permission or the "Access to Module Design" permission is required to edit the portal's menu structure (Edit the Portal's Menu Structure). |
| Access to the Processes Module | In Portal Manager, rights holders have access to the Processes module (Processes). |
| Access to the Users Module | In Portal Manager, rights holders have access to the Users module (User). |
| Use Chat | Copyright holders can use Chat. |
Publish Velocity and Groovy Scripts | This permission allows Velocity and Groovy scripts to be published on the server. |
Manage Global Language Constants | Rights holders can edit language constants in Portal Properties / Country Settings / Global Texts and in applications. |
Starting with Intrexx version 12.0.1 Manage Security Settings | Rights holders can manage connection data in the "Integration" module and have access to the login information store. |
Access to Integration Modules | Automatically checks the "Allow" checkbox for all applicable portal permissions, so that they do not need to be selected individually. |
| Perform Data Transfer | In Portal Manager, rights holders have the right to perform data transfers (Data Transfer). |
| Manage FileWalker Connections | In Portal Manager, rights holders have the right to manage FileWalker connections (FileWalker). |
| Manage API Keys | In Portal Manager, rights holders have the ability to manage API keys for the Intrexx Application API (Intrexx Application API). |
| Register OData Services | In Portal Manager, rights holders have the right to register OData services (OData Connector - Consuming Data). |
| Provide OData Services | In Portal Manager, rights holders have the right to offer OData services (OData Connector - Publish Data). |
| Register Web Services | In Portal Manager, rights holders have the right to register web services ( Register a Web Service). |
| Offer Web Services | In Portal Manager, rights holders have the right to offer web services (Web Service). |
| Configure WebDAV | Authorized users can access "WebDAV" in the "Tools" module (Configure WebDAV). |
| Document Integration | In Portal Manager, rights holders have the right to set up document integration (Collaboration - Documents). |
In Portal Manager, authorized users have the right to register SAP Gateway sources (Connector for SAP Gateway). | |
| Register Lotus Notes Sources | In Portal Manager, authorized users have the right to register Lotus Notes sources (Connector for IBM Lotus Notes). |
| Manage Microsoft Exchange Sources | In Portal Manager, users with the appropriate permissions can manage Microsoft Exchange sources (Connector for Microsoft Exchange). |
| Manage SAP Business Suite Sources | In Portal Manager, authorized users have the right to manage SAP Business Suite sources (Connector for SAP Business Suite - Create a Connection). |
| Register M-Files Services | In Portal Manager, rights holders have the right to register M-Files services (Connector for M-Files 2.0). |
| Register for dg hyparchive Services | Rights holders have the right to register dg hyparchive services in Portal Manager (Connector for dg archive). |
| Access to Tools | With this setting, the following permissions are granted for functions in the "Tools" module: |
| Use System Monitor | In Portal Manager, rights holders have the right to use the System Monitor (System Monitor). |
| Search Index Management | Authorized users have access to the Lucene index management (Search) feature. |
| Manage Task Scheduling | In Portal Manager, authorized users have the right to manage task scheduling (Task Planning). |
| Manage Request Variables | In Portal Manager, rights holders have the right to manage request variables (Form and Request Value Validation). |
| Access to Email Service | Rights holders can access the email service in Portal Manager (Email Service). |
Special Considerations for Users Who Are Not Members of the "Administrators" User Group
- Users with the "Change Portal Properties" permission can make changes in the "Documents" section of the portal properties without having the "Access to Applications Module" permission.
- Users with the "Change Portal Properties" permission can make changes in the "Country Settings" section of the portal properties without needing the "Access to Design Module" permission. The "Access to Module Design" permission has no effect on this section in the portal properties. To edit global language constants, you need the "Manage Global Language Constants" permission.
- The "Manage Security Settings" permission is also required for the settings under "Security" and "Certificates" in the portal properties. Users without this permission cannot view these pages.
User
In the "Users" module, permissions are managed at two different levels: global permissions and individual permissions.
Global Rights
Global user permissions are managed through the "Users / Permissions" main menu. Authorized users can, for example, edit object classes and object instances, access the Schema Manager, and add, edit, or delete classes or attributes there, or modify the organizational chart.
Administration
The "Write Configuration" permission allows you to edit existing object classes in the Schema Manager.
Object Classes
Administer Class
This permission allows you to edit the currently selected class in the Schema Manager.
Create a New Object
Allows you to create new objects within the class in the Schema Manager.
Object Instances
Administer
This right applies to instances derived from the base classes Container, Set, and User. It allows you to edit all instances derived from the respective base class, including instances of subclasses.
Please note that when global permissions are assigned, they override individual permissions.
Individual Rights
Individual permissions are managed through the "Edit / Permissions" main menu. This main menu is accessible when a user object is selected.
Add User Objects
You can find all the information about selecting authorized users in the upper part of this dialog box here.
"Administer" Permission
With this individual right to edit the properties of individual object instances, you allow values to be changed that are physically stored in the database for each instance—such as the instance’s name, or address and contact information for an instance of the "User" object.
Apply setting to child nodes
With this setting, the "Administer" permission is applied to—or revoked from—all objects subordinate to the current user object if you have disabled the permission in the parent object that is currently selected.
Standard Users and User Groups
Newly created portals already include the user groups "Administrators" and "Users." You'll also find the users "Administrator" and "Anonymous" there. You can find information about the rights of these users and user groups here.
Application Permissions
The "Applications" module is used to define access rights to applications.
In addition, administrative rights that allow for technical modifications to the application can be granted. You can edit application permissions via the "Application / Permissions" main menu or the "Edit / Properties" main menu when the application node is selected.
On the left side of the dialog, you'll see tabs that represent the areas in which access rights to an application are managed:
Application
Access to the application link and the home page in the browser; administrative privileges
Pages
Access to Other Individual Pages
Data Groups
Read and write access to the application data
File Fields
Read and Write Permissions on File Fields
Search Configurations
Rights to Search Configurations
Topics
Rights to Topics
API Endpoints
The right to use the Intrexx Application API.
Click here to learn how to add rights holders and assign individual rights in the right-hand section of the dialog box.
New or modified permissions are transferred to the server when the application is published.
Application
Full Access
This setting automatically selects all other permissions.
Manage Application
Rights holders are authorized to manage the application in the "Applications" module.
Use the application
Authorized users can access the application link and the application's home page in their browser.
The "Administrators" user group has full access to all pages and data groups in the application, as well as to the application itself. This setting cannot be changed in the application permissions. Remove the rights holder from the Administrators user group if you do not want to grant them the right to administer applications. The application's author always has the right to manage the application. This right is automatically entered when the application is created.
Pages
Allows access to the individual pages of the application. If you select one or more pages in the left pane, you can configure the permissions for those pages in the right pane. The browser automatically hides all unauthorized pages. Buttons that link to an unauthorized page will not be displayed in the browser.
Data Groups
Here, you specify in which data groups data may be read, added, modified, or deleted.
Data group permissions for Intrexx Share are controlled internally via Java classes and cannot be modified here.
Full Access
Selects all other rights.
Read a record
The rights holder may access the application's data.
Read Data Set (Custom)
Data subjects may access the existing data records that they themselves have stored.
Add a record
Copyright holders may add new data.
Edit Record
Rights holders may modify existing data records.
Edit Record (Custom)
Data subjects may modify existing data records that they have stored themselves.
Delete Record
Rights holders may delete existing data records.
Delete Record (Your Own)
Data subjects may delete existing data records that they have stored themselves.
File Data Fields
If file data fields have been created in a data group, you can set the permissions here
Full Access (selects all other permissions)
Read File
Read File (Custom)
Add File
Edit File
Edit File (Your Own)
Delete File
Delete File (Your Own)
be granted. To do this, select the corresponding file field in the application structure in the left pane of the dialog box.
Apply the permissions for the data group
With this setting, all permissions configured for the data group are applied to all file fields it contains. Permissions for individual data fields can only be set if this setting is not enabled.
If separate permissions are assigned to a single file field, a conflict check is performed. In the permissions table, permissions for which a conflict has been detected are highlighted in red. A conflict occurs when permissions have been granted for a file field that are not permitted according to the data group. If, for example, a user has only read access to a data group but is granted delete permissions for a file field in that data group, a conflict occurs. The "Delete" option will then be highlighted in red.
Search Configurations
In the left pane of the dialog box, select the search configuration for which you want to manage permissions.
Apply Permissions to the Data Group
With this setting, the permissions for the data group you selected in the search configuration settings will be applied.
Topics
"Topics" are related to WebSockets. They represent the object that delivers or provides WebSocket messages. A "consumer" can subscribe to a topic. A topic can be compared to a news feed that you can subscribe to.
You can set up the following rights for topics:
Full Access
If you select this option, the user in question will have the "Read Topic" and "Post in Topic" permissions.
Read this topic
This setting allows you to control which users see WebSocket messages in their browser.
Post in this thread
This right applies to the user of a process that contains a WebSocket action or a Groovy action with WebSocket functionality. You can have processes run in a user context. In that case, the rights of the relevant user are relevant. If the user does not have the "Post to Topic" permission, the process will not send a WebSocket message to the topic, nor will it be displayed in the browser.
For more information on WebSockets, see the following sections:
API Endpoints
This section displays the API endpoints you have created within the application. You can select one or more API endpoints and then assign a user or user group to them.
For more information on assigning permissions to API endpoints, see the section " Assign a user to an API endpoint."
For more information about the Intrexx Application API, see the " Intrexx Application API" section.
Menu Structure
Permissions can be assigned for each individual menu item in the portal. These rights can be managed via the main menu under "Portal / Edit Menu Structure. " Menu items that a user is not allowed to select are automatically hidden in the browser.
The "Manage Menu Item (CMS)" permission allows articles from the CMS application to be published under this menu item. Articles are published directly in the CMS. For menu items that originate from the CMS, permissions cannot be managed using the Menu Designer. Deleting a CMS menu item is also only possible through the CMS. Menu items that link to CMS content can only be managed through the CMS.
The "Select Menu Item" permission allows authorized users to select the menu item in the browser.
When you select the "Full Access" permission, all permissions are automatically marked as "Allowed" and are therefore granted when you click "OK."
You can find more information on "Editing the Menu Structure" here.
FileWalker
Access to files on the network is controlled in two places: in the connection settings in the "Integration" module and in the properties of the FileWalker element in the "Applications" module.
Grant Permissions in the "Integration" Module
Click here to learn how to add users to the list of authorized users.
Full Access
This setting automatically selects all other permissions.
Administration
This permission allows you to manage the connection settings.
Use in Applications
Rights holders are authorized to select the connection in the "Applications" module and assign it to a FileWalker element.
Please note that the permissions for the FileWalker connection are subject to the directory permissions of individual users.
Grant Permissions in the "Applications" Module
For the "FileWalker" application element, permissions are granted on the "Permissions" tab in the Properties dialog box.
Click here to learn how to add users to the list of authorized users.
Full Access
Automatically selects all other permissions.
Direct Access
Direct access to the files; changes are made to the original files.
Download
Downloading files.
Create a file
Creating new files.
Copy File
Create copies of a file.
Overwrite File
Overwriting files is allowed.
Rename File
File names can be changed.
Delete File
Files can be deleted.
Create a directory
Additional directories can be created.
Rename Directory
Directory names can be changed.
Delete Directory
Directories can be deleted.
Enable the desired permissions by checking the corresponding checkbox in the "Allow" column. FileWalker users also need permissions for the application and for the page that contains the FileWalker element.
Web Service
To configure web services, you must have the portal permissions "Register Web Services" and access to the "Tools" module.
Implementation of a Login Module
You can find all the information on this topic here.
Generic Rights Management
Requirements
To access Generic Rights Management, the "Enable expert options" checkbox must be selected under "Tools > Options > Portals."
Target Audience
Generic Rights Management is designed for experts who want to manage additional rights beyond those assigned through the dialog-based interface. To use this feature, it helps if you are familiar with "Java Permission Classes."
Function Description
Generic Rights Management allows you to assign the rights classes provided by Intrexx—as well as your own rights classes—to specific objects. You can then assign the objects to rights holders. You can specify which actions should be performed in each case. Later, at runtime, you can use Groovy, for example, to check whether a specific rights holder is allowed to perform a specific action on a specific object and respond accordingly.
The following section provides an example of how to add (another) permission holder to an Intrexx permission class and how to add an additional permission.
Using Intrexx Permission Classes - Adding Permission Holders
Step-by-Step
To add an (additional) permission holder to an Intrexx permission class, follow these steps:
In the main menu, click "Portal > Expert Area > Generic Rights."
To access this menu item, the "Enable expert options" checkbox must be selected under "Tools > Options > Portals."
The "Generic Rights Management" dialog box appears.
Open the "Permission Class" drop-down list.
The rights classes provided or used by Intrexx are displayed.
For information on Intrexx permission classes, see the following links:
Select the desired permission class (
).In the screenshot shown below, the permission class `de.uplanet.lucy.security.permission.ApplicationPermission` has been selected.
The "Object" section (
) displays all objects (applications) that use this permission class. In this case, the identifier is the GUID of the respective application.As soon as you select an identifier, the rights holders are displayed in the "Rights Holders" section (
).As soon as you select a rights holder, the available actions will be displayed in the "Actions" field (
). The "Actions" field is an input field. Here you can add or remove actions (separated by commas).Click the "
" icon.The "Add Rights Holder" dialog box appears.
Select the desired rights holder.
The copyright holder is displayed.
Enter the desired permissions in the "Actions" field.
The screenshot shown below shows the " administration,access" permissions.
Click "Finish."
More Information
Add Your Own Rights Classes
Step-by-Step
To add a custom or new rights class, follow these steps:
Click the "
" icon.The "Rights Class" dialog box appears.
Enter the rights class.
In the screenshot below, this is `java.io.FilePermission`.
Click "OK."
You will return to the "Generic Rights Management" dialog box.
The recorded rights class is displayed.
Click the "
" icon.A new row appears in the "Object" section.
Click in the new row and enter the identifier.
In the screenshot shown below, this is a path to a file.
(For more information, see the FilePermission class
at .)Click the "
" icon in the "Rights Holder" section.The "Add Rights Holder" dialog box appears.
Select the desired rights holder.
You will return to the "Generic Rights Management" dialog box.
The copyright holder is displayed.
Enter the desired permissions in the "Actions" field.
The screenshot below shows the read and write permissions.
Click "Finish."
More Information

























