The tables below provide a comprehensive view of all permissions assigned to each default role, group and user.

You can get a list of all permissions assigned to a user or group using the permission list tool.

Roles

anonymous

The anonymous role defines the permissions of public, unauthenticated users. Permissions on the author and public instances differ.

InstanceSpacePermissionScopePath
bothDmsRead onlySelected and sub nodes/
 ExpressionsRead onlySelected and sub nodes/
 ResourcesRead onlySelected and sub nodes/
 StoreRead onlySelected and sub nodes/
authorURLDeny accessn/a*
  Deny accessn/a/.magnolia*
 WebsiteDeny AccessSelected and sub pages/
publicURLGet & Postn/a*
  Deny accessn/a/.magnolia*
  Deny accessn/a/.magnolia/*
  Deny accessn/a/demo-project/members-area/protected*
 WebsiteRead onlySelected and sub pages/

Note that in addition to the anonymous role, the systems user, anonymous, is assigned the categorization-base, contact-base, imaging-base and public-user-registration-base (public only) roles to provide access to all necessary assets.

superuser

The superuser role provides full access to the system.

SpacePermissionScopePath
ConfigRead/WriteSelected and sub nodes/
 Read/WriteSelected and sub nodes/modules/workflow/config/flows
DataRead/WriteSelected and sub nodes/
DmsRead/WriteSelected and sub nodes/
ExpressionsRead/WriteSelected and sub nodes/
ForumRead onlySelected and sub nodes/
ImagingRead/WriteSelected and sub nodes/
PackagerRead/WriteSelected and sub nodes/
ResourcesRead/WriteSelected and sub nodes/
ScriptsRead/WriteSelected and sub nodes/
StoreRead/WriteSelected and sub nodes/
TemplatesRead/WriteSelected and sub nodes/
URLGet & Postn/a*
UsergroupsRead/WriteSelected and sub nodes/
UserrolesRead/WriteSelected and sub nodes/
UsersRead/WriteSelected and sub nodes/
WebsiteRead/WriteSelected and sub pages/

Note that in addition to the superuser role, the systems user, superuser, is assigned the forum_ALL-admin role and to the publishers group to provide unlimited access to all workspaces.

demo-project roles

The demo-project roles allow users to access the system from STK point of view and provide varying permissions for editors, publishers and protected pages.

RoleSpacePermissionScopePath
demo-project-baseConfigRead onlySelected and sub nodes/modules/adminInterface/config/menu/website
  Read onlySelected and sub nodes/modules/adminInterface/config/menu/dms
  Read onlySelected node/modules/adminInterface/config/menu/data
  Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/Contact
  Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/category
  Read onlySelected and sub nodes/modules/data/config/types
 DataRead onlySelected and sub nodes/
 DmsRead onlySelected and sub nodes/templating-kit
 ResourcesRead onlySelected and sub nodes/
 URLGet & Postn/a*
demo-project-editorConfigRead onlySelected and sub nodes/modules/standard-templating-kit/templates
 DataRead/WriteSelected and sub nodes/
 DmsRead/WriteSelected and sub nodes/demo-project
  Read onlySelected and sub nodes/$
 WebsiteRead/WriteSelected and sub pages/demo-project
  Read onlySelected and sub pages/$
demo-project-publisherDataRead onlySelected and sub nodes/
 DmsRead onlySelected and sub nodes/demo-project
  Read onlySelected and sub nodes/$
 WebsiteRead onlySelected and sub pages/demo-project
  Read onlySelected and sub pages/$
demo-project-memberURLGet & Postn/a/demo-project/members-area/protected*

Forum roles

RoleSpacePermissionScopePath
forum-baseForumRead onlySelected and sub nodes/
 URLGet & Postn/a/.magnolia/pages/forum*
forum-moderator-baseConfigRead onlySelected and sub nodes/modules/adminInterface/config/menu/forum
 ForumRead onlySelected and sub nodes/
 URLGet & Postn/a*
forum-pagecomments-adminForumAdminister (Moderate, Delete and Activate)Selected and sub nodes/pagecomments
forum-pagecomments-moderatorForumModerate and DeleteSelected and sub nodes/pagecomments
forum-pagecomments-userForumPost (Write)Selected and sub nodes/pagecomments
forum_ALL-adminForumAdminister (Moderate, Delete and Activate)Selected and sub nodes/
 URLGet & Postn/a/.magnolia/pages/forum*
forum_ALL-moderatorForumModerate and DeleteSelected and sub nodes/
 URLGet & Postn/a/.magnolia/pages/forum*
forum_ALL-userForumPost (Write)Selected and sub nodes/
 URLGet & Postn/a/.magnolia/pages/forum*

Base roles

categorization-base

SpacePermissionScopePath
DataRead onlySelected and sub nodes/categorization

contact-base

SpacePermissionScopePath
DataRead onlySelected and sub nodes/contacts

imaging-base

SpacePermissionScopePath
ImagingRead/WriteSelected and sub nodes/

public-user-registration-base

SpacePermissionPath
URLGet & Post/.magnolia/pages/password-reminder*
 Get & Post/.magnolia/pages/user-validation*
 Get & Post/.magnolia/pages/register*

resources-base

SpacePermissionScopePath
ConfigRead onlySelected and sub nodes/modules/resources
 Read onlySelected and sub nodes/modules/adminInterface/config/menu/templating-kit/resources
 Read onlySelected node/modules/adminInterface/config/menu/templating-kit
ResourcesRead/WriteSelected and sub nodes/

rss-aggregator-base

SpacePermissionScopePath
DataRead onlySelected and sub nodes/rssaggregator

scripter

SpacePermissionScopePath
ConfigRead onlySelected node/modules/adminInterface/config/menu/tools
 Read onlySelected node/modules/adminInterface/config/menu/tools/groovyInteractiveShell
 Read onlySelected node/modules/adminInterface/config/menu/tools/scripts
ScriptsRead/WriteSelected and sub nodes/
URLGet & Postn/a*

security-base

SpacePermissionScopePath
URLDeny accessn/a/.magnolia/pages/installedModulesList.html
 Deny accessn/a/.magnolia/pages/jcrUtils.html
 Deny accessn/a/.magnolia/log4j
 Deny accessn/a/.magnolia/pages/configuration.html
 Deny accessn/a/.magnolia/pages/logViewer.html
 Deny accessn/a/.magnolia/pages/sendMail.html

templater-base

SpacePermissionScopePath
ConfigRead onlySelected node/modules/inplace-templating/
 Read onlySub nodes/modules/inplace-templating
 Read onlySelected and sub nodes/modules/adminInterface/config/menu/templating-kit/templates
TemplatesRead/WriteSelected and sub nodes/

workflow-base

SpacePermissionScopePath
ConfigRead onlySelected and sub nodes/modules/workflow/config/flows
 Read onlySelected and sub nodes/modules/adminInterface/config/menu/inbox
ExpressionsRead/WriteSelected and sub nodes/
StoreRead/WriteSelected and sub nodes/

Groups

demo-project-editors

Assigned groupAssigned roleSpacePermissionScopePath
 demo-project-baseConfigRead onlySelected and sub nodes/modules/adminInterface/config/menu/website
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/dms
   Read onlySelected node/modules/adminInterface/config/menu/data
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/Contact
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/category
   Read onlySelected and sub nodes/modules/data/config/types
  DataRead onlySelected and sub nodes/
  DmsRead onlySelected and sub nodes/templating-kit
  ResourcesRead onlySelected and sub nodes/
  URLGet & Postn/a*
 demo-project-editorConfigRead onlySelected and sub nodes/modules/standard-templating-kit/templates
  DataRead/WriteSelected and sub nodes/
  DmsRead/WriteSelected and sub nodes/demo-project
   Read onlySelected and sub nodes/$
  WebsiteRead/WriteSelected and sub pages/demo-project
   Read onlySelected and sub pages/$
 imaging-baseImagingRead/WriteSelected and sub nodes/
editorsworkflow-baseConfigRead onlySelected and sub nodes/modules/workflow/config/flows
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/inbox
  ExpressionsRead/WriteSelected and sub nodes/
  StoreRead/WriteSelected and sub nodes/

demo-project-publishers

Assigned groupAssigned roleSpacePermissionScopePath
 demo-project-baseConfigRead onlySelected and sub nodes/modules/adminInterface/config/menu/website
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/dms
   Read onlySelected node/modules/adminInterface/config/menu/data
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/Contact
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/category
   Read onlySelected and sub nodes/modules/data/config/types
  DataRead onlySelected and sub nodes/
  DmsRead onlySelected and sub nodes/templating-kit
  ResourcesRead onlySelected and sub nodes/
  URLGet & Postn/a*
 demo-project-publisherDataRead onlySelected and sub nodes/
  DmsRead onlySelected and sub nodes/demo-project
   Read onlySelected and sub nodes/$
  WebsiteRead onlySelected and sub pages/demo-project
   Read onlySelected and sub pages/$
 imaging-baseImagingRead/WriteSelected and sub nodes/
publishersworkflow-baseConfigRead onlySelected and sub nodes/modules/workflow/config/flows
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/inbox
  ExpressionsRead/WriteSelected and sub nodes/
  StoreRead/WriteSelected and sub nodes/

demo-project-members

Author instance

Assigned rolesSpacePermissionScopePath
anonymousDmsRead onlySelected and sub nodes/
 ExpressionsRead onlySelected and sub nodes/
 ResourcesRead onlySelected and sub nodes/
 StoreRead onlySelected and sub nodes/
 URLDeny accessn/a*
  Deny accessn/a/.magnolia*
 WebsiteDeny AccessSelected and sub pages/
demo-project-memberURLGet & Postn/a/demo-project/members-area/protected*
public-user-registration-baseURLGet & Postn/a/.magnolia/pages/password-reminder*
  Get & Postn/a/.magnolia/pages/user-validation*
  Get & Postn/a/.magnolia/pages/register*
resources-baseConfigRead onlySelected and sub nodes/modules/resources
  Read onlySelected and sub nodes/modules/adminInterface/config/menu/templating-kit/resources
  Read onlySelected node/modules/adminInterface/config/menu/templating-kit
 ResourcesRead/WriteSelected and sub nodes/
imaging-baseImagingRead/WriteSelected and sub nodes/
contact-baseDataRead onlySelected and sub nodes/contacts

Public instance

Assigned roleSpacePermissionScopePath
anonymousDmsRead onlySelected and sub nodes/
 ExpressionsRead onlySelected and sub nodes/
 ResourcesRead onlySelected and sub nodes/
 StoreRead onlySelected and sub nodes/
 URLGet & Postn/a*
  Deny accessn/a/.magnolia*
  Deny accessn/a/.magnolia/*
  Deny accessn/a/demo-project/members-area/protected*
 WebsiteRead onlySelected and sub pages/
demo-project-memberURLGet & Postn/a/demo-project/members-area/protected*
public-user-registration-baseURLGet & Postn/a/.magnolia/pages/password-reminder*
  Get & Postn/a/.magnolia/pages/user-validation*
  Get & Postn/a/.magnolia/pages/register*
resources-baseConfigRead onlySelected and sub nodes/modules/resources
  Read onlySelected and sub nodes/modules/adminInterface/config/menu/templating-kit/resources
  Read onlySelected node/modules/adminInterface/config/menu/templating-kit
 ResourcesRead/WriteSelected and sub nodes/
imaging-baseImagingRead/WriteSelected and sub nodes/
contact-baseDataRead onlySelected and sub nodes/contacts

editors

workflow-base

Assigned roleSpacePermissionScopePath
workflow-baseConfigRead onlySelected and sub nodes/modules/workflow/config/flows
  Read onlySelected and sub nodes/modules/adminInterface/config/menu/inbox
 ExpressionsRead/WriteSelected and sub nodes/
 StoreRead/WriteSelected and sub nodes/

publishers

workflow-base

Assigned roleSpacePermissionScopePath
workflow-baseConfigRead onlySelected and sub nodes/modules/workflow/config/flows
  Read onlySelected and sub nodes/modules/adminInterface/config/menu/inbox
 ExpressionsRead/WriteSelected and sub nodes/
 StoreRead/WriteSelected and sub nodes/

The editors and publishers groups are created by the Workflow module and assigned identical permissions. Two distinct groups are necessary for the workflows to function correctly. For more information see Workflow definition.

Users

anonymous (systems user)

Author instance

Assigned roleSpacePermissionScopePath
anonymousDmsRead onlySelected and sub nodes/
 ExpressionsRead onlySelected and sub nodes/
 ResourcesRead onlySelected and sub nodes/
 StoreRead onlySelected and sub nodes/
 URLDeny accessn/a*
  Deny accessn/a/.magnolia*
 WebsiteDeny AccessSelected and sub pages/
categorization-baseDataRead onlySelected and sub nodes/categorization
contact-baseDataRead onlySelected and sub nodes/contacts
imaging-baseImagingRead/WriteSelected and sub nodes/

Public instance

Assigned roleSpacePermissionScopePath
anonymousDmsRead onlySelected and sub nodes/
 ExpressionsRead onlySelected and sub nodes/
 ResourcesRead onlySelected and sub nodes/
 StoreRead onlySelected and sub nodes/
 URLGet & Postn/a*
  Deny accessn/a/.magnolia*
  Deny accessn/a/.magnolia/*
  Deny accessn/a/demo-project/members-area/protected*
 WebsiteRead onlySelected and sub pages/
categorization-baseDataRead onlySelected and sub nodes/categorization
contact-baseDataRead onlySelected and sub nodes/contacts
imaging-baseImagingRead/WriteSelected and sub nodes/

superuser (systems user)

Assigned groupAssigned roleSpacePermissionScopePath
 superuserConfigRead/WriteSelected and sub nodes/
   Read/WriteSelected and sub nodes/modules/workflow/config/flows
  DataRead/WriteSelected and sub nodes/
  DmsRead/WriteSelected and sub nodes/
  ExpressionsRead/WriteSelected and sub nodes/
  ForumRead onlySelected and sub nodes/
  ImagingRead/WriteSelected and sub nodes/
  PackagerRead/WriteSelected and sub nodes/
  ResourcesRead/WriteSelected and sub nodes/
  StoreRead/WriteSelected and sub nodes/
  TemplatesRead/WriteSelected and sub nodes/
  URLGet & Postn/a*
  UsergroupsRead/WriteSelected and sub nodes/
  UserrolesRead/WriteSelected and sub nodes/
  UsersRead/WriteSelected and sub nodes/
  WebsiteRead/WriteSelected and sub pages/
 forum_ALL-adminForumAdminister (Moderate, Delete and Activate)Selected and sub nodes/
  URLGet & Postn/a/.magnolia/pages/forum*
publishersworkflow-baseConfigRead onlySelected and sub nodes/modules/workflow/config/flows
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/inbox
  ExpressionsRead/WriteSelected and sub nodes/
  StoreRead/WriteSelected and sub nodes/

eric (user)

Assigned groupAssigned roleSpacePermissionScopePath
demo-project-editorsdemo-project-baseConfigRead onlySelected and sub nodes/modules/adminInterface/config/menu/website
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/dms
   Read onlySelected node/modules/adminInterface/config/menu/data
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/Contact
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/category
   Read onlySelected and sub nodes/modules/data/config/types
  DataRead onlySelected and sub nodes/
  DmsRead onlySelected and sub nodes/templating-kit
  ResourcesRead onlySelected and sub nodes/
  URLGet & Postn/a*
 demo-project-editorConfigRead onlySelected and sub nodes/modules/standard-templating-kit/templates
  DataRead/WriteSelected and sub nodes/
  DmsRead/WriteSelected and sub nodes/demo-project
   Read onlySelected and sub nodes/$
  WebsiteRead/WriteSelected and sub pages/demo-project
   Read onlySelected and sub pages/$
 imaging-baseImagingRead/WriteSelected and sub nodes/
editorsworkflow-baseConfigRead onlySelected and sub nodes/modules/workflow/config/flows
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/inbox
  ExpressionsRead/WriteSelected and sub nodes/
  StoreRead/WriteSelected and sub nodes/

peter (user)

Assigned groupAssigned roleSpacePermissionScopePath
demo-project-publishersdemo-project-baseConfigRead onlySelected and sub nodes/modules/adminInterface/config/menu/website
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/dms
   Read onlySelected node/modules/adminInterface/config/menu/data
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/Contact
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/data/category
   Read onlySelected and sub nodes/modules/data/config/types
  DataRead onlySelected and sub nodes/
  DmsRead onlySelected and sub nodes/templating-kit
  ResourcesRead onlySelected and sub nodes/
  URLGet & Postn/a*
 demo-project-publisherDataRead onlySelected and sub nodes/
  DmsRead onlySelected and sub nodes/demo-project
   Read onlySelected and sub nodes/$
  WebsiteRead onlySelected and sub pages/demo-project
   Read onlySelected and sub pages/$
 imaging-baseImagingRead/WriteSelected and sub nodes/
publishersworkflow-baseConfigRead onlySelected and sub nodes/modules/workflow/config/flows
   Read onlySelected and sub nodes/modules/adminInterface/config/menu/inbox
  ExpressionsRead/WriteSelected and sub nodes/
  StoreRead/WriteSelected and sub nodes/

Users eric and peter have workflow permissions by their assignment to the demo-project-editors and demo-project-publishers groups that are in turn assigned to the editors and publishers groups.

#trackbackRdf ($trackbackUtils.getContentIdentifier($page) $page.title $trackbackUtils.getPingUrl($page))
  • No labels