{"id":3212,"date":"2015-04-23T17:26:42","date_gmt":"2015-04-23T09:26:42","guid":{"rendered":"http:\/\/localhost\/help\/?page_id=3212"},"modified":"2020-11-11T17:18:09","modified_gmt":"2020-11-11T09:18:09","slug":"applying-security-for-explorer","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/applying-security-for-explorer\/","title":{"rendered":"Object Access"},"content":{"rendered":"\n<p class=\"left-bar-yellow\">This article applies to P2 Explorer versions 4.3.0-4.5.5 ONLY. For the latest versions, see <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/\">Security<\/a>.<\/p>\n<p class=\"intro-text\">Explorer uses P2 Security to secure the following objects:<\/p>\n<ul>\n<li class=\"intro-text\">Workspaces<\/li>\n<li class=\"intro-text\">Pages<\/li>\n<li class=\"intro-text\">Trends<\/li>\n<\/ul>\n<p class=\"intro-text\">There are two types of roles in P2\u00a0Security: <em>Application Roles<\/em> and <em>Global Roles<\/em>.\u00a0<\/p>\n<p class=\"left-bar\">Read more: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/application-and-global-roles\/\">Application and Global Roles<\/a><\/p>\n<p class=\"intro-text\">Users are assigned to Global Roles, and the Global Roles can be mapped to the Application Roles, which transfers those application access privileges to users with that Global Role.\u00a0<\/p>\n<p class=\"note\">Note: By default, if no users are assigned to an object, then all users have access to that object. As soon as one or more users are assigned, access is restricted to those users.<\/p>\n<p class=\"intro-text\">For example, if there are no users at all assigned to a workspace, then this is interpreted as being set to 'allow all', giving all users access to the workspace. \u00a0As soon as one user is assigned, then only that user can access that workspace. \u00a0If you want others to be able to see this workspace, then they need to be added as well.<\/p>\n<h2 class=\"page-subheading\">Tutorial: Assigning User Privileges to a Workspace<\/h2>\n<p class=\"note\">Note: This procedure also applies to\u00a0objects in P2 Server (Attribute, Dataset, Entity, Hierarchy, Link, Tag, Template).<\/p>\n<p class=\"intro-text\">To access P2 Security, go to:<\/p>\n<p><code>https:\/\/SERVER_NAME.MY_DOMAIN.COM\/P2.Security.Connect<\/code><\/p>\n<p class=\"intro-text\">Note that the server name must be the fully qualified domain name.<\/p>\n<p class=\"intro-text\">Applying security consists of 3 steps:\u00a0<\/p>\n<ul>\n<li class=\"intro-text\">Adding Global Roles<\/li>\n<li class=\"intro-text\">Assigning Application Roles to the Global Roles<\/li>\n<li class=\"intro-text\">Assigning privileges to the Global Roles<\/li>\n<\/ul>\n<h3>Step 1. Adding Global Roles<\/h3>\n<p class=\"intro-text\">The first thing you should do is work out what your\u00a0<strong>Global Roles<\/strong> are, and then add these in the \u201cGlobal Roles\u201d section in P2 Security.\u00a0<\/p>\n<p class=\"intro-text\">These are roles that exist across applications, so they would apply to both P2 Server and P2 Explorer. These are the different categories of\u00a0users that exist in your customers' business.<\/p>\n<p class=\"intro-text\">Another type of Global role that would commonly be added is some type of System Administration role.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/Globalroles1.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3227 size-large\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/Globalroles1-800x433.png\" alt=\"\" width=\"800\" height=\"433\" \/><\/a><\/p>\n<ul>\n<li class=\"intro-text\">To add a Global Role, click the Add <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3222 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/addbutton.png\" alt=\"addbutton\" width=\"18\" height=\"18\" \/>\u00a0button in the top right of the blue toolbar. \u00a0This will simply allow you to add a name and description.<\/li>\n<li class=\"intro-text\">In here, add the different groups, such as Accountants, Engineers, Developers etc, whatever you need for your organisation.<\/li>\n<\/ul>\n<h3>Step 2. Assigning Application Roles to Global Roles<\/h3>\n<p class=\"intro-text\">If you have a use for any of the Application roles that exist, now is the time to assign them. \u00a0At this point in time, all we have in P2 Explorer is the \u201cExplorer Administrator\u201d role. \u00a0By assigning this Application Role to a Global Role that you have created (such as System Administrator), then you are automatically adding all of the privileged settings to that Global Role in one easy step. When you're configuring the other applications (such as\u00a0P2 Server), then you can assign the same types of Application Roles to this same Global Role, creating a super group that can administer all of the applications.<\/p>\n<p class=\"intro-text\">Note that these Application Roles are built into the application and are fixed, as opposed to the Global Roles\u00a0that are defined by you in P2 Security. \u00a0At this stage it is just a shortcut to adding administration rights for each of the\u00a0applications and allowing you assign it to a Global Role that you have created.<\/p>\n<p class=\"intro-text\">To do these assignments:<\/p>\n<ol>\n<li class=\"intro-text\">Go to the \u201cRole Mapping\u201d section.\u00a0<\/li>\n<li class=\"intro-text\">Choose the application (P2.Explorer) in the left box.<\/li>\n<li class=\"intro-text\">Then choose the role in the right box (Explorer Administrator).<\/li>\n<li class=\"intro-text\">Then, down the bottom left it will show you the list of Global Roles that you have created earlier.\u00a0<\/li>\n<li class=\"intro-text\">To assign a new role, click the role you want to add in the right box, and then click the left arrow to move it into the left box.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/rolemappings.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3389 size-large\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/rolemappings-800x416.png\" alt=\"\" width=\"800\" height=\"416\" \/><\/a><\/p>\n<h3>Step 3. Assigning Privileges to Global Roles for P2 Explorer<\/h3>\n<p class=\"intro-text\">This section is probably where you will be doing most of your work in\u00a0granting\u00a0access to a workspace or a page for a particular Global Role.<\/p>\n<ol>\n<li class=\"intro-text\">For this part, we need to go down to the bottom of the sidebar (on the left), and choose the application you are administering in the \u201cAccess\u201d section. E.g. P2.Explorer.<\/li>\n<li class=\"intro-text\">Choosing this will update the right side on the interface.\u00a0 The section that you are interested in is the <strong>Objects' Security<\/strong> section.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/Objectsecurity.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-3231\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/Objectsecurity-800x450.png\" alt=\"Objectsecurity\" width=\"800\" height=\"450\" \/><\/a><\/p>\n<p class=\"intro-text\">Now, at this point you need to know what you are going to secure: the entire workspace (which will flow down to pages and trends) or a single page or trend.<\/p>\n<p class=\"intro-text\">Let's assume that you are going to secure the whole workspace.\u00a0<\/p>\n<ol>\n<li class=\"intro-text\">Choose <strong>Workspace<\/strong> in the Object Type drop-down list. This will make a call to P2 Explorer and it will return a list of Workspaces that are available in the system.<\/li>\n<li class=\"intro-text\">Click the workspace that you want to secure (in the list). An Edit icon will appear in the top right of the Objects' Security toolbar.\u00a0<\/li>\n<li class=\"intro-text\">Click the Edit icon to open the access editor.<\/li>\n<\/ol>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/objectsecurityworkspace.png\" rel=\"lightbox-3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-3233\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/objectsecurityworkspace-800x193.png\" alt=\"objectsecurityworkspace\" width=\"800\" height=\"193\" \/><\/a><\/p>\n<p class=\"intro-text\">In this example, we're configuring the <em>Development<\/em> workspace.<\/p>\n<p class=\"intro-text\">There are 2 types of privileges:<\/p>\n<ul>\n<li class=\"intro-text\"><strong>View<\/strong>. Read-only access to the object you are configuring. In this example, this means read-only access to the Development workspace.<\/li>\n<li class=\"intro-text\"><strong>Modify<\/strong>. Access to Explorer Studio for the object you are configuring. In this example, this allows the users with this role to modify the pages and trends\u00a0in the Development workspace.<\/li>\n<\/ul>\n<p class=\"intro-text\">There are 2 ways to grant access:<\/p>\n<ul>\n<li class=\"intro-text\"><strong>Allow All<\/strong>. Assigns View and Modify privileges to all of the Global Roles defined in your system.<\/li>\n<li class=\"intro-text\"><strong>Custom<\/strong>. Allows you to set individual View or Modify privileges for each of the roles that you have defined in Step 1.<\/li>\n<\/ul>\n<p class=\"intro-text\">When you have finished assigning access privileges, click <strong>OK<\/strong> and the privileges will be updated, effective immediately.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/editaccess.png\" rel=\"lightbox-4\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-3234\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2015\/04\/editaccess-378x600.png\" alt=\"editaccess\" width=\"378\" height=\"600\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Explorer uses P2 Security to secure Workspaces, Pages and Trends. This article describes how to use P2 Security to secure these objects.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-explorer\/security\/applying-security-for-explorer\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":4672,"parent":26597,"menu_order":10,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[680],"tags":[92,196,316,608],"class_list":["post-3212","page","type-page","status-publish","has-post-thumbnail","hentry","category-security-4-3-0-4-5-5","tag-page","tag-security","tag-trends","tag-workspace","Product-ex"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=3212"}],"version-history":[{"count":2,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3212\/revisions"}],"predecessor-version":[{"id":45664,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3212\/revisions\/45664"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/26597"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/4672"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=3212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=3212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=3212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}