{"id":38025,"date":"2018-04-20T12:01:08","date_gmt":"2018-04-20T04:01:08","guid":{"rendered":"http:\/\/localhost\/help\/?page_id=38025"},"modified":"2024-07-05T10:35:09","modified_gmt":"2024-07-05T02:35:09","slug":"locking-down-an-object","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/locking-down-an-object\/","title":{"rendered":"Locking Down an Object"},"content":{"rendered":"\n<p class=\"left-bar\">This article applies to versions 4.6 and later of IFS OI Explorer.<\/p>\n<p class=\"intro-text\">All roles have\u00a0<em>implicit<\/em> view privileges for all objects in the system, which is designed to allow security administrators to apply object-level privileges to certain roles. When locking down an object, you will need to remove this privilege from each role.<\/p>\n<p class=\"intro-text\">When applying object-level privileges, it is important to remember the cascading nature of privileges applied at the resource-level. If a role has <em>explicit<\/em> View privileges on a <strong>resource<\/strong>, all users with that role can view all objects for that resource, regardless of the privileges at the object level.\u00a0<\/p>\n<div class=\"best-prac\"><i class=\"fa fa-star fa-2x fa-pull-left\"><\/i><span class=\"best-prac-text\">TOP TIP<\/span><\/p>\n<p class=\"intro-text\">If you intend on doing a lot of object-level security, avoid using resource-level security.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-resource.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38011\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-resource.png\" alt=\"\" width=\"880\" height=\"193\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-resource.png 880w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-resource-768x168.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-resource-150x33.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-resource-24x5.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-resource-36x8.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-resource-48x11.png 48w\" sizes=\"auto, (max-width: 880px) 100vw, 880px\" \/><\/a><\/p>\n<p class=\"intro-text\">In the scenario above, Role 1 has been granted an explicit privilege for the resource. Roles 2 and 3, while not given resource privileges, still have default privileges for Object 1.\u00a0\u00a0<\/p>\n<p class=\"intro-text\">However, Role 3 has been given an explicit privilege for Object 2. In doing so, Role 2 is effectively locked out and cannot see Object 2. However, Role 1 still has access to Object 2 because the role has privileges at the resource level, which overrides the object-level privileges.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-security-works\/\">How Security Works<\/a>, <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-roles-work\/\">How Roles Work<\/a>, <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/how-object-access-works\/\">How Object Access Works<\/a><\/p>\n<p class=\"intro-text\">When locking down an object (such as a workspace), you will initially notice that default view privileges have been granted to all roles, even if this has not specifically been defined for the role at the resource level. It is these default privileges that we need to pay attention to.<\/p>\n<p class=\"intro-text\"><strong>From this (in the object e.g. workspace)<\/strong>:<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-default-view-a.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-38064 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-default-view-a.png\" alt=\"\" width=\"611\" height=\"239\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-default-view-a.png 611w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-default-view-a-150x59.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-default-view-a-24x9.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-default-view-a-36x14.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-default-view-a-48x19.png 48w\" sizes=\"auto, (max-width: 611px) 100vw, 611px\" \/><\/a><\/p>\n<p class=\"intro-text\">To lock down an object, you need to remove all of the View privileges for all roles, except for the role you want to have access.<\/p>\n<p class=\"intro-text\"><strong>To this<\/strong>:<br \/>\n<a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-a.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-38063 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-a.png\" alt=\"\" width=\"610\" height=\"239\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-a.png 610w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-a-150x59.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-a-24x9.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-a-36x14.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-a-48x19.png 48w\" sizes=\"auto, (max-width: 610px) 100vw, 610px\" \/><\/a><\/p>\n<p class=\"intro-text\"><strong>Exception<\/strong>: You will not be able to remove the blue inherited privileges. These indicate that the privilege is inherited from an explicit module- or resource-level privilege, such as an admin-level privilege.<\/p>\n<p class=\"intro-text\">While it's easy to understand admin-level privileges, it's the resource-level privileges that can trip you up when trying to secure an object.\u00a0\u00a0<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/add-an-administrator\/\">Add an Administrator<\/a><\/p>\n<p class=\"intro-text\">For example, if one of your roles has resource-level view over an object you are trying to secure, you will not be able to remove that privilege at the object level. In the example below, all users with the Workspace Editor role have explicit View privileges for all workspaces, at the resource level. This is indicated by the blue dot for the Workspace Editor. This cannot be removed at the object level, so these users will still be able to see all pages in all workspaces.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-resource-a.png\" rel=\"lightbox-3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38062\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-resource-a.png\" alt=\"\" width=\"617\" height=\"232\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-resource-a.png 617w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-resource-a-150x56.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-resource-a-24x9.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-resource-a-36x14.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-view-resource-a-48x18.png 48w\" sizes=\"auto, (max-width: 617px) 100vw, 617px\" \/><\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Example: Locking Down a Workspace<\/h2>\n<p class=\"intro-text\">In this example, we show you how to lock down an object. Let's use workspaces as an example \u2014 and <em>Operations<\/em> as the workspace object we want to lock down.\u00a0<\/p>\n<h3>Step 1. Server Management Role Privileges<\/h3>\n<p class=\"intro-text\">The first step is to make sure that no roles have resource-level privileges for workspaces. This step must be performed by a Security administrator.<\/p>\n<p class=\"intro-text\">The exception is the administrator role for the module which owns the object you are locking down. In this case, you might allow Administrators and Explorer Administrators resource-level privileges, but no other role.<\/p>\n<p class=\"intro-text\"><strong>You will need to go through each and every role, one by one, and make sure that all privileges for workspaces are off. It may be easier to first check the workspace to see which roles are affected.<\/strong><\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/change-a-roles-privileges\/\">Change a Role's Privileges<\/a><\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b.png\" rel=\"lightbox-4\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-38095 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b.png\" alt=\"\" width=\"1425\" height=\"795\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b.png 1425w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b-768x428.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b-150x84.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b-1280x714.png 1280w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b-24x13.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b-36x20.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-object-step1b-48x27.png 48w\" sizes=\"auto, (max-width: 1425px) 100vw, 1425px\" \/><\/a><\/p>\n<h3>Step 2. Object Privileges<\/h3>\n<p class=\"intro-text\">This step must be performed by an Explorer administrator.<\/p>\n<p class=\"intro-text\">Open the module in which the object is located. In the case of workspaces, these are located in Explorer. However other objects, such as datasources, are located in other modules and the privileges can be found alongside the configuration options (for the datasources example, these are in <em>Server Management &gt; Configuration &gt; Datasources<\/em>).<\/p>\n<p class=\"intro-text\">Open the workspace you want to lock down, and click the <img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-38098 size-full\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/settings-cog-small-icon.png\" alt=\"\" width=\"12\" height=\"12\" \/>\u00a0<strong>Settings<\/strong>\u00a0button.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace.png\" rel=\"lightbox-5\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38097\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace.png\" alt=\"\" width=\"1226\" height=\"416\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace.png 1226w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-768x261.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-150x51.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-24x8.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-36x12.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-48x16.png 48w\" sizes=\"auto, (max-width: 1226px) 100vw, 1226px\" \/><\/a><\/p>\n<p class=\"intro-text\">Take note of the <strong>View<\/strong> privileges, and especially the <strong>blue<\/strong> ones. These are the roles that have the privilege applied at the resource or module level. If you do not want any of these roles to see this workspace, go back into <strong>Role Privileges<\/strong> and remove it from the role (see Step 1 above).<\/p>\n<p class=\"intro-text\">Next, you will notice that the remaining roles all have <strong>explicit<\/strong> (green) view privileges for the workspace. This is because of default security, whereby all users have view access to all objects. We can override this default security here.<\/p>\n<p class=\"left-bar\">Related: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/default-security-for-everyone\/\">Default Security for Everyone<\/a><\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles.png\" rel=\"lightbox-6\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38099\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles.png\" alt=\"\" width=\"872\" height=\"566\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles.png 872w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-768x498.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-150x97.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-24x16.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-36x23.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-48x31.png 48w\" sizes=\"auto, (max-width: 872px) 100vw, 872px\" \/><\/a><\/p>\n<p class=\"intro-text\">For each role, except the Managers role, go through and untick the <strong>green<\/strong> View privilege. The only role want to be able to view this workspace is the <strong>Managers<\/strong> role, so that will remain green.\u00a0<\/p>\n<p class=\"intro-text\">Then, click <strong>Save<\/strong>.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-deny.png\" rel=\"lightbox-7\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38100\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-deny.png\" alt=\"\" width=\"1018\" height=\"424\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-deny.png 1018w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-deny-768x320.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-deny-150x62.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-deny-24x10.png 24w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-deny-36x15.png 36w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2018\/04\/security-46-workspace-roles-deny-48x20.png 48w\" sizes=\"auto, (max-width: 1018px) 100vw, 1018px\" \/><\/a><\/p>\n<p class=\"intro-text\">You have now locked down the <strong>Operations<\/strong> workspace so that only <strong>Managers<\/strong> and some administrators are able to view it.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This article describes how to lock down an object, such as a workspace, so that only a certain role is able to view it.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/p2-server\/security\/locking-down-an-object\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":1,"featured_media":37939,"parent":3652,"menu_order":31,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[11],"tags":[639,196],"class_list":["post-38025","page","type-page","status-publish","has-post-thumbnail","hentry","category-tutorial","tag-object-security","tag-security","Version-4-6-0","Product-srv"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/38025","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=38025"}],"version-history":[{"count":3,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/38025\/revisions"}],"predecessor-version":[{"id":67816,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/38025\/revisions\/67816"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/3652"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/37939"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=38025"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=38025"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=38025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}