[This is preliminary documentation and is subject to change.]
Namespace: ContentStudio.Security
Assembly: CSServer5 (in CSServer5.dll) Version: 5.7.5016.0 (5.7.5016.0)
Member name | Value | Description | |
---|---|---|---|
None | 0 | No rights are defined | |
Logon | 1 | User can log on to the Content Studio web interface. | |
AdvancedEdit | 2 | Used by the Content Studio web interface when displaying the visual document editor - Webitor. If this right is set the user can see advanced editing features like displaying source code directly. | |
BypassRevision | 4 | Can bypass revision and publish direct in the Content Studio interface. This bit is valid only when revision support is enabled. | |
LimitedUserInterface | 8 | If set the user can only use the simple user interface. Users holding the GlobalGroupAdmin flag are excluded from this constraint. | |
WriteActiveContent | 16 |
The user can save document with executable content. Also needed for components and categories that hold components.
This right also allows the caller to save uploaded files with restricted file extensions.
Restricted file are defined in the Policies.policy file and by default this policy restricts the the following file extensions that are recognized by the IIS:
| |
DestroyDocuments | 32 | The user can delete document from the recycling bin provided that she has DELETE permissions on affected documents. Normally the caller must have admin permissions on the document but this flag bypasses this constraint. | |
Syncronize | 64 | The user can synchronize document but not delete all the site files. Normally the caller must have globalgroupadmin rights but this flag bypasses this constraint. | |
RestartWebSite | 128 | The user can restart the web site using the Content Studio API (or from the user interface). | |
ServiceQueueAdmin | 256 | The caller can manage the background service queue. This right is used by the CS Service Manager background process only and should not be given to other users. By default the SERVICE group, which indicates that the calling process runs as a Windows service, and the local ADMINISTRATORS group have this right and there are no known reasons to assign this right to any other group. WarningIf this right is removed for the Service Manager account (the SERVICE group) all background processes such as asynchronous Xml indexing and Event Actions will stop working. | |
OwnGroupAdmin | 512 | Allow members to admin group permissions on groups where they are members. This flag is not used in Content Studio version 4.0 and later. | |
GlobalGroupAdmin | 1024 | User can admin all groups and rights. Callers that have this right are effectively administrators in Content Studio. | |
ControlOwnObjects | 2048 |
User can fully control any object she owns.
A user needs the ControlOwnObjects right in order to be able to change permissions on a securable object when the user is the owner but does not explicitly has permission to change the object's permission settings. Users that holds the GlobalGroupAdmin" right have this right implicitly. | |
MaxFlags | -1 | All flag values are set. This value should not be assigned to any object. |