Theme
Permissions
Permissions live on your Storage Connector and are granted per user, per virtual file system. See Permissions for how to set them.
The twelve abilities
| Ability | What it allows |
|---|---|
| List folder contents | Seeing what is in a folder |
| Create folders | Making a new folder |
| Edit folder metadata | Changing a folder's timestamps |
| Rename folders | |
| Delete folders | |
| Download files | Reading a file |
| Upload files | Creating a new file |
| Overwrite or append to files | Changing an existing file |
| Edit file metadata | Changing a file's timestamps |
| Rename files | |
| Delete files | |
| Create symbolic links |
The five presets
| Ability | View and download | Upload only | Drop box | Full access | Everything |
|---|---|---|---|---|---|
| List folder contents | yes | yes | yes | yes | |
| Create folders | yes | yes | yes | ||
| Edit folder metadata | yes | yes | |||
| Rename folders | yes | yes | |||
| Delete folders | yes | yes | |||
| Download files | yes | yes | yes | ||
| Upload files | yes | yes | yes | yes | |
| Overwrite or append to files | yes | yes | |||
| Edit file metadata | yes | yes | |||
| Rename files | yes | yes | |||
| Delete files | yes | yes | |||
| Create symbolic links | yes |
Two that catch people out:
- Upload only grants creating folders and adding new files. It does not grant overwriting, and it does not grant downloading. A user can put a file there and cannot read it back or replace it.
- Drop box grants uploading and nothing else, not even listing. The user cannot see what is in the folder, including their own earlier uploads.
The custom groups
Custom offers six grouped toggles rather than twelve raw abilities.
| Toggle | Grants |
|---|---|
| Browse folders | List folder contents |
| Download | Download files |
| Upload and overwrite | Upload files; overwrite or append to files |
| Create and rename | Create folders; rename folders; rename files; edit folder metadata; edit file metadata |
| Delete | Delete files; delete folders |
| Symbolic links | Create symbolic links |
Path rules
Inside one folder, rules can grant access to a subtree, for example /reports.
Rules only ever allow. Anything not covered by a rule is denied. A rule cannot subtract from access.
How the two halves combine
Access is the intersection of a Portal decision and a Connector decision.
| The Portal says | The Connector says | Result |
|---|---|---|
/ maps to Company files | Full access to Company files | A working home directory |
/ maps to Company files | nothing | The folder appears and will not open |
| nothing | Full access to Company files | Permission to a folder that never appears |
| nothing | nothing | No access |
Rules that apply regardless of permissions
A move never crosses a virtual file system boundary, including between two on the same Connector. Clients fall back to copy and delete.
Exactly one mount must be at /. That is where the user lands.
A valid identity with no local grant is refused. There is no default access and no default home directory.
Where a refusal is recorded
Users are told the operation was denied and never why.
The full reason is in the Connector's own Activity log, filterable by Denied only, and in the signed record that cannot be turned off.