[Geoserver-users] Creating users with different privileges

Hi,

I’ve read something up on Geoserver 2.2.3 security in docs, but I quite don’t get how it is supposed to work. Let’s say I’d like to have one ADMIN account with privileges to access and change all the workspaces/stores/layers and several USER accounts that would only be able to change workspaces/stores/layers they created on their own.

Can this be done via the user interface? Thank you.


Michal Zimmermann (zimmi)
WWW: http://www.zimmi.cz

AFAIK there is no concept of a workspace owner. Try the following

add a user for each workspace
add a role for each workspace
assign the role to the user
add a data access rule for the workspace using the role

Hope that helps

Christian

Zitat von Michal Zimmermann <zimmicz@anonymised.com>:

Hi,
I've read something up on Geoserver 2.2.3 security in docs, but I quite
don't get how it is supposed to work. Let's say I'd like to have one ADMIN
account with privileges to access and change all the
workspaces/stores/layers and several USER accounts that would only be able
to change workspaces/stores/layers they created on their own.

Can this be done via the user interface? Thank you.

--
Michal Zimmermann (zimmi)
WWW: http://www.zimmi.cz

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.

Could you provide some more details please? Right now I have 67 workspaces in Geoserver and I don’t think creating separate roles for each of them is what I’m looking for. Is it possible to define a role, assign it to multiple users and to multiple workspaces?

I would be most glad for an example or a how-to,as the concept of users/roles/services/groups seems quite complicated to me.

···

On Sun, Jan 20, 2013 at 5:58 AM, <christian.mueller@anonymised.com> wrote:

AFAIK there is no concept of a workspace owner. Try the following

add a user for each workspace
add a role for each workspace
assign the role to the user
add a data access rule for the workspace using the role

Hope that helps

Christian

Zitat von Michal Zimmermann <zimmicz@anonymised.com>:

Hi,
I’ve read something up on Geoserver 2.2.3 security in docs, but I quite
don’t get how it is supposed to work. Let’s say I’d like to have one ADMIN
account with privileges to access and change all the
workspaces/stores/layers and several USER accounts that would only be able
to change workspaces/stores/layers they created on their own.

Can this be done via the user interface? Thank you.


Michal Zimmermann (zimmi)
WWW: http://www.zimmi.cz


This message was sent using IMP, the Internet Messaging Program.


Michal Zimmermann (zimmi)
WWW: http://www.zimmi.cz

On Sun, Jan 20, 2013 at 5:58 AM, <christian.mueller@anonymised.com> wrote:

AFAIK there is no concept of a workspace owner. Try the following

add a user for each workspace
add a role for each workspace
assign the role to the user
add a data access rule for the workspace using the role

Afaik Justin added the concept of workspace level admin when
working on the “per service workspace” improvements a few
months ago.

See:
http://geoserver.org/display/GEOS/GSIP+74±+Finer+Grained+Admin+Security

Cheers
Andrea

==
Our support, Your Success! Visit http://opensdi.geo-solutions.it for more information.

Ing. Andrea Aime
@geowolf
Technical Lead

GeoSolutions S.A.S.
Via Poggio alle Viti 1187
55054 Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 339 8844549

http://www.geo-solutions.it
http://twitter.com/geosolutions_it


Zitat von Michal Zimmermann <zimmicz@anonymised.com>:

Could you provide some more details please? Right now I have 67 workspaces
in Geoserver and I don't think creating separate roles for each of them is
what I'm looking for. Is it possible to define a role, assign it to
multiple users and to multiple workspaces?

Yes it is. Or alternatively, you can assign role to user groups and add users to the group.

I would be most glad for an example or a how-to,as the concept of
users/roles/services/groups seems quite complicated to me.

On Sun, Jan 20, 2013 at 5:58 AM, <christian.mueller@anonymised.com> wrote:

AFAIK there is no concept of a workspace owner. Try the following

add a user for each workspace
add a role for each workspace
assign the role to the user
add a data access rule for the workspace using the role

Hope that helps

Christian

Zitat von Michal Zimmermann <zimmicz@anonymised.com>:

Hi,

I've read something up on Geoserver 2.2.3 security in docs, but I quite
don't get how it is supposed to work. Let's say I'd like to have one ADMIN
account with privileges to access and change all the
workspaces/stores/layers and several USER accounts that would only be able
to change workspaces/stores/layers they created on their own.

Can this be done via the user interface? Thank you.

--
Michal Zimmermann (zimmi)
WWW: http://www.zimmi.cz

------------------------------**------------------------------**----
This message was sent using IMP, the Internet Messaging Program.

--
Michal Zimmermann (zimmi)
WWW: http://www.zimmi.cz

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.