Which is having higher precedence ACL or Closed Group. | Community
Skip to main content
Level 6
August 3, 2022
Solved

Which is having higher precedence ACL or Closed Group.

  • August 3, 2022
  • 4 replies
  • 2089 views

Lets say I have MyFolder in Assets.

I have set 10 users ACL as jcr:read.

out of 10 only for 4 users I have set as a closed users/group.

Then in effect how many users will able to access the Myfolder.

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by Sachin_Arora_

I validated directly on publisher after login from 2 different users. User A from Group A and User B from Group B. I tested on we-retail assets folder and for only User A it was visible in CRXDE.

4 replies

Ravi_Pampana
Community Advisor
Community Advisor
August 3, 2022

Hi,

 

I think all 10 users should have access to the folder as all of them are given read access. 

Adobe Employee
August 3, 2022

Please check the ACL resolution for specific groups. That will give you an idea about the permission being set on on the specific resources.

 

Go to Tools -> Security->Permissions and select the user for which you want to check the permissions

Level 3
August 4, 2022

Hello - All 10 users should have read access to the "Assets" folder.

Level 6
August 4, 2022

Hi @s1101v 

If this is so then what is the usecase of CUG

Sachin_Arora_
Community Advisor
Community Advisor
August 4, 2022

Only 4 users should have access as CUG will allow jcr:read access to only those users/group which are added at folder level. For other 6 users, even if you give read access it will be non-effective and that folder wont be accessible to them.

Refer this screenshot from : 

https://experienceleague.adobe.com/docs/experience-manager-learn/assets/advanced/closed-user-groups.html?lang=en

I have validated similar use case using 2 groups(A and B) while only group A was added in CUG. Both groups had full access of content in terms of permission but for only group A folder is accessible. 

Level 6
August 4, 2022

hi @sachin_arora_  Thank you 

I have validated similar use case using 2 groups(A and B) while only group A was added in CUG. Both groups had full access of content in terms of permission but for only group A folder is accessible. 

How you check this 

using json responce?

Sachin_Arora_
Community Advisor
Sachin_Arora_Community AdvisorAccepted solution
Community Advisor
August 4, 2022

I validated directly on publisher after login from 2 different users. User A from Group A and User B from Group B. I tested on we-retail assets folder and for only User A it was visible in CRXDE.