AEM6 - User is member of two groups which have rules that exclude each other
Hi everyone
I'm currently having a problem with permissions for a user who is a member of two groups which have read rules that exclude the other group.
E. g. the structure might be /content/internet/country1/... and /content/internet/country2/... For both countries there is a reader group that has read rights for the respective country while all other countries are denied (e.g. 100-reader-country1 can only read /content/internet/country1/.. & 100-reader-country2 can only read /content/internet/country2/...). There are other groups like 200-contributor-country1 (inherites from 100-reader-country1 and adds write/update/delete rights) and 300-approver-country1 (inherits from 200-contributor-country1 and adds replication rights) . This is working fine as long as a user is only a member of a group that belongs to a single country. As soon as such a user is a member of two different country groups he gets denied to both countries (e.g. 100-reader-country1 denies him to read /content/internet/country2/... and 100-reader-country2 denies him to read /content/internet/country1/...).
Is there a way to allow a user who is a member of 300-approver-country1 & 300-approver-country2 access to those two country sites w/o creating an extra group for this use case?
Any help is much appreciated.