Node with deny permission editable by users on administrators group - AEM 6.5 | Community
Skip to main content
Level 2
November 6, 2020
Solved

Node with deny permission editable by users on administrators group - AEM 6.5

  • November 6, 2020
  • 2 replies
  • 1636 views

Hi community!

 

I have a node on CRX with rep:policy deny jcr:write to everyone, I have modified permission programatically because I need to activate / deactivate permissions according to  property, but users on administrators group can modify node. Why?? Any suggestion?  I am working with AEM 6.5  Thanks.

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by ramgopalm545617

It all depends on the order of the ACLs in aem, go to crx de and check the access control in the right side panel. 

Try rearranging the order of the rules, you can drag the ACLs in the list, the last rule will take precedence. 

2 replies

SureshDhulipudi
Community Advisor
Community Advisor
November 6, 2020

by default administrators group has full control - the precedence is deny first and then allow, as the admin group has full access, the users on admin group will get automatically all access including modify.

You can try create a custom admin group and add those users, then provide necessary access.

abcr1Author
Level 2
November 9, 2020
ramgopalm545617Accepted solution
Level 4
November 9, 2020

It all depends on the order of the ACLs in aem, go to crx de and check the access control in the right side panel. 

Try rearranging the order of the rules, you can drag the ACLs in the list, the last rule will take precedence.