Difference between revisions of "NF1.0 Role Inheritance"

From iDempiere en
(template)
 
m (Text replace - "http://jira.idempiere.com" to "http://idempiere.atlassian.net")
 
(17 intermediate revisions by 3 users not shown)
Line 7: Line 7:
 
'''Description:'''
 
'''Description:'''
  
<span style="color:red">'''''To Be Documented'''''</span>
+
Actually iDempiere supports role inheritance - a role can be composed by included roles, and in such case it inherits the configuration for menu access options and for org access.
  
'''Technical Info:''' [http://jira.idempiere.com/browse/IDEMPIERE-366 IDEMPIERE-366]
+
This feature extended the concept to enable defining master roles in System client, the master roles in System client can have menu access options (but cannot have org access options, because orgs are not available on System).
  
 +
* The Client (not System) roles can inherit from System roles the access options, and configure exceptions for the roles: adding specific access not included in master role or  disabling (adding and inactivating) options included in the master role
  
[[Category:New Features v0.01|S]]
+
* The inheritance work just for menu items, documents, but not for org.
[[Category:To Be Documented]]
+
 
 +
* Users cannot be assigned to Master Roles.
 +
 
 +
* The list of "Included roles" only show "Master Roles"
 +
 
 +
 
 +
New Flag in the Window Role "Master Role" to create a Master Role
 +
 
 +
[[File:role1.png]]
 +
 
 +
The Client (not System) roles can inherit from Master Role, In the tab "Included Roles" in window "Role"
 +
 
 +
[[File:role2.png]]
 +
 
 +
Is it possible also to configure Document Action Access on System Master Roles to be inherited to roles, to do that you must create base documents on System.
 +
 
 +
'''Technical Info:''' [http://idempiere.atlassian.net/browse/IDEMPIERE-366 IDEMPIERE-366]
 +
 
 +
[[en:NF1.0 Role Inheritance]]
 +
[[de:NF1.0 Rolle vererben]]
 +
 
 +
 
 +
[[Category:New Features|S]]
 +
[[Category:New Features v1.0|S]]
 +
[[Category:New Features Security]]
 +
[[Category:User Manual]]
 +
[[Category:Security]]
 +
[[Category:Role]]
 +
[[Category:User]]

Latest revision as of 20:57, 2 September 2016

Feature: Role Inheritance

Goal: Security

Sponsor: Trek Global

Description:

Actually iDempiere supports role inheritance - a role can be composed by included roles, and in such case it inherits the configuration for menu access options and for org access.

This feature extended the concept to enable defining master roles in System client, the master roles in System client can have menu access options (but cannot have org access options, because orgs are not available on System).

  • The Client (not System) roles can inherit from System roles the access options, and configure exceptions for the roles: adding specific access not included in master role or disabling (adding and inactivating) options included in the master role
  • The inheritance work just for menu items, documents, but not for org.
  • Users cannot be assigned to Master Roles.
  • The list of "Included roles" only show "Master Roles"


New Flag in the Window Role "Master Role" to create a Master Role

Role1.png

The Client (not System) roles can inherit from Master Role, In the tab "Included Roles" in window "Role"

Role2.png

Is it possible also to configure Document Action Access on System Master Roles to be inherited to roles, to do that you must create base documents on System.

Technical Info: IDEMPIERE-366

Cookies help us deliver our services. By using our services, you agree to our use of cookies.