cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Showing results for 
Search instead for 
Did you mean: 

Community Tip - You can change your system assigned username to something more personal in your community settings. X

ACLs for DefaultEPMDocument instead of EPMDocument?

pwilliams-3
12-Amethyst

ACLs for DefaultEPMDocument instead of EPMDocument?

Hi Everyone,
We are going to start using Arbortext IsoDraw which requires the usage and configuration of the DynamicDocument and IllustrationSource.

[cid:image001.png@01CED54A.16E70C60]

I have 2 roles on the product team: RoleA is a CAD/IsoDraw user and creates CAD Documents, Dynamic Documents and Illustration Sources; RoleB is a CAD user and creates CAD Documents. I want to validate with you all the following requirements and I want to know if there is a configuration that can make this possible:

1. RoleA CAN create CAD Documents, Dynamic Documents and Illustration Sources.

2. RoleB CAN create CAD Documents but CANNOT create Dynamic Documents or Illustration Sources.

In the Policy Administrator I can't configure an ACL at the CAD Document level. Only the EPM Document and the other soft types are available. I want to do this so that if a user in RoleB tries to create a Dynamic Document, and an ACL is NOT found, then Windchill doesn't allow him to create the Dynamic Document because an EPMDocument ACL IS found. Sorry if that was hard to follow.

I guess my basic question is this: If an ACL is NOT found for an EPMDocument soft type and role, will Windchill use the ACL defined at the parent type and role to grant the access?


Patrick Williams | Engineering Systems | c: 616.947.2110
[cid:image003.jpg@01CED54D.E10592C0]

1 REPLY 1

>> I guess my basic question is this: If an ACL is NOT found for an
EPMDocument soft type and role, will Windchill use the ACL defined at the
parent type and role to grant the access?



Yes, it will. Assuming same domain level, If I grant create on EPMDocument
and deny create on Dynamic Document, for the same principal, it would negate
or be equivalent to no rule existing so "none" or implicit deny. Addiing in
additional domains behaves same way but adds additional dimensions like
going from 2D to 3D to 4D and truth table becoming more complicated.



Personally, I try to wipe out all default ACL's and re-grant as soft types
just to control things better.








Announcements


Top Tags