Question

Photo of Ross Li

0

Inherited edit rights not working

We have added most of our staff into the Organization Chart and enabled each ministry group to be a security role. In our group viewer, we have a root folder for each ministry with a lot of sub groups underneath. We are using Small Group type for most of there groups. So we assigned each ministry's security role to have edit rights to each ministry subfolder. The edit right will work for each folder, but not any of the subfolder. When checking the group security with an administrator here is what it shows.

Screen Shot 2016-06-07 at 2.03.24 AM.png

 

User in the Care Groups security role has no edit rights in sub groups that inherited the rule from the root folder, same user has edit rights on the root folder, am I missing something here?

  • Photo of Jim Michael

    0

    What version of Rock are you running? There was a fix for a Group inheritance bug that came in 4.6. Not sure if this is your issue, but if you're not on 4.6, definitely upgrade! I can't see in your screen shot but I'm guessing that the All Users is "deny", which is ABOVE your Group - Care Groups role, which is short-circuiting the rights in this case. Recall that rights always flow from top to bottom and the FIRST entry that applies gets used (in this case, All users deny gets applied since the people in Care Groups are also in All Users).

    • Ross Li

      This environment is still on 4.1. I will do a backup than upgrade and see if this still happens on 4.6. In 4.1, it seems like the inherited rule is added to the bottom of the list.

    • Jim Michael

      Yep, that's the way the bug manifests itself. I'm 95% sure upgrading to 4.6 will fix your issue.

    • Ross Li

      Confirmed that the precedence for inherited security rights are now set at the top in 4.6