The way I use user groups, certain groups should not have any filter associated. (E.g. based on skill and trust certain people get method change function privileges. I do this via a group so that it is easy to audit) Anyone being added to such a user group will already be a member of another group(s) and there they may have one or more filters already. When creating such groups I used to untick the default filter and move on, thinking that I was getting what I wanted. This morning I noticed (version 7.1.0.413937) that the default filter gets added back when you're not looking. There seems to be no way of creating a user group without a filter. Is that true or can anyone tell me how to make sure that no filter gets defaulted into the group?
Sam Troost
Hello Sam,
it seems as if this is an inconsistent behavior in our administration module. I will discuss this with the developers, but I would ask you kindly to report this bug to the ARIS Support to enter the official and formal correct procedure to solve the problem and get the solution into our service release and back to the customer.
Regards
Uwe
Hi André and Sam,
the last comment is correct regarding the current behavior. But Sam's use case makes sense and so we think about to change this. It should be possible to create also user groups without assigned filter. If it comes to the situation, that a certain user has no assigned filter and also does not get a filter via his group(s) he should not be able to log in and get an error message in this case. This should be a satisfying solution for all required use cases.
Regards
Uwe
Hi Uwe,
I understood your idea.. but I tried to simulate and I created a new user without filter but the ARIS shows this message: "there is no method filter available. Filter 'entire method' is used. Do yo want to proceed?"
I click in OK but when I access the proprieties of user the filter "entire" is assigned to user automatically so when the user try the login isn't possible shows the error massage like this case of topic...
well I don't see why to create a new user/group without a filter...
Regards,
..
.
Hello André,
there is only one special case where a usergroup without a filter makes sense. If you make sure in administration that all single users have assigend the right filter(s) they need for their work and if you want to combine the users to groups only to manage the access rights it might be that some users get additional filters assigned via the group at the moment, because there is o way to create a group without filter assigment.
We discuss at the moment if we should change the behavior to support also this use case and to include it into one of the next service releases. Currently it works only the way you have described.
Regards
Uwe
Hi André and Sam,
did some test in the last week and the existing behavior is ok. It is possible to create a user group without an assigned filter. Unfortunately the properties dialog displays in this case the standard filter of the database, but this filter is not propagated to the users of the group!
I did the following: Created two users, each of them assigned to a different reduced filter. Created a user group with these users but without filter (in property dialog appears the entire method checked, because this is the standard filter of the database). If I now log in as one of the users I can only see the content matching his reduced filter, ignoring the fact, that the entire methos seems to be assigned to the user group if I open the property dialog.
So from my point of view all possible use cases can be done with the current version.
Best regards
Uwe