Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #240249

Re: Development permissions

From "Paul M. Foster" <paulf@quillandmouse.com>
Newsgroups linux.debian.user
Subject Re: Development permissions
Date 2021-09-22 06:20 +0200
Message-ID <D01TH-1xs-3@gated-at.bofh.it> (permalink)
References <D00XD-Z0-1@gated-at.bofh.it> <D01qG-18M-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 9/21/21 11:42 PM, Georgi Naplatanov wrote:
> On 9/22/21 06:09, Paul M. Foster wrote:
>> Folks:
>>
>> This is probably a stupid question for many of you, but I've been
>> struggling with it since I started using Linux in 1996.
>>
>> Say you have a directory in which there are development files. A number
>> of users will be creating, deleting and modifying the files there. This
>> is the type of situation which might have been common on old Unix
>> university systems. (Users might be accessing files via Samba, NFS, or
>> locally.)
>>
>> Just to make this more concrete, assume the development tree is in
>> /var/www/html/website.
>>
>> Without setting directory and file permissions to 777, how do you allow
>> the above? What combinations of groups, directory owners/permissions and
>> file owners/permissions might make this possible?
>>
> Hi Paul,
>
> you can create a user group, add all developers to it and give this
> group permissions to read and write to that particular folder
> (/var/www/html/website).
>
> If you need more granular permissions (e.g. several development teams)
> then you can use ACLs (Access Control List).
>
> Kind regards
> Georgi
>
This is more or less the solution I tried. However, when a user creates 
a file on this system, the permissions are (for example) paulf:paulf. 
This means that, despite the directory permissions, other users won't be 
able to modify the file normally (assuming a system umask of 022).

However, I did just read an excellent explanation of the setgid bit, 
which apparently, sets the GID of a created file to that of the 
directory, rather than the file's creator. This might work. I haven't 
tested it yet.

I've heard of ACLs, but never had the need to user or learn about this. 
I'm assuming that attending to ACL issues requires additional steps in 
the creation/editing/deletion of files?

Paul

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Development permissions "Paul M. Foster" <paulf@quillandmouse.com> - 2021-09-22 05:20 +0200
  Re: Development permissions Charles Curley <charlescurley@charlescurley.com> - 2021-09-22 05:50 +0200
    Re: Development permissions "Paul M. Foster" <paulf@quillandmouse.com> - 2021-09-22 06:20 +0200
      Re: Development permissions David Christensen <dpchrist@holgerdanske.com> - 2021-09-22 06:30 +0200
      Re: Development permissions Felix Miata <mrmazda@earthlink.net> - 2021-09-22 06:40 +0200
      Re: Development permissions Anssi Saari <as@sci.fi> - 2021-09-22 09:30 +0200
  Re: Development permissions Georgi Naplatanov <gosho@oles.biz> - 2021-09-22 05:50 +0200
    Re: Development permissions "Paul M. Foster" <paulf@quillandmouse.com> - 2021-09-22 06:20 +0200
      Re: Development permissions Andrei POPESCU <andreimpopescu@gmail.com> - 2021-09-22 07:40 +0200
        Re: Development permissions Andrei POPESCU <andreimpopescu@gmail.com> - 2021-09-25 08:40 +0200
      Re: Development permissions Georgi Naplatanov <gosho@oles.biz> - 2021-09-22 07:40 +0200
      Re: Development permissions Tim Woodall <debianuser@woodall.me.uk> - 2021-09-22 10:30 +0200
  Re: Development permissions Reco <recoverym4n@enotuniq.net> - 2021-09-22 09:00 +0200
    Re: Development permissions Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2021-09-24 10:30 +0200
      Re: Development permissions Reco <recoverym4n@enotuniq.net> - 2021-09-24 11:30 +0200
        Re: Development permissions Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2021-09-24 11:50 +0200
          Re: Development permissions Reco <recoverym4n@enotuniq.net> - 2021-09-24 15:30 +0200
        Re: Development permissions <tomas@tuxteam.de> - 2021-09-24 14:10 +0200
          Re: Development permissions Reco <recoverym4n@enotuniq.net> - 2021-09-24 15:10 +0200
            Re: Development permissions Andy Smith <andy@strugglers.net> - 2021-09-24 15:50 +0200
            Re: Development permissions <tomas@tuxteam.de> - 2021-09-24 16:10 +0200
  Re: Development permissions Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-09-24 04:40 +0200

csiph-web