Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #240256

Re: Development permissions

From Georgi Naplatanov <gosho@oles.biz>
Newsgroups linux.debian.user
Subject Re: Development permissions
Date 2021-09-22 07:40 +0200
Message-ID <D0398-2jy-5@gated-at.bofh.it> (permalink)
References <D00XD-Z0-1@gated-at.bofh.it> <D01qG-18M-5@gated-at.bofh.it> <D01TH-1xs-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 9/22/21 07:15, Paul M. Foster wrote:
> 
> On 9/21/21 11:42 PM, Georgi Naplatanov wrote:
>> On 9/22/21 06:09, Paul M. Foster wrote:
>>> Folks:
>>>
>>> This is probably a stupid question for many of you, but I've been
>>> struggling with it since I started using Linux in 1996.
>>>
>>> Say you have a directory in which there are development files. A number
>>> of users will be creating, deleting and modifying the files there. This
>>> is the type of situation which might have been common on old Unix
>>> university systems. (Users might be accessing files via Samba, NFS, or
>>> locally.)
>>>
>>> Just to make this more concrete, assume the development tree is in
>>> /var/www/html/website.
>>>
>>> Without setting directory and file permissions to 777, how do you allow
>>> the above? What combinations of groups, directory owners/permissions and
>>> file owners/permissions might make this possible?
>>>
>> Hi Paul,
>>
>> you can create a user group, add all developers to it and give this
>> group permissions to read and write to that particular folder
>> (/var/www/html/website).
>>
>> If you need more granular permissions (e.g. several development teams)
>> then you can use ACLs (Access Control List).
>>
>> Kind regards
>> Georgi
>>
> This is more or less the solution I tried. However, when a user creates
> a file on this system, the permissions are (for example) paulf:paulf.
> This means that, despite the directory permissions, other users won't be
> able to modify the file normally (assuming a system umask of 022).
> 
> However, I did just read an excellent explanation of the setgid bit,
> which apparently, sets the GID of a created file to that of the
> directory, rather than the file's creator. This might work. I haven't
> tested it yet.
> 
> I've heard of ACLs, but never had the need to user or learn about this.
> I'm assuming that attending to ACL issues requires additional steps in
> the creation/editing/deletion of files?
> 

I have not used ACLs either. I heard about them about 15 or more years
ago and it required parameter (as I can remember) during file system
creation. I don't know what is the situation now.

Kind regards
Georgi

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Development permissions "Paul M. Foster" <paulf@quillandmouse.com> - 2021-09-22 05:20 +0200
  Re: Development permissions Charles Curley <charlescurley@charlescurley.com> - 2021-09-22 05:50 +0200
    Re: Development permissions "Paul M. Foster" <paulf@quillandmouse.com> - 2021-09-22 06:20 +0200
      Re: Development permissions David Christensen <dpchrist@holgerdanske.com> - 2021-09-22 06:30 +0200
      Re: Development permissions Felix Miata <mrmazda@earthlink.net> - 2021-09-22 06:40 +0200
      Re: Development permissions Anssi Saari <as@sci.fi> - 2021-09-22 09:30 +0200
  Re: Development permissions Georgi Naplatanov <gosho@oles.biz> - 2021-09-22 05:50 +0200
    Re: Development permissions "Paul M. Foster" <paulf@quillandmouse.com> - 2021-09-22 06:20 +0200
      Re: Development permissions Andrei POPESCU <andreimpopescu@gmail.com> - 2021-09-22 07:40 +0200
        Re: Development permissions Andrei POPESCU <andreimpopescu@gmail.com> - 2021-09-25 08:40 +0200
      Re: Development permissions Georgi Naplatanov <gosho@oles.biz> - 2021-09-22 07:40 +0200
      Re: Development permissions Tim Woodall <debianuser@woodall.me.uk> - 2021-09-22 10:30 +0200
  Re: Development permissions Reco <recoverym4n@enotuniq.net> - 2021-09-22 09:00 +0200
    Re: Development permissions Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2021-09-24 10:30 +0200
      Re: Development permissions Reco <recoverym4n@enotuniq.net> - 2021-09-24 11:30 +0200
        Re: Development permissions Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2021-09-24 11:50 +0200
          Re: Development permissions Reco <recoverym4n@enotuniq.net> - 2021-09-24 15:30 +0200
        Re: Development permissions <tomas@tuxteam.de> - 2021-09-24 14:10 +0200
          Re: Development permissions Reco <recoverym4n@enotuniq.net> - 2021-09-24 15:10 +0200
            Re: Development permissions Andy Smith <andy@strugglers.net> - 2021-09-24 15:50 +0200
            Re: Development permissions <tomas@tuxteam.de> - 2021-09-24 16:10 +0200
  Re: Development permissions Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-09-24 04:40 +0200

csiph-web