Overview of Permission Conflicts in Legacy Groups
When transitioning from the legacy permissions system to a new one, conflicts can arise if groups previously included both readers and contributors. The way permissions are assigned and interpreted changes, which can impact user access levels.
- Legacy groups could contain both readers and contributors.
- In the new Permissions system, readers and contributors are combined into a single role called Site Users
Key Terms
Understanding the following terms is essential for grasping how permission conflicts occur:
- Legacy Permissions: The original system for assigning user roles and access rights.
- Reader: A legacy role user who can view content but cannot make changes.
- Contributor: A legacy role for a user who can edit or add content.
- Admin Area: The section of the system where administrative tasks are performed.
- Site User: In the new system, a consolidated role combining readers and contributors.
Background: Legacy vs. New Permissions System
In the legacy system, groups could have a mix of readers and contributors. Even if a group had permission to access the admin area or edit content, readers within that group were still restricted by their role and could not perform those actions.
The new permissions system consolidates the contributor and reader roles into a single "site user" role. This means that all users in such a group may now have elevated permissions, potentially allowing former readers to access areas or perform actions they previously could not.
- Legacy groups enforced role-based restrictions even within the same group.
- The new system simplifies roles but may grant broader access.
Options for a Successful Migration
Organizations must decide how to handle groups that previously mixed readers and contributors. Options include creating separate groups for different access levels or granting all users in the group the same elevated permissions.
Decide whether to split groups by access level or unify permissions.
- Example
- Legacy Group: "Our Team"
- New Groups:
- Our Team - Read Access
- Our Tean - Admin Access
- Example