Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

ACL

The ACL of a mount grants rights, path by path; everything else is refused. It is written under [[roles.mounts.acl]], and its path is relative to the mount.

Writing an ACL

[[roles.mounts]]
backend = "disque"
mount_path = "/partenaire"
home_dir = "/partenaires/acme"

[[roles.mounts.acl]]
path = "/"                    # /partenaire for the user
rights = ["list"]             # not recursive: this folder only

[[roles.mounts.acl]]
path = "/in"                  # /partenaire/in
rights = ["write", "list"]
recursive = true              # and everything below it

All the keys: Reference [[roles.mounts.acl]].

An ACL governs only its own mount, even on a backend mounted twice.

The rights

Each operation requires its right on each path it names:

OperationRequired right
upload, mkdirwrite on the path, and on each parent that must be created
downloadread
listinglist on the listed directory
stat (SFTP), HEAD (REST)read or list
deleting a file, an empty directorydelete
deleting a non-empty directorydelete on the whole tree
renamerename on the source and the destination, and write where the moved content lands

A listing shows the whole directory, without filtering by the ACL. list on /in does not give list on /.

Which entry decides

  1. Refusal by default: a path that no entry governs is refused.
  2. The most specific entry decides: the one for the exact path, otherwise the closest recursive entry above it.
  3. A more specific entry that does not grant the right refuses, even under a broader entry that grants it.
[[roles.mounts.acl]]
path = "/"
rights = ["read", "write", "list", "delete", "rename"]
recursive = true

[[roles.mounts.acl]]
path = "/archives"
rights = ["read", "list"]
recursive = true

Here everything is writable, except /archives and its content, read only.

A move is judged again on what it carries: a folder that contains a protected subfolder does not move to a place governed by a broader entry, where the subtree would lose its protection.

Several roles on one mount

Two roles on the same mount put their ACLs together:

  • two entries at the same path merge their rights, and a single recursive makes the union recursive;
  • at different paths, the most specific entry decides, whichever role it comes from.

A narrow entry from one role can therefore restrict what a broad entry from another granted. The result is shown in the console, in the roles tab of a session (GET /admin/sessions/<id>/roles).

Synthetic directories

With several mounts under names, a path under no mount (/, /partenaires) is synthetic: it belongs to no backend.

OperationOn a synthetic path
listingthe mounts and the synthetic directories it contains
stata directory, dated from the start of the session
?rights (REST)["list"]
any other operationrefused
path under which there is no mount (/inconnu)not found

A mount point (/partenaires/acme) is listed according to its ACL, but is not written, deleted or renamed.

Name case

When a backend’s ACL folds case (case_insensitive), /Archives and /archives are a single path: write it once per mount.