ACL
The ACL of a mount grants rights, path by path; everything else is refused.
It is written under [[roles.mounts.acl]], and its path is
relative to the mount.
Writing an ACL
[[roles.mounts]]
backend = "disque"
mount_path = "/partenaire"
home_dir = "/partenaires/acme"
[[roles.mounts.acl]]
path = "/" # /partenaire for the user
rights = ["list"] # not recursive: this folder only
[[roles.mounts.acl]]
path = "/in" # /partenaire/in
rights = ["write", "list"]
recursive = true # and everything below it
All the keys: Reference [[roles.mounts.acl]].
An ACL governs only its own mount, even on a backend mounted twice.
The rights
Each operation requires its right on each path it names:
| Operation | Required right |
|---|---|
upload, mkdir | write on the path, and on each parent that must be created |
| download | read |
| listing | list on the listed directory |
stat (SFTP), HEAD (REST) | read or list |
| deleting a file, an empty directory | delete |
| deleting a non-empty directory | delete on the whole tree |
| rename | rename on the source and the destination, and write where the moved content lands |
A listing shows the whole directory, without filtering by the ACL. list on
/in does not give list on /.
Which entry decides
- Refusal by default: a path that no entry governs is refused.
- The most specific entry decides: the one for the exact path, otherwise
the closest
recursiveentry above it. - A more specific entry that does not grant the right refuses, even under a broader entry that grants it.
[[roles.mounts.acl]]
path = "/"
rights = ["read", "write", "list", "delete", "rename"]
recursive = true
[[roles.mounts.acl]]
path = "/archives"
rights = ["read", "list"]
recursive = true
Here everything is writable, except /archives and its content, read only.
A move is judged again on what it carries: a folder that contains a protected subfolder does not move to a place governed by a broader entry, where the subtree would lose its protection.
Several roles on one mount
Two roles on the same mount put their ACLs together:
- two entries at the same path merge their rights, and a single
recursivemakes the union recursive; - at different paths, the most specific entry decides, whichever role it comes from.
A narrow entry from one role can therefore restrict what a broad entry from
another granted. The result is shown in the console, in the roles tab of a
session (GET /admin/sessions/<id>/roles).
Synthetic directories
With several mounts under names, a path under no mount (/,
/partenaires) is synthetic: it belongs to no backend.
| Operation | On a synthetic path |
|---|---|
| listing | the mounts and the synthetic directories it contains |
stat | a directory, dated from the start of the session |
?rights (REST) | ["list"] |
| any other operation | refused |
path under which there is no mount (/inconnu) | not found |
A mount point (/partenaires/acme) is listed according to its ACL, but is
not written, deleted or renamed.
Name case
When a backend’s ACL folds case
(case_insensitive),
/Archives and /archives are a single path: write it once per mount.