{"id":237,"date":"2019-11-01T13:44:46","date_gmt":"2019-11-01T13:44:46","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/access-roles-leading-to-a-user\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"accespathuser","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/accespathuser","title":{"rendered":"Access rules in multi-tenant apps should lead to CurrentUser"},"content":{"rendered":"\n<p> For multi-tenant apps check if entity has access rule with xPath leading to the current user .<\/p>\n\n\n\n<p> Make very sure that for apps which serve multiple customers (e.g. companies) have very strict entity access so a user can only see what should be accessible for this user. <\/p>\n\n\n\n<p> A multi-tentant app usually has a \u2018tenant\u2019 entity. The \u2018tenant\u2019 entity has an association to the user as usually stored in Administration.Account. All other entities that contain data per tentant have an xpath on the entity access rule leading to the current user via the \u2018tenant\u2019 entity. So by requiring all access rules for a certain project role to have an xpath ending with \u2018tenant\u2019 and account means requiring a good secure configuration.  <\/p>\n\n\n\n<p>As parameter, you can specifically specify what the access rule should look like, see the template:<\/p>\n\n\n\n<p><code>\u2018<\/code><strong><code>&lt;Project-Role>;&lt;Match-operator:endsWith|equals|excludeEntity|excludeModuleRole>;&lt;Path>;   (multiple lines possible)<\/code><\/strong><code>\u2019<\/code>  <\/p>\n\n\n\n<p>Options excludeEntity and excudeModuleRole are added in v1.5 to be able to easy handle exceptions like data for all users.<\/p>\n\n\n\n<p>Example where the role &#8216;User&#8217; requires all entity access to go via  Administration.Project to  Administration.Account  over association   Administration.Account_Projects_Member : <\/p>\n\n\n\n<p><code>User;endsWith;Administration.Project\/Administration.Account_Projects_Member='[%CurrentUser%]']<\/code><\/p>\n\n\n\n<p>Also allowed is direct access on  Administration.Account :<\/p>\n\n\n\n<p><code>User;equals;[id='[%CurrentUser%]'] <\/code><\/p>\n\n\n\n<p>So multiple lines are tried. Only one needs to match, so if none match it is a violation.<\/p>\n\n\n\n<p>Real example : Configuration for the SMART Digital Factory itself<\/p>\n\n\n\n<p><code>User;endsWith;Administration.Project\/Administration.Account_Projects_Member='[%CurrentUser%]']; \/\/ via multi tenant entity<br> User;endsWith;_Account='[%CurrentUser%]']; \/\/ per user data<br> User;excludeEntity;Administration.Account,Administration.Project;\/\/ exception for Account and Project, the multi tenant entity<br> User;excludeModuleRole;UserGlobal; \/\/ exceptions to multi tenancy via module role named UserGlobal<\/code><\/p>\n\n\n\n<p>So most user data goes via the first config line. Some data like user settings or temporary downloads of files go via the second config line. For Account and the multi tenant entity we make an exception. These should be check manually. Alternatively we could add config lines matching equal for them.<\/p>\n\n\n\n<p>For data that is needed for all users, thus across tenants, we use a module role with a different name. This also brings additional clarity to the design!<\/p>\n\n\n\n<p>Real example : Configuration for APM Manager <\/p>\n\n\n\n<p><code>APMUser;endsWith;Administration.Account_EnvironmentReadPermissions='[%CurrentUser%]']; \/\/ per environment read<br> APMUser;endsWith;Administration.Account_EnvironmentWritePermissions='[%CurrentUser%]']; \/\/ per environment write<br> APMUser;endsWith;Administration.Account_EnvironmentAdminPermissions='[%CurrentUser%]']; \/\/ per environment admin<br> APMUser;endsWith;_Project\/Administration.Project\/Administration.Account_ProjectMember='[%CurrentUser%]']; \/\/ per project<br>APMUser;endsWith;_Account='[%CurrentUser%]']; \/\/ per user data<br> APMUser;excludeEntity;Administration.Account,Administration.Project;<\/code><\/p>\n\n\n\n<p>APM has a multi tenant entity Project and within project you can configure multiple environments. So the setup is a bit more complex, but still the same principles apply.<\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-237","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/237"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=237"}],"version-history":[{"count":11,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/237\/revisions"}],"predecessor-version":[{"id":1172,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/237\/revisions\/1172"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Anonymous users should only be allowed to create non-persistent entities","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/anonymouscreateobject","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1249"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=237"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}