ACL problem

I think I’ve lost my mind. I’ve unchecked the delete attribute to every entry in the ACL of a database I have. Yet, I (or anyone) can still delete documents. The database is on a server and enforce consistant acl is on. Could the ACL be corrupt? I feel like I’m forgetting something basic.

Subject: ACL problem

Have you tried using the Effective Access button in the Admin Client - Manage ACL tool ? Does this match what you see in the ACL? If not then it is possible you have a corrupt ACL.

You don’t mention what sort of database this is. If it is not a standard template then are you sure that the documents are deleted, not just removed from the view / folder by the QueryDocumentDelete event?

Subject: RE: ACL problem

Well it is still a mystery. I’ll try and add more here:There are 3 ACL entries as follows:

-Default-

Unspecified Author

Create Documents

NO DELETE rights

Write Public Documents

Replicate or Copy Documents

Dom/ISIS

Server Manager

NO DELETE rights

Scott Kingery/ISIS (me)

Person Manager

NO DELETE RIGHTS

I shut down my Notes session and started a new one using a different ID that. The effective access of the ID is used is:

-Default-

Create

Read public

Write public

Replicate or copy

The effective Access button in the Admin Client does match the ACL.

The template is a modified mail file to provide just a calendar.

Subject: RE: ACL problem

What does the template’s ACL look like?

Subject: ACL problem

Anytime you are change any of the ACL settings (like removing the delete privilege), all users of the database have to leave the database in order for the new ACL settings to take affect.

I don’t think it is corrupt, but you have users in the database whose client does not have the updated ACL settings.

Subject: RE: ACL problem

Thanks Joe. I replicated the database to a server that only I have access too and I can still delete documents. It’s really weird.

Subject: RE: ACL problem

What is weird if you have access and delete?

I would say close your notes client down and then reopen and see if you still have those privileges.

Subject: ACL problem

Scott,

You did not provide enough steps for us to determine whether there is a problem. As the previous posters suggested, client/user has to close the database first, then reopen for the new right to kick in. If that does not work, please provide a step by step on how this can be reproduced.

And also is the document a public document ? If it is, then what is the “Write public document” is what determine whether a user can delete that public document or not.

Thanks,

ShiuFun