I tried the following thing. I had a nsf on local , created a form and put a readers field on it computed to some arbitrary string. When i save the document created by this form i can see the document although i expected to not see it because of the readers field.
I tried similar thing in an nsf on a server and there it works as expected. I cannot see the documents i saved because of the readers field value
Can any one help me understand this behaviour. Why does the readers field not show the desired affect when i was trying it on local ?
… but only if you check the “Enforce Consistency ACL in all replicas” in the DB’s ACL. By the other hand, Only ACL’s Roles and People Name are secure to use. If you include some Group name, it is validated with the Local Address Book, and obviously, the user can create the group if not exists, or add him/her self if already exists.