Permission Table Quick Reference

Example:

 @mygroup,
 @someothergroup,
 rd_*.*,
 ed_*.*,
 -ed_Internal*.*,
 -ed_*.*Private

By default, no permissions are granted. Different permission entries may be specified to alter this (separate by comma):

  • @<group> - grants all rights that <group> possesses (these group membership entries take effect at their place of occurrence in affirmative direction only)
  • * - grants all rights
  • pr - may change his profile
  • pw - may change his password
  • ps - may set passwords for users/groups below
  • ad - may access admin tool
  • cu - may create or delete users/groups
  • eu - may edit permissions of users/groups below
  • ip - may alter ip adress related settings
  • rd_<pagespec> - may read all pages/groups matching <pagespec>
  • ed_<pagespec> - may edit all pages/groups matching <pagespec>
  • up_<pagespec> - may upload to all pages/groups matching <pagespec>
  • hi_<pagespec> - may view history (page changes) of all pages/groups matching <pagespec>
  • xx_<pagespec> - level joker matching on all page related levels
  • ...{$AuthId}... - in all LoggedInUsers permission tables replaced by upper-cased version of user name the client is logged in as
  • #... - rest of line is comment (note it also must have a comma at the end to separate it from other entries)

<pagespec> is a pattern which can contain '*' and '?' to match an arbitrary string and a single character, respectively. It must contain the dot. Examples: Site.*, PerDayLog_????_??_??.*, *.*MySpecialEnding.

By prepending an entry with a minus, i.e. -<entry>, the respective right is denied. For this purpose the entries are interpreted in the order they occur in the permission table, switching permission on or off as they apply. The complete table is processed to obtain the final result. So

 rd_*.*
 -rd_Site.*
 rd_Site.PageActions

grants the right to read the complete pmwiki site apart from the 'Site' group, with the exception in turn of the page 'Site.PageActions'. (Note that the negation is not possible for group membership entries and the * entry.)

Edit this quick reference