Permission Table Quick Reference
Example:
@mygroup, @someothergroup, rd_*.*, ed_*.*, -ed_Internal*.*, -ed_*.*Private
By default, no permissions are granted. Different permission entries may be specified to alter this (separate by comma):
@<group>- grants all rights that<group>possesses (these group membership entries take effect at their place of occurrence in affirmative direction only)*- grants all rightspr- may change his profilepw- may change his passwordps- may set passwords for users/groups belowad- may access admin toolcu- may create or delete users/groupseu- may edit permissions of users/groups belowip- may alter ip adress related settingsrd_<pagespec>- may read all pages/groups matching<pagespec>ed_<pagespec>- may edit all pages/groups matching<pagespec>up_<pagespec>- may upload to all pages/groups matching<pagespec>hi_<pagespec>- may view history (page changes) of all pages/groups matching<pagespec>xx_<pagespec>- level joker matching on all page related levels...{$AuthId}...- in all LoggedInUsers permission tables replaced by upper-cased version of user name the client is logged in as#...- rest of line is comment (note it also must have a comma at the end to separate it from other entries)
<pagespec> is a pattern which can contain '*' and '?' to match an arbitrary string and a single character, respectively. It must contain the dot. Examples: Site.*, PerDayLog_????_??_??.*, *.*MySpecialEnding.
By prepending an entry with a minus, i.e. -<entry>, the respective right is denied. For this purpose the entries are interpreted in the order they occur in the permission table, switching permission on or off as they apply. The complete table is processed to obtain the final result. So
rd_*.* -rd_Site.* rd_Site.PageActions
grants the right to read the complete pmwiki site apart from the 'Site' group, with the exception in turn of the page 'Site.PageActions'. (Note that the negation is not possible for group membership entries and the * entry.)