1.3.5.8.1.3. Tabbed page "Rights assignment"

All assigned or all existing users and groups from all trusted domains/forests are listed on the Rights assignment [Assign rights] Tabbed page.

[Note]Note

Depending on the environment, the list may not be complete.

[Tip]Tip

Working method when configuring:

-> Enter search text

-> select all available [all existing]

-> Perform search

In this way, work through the desired groups or users step by step. Case sensitivity can be crucial. The valid configuration is visible after selecting the radio button Assigned only [only assigned]. If a group or user cannot be found at all, the Add manually... [Add manually ...] button can be used. button can be used.

The button becomes active if only assigned is active and users [User] or groups [Groups] are selected somewhere.

By default, a logged-in user can see, control and delete their own pipelines, create and delete their own analyses and see all analyses; 3DfindIt User should also be activated by default. Otherwise there is no access to 3DfindIt. See also below.

"Rights assignment [Assign rights]" Tabbed page (only assigned [only assigned] )

"Rights assignment [Assign rights]" Tabbed page (only assigned [only assigned] )

If you want a special user or a special group to have extended rights, proceed as follows:

  1. Under Known users/groups, select the option All existing [all existing].

    -> All users/groups are listed.

    "Rights assignment [Assign rights]" Tabbed page ( all available [all existing] )

    "Rights assignment [Assign rights]" Tabbed page ( all available [all existing] )

  2. Select the desired user or group under Users/Groups [Users/groups].

  3. Activate the desired profiles on the right under Profiles.

    [Note]Note

    If no predefined profile fits, you can define your own on the Rights Tabbed page.

    [Note]Note

    If you want to assign all available rights to a user/group, make sure that you do not accidentally activate the Deny Access to 3Dfindit (3dfindit-nonuser) profile.

Priority

In principle, the following applies:

  • User configurations overwrite group configurations

  • Overwrite group configurations Defaults (logged in/not [Logged in] logged in [Not logged in] )

  • If a user is a member of different groups, the rights of the group with higher priority are taken.

Testing

Click on Test... the Check authentication [Check authentification...] dialog box opens.... [Check authentification...]

Check authentication... [Check authentification...]

Check authentication... [Check authentification...]

Enter your user name [Username] and password [Password].

Click on Load to load all user data and rights.

By clicking on Log in [Login], you can check whether the Windows login is correct. If the entry is incorrect, the evaluation is empty. Entering the password is optional.

Check authentication. [Check authentification...]..: Incorrect password

Check authentication. [Check authentification...]..: Incorrect password

1.3.5.8.1.3.1.  Additional points to note with 3Dfindit
  • 3DFindit User:

    When using 3dfindit, at least 3Dfindit User must be activated in PARTadmin under Profiles for the authorized users and groups; otherwise there is no access to 3Dfindit.

  • 3DFindit Admin:

    May list all 3Dfindit users and all active sessions.

    Can see the user assignments in the PARTapplicationServer dashboard.

  • LinkDb User:

    If the function Add [Add to link database] to link database [Add to link database] (also variants) is to be executable in 3Dfindit, the profile LinkDb user. Can add parts to link database. (linkdb-user) must be activated.

    [Note]Note

    This is the default setting for logged-in users.

    However, if a SiteSetup already exists due to changes, the role must be activated manually.

    [Note]Note

    No rights are required to use the Request ERP number function.

  • LinkDb Administrator:

    If existing data records are to be edited, the profile LinkDb administrator. Can add/modify/delete data in link database (linkdb-admin) must be activated.

  • Deny Access to 3Dfindit (3dfindit-nonuser)

    If you want to lock out specific users or groups from 3Dfindit, you can assign this profile to take away their usage rights - even if another configuration says that the user is a 3Dfindit user.

    Example:

    CNS\CNS_AGB => 3dfindit-user
    CNS\specific_user => 3dfind-nonuser

    Alle AGB-User sind erlaubt - aber der spezifische User ist nicht erlaubt.

    The setting is therefore required if you want to deny access to certain groups or users, despite the fact that other groups or * allow it.

To view the rights in detail, switch to the Rights tabbed page.

1.3.5.8.1.3.2. Configure display in the category tree via rights management

In a client-server environment, the tabbed page Rights assignment [Assign rights] also controls which categories are to be displayed in PARTadmin on clients in the Category dialog area.

There is always full access to the category structure [Category] on the server.

Default admin setting

Default admin setting

[Important]Important

Immediately after setting up the client-server environment, the category tree is displayed in full on all clients. If this is not desired, the configuration options described below must be carried out first.

If you want to carry out the configuration on a client, make sure that you are logged in with a user who has admin rights, as this is the only way to access the Application Server > Rights management [Rights administration] menu item.

1.3.5.8.1.3.2.1. Configure "PARTadmin Admin Mode"

In standard admin mode, the complete category structure [Category] is displayed.

  1. In the category structure [Category] under Application Server, select Rights management [Rights administration].

  2. Select the Rights assignment [Assign rights] tab.

  3. In the Known users/groups dialog area, select the desired user or group (here in the example "admin1").

  4. If the admin mode is to be activated, either activate the profile PARTadmin Administrator Mode (All Settings) (partadmin-admin) in the Known Profiles [Known profiles] dialog area or leave ALL options deactivated (which corresponds to activating all options [see following figure]).

  5. Click Finally, click the Save button.

1.3.5.8.1.3.2.2. Configure "PARTadmin user mode"
  1. In the category structure [Category] under Application Server, select Rights management [Rights administration].

  2. Select the Rights assignment [Assign rights] tab.

  3. Select the desired user or group in the Known users/groups dialog area.

  4. Activate the PARTadmin user mode (partadmin-user) profile in the Known profiles dialog area. The other profiles starting with "PARTadmin" must be deactivated.

    PARTadmin user mode activated

    PARTadmin user mode activated

    [Note]Note

    Only the profiles starting with "PARTadmin" are relevant for the display in the category structure [Category].

  5. Click Finally, click the Save button.

  6. If you want to check the setting, switch to a client (if you are not already).

  7. Click on the Change user button.

    → The Authenticate user dialog box opens.

  8. Log in with the configured user and check the display in the category structure [Category].

    → Only the categories CAD integration and configuration files [Configuration files] > $CADENAS_USER are displayed.

    Mode of a standard user who is only allowed to change his own settings.

    Mode of a standard user who is only allowed to change his own settings.

1.3.5.8.1.3.2.3. Configure "PARTadmin ERP mode"
  1. In the category structure [Category] under Application Server, select Rights management [Rights administration].

  2. Select the Rights assignment [Assign rights] tab.

  3. Select the desired user or group in the Known users/groups dialog area.

  4. Activate the PARTadmin Erp Admin Mode (partadmin-erpadmin) profile in the Known Profiles [Known profiles] dialog area.

    [Note]Note

    Only the profiles starting with "PARTadmin" are relevant for the display in the category structure [Category].

  5. Click Finally, click the Save button.

  6. If you want to check the setting, switch to a client (if you are not already).

  7. Click on the Change user button.

    → The Authenticate user dialog box opens.

  8. Log in with the configured user and check the display in the category structure [Category].

    → Only the categories ERP environment and configuration files [Configuration files] > $CADENAS_USER are displayed.

    Category tree with category "ERP environment [ERP environment]"

    Category tree with category "ERP environment [ERP environment]"

1.3.5.8.1.3.2.4. Configure "PARTadmin catalog mode"
  1. In the category structure [Category] under Application Server, select Rights management [Rights administration].

  2. Select the Rights assignment [Assign rights] tab.

  3. Select the desired user or group in the Known users/groups dialog area.

  4. Activate the PARTadmin Catalog Admin Mode (partadmin-catalogadmin) profile in the Known Profiles [Known profiles] dialog area.

    [Note]Note

    Only the profiles starting with "PARTadmin" are relevant for the display in the category structure [Category].

  5. Click Finally, click the Save button.

  6. If you want to check the setting, switch to a client (if you are not already).

  7. Click on the Change user button.

    → The Authenticate user dialog box opens.

  8. Log in with the configured user and check the display in the category structure [Category].

    → Only the categories Catalogs and Configuration files > $CADENAS_USER are displayed.

    Category tree with category "Catalogs [Catalogs]"

    Category tree with category "Catalogs [Catalogs]"

1.3.5.8.1.3.3. Restricted access to PARTlinkManager with client access

The following applies to access to PARTlinkManager:

  • Anyone can use PARTlinkManager on the server and therefore has the right to read, change and write entries.

  • On clients, only users with the linkdb-linkmanager right or the linkdb-admin profile have these rights.

    The system checks whether this right exists when you log in. If not, the following message appears:

    You need the right 'linkdb-linkmanager' or the profile 'linkdb-admin' to use this application.