Hi,
we have defined groups for LDAP users to give them different access to certain parts of the adminUI.
But in all groups I have to add ROLE_ADMIN_UI (which makes more or less sense), but also ROLE_ANONYMOUS.
What is the reason for that in the adminUI ?
Even if this role is needed to "show" the login page (a fact which I as an adopter also do not understand),
this role could/should be removed after a successfully login into the adminUI.
After the migration many of our series and events are available to everybody in the adminUI,
because they have attached the role ROLE_ANONYMOUS.
These media received this role to make them public in the engage node and
to allow an integration in a web-page (otherwise Opencast player would not play them).
But it was never the intension to show each detail to everybody in the adminUI.
Regards
Ruth
_______________________________
Universität zu Köln
Regionales Rechenzentrum (RRZK)
Weyertal 121, Raum 4.08
D-50931 Köln