I know this has been discussed numerous times here but wanted to bring it up again with a specific case.
Here is the scenario:
Two tiers of users - Admins and Staff (arbitrary names)
Both groups have access to an internal system with the ability to edit and download and essentially utilize all features equally. Both groups have the 'e0' (edit access to workflow Open) and the 'ea0' (edit access to Active) permissions. The admin group has in addition the 'v' (can download restricted) permission and the full 'ea1' thru 'ea3' permissions allowing unrestricted editing and access regardless of resource state. OK
Arbitrarily, some usage embargoed images get uploaded by an admin user and they want to RESTRICT the download/edit capability of other staff, but it is important for the whole company to know they exist (not confidential/classified). Naturally the logical idea would be to RESTRICT access to the aforementioned images. OK
Under these conditions, which IMO are pretty standard non-corner-case conditions (as far as permissions), the RESTRICT functionality does nothing. Those newly restricted images are still downloadable by the Staff group. The only way I can seem to get the restrict concept to work is if the 'e0' permission is removed (unchecked) from the Staff group of users. But now, nothing is editable in any access state by that group. Not OK
Going a step further, in an effort to find some solution for these users, we marked the resources 'confidential' and that works great, just as advertised and all-in-all inline with the verbiage of the permission bits. Why is the 'restricted' state so different and not so great?
Seemingly there is some overlap and misunderstanding/misuse of the entire 'e' range of permissions. I read the discussion from 2013 about somehow editing maybe == downloading, this could be same issue, but 2016 version.
Full permission setup nothing overriding in config.php or elsewhere. This particular install is on svn7450, but has been tested with the same results on svn7667. In the system setup, manage sizes: allow restricted download is unchecked.
Admin: s,v,g,q,f*,e-2,e-1,e0,e1,e2,e3,c,i,n,h,j*,t,r,R,Ra,o,m,u,k,a,e
Staff: s,g,q,f*,e0,ea1,ea2,ea3,d,n,dtu,j*
Any ideas and commentary more than welcome.