cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Lifecycle State Transition Security - Add a toggle option "Everyone Denied"

Lifecycle State Transition Security - Add a toggle option "Everyone Denied"

When configuring new Lifecycle Definitions, there are {typically, on average} 1 to 3 transitions out of each state that are needed.  The default behavior is "No restrictions on this transition".  Which means that more time is spent configuring the transitions that we don't want (edit transition, security tab, uncheck  "No restrictions on this transition", Add, select member 'everyone', Add to current members, change permission to 'Deny', Ok) than the transitions we do want.   This is especially crucial when the lifecycle definition has many states.

The toggle option (between 'no restriction' to 'everyone denied') would simply let the admin turn off that transition in one step!

No Restrictions (default)No Restrictions (default)Everyone Denied (selected)Everyone Denied (selected)

8 Comments
Anonymous
Not applicable

Hi!

Today, when you add a new state in a lifecycle, you need to save it before modifying restrictions on the state and on the transitions.

But when you save it, Vault allows by default all transitions to everybody, so as soon as you save everybody can put files in this new state even if you don't want... Because by default the following option is checked (see picture).

 

Is it possible to allow anything by default, or to have an option somewhere saying "when ceating a new state I want to allow everything" or "I want to allow nothing".

smilinger
Advisor

When adding new lifecycle definitions, Vault will create transitions for all the states automatically, for example, if I create a new definition of 6 states, there will be 6x5=30 transitions. Most of these transitions are useless, I need to edit these transitions and disable them one by one. It is a very tedious and frustrating process and makes no sense.

 

I hope we can opt to add these transitions manually so that only the really meaningful transitions are listed in the lifecycle definition dialog, no need to edit 30 (or even more) transitions. Another option, maybe we can add a delete button above the transitions list, so we can simply delete those unwanted transitions.

RajSchmidt
Advisor

I rather like the great freedom I have in Vault when configuring lifecycles. But I agree that it is hard work to root out the unnecessary transitions. It would help a lot if the default right for all transitions would be “Denied for all” instead of “No restrictions”. After that you can open up the transitions you need.

RajSchmidt
Advisor

Excellent idea! I would not even need a new toggle. It would be enough if the “Everyone/Denied” would be the default.

(Strangely enough – if you copy a lifecycle every permission is switched to “Denied”. Another pain in the behind.)

Great idea! 

I'm getting tired of opening all possible transitions and disabling most of them (why is 'no restrictions' the default setting?!). I'd also would like to do this in the main overview so you can easily disable certain transitions and don't have to open and edit all transition:

 

lifecycleTransitions.JPG

pleguellec
Explorer

@Silvia.van.Emmerik , enabling/disabling transitions from the main Transitions window is an excellent idea.  You should post it as its own thread.  Also, regarding my original post, I have found a workaround - if you simply uncheck the "no restrictions on this transition" and DO NOT add any members to the security (blank list), select OK, it will give you a message - "You did not specify any members in the ACL.  Are you sure you want to continue?" - and select Yes.  This means that no-one is allowed (as there is no-one in the ACL list) and essentially  achieve the same result as 'everyone denied'.  

Hi all,
Most transitions in a lifecycle will never be used, even not by an adminstrator. To save a lot (really a lot!) of mouseclicks I would like to disable certain transitions directly in the main lifecycle window like this:


lifecycleTransitions.JPG

I now have to edit each transition, go to security tab, uncheck the "no restrictions on this transition" and Enter twice.
I've got lifecycles with more than 10 states, hope somebody can do the maths for the number of mouseclicks, I don't want to know 😉

Tags (2)

Can't find what you're looking for? Ask the community or share your knowledge.

Submit Idea