Hi there,
I wonder How to param ProjeQtOr with profile & rights in order to manage all projects in my Collectivity.
I create a Reader Profile (only reader !) and I would like to organize my projects in this way, for example with my direction:
1 - Global DSI
|- 1.1 - Application & office service
|- 1.1.1 - Application pole
| - 1.1.1.1 Project 1
| - 1.1.1.2 Project 2
|- 1.1.2 - Office pole
|- 1.1.2.1 Project 1
|- 1.1.2.1 Project 2
|- 1.2 - Network & telephony service
|- 1.2.1 - Network pole
|- 1.2.1.1 Project 1
|- 1.2.1.2 Project 2
|- 1.2.2 Telephony pole
|- 1.2.2.1 Project 1
|- 1.2.2.2 Project 2
I have a User named Albert with default profile "Project Leader".
I would like Albert see all projects under "1.1 Application & office service", so I affect him to the project "1.1 Applicatioin & office service" with reader profile : OK.
I give him also the possibility to manage project under "1.1.1 Application office" so I affect him with Project Leader profil by here: OK.
I don't want him to be able to create or modify project under "1.1.2 - Office pole" or even "1 - Global DSI" or "1.1 - Application& office service" : KO !
Currently, he is able to create project under this directories, why ? He has only a Reader profile on this directories.
Is-it a bug ?
Best regards,
Florian
“Be a yardstick of quality. Some people aren't used to an environment where excellence is expected.” ~ Steve Jobs
"...and while some may see them as the crazy ones, we see genius, because the ones who are crazy enough to think that they can change the world, are the ones who do." ~ Think Different
Good morning !
What version of ProjeQTOr are you on? Have these directories been copied? Did you create them after the ones that should work? What profile does your user have on these directories? Is this a legacy profile? Inherited from project 1.1.1? And after that, what right did you put on the project leader profile? Is he a manager? manager +? (Attention to the +) Have you checked the creation rights on this profile?
Good afternoon !
We use currently ProjeQtOr V10.2.1 (and I install the last version each time when it is released)
These projects have not been copied. I have created them before I affect Albert on it.
Like I said it, Albert has a profile "reader" on the "1.1 - Application & office service" It's a new profile that I have created. It is like Supervisor but without any modify/create right. ==> Only "reader" (not reader+)
So I think Albert should have a inherited reader profil for sub-project under "1.1 - Application & office service".
Albert is affect with a Project Leader profile only on "1.1.1 Application pole" so he can create projects under this project.
Best regards,
Florian
“Be a yardstick of quality. Some people aren't used to an environment where excellence is expected.” ~ Steve Jobs
"...and while some may see them as the crazy ones, we see genius, because the ones who are crazy enough to think that they can change the world, are the ones who do." ~ Think Different
I am sorry but no... It is impossible
I've tested everything possible and unimaginable, both on 10.1 and 10.2 with an all single reader profile i created and a wbs identical to yours... I absolutely can't create a project or sub-project if I don't have rights. I can only create on the 1.1.1 project where I am a project manager. I have no rights elsewhere...
So I don't see anything else to say than check your access rights. You must have left something behind that gives him that right.
Hi,
I have modified Albert's default's profile with "reader" and not "Project Leader". --> HE can always create project under 1.1.2 ! (but no modify it after ! )
I dont't understand why is it possible: I can create a project on 1.1 if I select this sub-project, and immediatley after, I have no rights to modify it.
it is the same if I keep empty the sub-project : my project is create to the root and Albert cannot modify this project after !
Is-it possible to prohibit the project creation if the user have no create rights on the tree structure of sub-project ?
“Be a yardstick of quality. Some people aren't used to an environment where excellence is expected.” ~ Steve Jobs
"...and while some may see them as the crazy ones, we see genius, because the ones who are crazy enough to think that they can change the world, are the ones who do." ~ Think Different
Hi
"I have modified Albert's default's profile with "reader" and not "Project Leader".
You are confusing Profiles and access mode.
The project leader is a profile that has several access modes on the different elements of projeQtOr that are set on the screen "access to data (project dependant)" or "access to data (not project dependant)".
Reader is not a profile for us. what did you set "reader" as the access mode? projects ? activities ? the tickets ? above all ... ???
HE can always create project under 1.1.2! (but no modify it after!)
So he has a creator access mode on the projects!? Have you checked ?
the same is true if I leave the sub-project empty: my project is created at the root and Albert cannot modify this project afterwards!
Is it therefore that it was created incorrectly and that the field "is sub-project of" remained empty?
The default access modes are configured in a certain way. If you change them, unfortunately, we can not guess.
Try to be clearer, Albert has a default profile, which one? He must also have a profile on the project in question, which one? On the project profile how are the access modes configured?
Hi,
I don't confusing Profiles and access mode. I said I have created a profil named "reader" (with Reader access mode everywhere only)
So "Reader" is now a profil for me. It's like a supervisor profile but without some modify rights.
I made it clear from the start that I had created a "Reader" profile in the first post 🙂
Currently, with Albert user we can create project with "sub-project" empty ! This is my issue I guess. Because if it is empty, the project is create on the root tree structure, or he is not supposed to have creation rights.
Albert default profile : My Reader Profile (because he don't be able to create project anywhere but only where he has a Project Leader profile on some project (like 1.1.1 and his sub-project))
Albert has "Project Leader" profile on 1.1.1 (and his all sub-project inherited)
So Albert should have right to create project only under 1.1.1. Not de rest.
Thank for help,
Best regards,
Florian
“Be a yardstick of quality. Some people aren't used to an environment where excellence is expected.” ~ Steve Jobs
"...and while some may see them as the crazy ones, we see genius, because the ones who are crazy enough to think that they can change the world, are the ones who do." ~ Think Different
Good Morning !
To put-it in a nutshell, I have 4 profiles in this order:
- [None rights profile] --> Order 205 --> Absolutely none rights everywhere
- [Reader profile] --> Order 210 --> Reader rights everywhere (not reader+)
- [Project Creator profile] --> Order 220 --> Reader rights everywhere but with creator rights on project.
- Project Leader --> Order 310 --> defaults ProjeQtor rights (no modify on this profil)
If I have understood correctly, the lower the order number, the more weight it has compared to the higher ones.
So, in my tree structure, I have this for Albert :
1 - Global DSI --> here [None rights profile]
|- 1.1 - Application & office service --> here [Reader profile]
|- 1.1.1 - Application pole --> here [Project Creator profile]
And when Albert create a new project --> he has Project Leader profile by default (it's his default profile on his account).
With this configuration, I identify many bugs:
1 - When Albert create a project : the default sub-project selected is where you are in the proejct tree (by example : 1.1), regardless of the rights on that part of the project tree. If we save, the project is created under this sub-project, even if we have no rights to create it here !
When you look at the list of sub-projects, you should only find sub-projects that you have the rights to create, right? However, we systematically find there the sub-project of our selector.
2 - When Albert creates a project: if he selects an empty choice in the sub-project, the project is created on the root project! Maybe because he has a default project manager profile on his account, but this is annoying. Isn't there a way to allow or disallow project creation on the root by account?
3 - Although Albert has no rights to 1 - Global, so he has no inheritance rights to 1.2, but he can still see the tree of all project names in the project selector. (But of course he does not see the projects in the project list).
Thank you,
Best regards,
Florian
“Be a yardstick of quality. Some people aren't used to an environment where excellence is expected.” ~ Steve Jobs
"...and while some may see them as the crazy ones, we see genius, because the ones who are crazy enough to think that they can change the world, are the ones who do." ~ Think Different
hi,
I did not read details of your organization, but i point out instantaneously that :
it seems that the sort order of the profiles and the corresponding rights is not the right one. Let me explain:
Logically, the smallest sort index in the list indicates the profile with all rights and therefore the largest index will be given to a profile with fewer rights
Ex for three profiles: TOP DOG number of sorting 1 Project leader 50 Guest 200 so numbers of the sort are increasing.
Sorting in reverse order, as it seems to be your case even if i dont check so much, naturally leads to strange behaviors
Hi Alain !
I have configured the profiles in this way to give more weight to the reader's profile than the project leader profile.
The aim is to have the reader's rights on a part of the project tree (not the whole project tree : the rest is with non right profile), and to give him the possibility to read and create his own project with all the rights (Project Manager profile by default) without having the right to modify the existents projects managed by others in the same sub-project (except if he has been added with the Project Manager profile of course)
By the way, thank you very much for your training 🙂 !
Best regards,
Florian
“Be a yardstick of quality. Some people aren't used to an environment where excellence is expected.” ~ Steve Jobs
"...and while some may see them as the crazy ones, we see genius, because the ones who are crazy enough to think that they can change the world, are the ones who do." ~ Think Different
I configured the profiles this way...
And it's the way to fix them that's wrong.
We have reproduced on several bases and everything is correct. The rights are well distributed and there is no bug and therefore nothing to correct on our side.
Again, review your data rights and access methods.
So that we can really look into your case and look in detail at what you have done on your base, please contact us to subscribe to support.
In addition to all replies, and to be clear, list of projects in project screen and in project selector may be different.
This is not a bug, this is an effect of your configuration.
Porject selector lists all projects for which the user can see an item, whatever it is (project, activity, action, metting, decision, ...)
So if user can see all actions on all project (for instance), list in project selector will show all projects.
Hi everybody,
Thank you !
Thanks to your precision, I finally realised that creating a profile with no rights was not the right solution.
So now I have the right rights everywhere: my user only sees what he is supposed to see everywhere: project view, planning, project selector... and he can create projects only in some sub-projects 🙂
But the bug of creating a project on a project where you only have read rights still exists.
You can try it: put rights on a read-only project, select it in the project selector, then create a new project: it will be automatically selected as a sub-project (although it will not appear in the list of sub-projects if you look at the drop-down menu) and if you save: the project is created under this project in spite of only reader access !
And sorry for creating a topic in the submit issues section, but in my opinion they were 2 different issues.
So now it's just the bug at creation.
To me we should close this topic and leave the other one open, and focus it on this bug.
What do you think about it?
With kind regards,
Florian
“Be a yardstick of quality. Some people aren't used to an environment where excellence is expected.” ~ Steve Jobs
"...and while some may see them as the crazy ones, we see genius, because the ones who are crazy enough to think that they can change the world, are the ones who do." ~ Think Different
I agree that creating a project as sub-project of a project where user has only read acces may look like access issue.
In fact is used to be blocking.
It was changed, taking into account rights to create project only, to allow to copy a project (for instance a template) before moving it.
On the other side, moving a project as sub-project of a readonly project is not allowed.