Item Level Security Issue with Folders within a Document Library in MOSS 2007

In MOSS 2007 you can give item level security to your files or
folders in a document library.
1) Lets say you have a normal word document library with the name
worddocuments on your wss site.
2) In this document library you have created a folder with the name
sharedfolderforguestusers.
3) You have given contribute rights to a user with the name user1 to
this folder and limited access right to the overall document library
i.e. the right which will allow the user to only see items that he has
rights to in this document library.
4) lets say we send the link to this document library to the user.
5) user navigates to the document library based on the link and he
can now only see the folder i.e. sharedfolderforguestusers that he has
contribute rights on.
6) what I found out that inside the folder when a user will try to
update any document or delete any document ,he can do that since he has
contribute rights to the folder but when he tries to upload any document
to the folder using the upload.aspx link for the document library he
gets prompted for security.I feel confidently that this has to be a
defect with MOSS 2007.the reason I am mentioning this is because if you open
the open using the link Open with windows Explorer from the Actions
menu and then copy a document to this folder with the authentication of
user1 ,you can upload a document but only when you do the same from
Upload.aspx link,you cant do the same.
I am not sure if you have ever come across this issue.I am using the
RTM edition of SharePoint that released in Novemeber 2006.

Any feedback will be useful.

Thanks

Noel

[1751 byte] By [NoelDsouza] at [2008-2-4]
# 1

I've found the same thing - give a user contributor rights to a folder in a list, but only limited access to the overall list and site (limited access permssions added by sharepoint not manually) and they can edit and delete items in the folder but can't add or upload.

Has anyone got any ideas on this?

DarenColes at 2007-9-7 > top of Msdn Tech,SharePoint Products and Technologies,SharePoint - Enterprise Content Management...
# 2
I spoke with a microsoft representative and he mentioned that this is a issue by design of the product .if they feel that there are many customers who will need this feature,then they will make changes to the product in future service packs or will release a patch.for now create document libraries and treat document libraries as folders.I hate to do this since we are doing the same thing we did in 2003.
NoelDsouza at 2007-9-7 > top of Msdn Tech,SharePoint Products and Technologies,SharePoint - Enterprise Content Management...
# 3
Add me to that list. If I give a user contributor rights to a folder in a library then they should be able to upload docs in that folder. Add items is part of the set of permissions given to a contributor. If I didn't want this user to be able to add/upload new docs then I would create a 'Contributor with No Upload' group and make them a member of that. If this is 'By Design' then it is very misleading.
DarenColes at 2007-9-7 > top of Msdn Tech,SharePoint Products and Technologies,SharePoint - Enterprise Content Management...
# 4
This is by design? Maybe that's ok for someone with Contribute rights, the problem I have is that I gave users "Read Only" access to the document library, if they open the folder with WIndows Explorer they can copy, move and delete any file in those directories. Is that by design also? If a user has "Read Only" access then they should not even get the "Open in Windows Explorer" option in the Actions drop down. Nice back door.
Rob_R at 2007-9-7 > top of Msdn Tech,SharePoint Products and Technologies,SharePoint - Enterprise Content Management...
# 5

Isn't this a HUGE problem? I was about to release the company Sharepoint site and in some last minute testing found out that a Read-Only user can add & delete documents in a Read-Only library just by clicking on the "Open with Windows Explorer" from the Action menu! No way that is "by design". Anyone know of a way to correct it? Can I remove the "Windows Explorer" item from the Actions menu?

Thanks,

Gary

GaryKearney at 2007-9-7 > top of Msdn Tech,SharePoint Products and Technologies,SharePoint - Enterprise Content Management...
# 6

Never mind! There was unexpected behavior (at least unexpected by me) when I was logged into a machine as myself but logged into a SharePoint site as a Read-Only user. If I am logged into both my machine and SharePoint site as a user that has Read-Only access to the site the Windows Explorer windows does not allow a delete. I does allow me to delete if I am logged into my machine as a SharePoint Admin user but logged into the SharePoint site as a Read-Only user. I'm cool with that.

GaryKearney at 2007-9-7 > top of Msdn Tech,SharePoint Products and Technologies,SharePoint - Enterprise Content Management...
# 7

MOSS 2007 disappointed me as there is no Out-Of-The-Box 'Item-level permissions' feature for Document Libraries, like we have for Lists.

However, Matt provided a solution at https://blogs.pointbridge.com/Blogs/morse_matt/Lists/Posts/Post.aspx?ID=8. The solution works fine at the UI level, but fails when the document library is opened as a Web Folder (WebDAV) or through Explorer View.

Will Microsoft release a fix for this most wanted feature?!!

KrishnanP at 2007-9-7 > top of Msdn Tech,SharePoint Products and Technologies,SharePoint - Enterprise Content Management...

SharePoint Products and Technologies

Site Classified