Jump to content

Recommended Posts

Posted (edited)

A user has reported a strange issue in HAP where they are able to create and upload files and folders to their userarea however any shares they have access to they are unable to write to even though the access rights are applied as they should be.

 

I have checked to make sure their user can be seen via the system by browsing to /HAP/api/ad/roles/*username* and this comes back as expected.

 

The users all can access and edit the folders on the network without any issues.

 

Is anybody able to offer any assistance - HAP has been rock solid for years.

 

Thanks

 

PS: just to add to this, it would appear if i leave the ENABLE WRITE TO box empty, i can still create new folders but the users cannot.

 

Even adding ALL and ALL to both read and write fields, this doesn't have an affect on the users.

Edited by timbo343
Posted
It would seem something is broken in HAP with NTFS and Security Permissions on folders. I'm really struggling to get my head around what is and what isn't working.
Posted

Where are they Nick?

 

I've got 3 different versions on the go for testing at the moment. It would seem that the windows folder and file security is causing issues when users try to either create new folders or delete. It would seem they need to have FULL access to the folders and users in groups aren't recognized either.

Posted (edited)

So, ive done some testing to find out what is actually happening:

 

Group: Staff

User: Test Staff (who is also a member of Group Staff)

Shared Folder: \\Shares\test

Test folder \\shares\test\123456

HAP Setting: Perform Read/Write checks = Off

Enable Read to: ALL

Enable Write to: ALL

Version of HAP - 10.5

Server OS: 2019

 

Test 1:

The shared folder \\shares\test has the following permissions:

- Windows Sharing Tab > Permissions > Group: Staff = Full

- Security Tab > Group Staff = Full

User Test Staff is unable to create / upload / delete / rename any items into \\shares\test or \\shares\test\123456

 

Test 2:

The shared folder \\shares\test has the following permissions:

- Windows Sharing Tab > Permissions > Group: Staff = Full

- Security Tab > Test Staff = Full & Group Staff = Full

User Test Staff is ABLE to create / upload / delete / rename items into \\shares\test or \\shares\test\123456. If user Test Staff creates any new items, they become the owner of those items.

 

This shows to me the HAP does not recognise users that are embedded in to groups? Is this a fault within the system? Surely we cannot be expected to add each user individually to the security tab of each folder?

Edited by timbo343
Posted (edited)

After doing a bit more testing i have found out the following:

 

 

This is the setting of group STAFF and TESTSTAFF is a member of the group STAFF - this is what we see:

HAP01.png

 

HAP001.PNG

 

 

 

If I add TESTSTAFF to the SECURITY tab then this shows:

 

HAP002.png

 

HAP002.PNG

 

 

 

@nickbro is this enough proof that AD groups does not work in Home Access Plus?

 

I have tried this on version 10, 10.5 and 10.6 and this is the case for all versions.

 

I would try version 9 if i had an install for it however i cannot seem to find version 9 on the net.

Edited by timbo343
Posted
The groups should work, if when you query the API it tells you the groups it has it's something else. I know on our setup the folder shares are everyone full control then using NTFS to restrict it. It could be because the admin user doesn't have permission to that shared it can't parse the permissions
Posted
The groups should work, if when you query the API it tells you the groups it has it's something else. I know on our setup the folder shares are everyone full control then using NTFS to restrict it. It could be because the admin user doesn't have permission to that shared it can't parse the permissions

 

I don't want EVERYONE to be set in the Sharing permissions as this is potentially a security risk.

 

Here is what i get when i query the API for TESTSTAFF:

 

HAP003.PNG

Posted
To me then it looks like HAP+ isn't able to get the share permissions because the admin user doesn't have permission to the share/folder structure. The initial query is done via the admin user then it impersonates the other user
Posted
To me then it looks like HAP+ isn't able to get the share permissions because the admin user doesn't have permission to the share/folder structure. The initial query is done via the admin user then it impersonates the other user

 

Let me do a rebuild of the server on a new server and see what that gives, it's strange it's happening on all file servers across the domain when i set up test folders.

Posted

@nickbro - it would seem after setting up a new test server the nested groups are working as expected. Looks like i'm going to have to ditch the server.

 

I also have taken some notes on how to setup up HAP 10.5 on server 2019 so i will get them typed up and posted on here so others know how to get HAP setup as it seems a lot of first time users seem to struggle.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...