Home →
Using LincDoc 3.1+ →
Security →
Using Laserfiche Repository-Specific Security
13.9. Using Laserfiche Repository-Specific Security
This topic describes how to configure Laserfiche-specific repository security settings, including prerequisites that must be met prior to configuring the repository's security.
Proceed to one of the following sections below for more information:
Completing Necessary Prerequisites
Prior to configuring security your Laserfiche repository, the following actions need to be completed:
- Install and configure the LincDoc connector on your Laserfiche server.
- Verify that the connector is working properly. If you are having any problems, review the troubleshooting topic.
- Verify that a Laserfiche repository is available. If not, one should be added to your list of available repositories.
- Confirm that the Generate .html launcher file? option is enabled.
- Verify that your eForm or Document Package security is properly configured. You need to have the appropriate levels set for run access roles (for example, the login role).
Note: Generally, for users to run the eForm or Document Package, the Status drop-down box on the Admin dialog box's initial tab is set to production, and the login role has been granted the run privilege on the Security tab. This configuration allows anyone with login access to actually run the eForm or Document Package, while more empowered users (such as administrators) can also edit the form.
Accessing the Laserfiche Repository Security Settings
Once you have completed the necessary prerequisites in the previous section, you need to access the Laserfiche repository's security settings.
- From the eForm or Document Package Admin dialog box, click the Repositories tab.
- If necessary, add the Laserfiche repository to the list of repositories.
- Click the config button for the Laserfiche repository.
The Configure dialog box appears.
- Click the Security Config button.
The Role Security Config dialog box appears.
This dialog box contains a list of security settings (on the left side of the dialog box) and two columns of roles: Role for owner and Role for non-owner. The only active security settings that you need to use are the following: read, read data, write, and show edit ui.
- Proceed to Specifying the Laserfiche Repository Security Settings below.
Specifying the Laserfiche Repository Security Settings
Once you access the Role Security Config dialog box, as described in the previous section, you need to adjust the repository's security settings, based on your individual repository scenario.
- If the repository is not sending a LincDoc login to Laserfiche (via the Send LincDoc login to Laserfiche? setting on the Configure dialog box):
- The owner of any documents submitted into Laserfiche is actually the user name in the handler.
- Modify the Role for non-owner settings for the following security settings: read, read data, write, and show edit ui.
To force a username/password prompt when opening a link (such as an "edit" or "sign" link, or the html launcher file inside the Laserfiche repository), assign the login role to the four security settings listed above.
To allow these same links to be opened without a valid username/password, assign the guest role to the four security settings listed above.
- The Role for owner settings have no effect, and therefore should be left blank.
- If the repository is sending a LincDoc login to Laserfiche (which requires that the LincDoc provider is an LDAP provider, and Laserfiche itself is also configured for its users/groups to be in that same LDAP directory (Active Directory)):
- The logged-in user becomes the owner, instead of the user name in the handler.
- Enable the appropriate roles in the corresponding lists:
- In most situations, the read, read data, write, and show edit ui settings should always be selected (checked) on for the owner for the login role.
- To allow non-owners access (but still requiring a valid username/password), select (check) the read, read data, write, and show edit ui settings for non-owners for the login role.
Important: If your eForm of Document Package is an open form (meaning that the guest role has the ability to run the form), and the guest role does not have the ability to write to the form, then the correct user must log in prior to running the html launcher file. Otherwise, the launcher may think a guest user is attempting to access the form and will deny access.
Once you have configured the Laserfiche security settings, save and close all open dialog boxes.