# Where to create user groups?

**URL:** <https://discourse.getcockpit.com/t/where-to-create-user-groups/1182>\
**Category:** Support\
**Created:** [January 30, 2020, 9:16pm UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182 "2020-01-30T21:16:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![witsec](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/witsec/32/818_2.png) [@witsec](https://discourse.getcockpit.com/u/witsec)\
**Post date:** [January 30, 2020, 9:16pm UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182/1 "2020-01-30T21:16:52Z")

</div>

Hi, new to Cockpit. Loving it so far.

Anyway, been trying out Cockpit through Docker, to try it out. I can’t seem to find out where to create user groups and set permissions.

Am I overlooking something…?

Thanks!

---

<div class="post-metadata">

**Author:** ![aolko](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/aolko/32/458_2.png) [@aolko](https://discourse.getcockpit.com/u/aolko)\
**Post date:** [January 30, 2020, 10:09pm UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182/2 "2020-01-30T22:09:21Z")

</div>

via [https://github.com/serjoscha87/cockpit\_GROUPS](https://github.com/serjoscha87/cockpit_GROUPS) . Currently bugged, see issues.

---

<div class="post-metadata">

**Author:** ![witsec](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/witsec/32/818_2.png) [@witsec](https://discourse.getcockpit.com/u/witsec)\
**Post date:** [January 31, 2020, 6:20am UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182/3 "2020-01-31T06:20:50Z")

</div>

Oh, I didn’t even know there was a groups add-on. Will check that out.

Thanks.

---

<div class="post-metadata">

**Author:** ![raffaelj](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/raffaelj/32/331_2.png) [@raffaelj](https://discourse.getcockpit.com/u/raffaelj)\
**Post date:** [February 1, 2020, 2:59pm UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182/4 "2020-02-01T14:59:43Z")

</div>

You can create groups via config file.

example for `/config/config.php`:

[https://getcockpit.com/documentation/reference/configuration](https://getcockpit.com/documentation/reference/configuration)

```php
# define additional groups
    'groups' => [
        'author' => [
            '$admin' => false,
            '$vars' => [
                'finder.path' => '/storage/upload'
            ],
            'cockpit' => [
                'backend' => true,
                'finder' => true
            ],
            'collections' => [
                'manage' => true
            ]
        ]
    ],

```

example for `/config/config.yaml` instead:

```auto
groups:
  author:
    cockpit:
      backend: true
    collections:
      manage: true

```

---

<div class="post-metadata">

**Author:** ![tommueller](https://avatars.discourse-cdn.com/v4/letter/t/aca169/32.png) [@tommueller](https://discourse.getcockpit.com/u/tommueller)\
**Post date:** [October 6, 2020, 1:21pm UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182/5 "2020-10-06T13:21:58Z")

</div>

Could anyone provide some more detailed description of the options and possibilities these group-settings can have? An example is nice, but for me it is not clear, what

```auto
groups:
  author:
    cockpit:
      backend: true

```

actually means.

My concrete questions:

- Can I create a group, that only has access to adding items to a single collection / singleton?
- Can I specify that a group can only upload files to a specific folder?

---

<div class="post-metadata">

**Author:** ![Hackbard](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/hackbard/32/854_2.png) [@Hackbard](https://discourse.getcockpit.com/u/Hackbard)\
**Post date:** [June 25, 2021, 10:48am UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182/6 "2021-06-25T10:48:07Z")

</div>

i got the exact same question.  
Did you have any new info?

---

<div class="post-metadata">

**Author:** ![abernh](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/abernh/32/859_2.png) [@abernh](https://discourse.getcockpit.com/u/abernh)\
**Post date:** [July 5, 2021, 12:16pm UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182/7 "2021-07-05T12:16:23Z")

</div>

If you search the source for `->hasaccess` you can find all kind of checks for specific resource access checks.

The group config matches the following pattern

```auto
  groups:
    GROUP_NAME:
      RESOURCE_NAME:
        ACTION_NAME:
          BOOLEAN

```

and (most of) the `hasaccess` methods follow that pattern:

```auto
    'hasaccess' => function($resource, $action, $group = null) {

```

### Resources : Actions

This is what I was able to extract from the source code:

- cockpit: accounts, backend, unlockresources, finder, settings, rest, webhooks, info
- collections: delete, create, manage
- forms: manage, create
- singletons: delete, create, manage
- SINGLETON\_NAME: edit, form
- COLLECTION\_NAME: entries\_delete, entries\_view, entries\_create (collection\_create) , entries\_edit (collection\_edit)

### $vars

Also searching for `getGroupVar(` the following variables can be extracted

- var : default
- media.path : ‘/’
- finder.path : ‘’
- allowed\_uploads : ‘\*’
- finder.allowed\_uploads : allowed\_uploads
- assets.allowed\_uploads : allowed\_uploads
- max\_upload\_size : 0
- assets.max\_upload\_size : max\_upload\_size

---

<div class="post-metadata">

**Author:** ![abernh](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/abernh/32/859_2.png) [@abernh](https://discourse.getcockpit.com/u/abernh)\
**Post date:** [July 5, 2021, 12:26pm UTC](https://discourse.getcockpit.com/t/where-to-create-user-groups/1182/8 "2021-07-05T12:26:48Z")

</div>

> [@tommueller](#):
>
> - Can I create a group, that only has access to adding items to a single collection / singleton?
> - Can I specify that a group can only upload files to a specific folder?

> [@Hackbard](#):
>
> i got the exact same question.

Untested but this follows the pattern.

```auto
  groups:
    GROUP_NAME:
      RESOURCE_NAME:
        entries_delete: false
        entries_view: false
        entries_create: true
        entries_edit: false

```

And I’m not sure but the following group variables that might have an impact on that matter of confining a user group to a specific directory

- var : default
- media.path : ‘/’
- finder.path : ‘’
- assets.allowed\_uploads : ‘\*’
