We have a Confluence deployment that, for the most part, uses AD groups and users. Recently we've been asked to provide access to our wiki to select vendor/partners. Within a particular space, we need to have our staff (all members of 'confluence_users') able to view & edit all pages. The vendor users should only be able to view specific pages (and not edit anything). The problem that I'm running into is that to pull this off, I have to have my staff set view restrictions on every page so that ourselves & the relevant vendor can view a page but no one else can.
For example,
- Page 1 - staff + vendor a
- Page 2 - staff + vendor b
- Page 3 - staff + vendor a + vendor c
- Page 4 - staff only
The permissions for page 4 are easy. The ones for pages 1, 2, and 3, however, are tricky because users forget to do things like add their own group to the view restrictions when they create pages.
We don't want to have to create AD accounts for the vendors, and would rather manage them via local accounts. As such, I've set up a local group for each vendor, and have placed their respective users into said groups. In order to simplify the space permissions, I'd like to also add the 'confluence_users' group to the vendor-specific groups. This doesn't appear possible though, since nesting doesn't seem to be an option for the internal directory.
Short of either adding our vendors to our primary domain (basically a non-starter) or creating an LDAP instance on the wiki server to manage them, is there any (relatively) simple way to accomplish this?
For reference, we're running Confluence 5.5.4 on Linux.
Thanks,