Permission model validator
Skill aborroy/aiup-alfresco/.cursor/skills/permission-model-validator
A Claude Code plugin that packages Alfresco extension development as slash commands, skills, and agents
npx -y skills add aborroy/aiup-alfresco --skill permission-model-validatorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 12 stars12 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Validates custom Alfresco permission model XML for well-formedness, no collision with built-in permission group names, correct permissionSet binding, and that any dynamic authority is registered and implements DynamicAuthority. Trigger automatically after generating or editing a *permissionDefinitions.xml or a *DynamicAuthority.java file.
SKILL.md
2.8 KB, as published. Nobody here has run it
Permission Model Validator
Validate the given custom Alfresco permission model and dynamic authorities against these rules.
XML Structure Validation
- The file must be well-formed XML with root element
<permissions>. - Each
<permissionSet>must declare atypeattribute bound to a custom type or aspect ({prefix}:...), not a redefinition of a core type that removes built-in groups. - Each
<permissionGroup>and<permission>must declare aname.
Built-in Name Collision
- FLAG as ERROR any
<permissionGroup name="...">or<permission name="...">whose name collides with a built-in Alfresco permission group/permission:Read,Write,Delete,AddChildren,ReadProperties,ReadChildren,WriteProperties,Consumer,Contributor,Editor,Collaborator,Coordinator,SiteManager,SiteCollaborator,SiteContributor,SiteConsumer,FullControl,All.- Why it breaks: redefining a core group name corrupts the global permission model and can silently alter access across the whole repository.
- Fix: use a project-scoped PascalCase name; compose on top of a core group with
<includePermissionGroup permissionGroup="Read" type="cm:cmobject"/>.
Registration Validation
- The model must be registered as an extension model, not a replacement: look for a Spring
bean with
parent="permissionModelBootstrap"and amodelproperty pointing at thepermissionDefinitions.xmlunderalfresco/extension/.- WARN if no such registration bean is found in a companion
*-context.xml.
- WARN if no such registration bean is found in a companion
- The registering context must be imported from
module-context.xml.
Dynamic Authority Validation
- If a
*DynamicAuthority.javaexists:- It must
implements DynamicAuthority(fromorg.alfresco.repo.security.permissions). - It must implement
hasAuthority,getAuthority, andrequiredFor. - FLAG as ERROR
runAsSysteminsidehasAuthority(privilege escalation + per-node perf hazard). - WARN if
hasAuthoritydoes not guard withnodeService.exists(). - The bean must be registered (id
{prefix}.{name}DynamicAuthority) and added to the globaldynamicAuthoritieslist.
- It must
- WARN if a permission/group omits
requiresTypewhere it logically applies only to the bound type.
Output
Report all violations with file path, line number, rule violated, and suggested fix. If no violations found, confirm the permission model is valid.