<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://trycatch.be/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SharePoint Stuff : security</title><link>http://trycatch.be/blogs/tom/archive/tags/security/default.aspx</link><description>Tags: security</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP2 (Build: 31104.93)</generator><item><title>I don't like the Definition Extraction feature</title><link>http://trycatch.be/blogs/tom/archive/2008/10/03/i-don-t-like-the-definition-extraction-feature.aspx</link><pubDate>Fri, 03 Oct 2008 14:05:00 GMT</pubDate><guid isPermaLink="false">12bbda7a-b33b-4de2-8627-f5e32a6b90ff:667</guid><dc:creator>Tom Vandaele</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://trycatch.be/blogs/tom/rsscomments.aspx?PostID=667</wfw:commentRss><comments>http://trycatch.be/blogs/tom/archive/2008/10/03/i-don-t-like-the-definition-extraction-feature.aspx#comments</comments><description>&lt;p&gt;I don&amp;#39;t know if any of you have already met the Definition Extraction feature in MOSS 2007? This feature, described in &lt;a target="_blank" href="http://jopx.blogspot.com/2008/04/moss-search-feature-definition.html"&gt;this blogpost&lt;/a&gt; by my collegue Joris Poelmans, has some disadvantages.... concerning security...&lt;br /&gt;&lt;br /&gt;As we all know (or should know), the MOSS 2007 Enterprise Search is security trimmed. Meaning a user can only see items in the search if he has read permissions on that particular content. Well, the Definition Extraction feature is NOT security trimmed... and does not take count of scope exclusion rules...&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How did we found out? Well, by applying this setup:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;We have a MOSS 2007 farm configured to crawl a file share. An exclusion rule was added that this content source (the fileshare) was to be excluded from the All Sites search scope.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;After that we did a search using the All Sites scope:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&amp;gt;&amp;gt; No documents from the fileshare popped up, except that the Definition Extraction feature got some info out of a document like: &amp;quot;Trycatch is a site...&amp;quot;&lt;br /&gt;&amp;gt;&amp;gt; When we did the same search query with a user that had no permissions whatsoever on the document containing the definition, again, the Definition Extraction feature gave the same results...&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Conclusion:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The Definition Extraction:&lt;br /&gt;&amp;gt;&amp;gt; ignores security&lt;br /&gt;&amp;gt;&amp;gt; ignores search scopes exclusions&lt;br /&gt;&lt;br /&gt;&lt;b&gt;and thus, I don&amp;#39;t like it at all...&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Keep on spinning&lt;br /&gt;Tom&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;ps: One personal note to finish this post. My domainname &lt;a target="_blank" href="http://www.electrosucks.be"&gt;http://www.electrosucks.be&lt;/a&gt; is finally being used, this for my new DJ profile. Check it out if you like Electro tunes. (One mixtape online, a second one will be coming very soon)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://trycatch.be/aggbug.aspx?PostID=667" width="1" height="1"&gt;</description><category domain="http://trycatch.be/blogs/tom/archive/tags/SharePoint/default.aspx">SharePoint</category><category domain="http://trycatch.be/blogs/tom/archive/tags/Personal/default.aspx">Personal</category><category domain="http://trycatch.be/blogs/tom/archive/tags/security/default.aspx">security</category><category domain="http://trycatch.be/blogs/tom/archive/tags/feature/default.aspx">feature</category></item></channel></rss>