Is the below question even possible?
User is part of AD groupA that has read/write access as well as AD groupB that is READONLY (for weblink. Have public portal)
If QF session is processed with this user (session is configured to use win auth), message "a read-only session is not authorized to make this operation" is received. If user, via win auth. logs on to LF client, user is unable to create document.
This is working as designed due to deny trumps allow I believe.
So how are we supposed to setup a user to be both able to use WebLink, and work in QF and/or LF client to store/edit documents ?