Skip to content

Manage page restrictions

chmod lists or changes explicit page restrictions (view = read, edit = update) for users and groups. It is not Unix chmod: numeric modes such as 755 are rejected. There is no chown in this release.

$ chmod ./SecretPage

Listing does not require -y. The output shows users (u:ACCOUNTID) and groups (g:GROUPID) on that page only. Effective access can still inherit from ancestors.

$ find ./HR -maxdepth 1 | chmod -n read=+g:GROUPID
$ find ./HR -maxdepth 1 | chmod -y read=+g:GROUPID

Piped stdin is a list of page paths (one per line). Put only the MODE (and flags) on the chmod command; do not mix extra source paths with the pipe. At most 100 paths.

find includes the start path, so this example applies to ./HR and its direct children. Add -name or pipe through grep if you need to drop the start path.

Writes require -y / --yes. Use -n / --dry-run first.

Remove a person, or clear explicit restrictions

Section titled “Remove a person, or clear explicit restrictions”
$ chmod -y update=-u:ACCOUNTID ./SecretPage
$ chmod -y read=-u:ACCOUNTID ./SecretPage
$ chmod -n clear ./SecretPage
$ chmod -y clear ./SecretPage
$ find ./folder -name 'Draft*' | chmod -y clear

clear deletes every explicit restriction on that page. You cannot remove your own edit (update) restriction.

Other MODE tokens:

$ chmod -y read=+u:ACCOUNTID ./SecretPage
$ chmod -y update=+u:ACCOUNTID ./SecretPage
$ chmod -y update=+g:GROUPID ./SecretPage
  • PATH must be a page. Space-level permissions are out of scope.
  • No recursive -R. Walk the tree with find, then pipe into chmod.
  • Multiple MODE tokens run in order and are not atomic. If a later action fails, earlier successful actions stay applied; the output lists applied / failed / skipped.
  • Account IDs and group IDs are Confluence IDs, not display names.