4.10. Administrative tasks¶
4.10.1. Create new user group¶
A dialog for creation of a new user group presented on Pic. 4.95.. To open this window select “Control panel” (see Pic. 4.3.) in the main menu (see item 1 in Pic. 4.2.). In control panel (see Pic. 4.4.) select “Create” option in “Groups” block.

Pic. 4.95. “Create new group” dialog.¶
In “Create new group” dialog enter full name and group name (short name), if necessary enter a group description, set group members and click “Create” button.
Note
A name for a group should contain only letters and numbers.
4.10.2. Create new user¶
A dialog for creation of a new user is presented on Pic. 4.96.. To open this window select “Control panel” (see Pic. 4.3.) in the main menu (see item 1 in Pic. 4.2.). In control panel (see Pic. 4.4.) select “Create” option in “Users” block.

Pic. 4.96. “Create new user” dialog.¶
In “Create new user” dialog enter the following information:
Full user name (e.g. John Smith)
Login – user login (e.g. smith)
Password
Group(-s) user belongs to (the list of available groups is provided below user info. If the required group is absent you need to create a new one (see Create new user group)).
Then click “Create” button.
4.10.3. Setting permissions¶
NextGIS Web is resource based so each component (layer, group, service) is a resource. NextGIS Web provides extended settings for resource access permissions.
Permissions could be set during resource creation (see. Adding resources), or using resource update (see. Layer settings). To manage permissions use a “Permissions” tab in create/update resource dialog (see. Pic. 4.97.).

Pic. 4.97. Permissions tab for resource.¶
You can grant, revoke and update permissions using this tab. You can grant different permissions to a single resource for different users and/or groups. A dialog with permission item settings is presented on fig. Pic. 4.98..

Pic. 4.98. Permission item settings dialog.¶
A dialog has the following elements:
Action
Principal
Permission
Resource
Propagate
Action defines the kind of the rule - allow or deny.
Note
By default everything is denied.
Principal - a user or a user group who is subject to a rule.
Permission - defines allowed or denied actions with the resource. There are the following available types of permissions:
All resources: All permissions
Resource: All permissions
Resource: Manage children
Resource: Change permissions
Resource: Read
Resource: Create
Resource: Update
Resource: Delete
Service: All permissions
Service: Connect
Service: Configure
Data structure: All permissions
Data structure: Write
Data structure: Read
Connection: All permissions
Connection: Write
Connection: Read
Connection: Connect
Web map: All permissions
Web map: Display
Data: All permissions
Data: Write
Data: Read
Metadata: All permissions
Metadata: Write
Metadata: Read
Resource - type of resource the rule created for. This setting is important for resource groups where it is required to grant permissions only to some types of resources. If there is no need to grant different permissions to different types of resources, select “All resources” for this setting.
Propagate checkbox defines if permission rules need to be applied to resources in sub-groups or not. Note, that setting permissions for lower level resource and propagating doesn’t cancel the need to set them for upward resources. For example, if you gave read access to a resource group that is contained by other groups, but you didn’t give appropriate permissions for higher level resources (up to root) the user will not get access to current resource group.
Permissions could be assigned to resources indirectly. For example permission “Web map: Display” could be assigned for a resource group and if a “Propagate” checkbox is checked this rule will be applied to every web map inside this resource group and inside all the subgroups.
Here is a description for available permission types.
All resources: All permissions - allows or denies any actions with resources.
Resource: All permissions - allows or denies any actions with resources excluding resource groups.
Resource: Manage children - allows or denies update of child resources settings.
Resource: Change permissions - allows or denies access permissions management for a resource.
Resource: Read - allows or denies reading of resources.
Resource: Create - allows or denies creation of resources.
Resource: Update - allows or denies modification of resources.
Resource: Delete - allows or denies deletion of resources.
Service: All permissions - allows or denies any actions with a service.
Service: Connect - allows or denies connections to a service.
Service: Configure - allows or denies modification of service setiings.
Data structure: All permissions - allows or denies any actions with data structure.
Data structure: Write - allows or denies modification of data structure.
Data structure: Read - allows or denies reading of the data structure.
Connection: All permissions - allows or denies any actions with connections.
Connection: Write - allows or denies modification of connections.
Connection: Read - allows or denies reading of connection parameters.
Connection: Connect - allows or denies usage of connection (defines if layers and data from the connection will be available for a user).
Web map: All permissions - allows or denies any actions with a web map.
Web map: Display - allows or denies display of a web map.
Data: All permissions - allows or denies any actions with data.
Data: Write - allows or denies data modification.
Data: Read - allows or denies reading of data.
Metadata: All permissions - allows or denies any actions with metadata.
Metadata: Write - allows or denies modification of metadata.
Metadata: Read - allows or denies reading of metadata.
When you assign rights to a particular resource take into account the rights of its constituent resources. For example to provide access to a WMS service you should grant the following permissions:
Service: Connect - to a connection itself.
Resource: Read - to all resources (vector and raster layers) published with WMS service.
Data structure: Read - to all resources (vector and raster layers) published with WMS service.
Data: Read - to all resources (vector and raster layers) published with WMS service.
If you have a complex system with several maps and different users who should work with these maps you can create user groups. You can assign different permissions to every group.
4.10.4. Example: Assigning permissions¶
4.10.4.1. Close a group for guests, open it for the user¶

Pic. 4.99. Settings for resourse group.¶

Pic. 4.100. Settings for root resource group.¶
You can also allow the user reading all higher resource groups as alternative.
4.10.4.2. Grant guest user resource display permission¶
Note
Guest users will be able to see administrative interface and view all folders excluding especially closed ones.

Pic. 4.101. Settings for root resource group.¶

Pic. 4.102. Settings for resourse group with maps.¶

Pic. 4.103. Settings for resource group with geodata.¶
4.10.4.3. Grant guest user web map display permission¶
Note
Guest users will be able to see only a web map and layers in a folder, other resources will be closed.

Pic. 4.104. Settings for root resource group.¶

Pic. 4.105. Settings for resourse group with maps.¶

Pic. 4.106. Settings for resource group with geodata.¶
4.10.4.4. Grant a single user permissions to a single resource group¶

Pic. 4.107. Settings for a resource group.¶

Pic. 4.108. Settings for root resource group.¶
4.10.4.5. Grant a permission to input data using a mobile application to a group of users¶
Create a separate group of users (“Contributors” in this example) and a separate resource group.

Pic. 4.109. Settings for a resource group.¶

Pic. 4.110. Settings for root resource group.¶
4.10.4.6. Disallow view of webmap to all not authendificated users, grant view to authendificated users¶
4.10.4.7. Disallow all access for guest users (without password)¶
4.10.5. Update user password¶
To update user password you can use administrative interface. To do it select “Control panel” (see Pic. 4.3.) in the main menu (see item 1 in Pic. 4.2.). In control panel (see Pic. 4.4.) select “List” option in “Users” block and click pencil icon near the user you want to update password for (see Pic. 4.111.). In opened window in “Password” field fill in a new password and click “Save” button.

Pic. 4.111. User editting window.¶
Also there is an option to change user password using command line:
Warning
Setting a password using a command line is not safe.
env/bin/nextgisweb --config config.ini change_password user password
env/bin/nextgisweb --config config.ini change_password user password
4.10.6. Customization of NextGIS Web outlook¶
You can customize the look of NextGIS Web, including logos, backgrounds, header and buttons colors etc. To do it select “Control panel” (see Pic. 4.3.) in the main menu (see item 1 in Pic. 4.2.). In control panel (see Pic. 4.4.) select “Custom CSS” in “Settings” block. In opened tab enter your own CSS rules. They will be used throughout your Web GIS on all its pages.
4.10.7. Custom CSS examples¶
4.10.7.1. Change header color¶
.header{background-color: #F44336; color: #fff;}
4.10.7.2. Remove NextGIS logo from Web map¶
.map-logo{display:none;}
4.10.7.3. Remove social networks sharing buttons¶
div.social-links {display:none;}
Remove hamburger button
span#rightMenuIcon {display:none;}
For return it back - open control panel by url http://username.nextgis.com/control-panel
4.10.7.4. Remove login button in upper right corner¶
ui.header-nav header__right {display:none;}
4.10.7.5. Remove identification window header¶
Identification window is a popup that is shown when you click on a feature on a Web map. This setting will hide it’s header and layer selector:
div.ngwPopup__content div div.dijitAlignTop,
div.ngwPopup__features span.ngwWebmapToolIdentify-controller {
display: none;
}
4.10.7.6. Advanced example¶
This example shows how to change the look of pretty much all changeable elements of NextGIS Web. You can try these examples as is or change it to your liking. You can also see them in action here.
/* Base background */
body{
background-color: #fff;
background-image:url("https://nextgis.ru/img/hypnotize_transparent.png");
}
/* Header text and background color */
.header{
background-color: #F44336;
color: #fff;
}
/* Separator color between logo and title */
.header__title-logo{
border-right: 1px solid rgba(255,255,255,.48) !important;
}
/* User info color in header */
.user-avatar__label{
background-color: #fff !important;
color: #F44336 !important;
}
.user-avatar .user-avatar__icon{
color: rgba(255,255,255,.82) !important;
}
/* Primary button */
.dijitButton--primary{
background-color: #fff !important;
color:#f44336 !important;
font-weight: bold !important;
border: 2px solid #f44336 !important;
}
.dijitButton--primary:hover{
background-color: #f44336 !important;
color: #fff !important;
}
/* Default button */
.dijitButton--default{
background-color: #fff !important;
color:#999 !important;
font-weight: bold !important;
border: 2px solid #999 !important;
}
.dijitButton--default:hover{
background-color: #999 !important;
color: #fff !important;
}
/* Tabs color */
.dijitTabContainerTop-tabs .dijitTabChecked{
border-top-color: #f44336 !important;
}
/* Left navigation panel on the map */
.navigation-menu{
background-color: #fff !important;
border-right: 1px solid rgba(0,0,0,.12) !important;
color: #000 !important;
}
4.10.8. Customize NextGIS UI Elements (White label)¶
White label is a special module that allows you to remove or replace NextGIS logos and names with your company logos and names. The module is purchased and installed separately. The module adds a new section to the Control Panel (см. Pic. 4.112.), which allows you to disable or override various interface elements mentioning NextGIS.

Pic. 4.112. ‘White label’ module in control panel¶
4.10.8.1. Company logo on Web map¶
In Control Panel, you can upload your logo in PNG format (see in:numref:logo_whitelabel_en) to display in the lower right corner of the map.

Pic. 4.113. Upload company logo file¶
If the file is not loaded, there is no logo (see in:numref:web-map_logo).

Pic. 4.114. Web map with NextGIS logo (left) and without logo (right)¶
4.10.8.2. Company URL¶
You can assigned a new hyperlink for a company website to a just added logo (см. Pic. 4.115.)

Pic. 4.115. Company URL¶
4.10.8.3. Help page¶
By default, help leads to http://nextgis.com/help/. You can set a different hyperlink (see in :numref: help_whitelabel_en) to ‘Help’ (see in Pic. 4.117.).

Pic. 4.116. Reroute a link to ‘help’¶

Pic. 4.117. ‘Help’ in the menu¶
4.10.8.4. Support URL¶
Also you can set URL for the technical support page (see in tech_support
).
This link will appear on error messages:

The default Web GIS name is specified without mentioning NextGIS.
In WMS and WFS services resources, NextGIS QGIS is replaced with **QGIS**(см. Pic. 4.118.).

Pic. 4.118. Replacing NextGIS QGIS (left) with QGIS (right) in WMS and WFS services¶
The social networks preview mentioning NextGIS is removed (см. Pic. 4.119.).

Pic. 4.119. Hiding the mention of NextGIS QGIS in web GIS links¶